-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathtest_brazil_security.py
37 lines (34 loc) · 1.22 KB
/
test_brazil_security.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
from cadurso import Cadurso
from tests.brazil.conftest import (
BuildingPermission,
Character,
GovernmentBuilding,
)
def test_security_roles_arrest_and_enter(
brazil_authz: Cadurso,
chief_minister: Character,
jill_layton: Character,
information_retrieval_center: GovernmentBuilding,
) -> None:
"""
Check that only SECURITY can ARREST_SUSPECTS,
and BUREAUCRAT or MINISTER can ENTER_DEPARTMENT.
We'll demonstrate that Jill, a CITIZEN, has neither capability.
For example, the Chief Minister can ENTER, but not ARREST (no SECURITY role).
"""
# Just for demonstration, we assume the Chief Minister is not SECURITY
assert brazil_authz.is_allowed(
chief_minister,
BuildingPermission.ENTER_DEPARTMENT,
information_retrieval_center,
)
assert not brazil_authz.is_allowed(
chief_minister, BuildingPermission.ARREST_SUSPECTS, information_retrieval_center
)
# Jill is only CITIZEN
assert not brazil_authz.is_allowed(
jill_layton, BuildingPermission.ENTER_DEPARTMENT, information_retrieval_center
)
assert not brazil_authz.is_allowed(
jill_layton, BuildingPermission.ARREST_SUSPECTS, information_retrieval_center
)