···5050 }
51515252 // Test using access token for a private repo that the user of the token owns
5353- req := NewRequestf(t, "GET", "/api/v1/repos/%s/%s/git/trees/%s?token=%s", user2.Name, repo16.Name, repo16TreeSHA, token)
5353+ req := NewRequestf(t, "GET", "/api/v1/repos/%s/%s/git/trees/%s", user2.Name, repo16.Name, repo16TreeSHA).
5454+ AddTokenAuth(token)
5455 MakeRequest(t, req, http.StatusOK)
55565657 // Test using bad sha
···5859 MakeRequest(t, req, http.StatusBadRequest)
59606061 // Test using org repo "org3/repo3" where user2 is a collaborator
6161- req = NewRequestf(t, "GET", "/api/v1/repos/%s/%s/git/trees/%s?token=%s", org3.Name, repo3.Name, repo3TreeSHA, token)
6262+ req = NewRequestf(t, "GET", "/api/v1/repos/%s/%s/git/trees/%s", org3.Name, repo3.Name, repo3TreeSHA).
6363+ AddTokenAuth(token)
6264 MakeRequest(t, req, http.StatusOK)
63656466 // Test using org repo "org3/repo3" with no user token
···169169 Units: []string{"repo.code"},
170170 }
171171172172- req = NewRequestWithJSON(t, "POST",
173173- fmt.Sprintf("/api/v1/orgs/%s/teams?token=%s", orgName, token), teamToCreate)
172172+ req = NewRequestWithJSON(t, "POST", fmt.Sprintf("/api/v1/orgs/%s/teams", orgName), teamToCreate).
173173+ AddTokenAuth(token)
174174175175 var apiTeam api.Team
176176···183183 // teamID := apiTeam.ID
184184185185 // Now we need to add the restricted user to the team
186186- req = NewRequest(t, "PUT",
187187- fmt.Sprintf("/api/v1/teams/%d/members/%s?token=%s", apiTeam.ID, restrictedUser, token))
186186+ req = NewRequest(t, "PUT", fmt.Sprintf("/api/v1/teams/%d/members/%s", apiTeam.ID, restrictedUser)).
187187+ AddTokenAuth(token)
188188 _ = adminSession.MakeRequest(t, req, http.StatusNoContent)
189189190190 // Now we need to check if the restrictedUser can access the repo
···218218219219 // Use API to create a conflicting pr
220220 token := getTokenForLoggedInUser(t, session, auth_model.AccessTokenScopeWriteRepository)
221221- req := NewRequestWithJSON(t, http.MethodPost, fmt.Sprintf("/api/v1/repos/%s/%s/pulls?token=%s", "user1", "repo1", token), &api.CreatePullRequestOption{
221221+ req := NewRequestWithJSON(t, http.MethodPost, fmt.Sprintf("/api/v1/repos/%s/%s/pulls", "user1", "repo1"), &api.CreatePullRequestOption{
222222 Head: "conflict",
223223 Base: "base",
224224 Title: "create a conflicting pr",
225225- })
225225+ }).AddTokenAuth(token)
226226 session.MakeRequest(t, req, http.StatusCreated)
227227228228 // Now this PR will be marked conflict - or at least a race will do - so drop down to pure code at this point...
···326326327327 // Use API to create a conflicting pr
328328 token := getTokenForLoggedInUser(t, session, auth_model.AccessTokenScopeWriteRepository)
329329- req := NewRequestWithJSON(t, http.MethodPost, fmt.Sprintf("/api/v1/repos/%s/%s/pulls?token=%s", "user1", "repo1", token), &api.CreatePullRequestOption{
329329+ req := NewRequestWithJSON(t, http.MethodPost, fmt.Sprintf("/api/v1/repos/%s/%s/pulls", "user1", "repo1"), &api.CreatePullRequestOption{
330330 Head: "unrelated",
331331 Base: "base",
332332 Title: "create an unrelated pr",
333333- })
333333+ }).AddTokenAuth(token)
334334 session.MakeRequest(t, req, http.StatusCreated)
335335336336 // Now this PR could be marked conflict - or at least a race may occur - so drop down to pure code at this point...