diff --git a/code/API_definitions/geofencing-subscriptions.yaml b/code/API_definitions/geofencing-subscriptions.yaml index 1312f20c..1c1af2d7 100644 --- a/code/API_definitions/geofencing-subscriptions.yaml +++ b/code/API_definitions/geofencing-subscriptions.yaml @@ -67,6 +67,7 @@ info: If an event occurs the application will send events to the provided webhook - 'sink'._ + # Authorization and authentication The "Camara Security and Interoperability Profile" provides details of how an API consumer requests an access token. Please refer to Identity and Consent Management (https://github.com/camaraproject/IdentityAndConsentManagement/) for the released version of the profile. @@ -77,6 +78,7 @@ info: + # Identifying the device from the access token This API requires the API consumer to identify a device as the subject of the API as follows: @@ -118,6 +120,7 @@ info: + # Request body strictness This API rejects requests with JSON request bodies that contain properties not declared in this specification, at any nesting level. Unknown properties result in a `400 INVALID_ARGUMENT` response. diff --git a/code/Test_definitions/geofencing-subscriptions.feature b/code/Test_definitions/geofencing-subscriptions-createGeofencingSubscription.feature similarity index 71% rename from code/Test_definitions/geofencing-subscriptions.feature rename to code/Test_definitions/geofencing-subscriptions-createGeofencingSubscription.feature index 9a0ccc52..4e1cde9d 100644 --- a/code/Test_definitions/geofencing-subscriptions.feature +++ b/code/Test_definitions/geofencing-subscriptions-createGeofencingSubscription.feature @@ -1,4 +1,4 @@ -Feature: Camara Geofencing Subscriptions API, vwip - Operations on subscriptions +Feature: Camara Geofencing Subscriptions API, vwip - Operation createGeofencingSubscription # Input to be provided by the implementation to the tester # @@ -52,42 +52,6 @@ Feature: Camara Geofencing Subscriptions API, vwip - Operations on subscriptions And type="org.camaraproject.geofencing-subscriptions.v0.subscription-started" And the response property "$.data.initiationReason" is "SUBSCRIPTION_CREATED" - @geofencing_subscriptions_04_Operation_to_retrieve_list_of_subscriptions_when_no_records - Scenario: Get a list of Geofencing subscriptions when no subscriptions available - Given a client without Geofencing subscriptions created - When the request "retrieveGeofencingSubscriptionList" is sent - Then the response code is 200 - And the response header "Content-Type" is "application/json" - And the response header "x-correlator" has the same value as the request header "x-correlator" - And the response body is an empty array - - @geofencing_subscriptions_05_Operation_to_retrieve_list_of_subscriptions - Scenario: Get a list of subscriptions - Given a client with Geofencing subscriptions created - When the request "retrieveGeofencingSubscriptionList" is sent - Then the response code is 200 - And the response header "Content-Type" is "application/json" - And the response header "x-correlator" has the same value as the request header "x-correlator" - And the response body has an array of items and each item complies with the OAS schema at "#/components/schemas/Subscription" - - @geofencing_subscriptions_06_Operation_to_retrieve_subscription_based_on_an_existing_subscription-id - Scenario: Get a subscription based on existing subscription-id. - Given the path parameter "subscriptionId" is set to the identifier of an existing Geofencing subscription - When the request "retrieveGeofencingSubscription" is sent - Then the response code is 200 - And the response header "Content-Type" is "application/json" - And the response header "x-correlator" has the same value as the request header "x-correlator" - And the response body complies with the OAS schema at "#/components/schemas/Subscription" - - @geofencing_subscriptions_07_Operation_to_delete_subscription_based_on_an_existing_subscription-id - Scenario: Delete a subscription based on existing subscription-id. - Given the path parameter "subscriptionId" is set to the identifier of an existing Geofencing subscription - When the request "deleteGeofencingSubscription" is sent - Then the response code is 202 or 204 - And the response header "x-correlator" has the same value as the request header "x-correlator" - And if the response property "$.status" is 204 then the response body is not available - And if the response property "$.status" is 202 then the response body complies with the OAS schema at "#/components/schemas/SubscriptionAsync" - @geofencing_subscriptions_08_subscription_ends_on_expiry Scenario: Receive notification for subscription-ended event on expiry Given an existing Geofencing subscription with some value for the property "expiresAt" in the near future @@ -107,16 +71,6 @@ Feature: Camara Geofencing Subscriptions API, vwip - Operations on subscriptions And type="org.camaraproject.geofencing-subscriptions.v0.subscription-ended" And the response property "$.data.terminationReason" is "MAX_EVENTS_REACHED" - @geofencing_subscriptions_10_subscription_delete_event_validation - Scenario: Receive notification for subscription-ended event on deletion - Given the path parameter "subscriptionId" is set to the identifier of an existing Geofencing subscription - When the request "deleteGeofencingSubscription" is sent - Then the response code is 202 or 204 - And event notification "subscription-ended" is received on callback-url - And notification body complies with the OAS schema at "#/components/schemas/EventSubscriptionEnded" - And type="org.camaraproject.geofencing-subscriptions.v0.subscription-ended" - And the response property "$.data.terminationReason" is "SUBSCRIPTION_DELETED" - @geofencing_subscriptions_subscription_ends_on_access_token_expired Scenario: Receive notification for subscription-ended event on access token expiry Given an existing Geofencing subscription created with a "$.sinkCredential.credentialType" set to "ACCESSTOKEN" @@ -379,6 +333,23 @@ Feature: Camara Geofencing Subscriptions API, vwip - Operations on subscriptions And the response property "$.code" is "INVALID_ARGUMENT" And the response property "$.message" contains a user friendly text + @geofencing_subscriptions_400.9_out_of_range + Scenario Outline: Create subscription with a property value out of its defined range + Given a valid geofencing subscription request body + And the request body property "" is set to "" + When the request "createGeofencingSubscription" is sent + Then the response status code is 400 + And the response property "$.status" is 400 + And the response property "$.code" is "OUT_OF_RANGE" + And the response property "$.message" contains a user friendly text + + Examples: + | property | value | + | $.config.subscriptionMaxEvents | 0 | + | $.config.subscriptionMaxEvents | 1000001 | + | $.config.subscriptionDetail.area.radius | 0 | + | $.config.subscriptionDetail.area.center.latitude | 91 | + # Error code 401 @geofencing_subscriptions_creation_401.1_no_authorization_header @@ -403,25 +374,6 @@ Feature: Camara Geofencing Subscriptions API, vwip - Operations on subscriptions And the response property "$.code" is "UNAUTHENTICATED" or "AUTHENTICATION_REQUIRED" And the response property "$.message" contains a user friendly text - @geofencing_subscriptions_401.3_no_authorization_header_for_delete_subscription - Scenario: No Authorization header for delete subscription - Given header "Authorization" is set without a token - When the request "deleteGeofencingSubscription" is sent - Then the response status code is 401 - And the response property "$.status" is 401 - And the response property "$.code" is "UNAUTHENTICATED" - And the response property "$.message" contains a user friendly text - - @geofencing_subscriptions_401.4_no_authorization_header_for_get_subscription - Scenario: No Authorization header for get subscription - Given header "Authorization" is not set to valid token - And path parameter "subscriptionId" is set to the identifier of an existing subscription - When the request "retrieveGeofencingSubscription" is sent - Then the response status code is 401 - And the response property "$.status" is 401 - And the response property "$.code" is "UNAUTHENTICATED" - And the response property "$.message" contains a user friendly text - @geofencing_subscriptions_creation_401.5_malformed_access_token Scenario: Malformed access token Given the header "Authorization" is set to a malformed token @@ -433,116 +385,6 @@ Feature: Camara Geofencing Subscriptions API, vwip - Operations on subscriptions And the response property "$.code" is "UNAUTHENTICATED" or "AUTHENTICATION_REQUIRED" And the response property "$.message" contains a user friendly text - @geofencing_subscriptions_401_expired_access_token_for_retrieve_subscription - Scenario: Expired access token for retrieve subscription - Given the header "Authorization" is set to an expired access token - And the path parameter "subscriptionId" is set to an existing subscription identifier - When the request "retrieveGeofencingSubscription" is sent - Then the response status code is 401 - And the response header "Content-Type" is "application/json" - And the response property "$.status" is 401 - And the response property "$.code" is "UNAUTHENTICATED" - And the response property "$.message" contains a user friendly text - - @geofencing_subscriptions_401_invalid_access_token_for_retrieve_subscription - Scenario: Invalid access token for retrieve subscription - Given the header "Authorization" is set to an invalid access token - And the path parameter "subscriptionId" is set to an existing subscription identifier - When the request "retrieveGeofencingSubscription" is sent - Then the response status code is 401 - And the response header "Content-Type" is "application/json" - And the response property "$.status" is 401 - And the response property "$.code" is "UNAUTHENTICATED" - And the response property "$.message" contains a user friendly text - - @geofencing_subscriptions_401_no_authorization_header_for_list_subscriptions - Scenario: No Authorization header for list subscriptions - Given the header "Authorization" is removed - When the request "retrieveGeofencingSubscriptionList" is sent - Then the response status code is 401 - And the response header "Content-Type" is "application/json" - And the response property "$.status" is 401 - And the response property "$.code" is "UNAUTHENTICATED" - And the response property "$.message" contains a user friendly text - - @geofencing_subscriptions_401_expired_access_token_for_list_subscriptions - Scenario: Expired access token for list subscriptions - Given the header "Authorization" is set to an expired access token - When the request "retrieveGeofencingSubscriptionList" is sent - Then the response status code is 401 - And the response header "Content-Type" is "application/json" - And the response property "$.status" is 401 - And the response property "$.code" is "UNAUTHENTICATED" - And the response property "$.message" contains a user friendly text - - @geofencing_subscriptions_401_invalid_access_token_for_list_subscriptions - Scenario: Invalid access token for list subscriptions - Given the header "Authorization" is set to an invalid access token - When the request "retrieveGeofencingSubscriptionList" is sent - Then the response status code is 401 - And the response header "Content-Type" is "application/json" - And the response property "$.status" is 401 - And the response property "$.code" is "UNAUTHENTICATED" - And the response property "$.message" contains a user friendly text - - @geofencing_subscriptions_401_expired_access_token_for_delete_subscription - Scenario: Expired access token for delete subscription - Given the header "Authorization" is set to an expired access token - And the path parameter "subscriptionId" is set to an existing subscription identifier - When the request "deleteGeofencingSubscription" is sent - Then the response status code is 401 - And the response header "Content-Type" is "application/json" - And the response property "$.status" is 401 - And the response property "$.code" is "UNAUTHENTICATED" - And the response property "$.message" contains a user friendly text - - @geofencing_subscriptions_401_invalid_access_token_for_delete_subscription - Scenario: Invalid access token for delete subscription - Given the header "Authorization" is set to an invalid access token - And the path parameter "subscriptionId" is set to an existing subscription identifier - When the request "deleteGeofencingSubscription" is sent - Then the response status code is 401 - And the response header "Content-Type" is "application/json" - And the response property "$.status" is 401 - And the response property "$.code" is "UNAUTHENTICATED" - And the response property "$.message" contains a user friendly text - - # Error code 403 - - @geofencing_subscriptions_403_subscription_mismatch - Scenario Outline: Access to subscription belonging to a different API client - Given the path parameter "subscriptionId" is set to an identifier of a valid subscription belonging to a different API client - When the request "" is sent - Then the response status code is 403 - And the response property "$.status" is 403 - And the response property "$.code" is "SUBSCRIPTION_MISMATCH" - And the response property "$.message" contains a user friendly text - - Examples: - | operation | - | retrieveGeofencingSubscription | - | deleteGeofencingSubscription | - - # Error code 404 - - @geofencing_subscriptions_404.1_retrieve_unknown_subscriptions_id - Scenario: Get subscription when subscriptionId is unknown to the system - Given the path parameter "subscriptionId" is set to a value not corresponding to any existing subscription - When the request "retrieveGeofencingSubscription" is sent - Then the response status code is 404 - And the response property "$.status" is 404 - And the response property "$.code" is "NOT_FOUND" - And the response property "$.message" contains a user friendly text - - @geofencing_subscriptions_404.2_delete_unknown_subscriptions_id - Scenario: Delete subscription with subscriptionId unknown to the system - Given the path parameter "subscriptionId" is set to a value not corresponding to any existing subscription - When the request "deleteGeofencingSubscription" is sent - Then the response code is 404 - And the response property "$.status" is 404 - And the response property "$.code" is "NOT_FOUND" - And the response property "$.message" contains a user friendly text - # Error code 422 @geofencing_subscriptions_422.1_create_with_an_unsupported_area @@ -563,6 +405,8 @@ Feature: Camara Geofencing Subscriptions API, vwip - Operations on subscriptions And the response property "$.code" is "GEOFENCING_SUBSCRIPTIONS.INVALID_AREA" And the response property "$.message" contains "The requested area is too small" + # Not applicable while "$.types" is limited to 1 item (maxItems: 1): a request with 2 items fails schema validation with 400 INVALID_ARGUMENT. + # Kept for a future version of the API that accepts more than one event type per subscription. @geofencing_subscriptions_422.3_create_with_unsupported_multiple_event_type Scenario: Multi event subscription not supported Given the API provider only allows one event to be subscribed per subscription request @@ -583,4 +427,4 @@ Feature: Camara Geofencing Subscriptions API, vwip - Operations on subscriptions Then the response code is 422 And the response property "$.status" is 422 And the response property "$.code" is "PRIVATE_KEY_JWT_NOT_CONFIGURED" - And the response property "$.message" contains a user friendly text \ No newline at end of file + And the response property "$.message" contains a user friendly text diff --git a/code/Test_definitions/geofencing-subscriptions-deleteGeofencingSubscription.feature b/code/Test_definitions/geofencing-subscriptions-deleteGeofencingSubscription.feature new file mode 100644 index 00000000..ea4b32e7 --- /dev/null +++ b/code/Test_definitions/geofencing-subscriptions-deleteGeofencingSubscription.feature @@ -0,0 +1,98 @@ +Feature: Camara Geofencing Subscriptions API, vwip - Operation deleteGeofencingSubscription + + # Input to be provided by the implementation to the tester + # + # Implementation indications: + # * List of device identifier types which are not supported, among: phoneNumber, networkAccessIdentifier, ipv4Address, ipv6Address + # + # Testing assets: + # * A device object which location is known by the network when connected. 2 distinct device are required for some scenario. + # * A moveable device to trigger area-left / area-entered events. + # * apiRoot: API root of the server URL + # + # References to OAS spec schemas refer to schemas specifies in geofencing-subscriptions.yaml + + Background: Common Geofencing Subscriptions setup + Given an environment at "apiRoot" + And the resource "/geofencing-subscriptions/vwip/" as geofencing base-url + And the header "Authorization" is set to a valid access token + And the header "x-correlator" complies with the schema at "#/components/schemas/XCorrelator" + + # Success scenarios + + # Note: Depending on the API managed personal data specific scenario update may be require to specify use of 2-legs or 3-legs access token. + + @geofencing_subscriptions_07_Operation_to_delete_subscription_based_on_an_existing_subscription-id + Scenario: Delete a subscription based on existing subscription-id. + Given the path parameter "subscriptionId" is set to the identifier of an existing Geofencing subscription + When the request "deleteGeofencingSubscription" is sent + Then the response code is 202 or 204 + And the response header "x-correlator" has the same value as the request header "x-correlator" + And if the response property "$.status" is 204 then the response body is not available + And if the response property "$.status" is 202 then the response body complies with the OAS schema at "#/components/schemas/SubscriptionAsync" + + @geofencing_subscriptions_10_subscription_delete_event_validation + Scenario: Receive notification for subscription-ended event on deletion + Given the path parameter "subscriptionId" is set to the identifier of an existing Geofencing subscription + When the request "deleteGeofencingSubscription" is sent + Then the response code is 202 or 204 + And event notification "subscription-ended" is received on callback-url + And notification body complies with the OAS schema at "#/components/schemas/EventSubscriptionEnded" + And type="org.camaraproject.geofencing-subscriptions.v0.subscription-ended" + And the response property "$.data.terminationReason" is "SUBSCRIPTION_DELETED" + + # Error code 401 + + @geofencing_subscriptions_401.3_no_authorization_header_for_delete_subscription + Scenario: No Authorization header for delete subscription + Given header "Authorization" is set without a token + And the path parameter "subscriptionId" is set to an existing subscription identifier + When the request "deleteGeofencingSubscription" is sent + Then the response status code is 401 + And the response property "$.status" is 401 + And the response property "$.code" is "UNAUTHENTICATED" + And the response property "$.message" contains a user friendly text + + @geofencing_subscriptions_401_expired_access_token_for_delete_subscription + Scenario: Expired access token for delete subscription + Given the header "Authorization" is set to an expired access token + And the path parameter "subscriptionId" is set to an existing subscription identifier + When the request "deleteGeofencingSubscription" is sent + Then the response status code is 401 + And the response header "Content-Type" is "application/json" + And the response property "$.status" is 401 + And the response property "$.code" is "UNAUTHENTICATED" + And the response property "$.message" contains a user friendly text + + @geofencing_subscriptions_401_invalid_access_token_for_delete_subscription + Scenario: Invalid access token for delete subscription + Given the header "Authorization" is set to an invalid access token + And the path parameter "subscriptionId" is set to an existing subscription identifier + When the request "deleteGeofencingSubscription" is sent + Then the response status code is 401 + And the response header "Content-Type" is "application/json" + And the response property "$.status" is 401 + And the response property "$.code" is "UNAUTHENTICATED" + And the response property "$.message" contains a user friendly text + + # Error code 403 + + @geofencing_subscriptions_403.2_delete_subscription_mismatch + Scenario: Access to subscription belonging to a different API client + Given the path parameter "subscriptionId" is set to an identifier of a valid subscription belonging to a different API client + When the request "deleteGeofencingSubscription" is sent + Then the response status code is 403 + And the response property "$.status" is 403 + And the response property "$.code" is "SUBSCRIPTION_MISMATCH" + And the response property "$.message" contains a user friendly text + + # Error code 404 + + @geofencing_subscriptions_404.2_delete_unknown_subscriptions_id + Scenario: Delete subscription with subscriptionId unknown to the system + Given the path parameter "subscriptionId" is set to a value not corresponding to any existing subscription + When the request "deleteGeofencingSubscription" is sent + Then the response code is 404 + And the response property "$.status" is 404 + And the response property "$.code" is "NOT_FOUND" + And the response property "$.message" contains a user friendly text diff --git a/code/Test_definitions/geofencing-subscriptions-retrieveGeofencingSubscription.feature b/code/Test_definitions/geofencing-subscriptions-retrieveGeofencingSubscription.feature new file mode 100644 index 00000000..679e486d --- /dev/null +++ b/code/Test_definitions/geofencing-subscriptions-retrieveGeofencingSubscription.feature @@ -0,0 +1,88 @@ +Feature: Camara Geofencing Subscriptions API, vwip - Operation retrieveGeofencingSubscription + + # Input to be provided by the implementation to the tester + # + # Implementation indications: + # * List of device identifier types which are not supported, among: phoneNumber, networkAccessIdentifier, ipv4Address, ipv6Address + # + # Testing assets: + # * A device object which location is known by the network when connected. 2 distinct device are required for some scenario. + # * A moveable device to trigger area-left / area-entered events. + # * apiRoot: API root of the server URL + # + # References to OAS spec schemas refer to schemas specifies in geofencing-subscriptions.yaml + + Background: Common Geofencing Subscriptions setup + Given an environment at "apiRoot" + And the resource "/geofencing-subscriptions/vwip/" as geofencing base-url + And the header "Authorization" is set to a valid access token + And the header "x-correlator" complies with the schema at "#/components/schemas/XCorrelator" + + # Success scenarios + + # Note: Depending on the API managed personal data specific scenario update may be require to specify use of 2-legs or 3-legs access token. + + @geofencing_subscriptions_06_Operation_to_retrieve_subscription_based_on_an_existing_subscription-id + Scenario: Get a subscription based on existing subscription-id. + Given the path parameter "subscriptionId" is set to the identifier of an existing Geofencing subscription + When the request "retrieveGeofencingSubscription" is sent + Then the response code is 200 + And the response header "Content-Type" is "application/json" + And the response header "x-correlator" has the same value as the request header "x-correlator" + And the response body complies with the OAS schema at "#/components/schemas/Subscription" + + # Error code 401 + + @geofencing_subscriptions_401.4_no_authorization_header_for_get_subscription + Scenario: No Authorization header for get subscription + Given header "Authorization" is not present + And path parameter "subscriptionId" is set to the identifier of an existing subscription + When the request "retrieveGeofencingSubscription" is sent + Then the response status code is 401 + And the response property "$.status" is 401 + And the response property "$.code" is "UNAUTHENTICATED" + And the response property "$.message" contains a user friendly text + + @geofencing_subscriptions_401_expired_access_token_for_retrieve_subscription + Scenario: Expired access token for retrieve subscription + Given the header "Authorization" is set to an expired access token + And the path parameter "subscriptionId" is set to an existing subscription identifier + When the request "retrieveGeofencingSubscription" is sent + Then the response status code is 401 + And the response header "Content-Type" is "application/json" + And the response property "$.status" is 401 + And the response property "$.code" is "UNAUTHENTICATED" + And the response property "$.message" contains a user friendly text + + @geofencing_subscriptions_401_invalid_access_token_for_retrieve_subscription + Scenario: Invalid access token for retrieve subscription + Given the header "Authorization" is set to an invalid access token + And the path parameter "subscriptionId" is set to an existing subscription identifier + When the request "retrieveGeofencingSubscription" is sent + Then the response status code is 401 + And the response header "Content-Type" is "application/json" + And the response property "$.status" is 401 + And the response property "$.code" is "UNAUTHENTICATED" + And the response property "$.message" contains a user friendly text + + # Error code 403 + + @geofencing_subscriptions_403.1_retrieve_subscription_mismatch + Scenario: Access to subscription belonging to a different API client + Given the path parameter "subscriptionId" is set to an identifier of a valid subscription belonging to a different API client + When the request "retrieveGeofencingSubscription" is sent + Then the response status code is 403 + And the response property "$.status" is 403 + And the response property "$.code" is "SUBSCRIPTION_MISMATCH" + And the response property "$.message" contains a user friendly text + + # Error code 404 + + @geofencing_subscriptions_404.1_retrieve_unknown_subscriptions_id + Scenario: Get subscription when subscriptionId is unknown to the system + Given the path parameter "subscriptionId" is set to a value not corresponding to any existing subscription + When the request "retrieveGeofencingSubscription" is sent + Then the response status code is 404 + And the response property "$.status" is 404 + And the response property "$.code" is "NOT_FOUND" + And the response property "$.message" contains a user friendly text diff --git a/code/Test_definitions/geofencing-subscriptions-retrieveGeofencingSubscriptionList.feature b/code/Test_definitions/geofencing-subscriptions-retrieveGeofencingSubscriptionList.feature new file mode 100644 index 00000000..d65ba075 --- /dev/null +++ b/code/Test_definitions/geofencing-subscriptions-retrieveGeofencingSubscriptionList.feature @@ -0,0 +1,73 @@ +Feature: Camara Geofencing Subscriptions API, vwip - Operation retrieveGeofencingSubscriptionList + + # Input to be provided by the implementation to the tester + # + # Implementation indications: + # * List of device identifier types which are not supported, among: phoneNumber, networkAccessIdentifier, ipv4Address, ipv6Address + # + # Testing assets: + # * A device object which location is known by the network when connected. 2 distinct device are required for some scenario. + # * A moveable device to trigger area-left / area-entered events. + # * apiRoot: API root of the server URL + # + # References to OAS spec schemas refer to schemas specifies in geofencing-subscriptions.yaml + + Background: Common Geofencing Subscriptions setup + Given an environment at "apiRoot" + And the resource "/geofencing-subscriptions/vwip/" as geofencing base-url + And the header "Authorization" is set to a valid access token + And the header "x-correlator" complies with the schema at "#/components/schemas/XCorrelator" + + # Success scenarios + + # Note: Depending on the API managed personal data specific scenario update may be require to specify use of 2-legs or 3-legs access token. + + @geofencing_subscriptions_04_Operation_to_retrieve_list_of_subscriptions_when_no_records + Scenario: Get a list of Geofencing subscriptions when no subscriptions available + Given a client without Geofencing subscriptions created + When the request "retrieveGeofencingSubscriptionList" is sent + Then the response code is 200 + And the response header "Content-Type" is "application/json" + And the response header "x-correlator" has the same value as the request header "x-correlator" + And the response body is an empty array + + @geofencing_subscriptions_05_Operation_to_retrieve_list_of_subscriptions + Scenario: Get a list of subscriptions + Given a client with Geofencing subscriptions created + When the request "retrieveGeofencingSubscriptionList" is sent + Then the response code is 200 + And the response header "Content-Type" is "application/json" + And the response header "x-correlator" has the same value as the request header "x-correlator" + And the response body has an array of items and each item complies with the OAS schema at "#/components/schemas/Subscription" + + # Error code 401 + + @geofencing_subscriptions_401_no_authorization_header_for_list_subscriptions + Scenario: No Authorization header for list subscriptions + Given the header "Authorization" is removed + When the request "retrieveGeofencingSubscriptionList" is sent + Then the response status code is 401 + And the response header "Content-Type" is "application/json" + And the response property "$.status" is 401 + And the response property "$.code" is "UNAUTHENTICATED" + And the response property "$.message" contains a user friendly text + + @geofencing_subscriptions_401_expired_access_token_for_list_subscriptions + Scenario: Expired access token for list subscriptions + Given the header "Authorization" is set to an expired access token + When the request "retrieveGeofencingSubscriptionList" is sent + Then the response status code is 401 + And the response header "Content-Type" is "application/json" + And the response property "$.status" is 401 + And the response property "$.code" is "UNAUTHENTICATED" + And the response property "$.message" contains a user friendly text + + @geofencing_subscriptions_401_invalid_access_token_for_list_subscriptions + Scenario: Invalid access token for list subscriptions + Given the header "Authorization" is set to an invalid access token + When the request "retrieveGeofencingSubscriptionList" is sent + Then the response status code is 401 + And the response header "Content-Type" is "application/json" + And the response property "$.status" is 401 + And the response property "$.code" is "UNAUTHENTICATED" + And the response property "$.message" contains a user friendly text