test: pin the mint route against the account's own token

`/auth/create-access-token` carries only `requireAuth`, so it never showed up
in the sweep over `requireUserActor` routes — the refusal lives in
`AuthService.createAccessToken`, which turns away any access-token actor
outright. That holds today, and a leaked full-access token minting itself a
sibling that survives revoking the original is exactly what the token swap is
meant to rule out, so it is worth a test rather than a reading.
This commit is contained in:
Juan Castro committed 2026-10-02 15:33:58 -04:00
1 parent 751f9316ae
commit 57f4b6107e
1 file changed
+2
@@ -101,6 +101,8 @@ describe('full-access token route admissions', () => {
['POST', '/auth/get-user-app-token', { origin: 'https://probe.test' }],
['POST', '/auth/grant-user-app', { app_uid: 'app-x', permission: 'p' }],
['POST', '/open_item', { path: '~/' }],
// Only `requireAuth` on the route; the refusal is AuthService's.
['POST', '/auth/create-access-token', { permissions: ['fs:read'] }],
];
it.each(REFUSED)(