Files
ita-ito-horaires/.github/workflows/ci.yml
T
vliaudatandClaude Opus 5 3146e29ffb fix: stop the end-to-end suite failing on its own transport check
The device routes were given a rule refusing unencrypted requests unless
DEVICE_ALLOW_HTTP says otherwise. The test harness serves plain http on
localhost, so /api/display started answering 403 and "changing today's
hours reaches the panel" failed.

The harness now sets the flag, which is honest: it has no TLS to offer.
The refusal itself stays covered by lib/device/transport.test.ts, where
the transport can be varied per request rather than per server.

This is the failure CI existed to catch, and it caught it. I ran the
unit tests after adding that rule and not the end-to-end suite, then
pushed three more times on top. The device API is exactly the surface
where only the end-to-end tests exercise the real request path.

The workflow actions are bumped at the same time: checkout and
setup-node v4 target Node 20 and were being forced onto Node 24, which
the run annotated as deprecated on every build. A warning nobody reads
becomes a failure eventually.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
2026-09-22 10:08:45 +02:00

108 lines
2.9 KiB
YAML

name: CI
on:
push:
branches: [main]
pull_request:
# A superseded run has nothing left to prove; stop it and free the runner.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
quality:
name: Lint, typecheck, tests
runs-on: ubuntu-latest
# The integration tests exercise the device API against a real database.
# Mocking Prisma here would only prove the mock works.
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: horaires_test
POSTGRES_USER: horaires
POSTGRES_PASSWORD: horaires
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U horaires -d horaires_test"
--health-interval 5s
--health-timeout 5s
--health-retries 20
env:
DATABASE_URL: postgresql://horaires:horaires@localhost:5432/horaires_test?schema=public
TEST_DATABASE_URL: postgresql://horaires:horaires@localhost:5432/horaires_test?schema=public
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: '22'
cache: npm
- run: npm ci
- run: npx prisma generate
- run: npx prisma migrate deploy
- run: npm run lint
- run: npm run typecheck
- run: npm run coverage
- run: npm run build
e2e:
name: End-to-end
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: horaires_e2e
POSTGRES_USER: horaires
POSTGRES_PASSWORD: horaires
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U horaires -d horaires_e2e"
--health-interval 5s
--health-timeout 5s
--health-retries 20
env:
DATABASE_URL: postgresql://horaires:horaires@localhost:5432/horaires_e2e?schema=public
TEST_DATABASE_URL: postgresql://horaires:horaires@localhost:5432/horaires_e2e?schema=public
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: '22'
cache: npm
- run: npm ci
- run: npx prisma generate
- run: npx prisma migrate deploy
# The runner can install the system packages a local machine cannot.
- run: npx playwright install --with-deps chromium
- run: npm run e2e
- uses: actions/upload-artifact@v7
if: failure()
with:
name: playwright-report
path: playwright-report/
retention-days: 7
docker:
name: Docker image
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: docker/setup-buildx-action@v4
- name: Build the runtime image
uses: docker/build-push-action@v7
with:
context: .
push: false
cache-from: type=gha
cache-to: type=gha,mode=max