Skip to content

Commit 9261ddf

Browse files
test: add test for impersonation with inaccessible connection
Verifies that when an admin uses 'View as' to impersonate a user who lacks access to a connection, the backend correctly denies access to that connection. This is the backend counterpart to the frontend fix - both layers must refuse access to ensure the security model holds. Co-authored-by: Venkat SF <venkatesh.sakamuri@stayflexi.com>
1 parent f47af6c commit 9261ddf

1 file changed

Lines changed: 38 additions & 0 deletions

File tree

‎backend/src/test/java/com/dbaagent/service/security/AccessControlServiceTest.java‎

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -359,6 +359,44 @@ void impersonatingDbaAllowsMutateSql() {
359359
assertFalse(accessControlService.isCurrentUserAdmin());
360360
}
361361

362+
/**
363+
* An admin viewing as a user who lacks access to a connection sees access denied.
364+
*
365+
* <p>This is the backend counterpart to the frontend fix: when the admin selects a
366+
* connection, then uses "View as" to switch to a user without access to that connection,
367+
* the UI should not be able to make API calls against the connection. The UI fix clears
368+
* the stale connectionId; this test ensures the backend also correctly denies access.
369+
*/
370+
@Test
371+
void impersonatingUserWithoutAccessDeniesConnection() {
372+
com.dbaagent.model.User impersonator = new com.dbaagent.model.User();
373+
impersonator.setId(1L);
374+
impersonator.setUsername("admin");
375+
impersonator.setRole("ADMIN");
376+
com.dbaagent.model.User target = new com.dbaagent.model.User();
377+
target.setId(2L);
378+
target.setUsername("mart-viewer");
379+
target.setRole("DEVELOPER");
380+
com.dbaagent.security.ImpersonationContext.enter(
381+
new com.dbaagent.security.ImpersonationContext.State(impersonator, target)
382+
);
383+
SecurityContextHolder.getContext().setAuthentication(
384+
new UsernamePasswordAuthenticationToken("mart-viewer", null, List.of())
385+
);
386+
387+
// The target user has no grant on conn-1
388+
when(connectionAccessService.resolveAccess("conn-1", "mart-viewer", false))
389+
.thenReturn(resolved("conn-1", EffectiveConnectionAccess.NONE, null));
390+
391+
// Verify: admin bypass is disabled during impersonation
392+
assertFalse(accessControlService.isCurrentUserAdmin());
393+
394+
// Verify: attempting to access the connection should throw 403
395+
ResponseStatusException ex = assertThrows(ResponseStatusException.class,
396+
() -> accessControlService.assertCanUseChatEditor("conn-1"));
397+
assertEquals(403, ex.getStatusCode().value());
398+
}
399+
362400
private ConnectionAccessService.ResolvedConnectionAccess resolved(
363401
String connectionId,
364402
EffectiveConnectionAccess effectiveAccess,

0 commit comments

Comments
 (0)