How to test role-based API permissions with Cypress

Viewed 439

I am trying to use Cypress to test user permissions for a REST API. Authorisation is done via a JWT token which is generated by calling another API endpoint. A 200 and a 401 response is returned for authorised and unauthorised users respectively for the list users endpoint.

Let's say the SUT has 8 roles: Role1, Role2...etc Role1 and Role2 should be allowed to access the list users endpoint.

As shown below, I currently have it set up so that it will correctly test that Role1 gets the correct response, however, I'm not sure how I should do it for multiple roles so that I can test that Role1 and Role2 get a 200 whilst Role3 etc receive a 401 response

I guess I want to wrap the entire suite of tests (i.e all endpoints, not just list users) in a "for each role in roles" loop but can't see how you can do that and not sure it would be the best way.

Any help would be appreciated

describe('Users - list', () => {
beforeEach(() => {
    cy.request({
        url:'users',
        headers: {
        'Authorization': 'JWT Role1Token'   
      }}).as('response')
})

it('Correct response code is returned', () => {
    cy.get('@response')
    .its('status')
    .should('equal', 200)        
})   

})

0 Answers
Related