test: add the end-to-end suite, on desktop and on a phone
Twenty-six tests across two viewports, covering what the spec asks for: changing today's hours reaches the panel, a message survives the translation service being unavailable, a closure period closes the days it covers — plus the authorisation paths and the sign-out regression. They run against the standalone build served the way the container serves it, not `next start`, which refuses to work with standalone output anyway. The suite therefore exercises the artifact that ships rather than a second arrangement that could drift from it. Sign-in mints the session cookie Auth.js would have issued rather than driving Authentik. What is under test is the application's behaviour for a given role; the handshake itself is verified against the live provider separately, and standing up an identity provider per run would trade a lot of machinery for coverage of somebody else's code. The secret lives in one module imported by both the config and the fixtures — when it differed, every signed-in test failed at once while looking like an authorisation bug. Database access goes through plain SQL rather than the Prisma client, whose generated module format Playwright's loader and Next's bundler disagree about. That traded one problem for a subtler one: node-postgres parses a DATE column into a local-midnight Date, so reading it back shifted the day at UTC+2. Dates are read as text now. The mobile profile runs on Chromium: WebKit needs system packages only root can install, and a suite nobody can run locally is a suite nobody runs. The config says how to switch to the real engine. Two real defects surfaced, both found by the tests rather than by reading. The seven "Ouvert" checkboxes on the hours page were indistinguishable to a screen reader; each now names its day. And on a phone the signed-in address appeared nowhere at all — the header hides it to save room — so nobody could tell which account was about to sign an audit entry on a device the shop shares. It is on the dashboard now. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
This commit is contained in:
+114
@@ -0,0 +1,114 @@
|
||||
import { randomUUID } from 'node:crypto';
|
||||
|
||||
import { encode } from '@auth/core/jwt';
|
||||
import { test as base, type Page } from '@playwright/test';
|
||||
import { Pool } from 'pg';
|
||||
|
||||
import { generateDeviceToken, hashToken } from '../lib/device/auth';
|
||||
import { E2E_AUTH_SECRET } from './constants';
|
||||
|
||||
/**
|
||||
* Database access for the end-to-end suite, over plain SQL.
|
||||
*
|
||||
* Deliberately not the Prisma client: it is generated as a TypeScript module
|
||||
* whose format Playwright's loader and Next's bundler disagree about, and the
|
||||
* suite only needs to empty a handful of tables and read a few rows back.
|
||||
* Raw SQL costs a few lines and removes the argument entirely.
|
||||
*/
|
||||
|
||||
let pool: Pool | undefined;
|
||||
|
||||
function db(): Pool {
|
||||
pool ??= new Pool({ connectionString: process.env.TEST_DATABASE_URL });
|
||||
return pool;
|
||||
}
|
||||
|
||||
export async function query<T = Record<string, unknown>>(
|
||||
text: string,
|
||||
values: unknown[] = [],
|
||||
): Promise<T[]> {
|
||||
const result = await db().query(text, values);
|
||||
return result.rows as T[];
|
||||
}
|
||||
|
||||
/**
|
||||
* Signing in without Authentik.
|
||||
*
|
||||
* Mints the session cookie Auth.js would have issued after a successful round
|
||||
* trip. What is under test is the application's behaviour for a given role;
|
||||
* the OIDC handshake is verified against the live provider separately, and
|
||||
* standing up an identity provider per test run would trade a lot of
|
||||
* machinery for coverage of somebody else's code.
|
||||
*/
|
||||
const COOKIE_NAME = 'authjs.session-token';
|
||||
|
||||
export type Role = 'admin' | 'viewer';
|
||||
|
||||
export async function signIn(page: Page, role: Role = 'admin'): Promise<void> {
|
||||
const token = await encode({
|
||||
secret: E2E_AUTH_SECRET,
|
||||
// Auth.js derives its encryption key from the cookie name.
|
||||
salt: COOKIE_NAME,
|
||||
maxAge: 3600,
|
||||
token: {
|
||||
sub: `e2e-${role}`,
|
||||
name: role === 'admin' ? 'Admin E2E' : 'Viewer E2E',
|
||||
email: `${role}@ita-ito.test`,
|
||||
role,
|
||||
groups: role === 'admin' ? ['horaires-admins'] : ['autre-groupe'],
|
||||
},
|
||||
});
|
||||
|
||||
await page.context().addCookies([
|
||||
{ name: COOKIE_NAME, value: token, domain: '127.0.0.1', path: '/', httpOnly: true },
|
||||
]);
|
||||
}
|
||||
|
||||
const WEEK: [number, boolean, string][] = [
|
||||
[0, true, '[]'],
|
||||
[1, true, '[]'],
|
||||
[2, false, '[{"open":"10:00","close":"18:30"}]'],
|
||||
[3, false, '[{"open":"10:00","close":"18:30"}]'],
|
||||
[4, false, '[{"open":"10:00","close":"18:30"}]'],
|
||||
[5, false, '[{"open":"10:00","close":"18:30"}]'],
|
||||
[6, false, '[{"open":"10:00","close":"18:30"}]'],
|
||||
];
|
||||
|
||||
/** Empties everything and restores a known week. */
|
||||
export async function resetDatabase(): Promise<void> {
|
||||
await query(`
|
||||
TRUNCATE device_logs, devices, screen_images, schedule_exceptions, vacation_periods,
|
||||
public_holidays, messages, translation_cache, audit_logs, weekly_schedules,
|
||||
settings, sync_states RESTART IDENTITY CASCADE
|
||||
`);
|
||||
|
||||
await query(`INSERT INTO settings (id, "updatedAt") VALUES ('singleton', now())`);
|
||||
|
||||
for (const [dayOfWeek, isClosed, slots] of WEEK) {
|
||||
await query(
|
||||
`INSERT INTO weekly_schedules (id, "dayOfWeek", "isClosed", slots) VALUES ($1, $2, $3, $4::jsonb)`,
|
||||
[randomUUID(), dayOfWeek, isClosed, slots],
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/** Pairs a panel and hands back its token, so the device API can be called. */
|
||||
export async function pairDevice(): Promise<string> {
|
||||
const token = generateDeviceToken();
|
||||
await query(
|
||||
`INSERT INTO devices (id, "macAddress", "friendlyId", "apiKeyHash", "updatedAt")
|
||||
VALUES ($1, $2, $3, $4, now())`,
|
||||
[randomUUID(), 'E2:E0:00:00:00:01', 'E2E001', hashToken(token)],
|
||||
);
|
||||
return token;
|
||||
}
|
||||
|
||||
/** Today as the shop reads it, which is not necessarily as the runner does. */
|
||||
export function today(offsetDays = 0): string {
|
||||
return new Intl.DateTimeFormat('en-CA', { timeZone: 'Europe/Zurich' }).format(
|
||||
new Date(Date.now() + offsetDays * 86_400_000),
|
||||
);
|
||||
}
|
||||
|
||||
export const test = base;
|
||||
export { expect } from '@playwright/test';
|
||||
Reference in New Issue
Block a user