fix: stop the end-to-end suite failing on its own transport check
The device routes were given a rule refusing unencrypted requests unless DEVICE_ALLOW_HTTP says otherwise. The test harness serves plain http on localhost, so /api/display started answering 403 and "changing today's hours reaches the panel" failed. The harness now sets the flag, which is honest: it has no TLS to offer. The refusal itself stays covered by lib/device/transport.test.ts, where the transport can be varied per request rather than per server. This is the failure CI existed to catch, and it caught it. I ran the unit tests after adding that rule and not the end-to-end suite, then pushed three more times on top. The device API is exactly the surface where only the end-to-end tests exercise the real request path. The workflow actions are bumped at the same time: checkout and setup-node v4 target Node 20 and were being forced onto Node 24, which the run annotated as deprecated on every build. A warning nobody reads becomes a failure eventually. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
This commit is contained in:
@@ -72,6 +72,11 @@ export default defineConfig({
|
||||
AUTH_URL: BASE_URL,
|
||||
AUTH_SECRET: E2E_AUTH_SECRET,
|
||||
AUTHENTIK_ADMIN_GROUP: 'horaires-admins',
|
||||
// The harness serves over plain http on localhost, so the device routes
|
||||
// would refuse every request. The refusal itself is covered by the unit
|
||||
// tests in lib/device/transport.test.ts, where the transport can be
|
||||
// varied per request instead of per server.
|
||||
DEVICE_ALLOW_HTTP: 'true',
|
||||
// Placeholders, never contacted: the suite mints its own session cookie.
|
||||
// They exist so the provider builds and the sign-in page renders its
|
||||
// normal button — CI has no .env to inherit these from.
|
||||
|
||||
Reference in New Issue
Block a user