|
171 | 171 |
|
172 | 172 | $response->assertStatus(404); |
173 | 173 | }); |
| 174 | + |
| 175 | + test('read token does not include provider token value by UUID', function () { |
| 176 | + $token = CloudProviderToken::create([ |
| 177 | + 'team_id' => $this->team->id, |
| 178 | + 'name' => 'Hidden Token Detail', |
| 179 | + 'provider' => 'hetzner', |
| 180 | + 'token' => 'hidden-cloud-provider-token-detail', |
| 181 | + ]); |
| 182 | + |
| 183 | + $readToken = $this->user->createToken('read-token', ['read'])->plainTextToken; |
| 184 | + |
| 185 | + $response = $this->withHeaders([ |
| 186 | + 'Authorization' => 'Bearer '.$readToken, |
| 187 | + 'Content-Type' => 'application/json', |
| 188 | + ])->getJson("/api/v1/cloud-tokens/{$token->uuid}"); |
| 189 | + |
| 190 | + $response->assertSuccessful(); |
| 191 | + expect($response->getContent())->not->toContain('"token":'); |
| 192 | + }); |
| 193 | + |
| 194 | + test('read sensitive token includes provider token value by UUID', function () { |
| 195 | + $token = CloudProviderToken::create([ |
| 196 | + 'team_id' => $this->team->id, |
| 197 | + 'name' => 'Visible Token Detail', |
| 198 | + 'provider' => 'hetzner', |
| 199 | + 'token' => 'visible-cloud-provider-token-detail', |
| 200 | + ]); |
| 201 | + |
| 202 | + $readSensitiveToken = $this->user->createToken('read-sensitive-token', ['read', 'read:sensitive'])->plainTextToken; |
| 203 | + |
| 204 | + $response = $this->withHeaders([ |
| 205 | + 'Authorization' => 'Bearer '.$readSensitiveToken, |
| 206 | + 'Content-Type' => 'application/json', |
| 207 | + ])->getJson("/api/v1/cloud-tokens/{$token->uuid}"); |
| 208 | + |
| 209 | + $response->assertSuccessful(); |
| 210 | + $response->assertJsonFragment(['token' => 'visible-cloud-provider-token-detail']); |
| 211 | + }); |
174 | 212 | }); |
175 | 213 |
|
176 | 214 | describe('POST /api/v1/cloud-tokens', function () { |
|
345 | 383 | 'Content-Type' => 'application/json', |
346 | 384 | ])->patchJson("/api/v1/cloud-tokens/{$token->uuid}", []); |
347 | 385 |
|
348 | | - $response->assertStatus(422); |
349 | | - $response->assertJsonValidationErrors(['name']); |
| 386 | + $response->assertStatus(400); |
| 387 | + $response->assertJson([ |
| 388 | + 'message' => 'Invalid request.', |
| 389 | + 'error' => 'Invalid JSON.', |
| 390 | + ]); |
350 | 391 | }); |
351 | 392 |
|
352 | 393 | test('cannot update token from another team', function () { |
|
0 commit comments