Class RootWebServiceTest
java.lang.Object
org.glassfish.jersey.test.JerseyTest
ubic.gemma.rest.util.BaseJerseyTest5
ubic.gemma.rest.util.BaseJerseyIntegrationTest5
ubic.gemma.rest.RootWebServiceTest
- All Implemented Interfaces:
org.springframework.beans.factory.Aware, org.springframework.context.ApplicationContextAware
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidtest()voidEnd-to-end confirmation that an authenticated user can rotate their own password: PUT /users/me/password with the correct current password re-encodes the credential.voidvoidA new password below the minimum length is rejected with 400.voidA wrong current password must be rejected with 400 — a hijacked session can't rotate the credential without proving knowledge of the existing one.void/users/me must carry the user's Spring Security authorities so the curation-UI can gate admin surfaces onGROUP_ADMINmembership.voidMethods inherited from class BaseJerseyIntegrationTest5
setUpAuthentication, tearDownSecurityContextMethods inherited from class BaseJerseyTest5
configure, configureClient, getTestContainerFactory, setApplicationContext, setUp, tearDownMethods inherited from class org.glassfish.jersey.test.JerseyTest
client, close, closeIfNotNull, configureDeployment, disable, enable, forceDisable, forceEnable, forceSet, getAsyncTimeoutMultiplier, getBaseUri, getClient, getLastLoggedRecord, getLoggedRecords, getPort, getSslContext, getSslParameters, isEnabled, set, set, setClient, target, target
-
Constructor Details
-
RootWebServiceTest
public RootWebServiceTest()
-
-
Method Details
-
testChangeMyPasswordEndToEnd
@Test public void testChangeMyPasswordEndToEnd()End-to-end confirmation that an authenticated user can rotate their own password: PUT /users/me/password with the correct current password re-encodes the credential. This is the primary "we have a valid, secure self-service path" regression guard. -
testChangeMyPasswordWrongCurrentIs400
@Test public void testChangeMyPasswordWrongCurrentIs400()A wrong current password must be rejected with 400 — a hijacked session can't rotate the credential without proving knowledge of the existing one. -
testChangeMyPasswordTooShortIs400
@Test public void testChangeMyPasswordTooShortIs400()A new password below the minimum length is rejected with 400. -
testChangeMyPasswordMissingFieldsIs400
@Test public void testChangeMyPasswordMissingFieldsIs400() -
test
@Test public void test() -
testGetMyselfAsAdminExposesAdminAuthority
@Test public void testGetMyselfAsAdminExposesAdminAuthority()/users/me must carry the user's Spring Security authorities so the curation-UI can gate admin surfaces onGROUP_ADMINmembership. Prior to 2026-06-05 the payload had no role signal and the SPA fell back to anonymous-only gating. Base test class sets admin in @BeforeEach. -
testGetMyselfAsRegularUserExposesUserAuthorityOnly
@Test public void testGetMyselfAsRegularUserExposesUserAuthorityOnly()
-