elevated permissions should include running privileged scripts w/ burnettk

This commit is contained in:
jasquat 2023-05-19 16:21:32 -04:00
parent 1752b513bb
commit e1285539e5
No known key found for this signature in database
2 changed files with 2 additions and 0 deletions

View File

@ -523,6 +523,7 @@ class AuthorizationService:
# can also start through messages as well # can also start through messages as well
permissions_to_assign.append(PermissionToAssign(permission="create", target_uri="/messages/*")) permissions_to_assign.append(PermissionToAssign(permission="create", target_uri="/messages/*"))
permissions_to_assign.append(PermissionToAssign(permission="create", target_uri="/can-run-privileged-script/*"))
permissions_to_assign.append(PermissionToAssign(permission="create", target_uri="/send-event/*")) permissions_to_assign.append(PermissionToAssign(permission="create", target_uri="/send-event/*"))
permissions_to_assign.append(PermissionToAssign(permission="create", target_uri="/task-complete/*")) permissions_to_assign.append(PermissionToAssign(permission="create", target_uri="/task-complete/*"))
permissions_to_assign.append(PermissionToAssign(permission="read", target_uri="/users/search")) permissions_to_assign.append(PermissionToAssign(permission="read", target_uri="/users/search"))

View File

@ -309,6 +309,7 @@ class TestAuthorizationService(BaseTest):
with_db_and_bpmn_file_cleanup: None, with_db_and_bpmn_file_cleanup: None,
) -> None: ) -> None:
expected_permissions = [ expected_permissions = [
("/can-run-privileged-script/*", "create"),
("/messages/*", "create"), ("/messages/*", "create"),
("/process-instances-reset/*", "create"), ("/process-instances-reset/*", "create"),
("/process-instances-resume/*", "create"), ("/process-instances-resume/*", "create"),