From 3146e29ffb642a9b10855b24fe778e384342c7db Mon Sep 17 00:00:00 2001 From: vl Date: Tue, 22 Sep 2026 10:08:45 +0200 Subject: [PATCH] fix: stop the end-to-end suite failing on its own transport check The device routes were given a rule refusing unencrypted requests unless DEVICE_ALLOW_HTTP says otherwise. The test harness serves plain http on localhost, so /api/display started answering 403 and "changing today's hours reaches the panel" failed. The harness now sets the flag, which is honest: it has no TLS to offer. The refusal itself stays covered by lib/device/transport.test.ts, where the transport can be varied per request rather than per server. This is the failure CI existed to catch, and it caught it. I ran the unit tests after adding that rule and not the end-to-end suite, then pushed three more times on top. The device API is exactly the surface where only the end-to-end tests exercise the real request path. The workflow actions are bumped at the same time: checkout and setup-node v4 target Node 20 and were being forced onto Node 24, which the run annotated as deprecated on every build. A warning nobody reads becomes a failure eventually. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd --- .github/workflows/ci.yml | 16 ++++++++-------- playwright.config.ts | 5 +++++ 2 files changed, 13 insertions(+), 8 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index bb62910..c70151e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -37,8 +37,8 @@ jobs: TEST_DATABASE_URL: postgresql://horaires:horaires@localhost:5432/horaires_test?schema=public steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@v7 + - uses: actions/setup-node@v7 with: node-version: '22' cache: npm @@ -74,8 +74,8 @@ jobs: TEST_DATABASE_URL: postgresql://horaires:horaires@localhost:5432/horaires_e2e?schema=public steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@v7 + - uses: actions/setup-node@v7 with: node-version: '22' cache: npm @@ -85,7 +85,7 @@ jobs: # The runner can install the system packages a local machine cannot. - run: npx playwright install --with-deps chromium - run: npm run e2e - - uses: actions/upload-artifact@v4 + - uses: actions/upload-artifact@v7 if: failure() with: name: playwright-report @@ -96,10 +96,10 @@ jobs: name: Docker image runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: docker/setup-buildx-action@v3 + - uses: actions/checkout@v7 + - uses: docker/setup-buildx-action@v4 - name: Build the runtime image - uses: docker/build-push-action@v6 + uses: docker/build-push-action@v7 with: context: . push: false diff --git a/playwright.config.ts b/playwright.config.ts index a7bfb61..f576775 100644 --- a/playwright.config.ts +++ b/playwright.config.ts @@ -72,6 +72,11 @@ export default defineConfig({ AUTH_URL: BASE_URL, AUTH_SECRET: E2E_AUTH_SECRET, AUTHENTIK_ADMIN_GROUP: 'horaires-admins', + // The harness serves over plain http on localhost, so the device routes + // would refuse every request. The refusal itself is covered by the unit + // tests in lib/device/transport.test.ts, where the transport can be + // varied per request instead of per server. + DEVICE_ALLOW_HTTP: 'true', // Placeholders, never contacted: the suite mints its own session cookie. // They exist so the provider builds and the sign-in page renders its // normal button — CI has no .env to inherit these from.