Skip to content

Add authorization tests for admin functions - #496

Closed
SrvFernandes wants to merge 1 commit into
ChainLearnOfficial:mainfrom
SrvFernandes:feat/auth-tests-admin-functions-munv2y3s
Closed

SrvFernandes wants to merge 1 commit into
ChainLearnOfficial:mainfrom
SrvFernandes:feat/auth-tests-admin-functions-munv2y3s

Conversation

@SrvFernandes

Copy link
Copy Markdown

Closes #495

Summary

Adds negative authorization tests for all admin functions in progress-tracker and credential-nft contracts that were previously untested.

Changes

  • Add tests/integration/progress_tracker_auth_tests.rs with non-admin auth tests for:
    • create_course
    • archive_course
    • set_course_content_hash
    • set_course_difficulty
    • set_course_tags
    • update_course_version
    • set_prerequisites
    • emergency_pause
  • Add tests/integration/credential_auth_tests.rs with non-admin auth tests for:
    • mint_credential
    • renew_credential
    • set_credential_display
    • transfer_admin
  • Each test verifies authorization failure without using mock_all_auths()

Testing

All new tests pass in CI, verifying that non-admin callers are properly rejected with authorization errors.

Bounty payout address (Base / EVM): 0x96eE7904BdCd8a82c71B4FFc3362C96b1Aae03e0
Bounty payout address (Stellar / Soroban): GCTRCN2H6EVVRQH4MKHVWMTY2SPC4ZTRHQZQOSKF5PXFRA4TNDGGF4VL

Signed-off-by: Sérgio <sveronezfernandes@gmail.com>
@DeFiVC DeFiVC closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

No authorization tests for progress-tracker admin functions (create_course, archive_course, set_prerequisites, etc.)

2 participants