Skip to content

[Maintainence]Added security test#596

Open
sumukhswamy wants to merge 9 commits intoopensearch-project:mainfrom
sumukhswamy:security-test
Open

[Maintainence]Added security test#596
sumukhswamy wants to merge 9 commits intoopensearch-project:mainfrom
sumukhswamy:security-test

Conversation

@sumukhswamy
Copy link
Copy Markdown
Collaborator

Description

This Cypress test verifies that an internal user with the reports_full_access role can be created, assigned the correct permissions, and mapped to the role in a security-enabled OpenSearch Dashboards environment. The test is especially relevant due to a regression introduced in OpenSearch 2.19, where a refactor of the PrivilegesEvaluator class in the security plugin removed the logic for setting or reading the requestTenantAccess field. This field is critical for the reporting plugin to determine which tenants a user can access. Without it, the reporting plugin receives a null value and denies access to reporting features, even for users who should have permission. This test helps ensure that user and role setup works as expected and highlights the impact of the missing requestTenantAccess logic on reporting access.

====================================================================================================

(Run Finished)

   Spec                                              Tests  Passing  Failing  Pending  Skipped  

┌────────────────────────────────────────────────────────────────────────────────────────────────┐
│ ✔ 01-create.spec.ts 01:55 15 15 - - - │
├────────────────────────────────────────────────────────────────────────────────────────────────┤
│ ✔ 02-edit.spec.ts 01:20 3 3 - - - │
├────────────────────────────────────────────────────────────────────────────────────────────────┤
│ ✔ 03-details.spec.ts 00:31 6 6 - - - │
├────────────────────────────────────────────────────────────────────────────────────────────────┤
│ ✔ 04-download.spec.ts 00:50 5 5 - - - │
├────────────────────────────────────────────────────────────────────────────────────────────────┤
│ ✔ 05-security.spec.ts 00:16 4 3 - 1 - │
└────────────────────────────────────────────────────────────────────────────────────────────────┘
✔ All specs passed! 04:53 33 32 - 1 -

Issues Resolved

[List any issues this PR will resolve]

Check List

  • New functionality includes testing.
    • All tests pass, including unit test, integration test and doctest
  • New functionality has been documented.
    • New functionality has javadoc added
    • New functionality has user manual doc added
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: sumukhswamy <sumukhhs@amazon.com>
Signed-off-by: sumukhswamy <sumukhhs@amazon.com>
@sumukhswamy sumukhswamy changed the title Added security test [Maintainence]Added security test Jun 25, 2025
Signed-off-by: sumukhswamy <sumukhhs@amazon.com>
Signed-off-by: sumukhswamy <sumukhhs@amazon.com>
@codecov
Copy link
Copy Markdown

codecov bot commented Jun 26, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 70.99%. Comparing base (2ab8705) to head (d6372f5).
Report is 10 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #596      +/-   ##
==========================================
- Coverage   71.02%   70.99%   -0.03%     
==========================================
  Files          31       31              
  Lines        2074     2072       -2     
  Branches      464      459       -5     
==========================================
- Hits         1473     1471       -2     
  Misses        595      595              
  Partials        6        6              
Flag Coverage Δ
dashboards-report 70.99% <ø> (-0.03%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: sumukhswamy <sumukhhs@amazon.com>
@cwperks
Copy link
Copy Markdown
Member

cwperks commented Jul 30, 2025

@sumukhswamy the tests will fail in this PR until all relevant code is open-sourced. Can you please contribute the code to security and common-utils repos?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants