test(auth_v2): cover deep SCIM path under keyMatch and drop stale comment

Add a platform_admin POST /scim/v2/Groups assertion alongside the existing
/scim/v2/Users DELETE so the multi-segment grant is pinned on a second deep
path, and correct the stale keyMatch2 comment to keyMatch.
This commit is contained in:
Yassin Kortam 2026-06-11 09:52:18 -07:00
parent 2fad79b4fe
commit 343909d632

View file

@ -87,10 +87,13 @@ def test_has_role_false_without_roles(engine):
def test_platform_admin_enforces_any_object_and_action(engine):
assert engine.enforce(_principal(roles=[Role.PLATFORM_ADMIN]), "/anything", "POST")
# keyMatch2: /scim/v2/* covers /scim/v2/Users
# keyMatch: "/*" / "/scim/v2/*" span path separators, so deep paths are covered
assert engine.enforce(
_principal(roles=[Role.PLATFORM_ADMIN]), "/scim/v2/Users", "DELETE"
)
assert engine.enforce(
_principal(roles=[Role.PLATFORM_ADMIN]), "/scim/v2/Groups", "POST"
)
def test_platform_viewer_is_read_only(engine):