3
0
mirror of https://github.com/snipe/snipe-it.git synced 2026-08-18 11:15:42 +00:00
Files
snipe-it/tests/Feature/Assets/AssetBarcodeAuthorizationTest.php
2026-08-07 17:43:15 +01:00

36 lines
1.1 KiB
PHP

<?php
namespace Tests\Feature\Assets;
use App\Models\Asset;
use App\Models\User;
use Tests\TestCase;
class AssetBarcodeAuthorizationTest extends TestCase
{
public function test_barcode_route_requires_asset_view_permission()
{
// Reg-test for the legacy barcode endpoint's missing authz:
// before the fix, any authenticated user could pull the barcode
// PNG for any asset regardless of permissions or company scope,
// enumerating protected asset tags via the rendered barcode.
$asset = Asset::factory()->create();
$this->actingAs(User::factory()->create())
->get(route('barcode/hardware', $asset->id))
->assertForbidden();
}
public function test_barcode_route_allows_asset_viewer()
{
// Baseline: a user with assets.view still succeeds. Guards
// against the authz gate over-reaching and breaking legitimate
// access.
$asset = Asset::factory()->create();
$this->actingAs(User::factory()->viewAssets()->create())
->get(route('barcode/hardware', $asset->id))
->assertOk();
}
}