import { expect, resetDatabase, signIn, test } from './fixtures'; test.beforeEach(async () => { await resetDatabase(); }); test('an anonymous visitor is sent to the sign-in screen', async ({ page }) => { await page.goto('/admin/horaires'); await expect(page).toHaveURL(/\/login/); await expect(page.getByRole('button', { name: /Se connecter/ })).toBeVisible(); }); test('an anonymous fetch of an admin route gets a status, not a login page', async ({ request }) => { const response = await request.post('/api/admin/holidays/sync'); expect(response.status()).toBe(401); }); test('an administrator reaches the dashboard', async ({ page }) => { await signIn(page, 'admin'); await page.goto('/admin'); await expect(page.getByRole('heading', { name: 'Tableau de bord' })).toBeVisible(); // The header also carries the address but hides it on a narrow screen, so // the assertion targets the line under the heading, which is always shown. await expect(page.getByText(/Connecté en tant que admin@ita-ito\.test/)).toBeVisible(); }); test('a read-only account can look but not change', async ({ page }) => { await signIn(page, 'viewer'); await page.goto('/admin/horaires'); await expect(page.getByText(/lecture seule/i).first()).toBeVisible(); // The save button is not merely disabled; it is not rendered at all. await expect(page.getByRole('button', { name: 'Enregistrer' })).toHaveCount(0); }); test('a read-only account is refused a write by the API', async ({ page, request }) => { await signIn(page, 'viewer'); const cookies = await page.context().cookies(); const response = await request.post('/api/admin/holidays/sync', { headers: { cookie: cookies.map((c) => `${c.name}=${c.value}`).join('; ') }, }); expect(response.status()).toBe(403); }); test('a read-only account can still sign out', async ({ page }) => { // Regression: gating page POSTs by role broke every form for viewers, // sign-out included. await signIn(page, 'viewer'); await page.goto('/admin'); await page.getByRole('button', { name: 'Se déconnecter' }).click(); await expect(page).toHaveURL(/\/login/); });