e2e/orgremove_test.go

v1.41.0
gitbay/e2e/orgremove_test.go history · blame · raw

73 lines · 2756 bytes

 1package e2e
 2
 3import (
 4	"os"
 5	"path/filepath"
 6	"strings"
 7	"testing"
 8)
 9
10// Removing a member from an org ends the access they held through its
11// teams (#196). Before the fix, team_members rows survived removal, so a
12// former member kept pushing.
13func TestOrgMemberRemovalEndsTeamAccess(t *testing.T) {
14	t.Parallel()
15	inst := startInstance(t)
16	aliceKey := inst.newKey(t, "alice")
17	bobKey := inst.newKey(t, "bob")
18	inst.admin(t, "admin", "user", "create", "alice", "--key", aliceKey+".pub")
19	inst.admin(t, "admin", "user", "create", "bob", "--key", bobKey+".pub")
20
21	for _, args := range [][]string{
22		{"org", "create", "acme"},
23		{"org", "settings", "members-role", "acme", "none"},
24		{"org", "members", "add", "acme", "bob"},
25		{"repo", "create", "acme/widget", "--private"},
26		{"org", "team", "create", "acme", "core"},
27		{"org", "team", "add", "acme", "core", "bob"},
28		{"org", "team", "grant", "acme", "core", "acme/widget", "write"},
29	} {
30		if _, errOut, code := inst.ssh(t, aliceKey, "", args...); code != 0 {
31			t.Fatalf("%v: %s", args, errOut)
32		}
33	}
34
35	// bob pushes through the team grant.
36	bobEnv := inst.gitEnv(bobKey)
37	work := t.TempDir()
38	mustGit(t, work, bobEnv, "clone", inst.sshURL("acme/widget"), "widget")
39	dir := filepath.Join(work, "widget")
40	if err := os.WriteFile(filepath.Join(dir, "README"), []byte("hi\n"), 0o644); err != nil {
41		t.Fatal(err)
42	}
43	mustGit(t, dir, bobEnv, "checkout", "-q", "-b", "main")
44	mustGit(t, dir, bobEnv, "add", "README")
45	mustGit(t, dir, bobEnv, "commit", "-q", "-m", "one")
46	mustGit(t, dir, bobEnv, "push", "-q", "origin", "main")
47
48	if _, errOut, code := inst.ssh(t, aliceKey, "", "org", "members", "remove", "acme", "bob"); code != 0 {
49		t.Fatalf("members remove: %s", errOut)
50	}
51	out, _, _ := inst.ssh(t, aliceKey, "", "org", "team", "show", "acme", "core", "--json")
52	if strings.Contains(out, `"bob"`) {
53		t.Fatalf("team still lists the removed member: %s", out)
54	}
55	if err := os.WriteFile(filepath.Join(dir, "README"), []byte("again\n"), 0o644); err != nil {
56		t.Fatal(err)
57	}
58	mustGit(t, dir, bobEnv, "commit", "-q", "-am", "two")
59	if out, code := gitRun(t, dir, bobEnv, "push", "-q", "origin", "main"); code == 0 {
60		t.Fatalf("removed member still pushes:\n%s", out)
61	}
62	if _, _, code := inst.ssh(t, bobKey, "", "repo", "show", "acme/widget"); code != 3 {
63		t.Fatalf("removed member still sees the private repo: exit %d", code)
64	}
65
66	// Re-adding to the org does not silently restore the team grant.
67	if _, errOut, code := inst.ssh(t, aliceKey, "", "org", "members", "add", "acme", "bob"); code != 0 {
68		t.Fatalf("members add: %s", errOut)
69	}
70	if _, _, code := inst.ssh(t, bobKey, "", "repo", "show", "acme/widget"); code != 3 {
71		t.Fatalf("re-added member regained the team grant: exit %d", code)
72	}
73}