diff --git a/bruno/environments/Bookmann.bru b/bruno/environments/Bookmann.bru index 483612b..f4d2363 100644 --- a/bruno/environments/Bookmann.bru +++ b/bruno/environments/Bookmann.bru @@ -12,6 +12,6 @@ vars { is_visible: true } vars:secret [ - token + token, refresh_token ] diff --git a/bruno/library/Get Libraries (Admin).bru b/bruno/library/Get Libraries (Admin).bru index 5d3d031..62127b7 100644 --- a/bruno/library/Get Libraries (Admin).bru +++ b/bruno/library/Get Libraries (Admin).bru @@ -6,6 +6,7 @@ meta { get { url: {{base_url}}/api/libraries + body: none auth: inherit } @@ -13,52 +14,6 @@ headers { Content-Type: application/json } -tests { - test_get_libraries_success(status, headers, body) { - if (status !== 200) { - throw new Error("Expected status 200, got " + status); - } - - const contentType = headers["content-type"]; - if (!contentType || !contentType.includes("application/json")) { - throw new Error("Expected content-type to contain application/json, got " + contentType); - } - - // Verify response body is valid JSON and has expected structure - let data; - try { - data = JSON.parse(body); - } catch (e) { - throw new Error("Response body is not valid JSON"); - } - - if (!Array.isArray(data)) { - throw new Error("Expected response body to be an array"); - } - - // Validate each library in array - data.forEach((library, index) => { - if (!library || typeof library !== "object") { - throw new Error("Library at index " + index + " is not an object"); - } - - if (!library.id) { - throw new Error("Library at index " + index + " missing required field: id"); - } - - if (!library.name) { - throw new Error("Library at index " + index + " missing required field: name"); - } - - if (!library.type) { - throw new Error("Library at index " + index + " missing required field: type"); - } - }); - - return true; - } -} - settings { encodeUrl: true timeout: 0 @@ -91,4 +46,4 @@ docs { - 401: Unauthorized - 403: Forbidden (admin access required) - 500: Internal server error -} \ No newline at end of file +} diff --git a/bruno/user/auth/Login User.bru b/bruno/user/auth/Login User.bru index 6a50099..8be6366 100644 --- a/bruno/user/auth/Login User.bru +++ b/bruno/user/auth/Login User.bru @@ -13,14 +13,20 @@ post { body:json { { "login": "test@example.com", - "password": "password123" + "password": "Password123!" } } script:post-response { function onResponse(res) { let data = res.getBody(); - return bru.setEnvVar("token", data.token, { persist: true }); + // If successful registration, set token environment variable + if (res.getStatus() === 201 || res.getStatus() === 200) { + if (data && data.access_token) { + + return bru.setEnvVar("token", data.access_token, { persist: true }); + } + } } onResponse(res); } diff --git a/bruno/user/auth/Register User.bru b/bruno/user/auth/Register User.bru index bc8fd05..a53de49 100644 --- a/bruno/user/auth/Register User.bru +++ b/bruno/user/auth/Register User.bru @@ -14,7 +14,7 @@ body:json { { "email": "test@example.com", "username": "testuser", - "password": "password123", + "password": "Password123!", "first_name": "Test", "last_name": "User" } @@ -23,7 +23,7 @@ body:json { script:post-response { function onResponse(res) { let data = res.getBody(); - + // If successful registration, set token environment variable if (res.getStatus() === 201 || res.getStatus() === 200) { if (data && data.token) { @@ -34,87 +34,6 @@ script:post-response { onResponse(res); } -tests { - test_register_user_success(status, headers, body) { - const contentType = headers["content-type"]; - if (!contentType || !contentType.includes("application/json")) { - throw new Error("Expected content-type to contain application/json, got " + contentType); - } - - // Verify response body is valid JSON and has expected structure - let data; - try { - data = JSON.parse(body); - } catch (e) { - throw new Error("Response body is not valid JSON: " + body); - } - - if (!data || typeof data !== "object") { - throw new Error("Expected response body to be an object"); - } - - // Handle both success and error responses - if (status === 500) { - // Backend error - should not happen but handle gracefully - if (data.error) { - throw new Error("Backend Error: " + data.error); - } else { - throw new Error("Backend Error: Internal server error during registration"); - } - } - - if (status === 201 || status === 200) { - // Successful registration - if (!data.token) { - throw new Error("Response missing required field: token"); - } - - if (!data.user) { - throw new Error("Response missing required field: user"); - } - - // Validate user object - if (!data.user.id) { - throw new Error("User object missing required field: id"); - } - - if (!data.user.email) { - throw new Error("User object missing required field: email"); - } - - if (!data.user.username) { - throw new Error("User object missing required field: username"); - } - - return true; - } - - throw new Error("Unexpected status code: " + status); - } - - test_register_user_error_409(status, headers, body) { - // Test case: User already exists - if (status === 409) { - const data = JSON.parse(body); - if (data.error && data.error.includes("already exists")) { - return true; // Expected conflict response - } - } - return false; // Not this test case - } - - test_register_user_error_400(status, headers, body) { - // Test case: Invalid input data - if (status === 400) { - const data = JSON.parse(body); - if (data.error) { - return true; // Expected bad request response - } - } - return false; // Not this test case - } -} - settings { encodeUrl: true timeout: 0 @@ -122,13 +41,13 @@ settings { docs { ## Register User - + Creates a new user account with role-based restrictions. - + **Method:** POST - + **Endpoint:** /api/auth/register - + **Request Body:** - `email` (string): Email address - `username` (string): Username @@ -136,7 +55,7 @@ docs { - `first_name` (string, optional): First name - `last_name` (string, optional): Last name - `role` (string): User role ("user" or "admin") - + **Response:** - `token` (string): JWT token - `user` (object): User details @@ -147,22 +66,22 @@ docs { - `first_name` (string, optional): First name - `last_name` (string, optional): Last name - `role` (string): User role ("user" or "admin") - + **Status Codes:** - 201: Created - 400: Invalid input data - 403: Forbidden - role-based restrictions apply - 409: User exists - + **Role Restrictions:** - **First User**: Automatically gets admin role regardless of request - **Existing Admins Present**: Only authenticated admins can create new admin accounts - **No Admins Yet**: Anyone can create first admin (auto-assigned) - **Regular User Creation**: Anyone can create regular user accounts - **Unauthenticated Users**: Can only create first admin, not subsequent admins - + **Examples:** - First admin creation: `{"email": "admin@example.com", "username": "admin", "password": "password123", "role": "admin"}` - Regular user creation: `{"email": "user@example.com", "username": "user", "password": "password123", "role": "user"}` - + }