Full-access tokens manage users, passwords and tokens

This commit is contained in:
Daniel Redetzke
2026-10-04 20:37:46 +03:00
parent ac2ce23613
commit 04a1d1ab85
3 changed files with 38 additions and 14 deletions
+6
View File
@@ -328,6 +328,12 @@ func TestAPI(t *testing.T) {
bearer("GET", "/tokens", 403)
bearer("GET", "/peers/"+id+"/setup", 403) // the link would set up a device
// A full-access token manages users and tokens, but not backups.
secret = call("POST", "/tokens", map[string]string{"name": "full", "scope": "rw"}, 201)["token"].(string)
bearer("GET", "/users", 200)
bearer("GET", "/tokens", 200)
bearer("GET", "/backup", 403)
call("DELETE", "/peers/"+id, nil, 200)
if len(store.Get().Peers) != 0 {
t.Fatal("peer not deleted")