test/docs(ownership): §7 apply_ownership journey + design/CLAUDE updates
End-to-end coverage of the M1 ownership claim through the real CLI + server: claim-on-first-apply + owner column, idempotent re-apply by the owner, a second project refused (409, naming the owner), --takeover by an admin, app-inheritance from the nearest claimed ancestor (owning project ok; foreign or absent project refused), and the capability gate — a member with only an editor GROUP role can reconcile but is refused --takeover (needs group-admin), with ownership unchanged after the failed takeover. - tests/apply_ownership.rs (registered in cli.rs); a grant_group_membership helper in tests/common/member.rs (group-level, mirroring the app one). - design doc §7 gains an M1-shipped status note; CLAUDE.md records §7 M1 and re-points 'Next' at M2 (attach ceiling) + M3 (blast-radius / pic projects ls). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -78,6 +78,29 @@ pub fn grant_membership(fx: &Fixture, app_slug: &str, user_id: &str, role: &str)
|
||||
);
|
||||
}
|
||||
|
||||
/// `POST /api/v1/admin/groups/{slug}/members` — grant `role` to `user_id` on a
|
||||
/// GROUP (hierarchy-aware). §7 takeover tests use this to give a member an
|
||||
/// `editor` group role — enough to reconcile a group node, but NOT to
|
||||
/// `--takeover` (which needs `GroupAdmin`).
|
||||
pub fn grant_group_membership(fx: &Fixture, group_slug: &str, user_id: &str, role: &str) {
|
||||
let client = reqwest::blocking::Client::new();
|
||||
let resp = client
|
||||
.post(format!(
|
||||
"{}/api/v1/admin/groups/{}/members",
|
||||
fx.url, group_slug
|
||||
))
|
||||
.bearer_auth(&fx.admin_token)
|
||||
.json(&json!({ "user_id": user_id, "role": role }))
|
||||
.send()
|
||||
.expect("grant group membership");
|
||||
assert!(
|
||||
resp.status().is_success(),
|
||||
"grant group membership failed: {} {}",
|
||||
resp.status(),
|
||||
resp.text().unwrap_or_default(),
|
||||
);
|
||||
}
|
||||
|
||||
/// `PATCH /api/v1/admin/apps/{slug}/members/{user_id}` — promote/demote.
|
||||
pub fn update_membership(fx: &Fixture, app_slug: &str, user_id: &str, role: &str) {
|
||||
let client = reqwest::blocking::Client::new();
|
||||
|
||||
Reference in New Issue
Block a user