I am trying to use Cypress to test user permissions for a REST API. Authorisation is done via a JWT token which is generated by calling another API endpoint. A 200 and a 401 response is returned for authorised and unauthorised users respectively for the list users endpoint.
Let's say the SUT has 8 roles: Role1, Role2...etc Role1 and Role2 should be allowed to access the list users endpoint.
As shown below, I currently have it set up so that it will correctly test that Role1 gets the correct response, however, I'm not sure how I should do it for multiple roles so that I can test that Role1 and Role2 get a 200 whilst Role3 etc receive a 401 response
I guess I want to wrap the entire suite of tests (i.e all endpoints, not just list users) in a "for each role in roles" loop but can't see how you can do that and not sure it would be the best way.
Any help would be appreciated
describe('Users - list', () => {
beforeEach(() => {
cy.request({
url:'users',
headers: {
'Authorization': 'JWT Role1Token'
}}).as('response')
})
it('Correct response code is returned', () => {
cy.get('@response')
.its('status')
.should('equal', 200)
})
})