诚实性修复: API限流Retry-After(wait=60s)+断言 / purge定时接线(04:00 cron+actor+测试) / Channel表单校验(ref+rules+validate) / README PG数字513
This commit is contained in:
@@ -230,7 +230,13 @@ def test_demo_middleware_does_not_affect_other_tenants(db, tenant, django_user_m
|
||||
"""正常租户写操作不受演示只读拦截。"""
|
||||
from rest_framework_simplejwt.tokens import RefreshToken
|
||||
|
||||
from apps.core.models import TenantMembership
|
||||
|
||||
user = django_user_model.objects.create_user(username="normal", password="pass12345")
|
||||
# This case is about the demo read-only middleware, not authorization.
|
||||
# Give the user the membership the permission layer requires so the write
|
||||
# actually reaches the middleware check.
|
||||
TenantMembership.objects.create(user=user, tenant=tenant, role="member")
|
||||
c = APIClient()
|
||||
c.credentials(HTTP_AUTHORIZATION=f"Bearer {RefreshToken.for_user(user).access_token}",
|
||||
HTTP_X_TENANT_ID=tenant.code)
|
||||
|
||||
Reference in New Issue
Block a user