mirror of
https://github.com/HeyPuter/puter.git
synced 2026-10-10 22:01:40 +00:00
test: pin the mint route against the account's own token
`/auth/create-access-token` carries only `requireAuth`, so it never showed up in the sweep over `requireUserActor` routes — the refusal lives in `AuthService.createAccessToken`, which turns away any access-token actor outright. That holds today, and a leaked full-access token minting itself a sibling that survives revoking the original is exactly what the token swap is meant to rule out, so it is worth a test rather than a reading.
This commit is contained in:
1 parent
751f9316ae
commit
57f4b6107e
1 file changed
+2
@@ -101,6 +101,8 @@ describe('full-access token route admissions', () => {
|
||||
['POST', '/auth/get-user-app-token', { origin: 'https://probe.test' }],
|
||||
['POST', '/auth/grant-user-app', { app_uid: 'app-x', permission: 'p' }],
|
||||
['POST', '/open_item', { path: '~/' }],
|
||||
// Only `requireAuth` on the route; the refusal is AuthService's.
|
||||
['POST', '/auth/create-access-token', { permissions: ['fs:read'] }],
|
||||
];
|
||||
|
||||
it.each(REFUSED)(
|
||||
|
||||
Reference in new issue
Block a user