Skip to content

test(configure_gcp): cover addMemberToPolicyBinding branches #1284

Description

@cristim

Context

PR #1279 added the addMemberToPolicyBinding helper at cmd/configure_gcp.go:402-420 to merge a new IAM member into the project policy returned by cloudresourcemanager.Projects.GetIamPolicy. The function is pure (in-memory, no SDK calls) and has three branches: existing-binding + member-already-present (no change), existing-binding + new-member (append to Members), no-binding (append a fresh Binding).

It is currently uncovered by any unit test, which is the only test the SDK-direct GCP path is amenable to (the surrounding grantGCPIAMRole requires a real Cloud Resource Manager client; there is no provisioner interface there as there is for the Azure SP path).

A regression here silently corrupts a GCP project's IAM policy (members appended twice, or wrong role) on every wizard run — exactly the failure mode feedback_no_silent_fallbacks.md warns against.

Acceptance

A cmd/configure_gcp_test.go table-driven test for addMemberToPolicyBinding covering:

  1. Idempotent when member already bound — given a policy with {role: roles/compute.admin, members: [sa@a]} and (member=sa@a, role=roles/compute.admin), returns false, no mutation.
  2. Appends to an existing role binding — given {role: roles/compute.admin, members: [sa@a]} and (member=sa@b, role=roles/compute.admin), returns true and the binding now contains both members.
  3. Creates a new binding for a missing role — given {role: roles/compute.viewer, members: [sa@a]} and (member=sa@a, role=roles/compute.admin), returns true and a new roles/compute.admin binding is appended; the original viewer binding is untouched.
  4. Empty policy — given a policy with no bindings, returns true and a single new binding is created with exactly the requested member.
  5. Multiple bindings of the same role — guard the assumption that the helper only touches the first matching binding; documents/asserts the intended behaviour either way (the SDK normally folds duplicates, but Cloud Resource Manager v1 does permit them).

No SDK call mocking needed; the function operates on *cloudresourcemanager.Policy directly.

Out of scope

  • Mocking GetIamPolicy / SetIamPolicy to test the round-trip in grantGCPIAMRole. That would require extracting a GCP-side provisioner interface analogous to azureSPProvisioner; track separately if pursued.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions