TestAddUserToGroupHandler tests the addUserToGroupHandler function
(t *testing.T)
| 554 | |
| 555 | // TestAddUserToGroupHandler tests the addUserToGroupHandler function |
| 556 | func TestAddUserToGroupHandler(t *testing.T) { |
| 557 | ovl, cleanup := setupTestOverlord(t) |
| 558 | defer cleanup() |
| 559 | |
| 560 | // Get the router with proper configuration |
| 561 | router := ovl.registerRoutes() |
| 562 | |
| 563 | // Login to get a JWT token |
| 564 | adminJWTToken, err := loginAs(router, adminUsername) |
| 565 | if err != nil { |
| 566 | t.Fatalf("Failed to login: %v", err) |
| 567 | } |
| 568 | |
| 569 | // Prepare request body |
| 570 | addRequest := struct { |
| 571 | Username string `json:"username"` |
| 572 | }{ |
| 573 | Username: "testuser", |
| 574 | } |
| 575 | |
| 576 | body, _ := json.Marshal(addRequest) |
| 577 | |
| 578 | // Test with admin user |
| 579 | req := createAuthRequest(adminJWTToken, "POST", "/api/groups/testgroup/users", body) |
| 580 | rr := httptest.NewRecorder() |
| 581 | |
| 582 | router.ServeHTTP(rr, req) |
| 583 | |
| 584 | // Check response |
| 585 | if rr.Code != http.StatusOK { |
| 586 | t.Errorf("Expected status code 200, got %d", rr.Code) |
| 587 | } |
| 588 | |
| 589 | // Verify user was added to the group |
| 590 | users, _ := ovl.dbManager.GetGroupUsers("testgroup") |
| 591 | found := false |
| 592 | for _, user := range users { |
| 593 | if user.Username == "testuser" { |
| 594 | found = true |
| 595 | break |
| 596 | } |
| 597 | } |
| 598 | if !found { |
| 599 | t.Errorf("User 'testuser' should be in group 'testgroup'") |
| 600 | } |
| 601 | |
| 602 | // Test with non-admin user (should be forbidden by middleware) |
| 603 | userJWTToken, err := loginAs(router, testUsername) |
| 604 | if err != nil { |
| 605 | t.Fatalf("Failed to login: %v", err) |
| 606 | } |
| 607 | |
| 608 | req = createAuthRequest(userJWTToken, "POST", "/api/groups/testgroup/users", body) |
| 609 | rr = httptest.NewRecorder() |
| 610 | |
| 611 | router.ServeHTTP(rr, req) |
| 612 | |
| 613 | // Check response - should be forbidden by middleware |
nothing calls this directly
no test coverage detected