Skip to content

fix(test-users): delete test users with the account that created them - #5247

Open
Coread wants to merge 1 commit into
nextfrom
fix_user_deletion
Open

Coread wants to merge 1 commit into
nextfrom
fix_user_deletion

Conversation

@Coread

@Coread Coread commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

COMPLETES #< INSERT LINK TO ISSUE >

This pull request addresses

CIG service created test users must be deleted with an authorized account. Test user deletion in integration tests has been failing for a while.

by making the following changes

< DESCRIBE YOUR CHANGES >

Change Type

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update
  • Tooling change
  • Internal code refactor

The following scenarios were tested

< ENUMERATE TESTS PERFORMED, WHETHER MANUAL OR AUTOMATED >

The GAI Coding Policy And Copyright Annotation Best Practices

  • GAI was not used (or, no additional notation is required)
  • Code was generated entirely by GAI
  • GAI was used to create a draft that was subsequently customized or modified
  • Coder created a draft manually that was non-substantively modified by GAI (e.g., refactoring was performed by GAI on manually written code)
  • Tool used for AI assistance (GitHub Copilot / Other - specify)
    • Github Copilot
    • Other - Please Specify
  • This PR is related to
    • Feature
    • Defect fix
    • Tech Debt
    • Automation

I certified that

  • I have read and followed contributing guidelines
  • I discussed changes with code owners prior to submitting this pull request
  • I have not skipped any automated checks
  • All existing and new tests passed
  • I have updated the documentation accordingly

Make sure to have followed the contributing guidelines before submitting.

@Coread
Coread requested a review from a team as a code owner September 24, 2026 16:12
@Coread Coread added the validated If the pull request is validated for automation. label Sep 24, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f311d050da

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

},
uri: `${cigServiceUrl}${BASE_PATH}/delete`,
});
return getClientCredentials({clientId, clientSecret, idbrokerUrl}).then((authorization) =>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Key cached client tokens by credentials

When one process removes users owned by more than one client, this call can authorize a deletion with the wrong account: getClientCredentials() returns the single module-global clientToken before considering the supplied clientId, clientSecret, or idbrokerUrl. After a user owned by client A has been created or removed, a later removeTestUser({...clientBCredentials}) still sends A's token, so the newly required creator-account authorization rejects deletion of B's user. Cache tokens per credential tuple (or avoid the global cache for this path).

Useful? React with 👍 / 👎.

@robstax robstax left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

codex comment seems technically possible, but i don't practically a concern?

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

validated If the pull request is validated for automation.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants