Enable user Plugins in adversarial setup #562

Open
opened 2026-10-01 00:45:08 +00:00 by kayg · 0 comments
Owner

A real-server adversarial pass using the split data-directory runner registered the owner and member successfully, but several probes could not reach their target APIs. The fresh Users received HTTP 403 with API is disabled in Settings → Apps from Files, Appearance and Tasks routes; examples include /api/v1/files/entries and task collection reads. tests/adversarial/setup.mjs creates the Users but does not enable those per-User Plugins before the probes run, so the broad round reports many unrelated failures and cannot validate these APIs. Update the setup or each probe to enable its required Plugins explicitly; do not change the endpoint behavior to bypass the User setting.

A real-server adversarial pass using the split data-directory runner registered the owner and member successfully, but several probes could not reach their target APIs. The fresh Users received HTTP 403 with `API is disabled in Settings → Apps` from Files, Appearance and Tasks routes; examples include `/api/v1/files/entries` and task collection reads. `tests/adversarial/setup.mjs` creates the Users but does not enable those per-User Plugins before the probes run, so the broad round reports many unrelated failures and cannot validate these APIs. Update the setup or each probe to enable its required Plugins explicitly; do not change the endpoint behavior to bypass the User setting.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#562
No description provided.