Skip to content

test: add authorization boundary tests for notifications - #900

Merged
Abd-Standard merged 1 commit into
Core-Foundry:mainfrom
pelumixxril:fix/issue-789-add-authorization-boundary-tests
Oct 2, 2026
Merged

Abd-Standard merged 1 commit into
Core-Foundry:mainfrom
pelumixxril:fix/issue-789-add-authorization-boundary-tests

Conversation

@pelumixxril

Copy link
Copy Markdown
Contributor

Overview

This PR adds authorization boundary tests that verify authenticated users cannot access or modify notification resources outside their permitted scope. It covers cross-user access rejection, resource ownership validation, and both read and write operations.

Related Issue

Changes

🔒 Authorization Boundary Tests

  • [MODIFY] contract/contracts/hello-world/src/tests/access_control_test.rs

    • Added cases asserting cross-user access to notification resources is rejected.
    • Added cases validating resource ownership checks on read and write paths.
  • [MODIFY] contract/contracts/hello-world/src/tests/notification_test.rs

    • Added notification-scoped tests covering read and write operations against out-of-scope users.
  • [MODIFY] contract/contracts/hello-world/src/tests/access_log_test.rs

    • Added assertions that unauthorized access attempts are recorded/reflected in the access log.
  • [MODIFY] contract/contracts/hello-world/src/tests/test_utils.rs

    • Added shared helpers for setting up multiple authenticated users and asserting rejection of out-of-scope access.

Verification Results

cargo test -p hello-world
✅ access_control_test, notification_test, access_log_test passed
Acceptance Criteria Status
Cross-user access is rejected ✅ Tests assert rejection for out-of-scope users
Resource ownership is validated ✅ Ownership checks exercised on read and write paths
Tests cover both read and write operations ✅ Read and write cases added across notification tests

Closes #789

@drips-wave

drips-wave Bot commented Sep 30, 2026

Copy link
Copy Markdown

@pelumixxril Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Abd-Standard
Abd-Standard merged commit 6d24241 into Core-Foundry:main Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add Authorization Boundary Tests

2 participants