summaryrefslogtreecommitdiff
path: root/features/1/unauthenticated.feature
diff options
context:
space:
mode:
authorAzul <azul@riseup.net>2016-05-18 20:21:04 +0200
committerAzul <azul@riseup.net>2016-05-18 20:21:04 +0200
commit83f59164fc069f2593cf6babbc18638d9a68c9a3 (patch)
treeb357b100bfd40eb098040c4214776a5fb9bbff9b /features/1/unauthenticated.feature
parente05a1b0f5ae40a2aa17976b3009cd563b8e4660a (diff)
features for API version 2 - keep old ones
Now we test both api versions. We want this for backwards compatibility.
Diffstat (limited to 'features/1/unauthenticated.feature')
-rw-r--r--features/1/unauthenticated.feature31
1 files changed, 31 insertions, 0 deletions
diff --git a/features/1/unauthenticated.feature b/features/1/unauthenticated.feature
new file mode 100644
index 0000000..aea7117
--- /dev/null
+++ b/features/1/unauthenticated.feature
@@ -0,0 +1,31 @@
+Feature: Unauthenticated API endpoints
+
+ Most of the LEAP Provider API requires authentication.
+ However there are a few exceptions - mostly prerequisits of authenticating. This feature and the authentication feature document these.
+
+ Background:
+ Given I set headers:
+ | Accept | application/json |
+ | Content-Type | application/json |
+
+ @tempfile
+ Scenario: Fetch provider config
+ Given there is a config for the provider
+ When I send a GET request to "/provider.json"
+ Then the response status should be "200"
+ And the response should be that config
+
+ Scenario: Authentication required response
+ When I send a GET request to "/1/configs"
+ Then the response status should be "401"
+ And the response should have "error" with "not_authorized_login"
+ And the response should have "message"
+
+ Scenario: Authentication required for all other API endpoints (incomplete)
+ Given I am not logged in
+ When I send requests to these endpoints:
+ | GET | /1/configs |
+ | GET | /1/configs/config_id.json |
+ | GET | /1/service |
+ | DELETE | /1/logout |
+ Then they should require authentication