feat(authz): test & cover batch cases
┌────────────────────────────────┬─────────────────────────────────┬───────────────────────┬─────────────────┬──────────────────────────────┐ │ Endpoint │ Phase 3A no-grant │ Phase 3B Viewer │ Phase 3C Editor │ Phase 3D Admin │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/files/get │ 400 (all failed) │ 200 (2 successful) │ — │ — │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/files/move │ 400 │ 400 (no Update) │ 200 │ — │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/files/copy │ 400 │ — │ 200 │ — │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/files/delete │ 400 │ 400 │ 400 (no Delete) │ — │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/folders/get │ 400 │ 200 │ — │ — │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/folders/create │ 400 │ — │ 201 │ — │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/folders/move │ 400 │ — │ 200 │ — │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/folders/copy │ 400 │ — │ 200 │ — │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/folders/delete │ 400 │ — │ 400 (no Delete) │ 200 │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/trash │ 400 │ — │ — │ 400 (owner-only, documented) │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ POST /api/batch/download │ 404 (NotFound) │ 200 + application/zip │ — │ — │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ GET /api/batch/download?... │ 404 │ 200 + zip │ — │ — │ ├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤ │ Phase 3E lifecycle cleanup │ grants table empty after delete │ │ │ │ └────────────────────────────────┴─────────────────────────────────┴───────────────────────┴─────────────────┴──────────────────────────────┘
This commit is contained in:
@@ -15,6 +15,7 @@ use crate::application::services::batch_operations::{
|
||||
};
|
||||
use crate::interfaces::api::deserializer;
|
||||
use crate::interfaces::api::handlers::ApiResult;
|
||||
use crate::interfaces::errors::AppError;
|
||||
use crate::interfaces::middleware::auth::AuthUser;
|
||||
|
||||
/// Maximum number of items allowed in a single batch request.
|
||||
@@ -1010,10 +1011,19 @@ async fn process_download_batch(
|
||||
.await
|
||||
.map_err(|e| {
|
||||
tracing::error!("Batch download ZIP failed: {}", e);
|
||||
(
|
||||
StatusCode::INTERNAL_SERVER_ERROR,
|
||||
"Batch download failed".to_string(),
|
||||
)
|
||||
// Surface DomainError variants (NotFound when no items were
|
||||
// authorized) with their natural HTTP status code instead of
|
||||
// collapsing everything to 500.
|
||||
match e {
|
||||
crate::application::services::batch_operations::BatchOperationError::Domain(de) => {
|
||||
let app: AppError = de.into();
|
||||
(app.status_code, app.message)
|
||||
}
|
||||
other => (
|
||||
StatusCode::INTERNAL_SERVER_ERROR,
|
||||
format!("Batch download failed: {}", other),
|
||||
),
|
||||
}
|
||||
})?;
|
||||
|
||||
// Read file size for Content-Length before splitting ownership
|
||||
|
||||
Reference in New Issue
Block a user