fix(09): WR-11 reject ambiguous admin logins and cross-field login or email collisions

This commit is contained in:
Jakub Zych
2026-10-01 21:17:50 +02:00
parent eb8c727790
commit 331351a73c
5 changed files with 70 additions and 8 deletions

View File

@@ -553,3 +553,26 @@ func itoa(id uint) string {
func adminAPI(rel string) string {
return cabana.DefaultAdminPrefix + "/api/v1" + rel
}
// TestLoginAmbiguousIdentifier pins WR-11: an identifier that is one admin's
// login and another's email resolves to nobody (a plain 401), so neither admin
// is silently locked out by the other; each can still sign in by the
// unambiguous field.
func TestLoginAmbiguousIdentifier(t *testing.T) {
gdb := adminGorm(t)
h := adminHandler(t, gdb, nil)
insertAdmin(t, gdb, "ambig@amb.test", "owner-a@amb.test", "password-of-a", true, false)
insertAdmin(t, gdb, "owner-b", "ambig@amb.test", "password-of-b", true, false)
for _, password := range []string{"password-of-a", "password-of-b"} {
rec := postJSON(t, h, adminAPI("/auth/login"), map[string]string{"login": "ambig@amb.test", "password": password})
if rec.Code != http.StatusUnauthorized {
t.Fatalf("ambiguous identifier with %q = %d %s, want 401", password, rec.Code, rec.Body.String())
}
}
if rec := postJSON(t, h, adminAPI("/auth/login"), map[string]string{"login": "owner-a@amb.test", "password": "password-of-a"}); rec.Code != http.StatusOK {
t.Fatalf("admin A by email = %d %s", rec.Code, rec.Body.String())
}
if rec := postJSON(t, h, adminAPI("/auth/login"), map[string]string{"login": "owner-b", "password": "password-of-b"}); rec.Code != http.StatusOK {
t.Fatalf("admin B by login = %d %s", rec.Code, rec.Body.String())
}
}