|
2 | 2 |
|
3 | 3 | from ddt import data, ddt, unpack |
4 | 4 |
|
5 | | -from openedx_authz.api.data import ContentLibraryData, RoleAssignmentData, RoleData, UserData |
| 5 | +from openedx_authz.api.data import ( |
| 6 | + ContentLibraryData, |
| 7 | + CourseOverviewData, |
| 8 | + OrgCourseOverviewGlobData, |
| 9 | + RoleAssignmentData, |
| 10 | + RoleData, |
| 11 | + UserData, |
| 12 | +) |
6 | 13 | from openedx_authz.api.users import ( |
7 | 14 | assign_role_to_user_in_scope, |
8 | 15 | batch_assign_role_to_users_in_scope, |
9 | 16 | batch_unassign_role_from_users, |
10 | 17 | get_all_user_role_assignments_in_scope, |
| 18 | + get_scopes_for_user_and_permission, |
11 | 19 | get_user_role_assignments, |
12 | 20 | get_user_role_assignments_for_role_in_scope, |
13 | 21 | get_user_role_assignments_in_scope, |
@@ -424,6 +432,79 @@ def test_unassign_all_roles_impacts_permissions(self): |
424 | 432 | ) |
425 | 433 | self.assertFalse(has_permission_after) |
426 | 434 |
|
| 435 | + @data( |
| 436 | + # No filter → should return all scopes where user has permission |
| 437 | + ( |
| 438 | + "alice", |
| 439 | + permissions.DELETE_LIBRARY.identifier, |
| 440 | + None, |
| 441 | + {"lib:Org1:math_101"}, |
| 442 | + ), |
| 443 | + # Filter only ContentLibraryData → should include library scopes only |
| 444 | + ( |
| 445 | + "alice", |
| 446 | + permissions.DELETE_LIBRARY.identifier, |
| 447 | + (ContentLibraryData,), |
| 448 | + {"lib:Org1:math_101"}, |
| 449 | + ), |
| 450 | + # Filter excludes the scope type → should return empty |
| 451 | + ( |
| 452 | + "alice", |
| 453 | + permissions.COURSES_VIEW_COURSE.identifier, |
| 454 | + (CourseOverviewData,), |
| 455 | + set(), |
| 456 | + ), |
| 457 | + # Multiple scopes (same type) |
| 458 | + ( |
| 459 | + "eve", |
| 460 | + permissions.MANAGE_LIBRARY_TEAM.identifier, |
| 461 | + (ContentLibraryData,), |
| 462 | + {"lib:Org2:physics_401"}, |
| 463 | + ), |
| 464 | + # Multiple scopes (different types) - filter to only one type |
| 465 | + ( |
| 466 | + "eduardo", |
| 467 | + permissions.COURSES_VIEW_COURSE.identifier, |
| 468 | + (CourseOverviewData,), |
| 469 | + {"course-v1:TestOrg+TestCourse+2024_T1"}, |
| 470 | + ), |
| 471 | + ( |
| 472 | + "eduardo", |
| 473 | + permissions.COURSES_VIEW_COURSE.identifier, |
| 474 | + None, |
| 475 | + {"course-v1:TestOrg+TestCourse+2024_T1", "course-v1:TestOrg+*"}, |
| 476 | + ), |
| 477 | + ( |
| 478 | + "eduardo", |
| 479 | + permissions.COURSES_VIEW_COURSE.identifier, |
| 480 | + (OrgCourseOverviewGlobData,), |
| 481 | + {"course-v1:TestOrg+*"}, |
| 482 | + ), |
| 483 | + ) |
| 484 | + @unpack |
| 485 | + def test_get_scopes_for_user_and_permission_with_filter( |
| 486 | + self, |
| 487 | + username, |
| 488 | + action, |
| 489 | + scope_filter, |
| 490 | + expected_scopes, |
| 491 | + ): |
| 492 | + """Test filtering scopes by scope_classes_filter. |
| 493 | +
|
| 494 | + Expected result: |
| 495 | + - When no filter is provided, all scopes are returned |
| 496 | + - When a filter is provided, only matching scope types are returned |
| 497 | + - When filter excludes scope types, result is empty |
| 498 | + """ |
| 499 | + scopes = get_scopes_for_user_and_permission( |
| 500 | + user_external_key=username, |
| 501 | + action_external_key=action, |
| 502 | + scope_classes_filter=scope_filter, |
| 503 | + ) |
| 504 | + |
| 505 | + scope_keys = {scope.external_key for scope in scopes} |
| 506 | + self.assertEqual(scope_keys, expected_scopes) |
| 507 | + |
427 | 508 |
|
428 | 509 | @ddt |
429 | 510 | class TestUserPermissions(UserAssignmentsSetupMixin): |
|
0 commit comments