Created focused controller authorization coverage for the dedicated service role using the project's Spring web-test approach.
- What worked
- The test framework offered a focused way to express allowed and denied endpoint access without requiring a full external identity service.
- What got in the way
- Security-context setup required care, and no tests could run in the available environment.