Skip to content

FCT2-22092: assert unauthenticated users are sent to the unauthorised - #250

Closed
kmshrajcps wants to merge 1 commit into
mainfrom
task/FCT2-22092-unauthorised-page-e2e
Closed

kmshrajcps wants to merge 1 commit into
mainfrom
task/FCT2-22092-unauthorised-page-e2e

Conversation

@kmshrajcps

Copy link
Copy Markdown
Contributor

Tests to cover Unauthorised page

…page

Covers FCT2-22092 (#241) against the deployed SPA and real gateway API,
where previously only the MSW integration suite asserted it.

Two scenarios, each keeping the Entra SSO cookies so the SPA still signs
in and only the gateway API rejects the request:

- Scenario 23 removes the Cms-Auth-Values cookie.
- Scenario 24 keeps the cookie but replaces its value with an invalid one.

Both load the home page and assert the units API returns 401, the user
lands on /unauthorised with the "You cannot access this service" heading
and the CMS Classic relaunch text, and the Register a case form is never
shown.

Falsified by running a copy with the valid cookie left intact: it fails
the status check (expected 401, received 200).
@sonarqubecloud

sonarqubecloud Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

@kmshrajcps kmshrajcps closed this Sep 24, 2026
@kmshrajcps

Copy link
Copy Markdown
Contributor Author

as there is another pull request raised to base with development branch

@kmshrajcps
kmshrajcps deleted the task/FCT2-22092-unauthorised-page-e2e branch September 24, 2026 12:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant