Skip to content

test(e2e): cross-org resource isolation (POL-257 cases 257-1c/3/3a/3b/4) - #11

Closed
G4614 wants to merge 1 commit into
mainfrom
fix/pol-334-cross-org-e2e-tests
Closed

G4614 wants to merge 1 commit into
mainfrom
fix/pol-334-cross-org-e2e-tests

Conversation

@G4614

@G4614 G4614 commented Sep 1, 2026

Copy link
Copy Markdown
Owner

Adds apps/e2e/cases/test_pol257_cross_org_isolation.py — automated e2e
coverage for the launchgate's cross-org isolation requirements.

Tests added

Test POL-257 case Assertion
test_257_1c_cross_org_key_rejected_for_other_org_namespace 257-1c org-B key in org-A namespace → 401
test_257_3_cross_org_get_box_returns_404 257-3 GET org-A box with org-B key → 404 (not 403)
test_257_3a_cross_org_delete_box_returns_404 257-3a DELETE org-A box with org-B key → 404; box survives
test_257_3b_cross_org_exec_returns_404 257-3b POST .../exec on org-A box with org-B key → 404
test_257_4_cross_org_network_isolation 257-4 org-B box cannot reach org-A box internally

CI behaviour

All tests are skipped when BOXLITE_E2E_CROSS_ORG_API_KEY is unset, so
existing CI pipelines and local runs without a second org are unaffected.
Set BOXLITE_E2E_CROSS_ORG_API_KEY (and optionally
BOXLITE_E2E_CROSS_ORG_PREFIX) in the CI secret store to enable.

Fixes POL-334.

🤖 Generated with Claude Code

Adds automated e2e tests covering the launchgate's cross-org isolation
requirements.  The tests require credentials for a second organisation
(BOXLITE_E2E_CROSS_ORG_API_KEY) and skip gracefully when absent, so CI
and local runs without a second org are unaffected.

Tests added:
  test_257_1c_cross_org_key_rejected_for_other_org_namespace
    – org-B key in org-A namespace → 401
  test_257_3_cross_org_get_box_returns_404
    – GET org-A's box with org-B key → 404 (not 403, not 401)
  test_257_3a_cross_org_delete_box_returns_404
    – DELETE org-A's box with org-B key → 404; box survives in org-A
  test_257_3b_cross_org_exec_returns_404
    – POST .../exec on org-A's box with org-B key → 404
  test_257_4_cross_org_network_isolation
    – org-B box cannot reach org-A box on internal addresses

Fixes POL-334.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@G4614 G4614 closed this Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant