Unverified Commit 85b8a92a authored by Minseong Choi's avatar Minseong Choi 💬
Browse files

test(api): pin restore's owner gate against a superseded former owner

handleRestoreBackup's owner-or-admin gate was not pinned by any test: the former-owner gate backstopped every non-owner case the suite exercised, so a broken owner gate would not redden. Add the mirror of the former-owner test — a released former owner (still the backup's former_owner, no longer the current owner) must get 403 — the sole subtest that fails when the owner gate is disabled. Found by the round-2 backup/restore mutation audit; production code unchanged.
parent c67a4d3f
Loading
Loading
Loading
Loading
+20 −0
Changes for internal/api/handlers_backups_test.go: 20 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -190,6 +190,26 @@ func TestRestoreBackup(t *testing.T) {
		}
	})

	t.Run("former owner after release -> 403, no restore", func(t *testing.T) {
		// Mirror of the guard above, pinning the owner gate rather than the former-owner
		// gate (handler comment: "must re-claim first"). owner1 took this backup, then
		// released survival to "newowner". owner1 is still the backup's former_owner — so
		// the former-owner gate would wave them through — but is no longer the current
		// owner. Only the owner gate stops them; without it a superseded owner could roll
		// a live server back onto their old world. (Disable that gate and this is the one
		// subtest that reddens — the former-owner gate does not backstop this case.)
		api, repo, _, restorer := mk()
		repo.byName["survival"].OwnerID = "newowner"
		api.External = staticExternal{p: owner} // owner1: former_owner, not current owner
		w := do(api.ExternalHandler(), "POST", path, "", nil)
		if w.Code != http.StatusForbidden {
			t.Fatalf("code = %d, want 403 (owner gate: former owner is no longer the current owner)", w.Code)
		}
		if restorer.calls != 0 {
			t.Fatal("a released former owner must not restore onto the current owner's server")
		}
	})

	t.Run("unknown server -> 404", func(t *testing.T) {
		api, _, _, _ := mk()
		api.External = staticExternal{p: owner}