test(e2e): Playwright + Vitest coverage harness and test instrumentation
Add an end-to-end and unit test suite for the SvelteKit frontend:
- Playwright e2e specs (tests/e2e/spa) with a throwaway container stack,
codegen scenarios, and an Istanbul-based coverage report pipeline.
- Vitest unit tests across API endpoints, components, stores and composables.
- `data-testid` hooks on interactive elements (AppShell, FileViewer,
ShareDialog, search, photos, files breadcrumbs, login/Nextcloud flows,
public share pages) so the e2e suite can target them deterministically.
- Serve the SPA app-shell CSP from a <meta> policy (svelte.config.js) plus a
middleware that skips the CSP header on HTML; move the Nextcloud Login Flow
v2 grant page to the SvelteKit /nextcloud/login route.
- `just front-codegen` recipe and start-server-spa.sh harness.
Make the test environment robust and consistent:
- Install a deterministic in-memory localStorage/sessionStorage in the Vitest
setup so storage behaves identically across Node versions (Node 26 ships a
native Web Storage global that otherwise shadows jsdom's).
- Pin devenv to Node 26 + PostgreSQL 18 and pin every CI job to Node 26.3.0
so the dev shell and CI run the same toolchain versions.
Repair the API/WebDAV (hurl) suite, which had drifted from the backend:
- Migrate the removed `/api/folders/{id}/listing` endpoint to `/resources`
(cursor-paginated `{items:[{resource_type,resource}]}` shape) across the
batch-copy, grants, nested-group, and WebDAV NC tests + the dav_helpers
wipe routine.
- Stop photos_etag from uploading the dedup-tracked fixture so the dedup
blob-lifecycle test can own its content-addressed blob exclusively.
- dedup_create now asserts the idempotent same-content re-upload (201 +
existing file id) instead of the stale 409 expectation.
Generated coverage reports, nyc output and the e2e server runtime data dir
are gitignored rather than committed.
This commit is contained in:
@@ -2,7 +2,7 @@ use askama::Template;
|
||||
use axum::{
|
||||
extract::{Path, Query, State},
|
||||
http::{HeaderMap, StatusCode, header},
|
||||
response::{Html, IntoResponse, Json, Response},
|
||||
response::{Html, IntoResponse, Json, Redirect, Response},
|
||||
};
|
||||
use serde_json::json;
|
||||
use std::collections::HashMap;
|
||||
@@ -29,31 +29,12 @@ struct DrivePickerTemplate {
|
||||
drives: Vec<DriveOption>,
|
||||
}
|
||||
|
||||
/// The Nextcloud Login Flow v2 "Grant Access" page. Rendered server-side via
|
||||
/// askama (no template variables — the username/password are collected by the
|
||||
/// embedded form); the template is embedded at compile time by the derive macro.
|
||||
#[derive(Template)]
|
||||
#[template(path = "nextcloud/login.html")]
|
||||
struct NextcloudLoginTemplate;
|
||||
|
||||
// Home identification is via `position_of_user_home_root_folder` from
|
||||
// `domain::repositories::drive_repository` — a generic helper that
|
||||
// keys off `drives.default_for_user == user_id` rather than folder
|
||||
// name, so user renames of the home folder don't silently break the
|
||||
// picker UX.
|
||||
|
||||
/// Serve an HTML page with a Content-Security-Policy header as defense-in-depth.
|
||||
fn html_with_csp(html: String) -> Response {
|
||||
(
|
||||
[(
|
||||
header::CONTENT_SECURITY_POLICY,
|
||||
"default-src 'none'; script-src 'unsafe-inline'; style-src 'self' 'unsafe-inline'; connect-src 'self'; form-action 'self'",
|
||||
)],
|
||||
Html(html),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
|
||||
pub async fn handle_login_initiate(State(state): State<Arc<AppState>>) -> Response {
|
||||
let nextcloud = match state.nextcloud.as_ref() {
|
||||
Some(nextcloud) => nextcloud,
|
||||
@@ -167,13 +148,10 @@ pub async fn handle_login_page(
|
||||
return StatusCode::NOT_FOUND.into_response();
|
||||
}
|
||||
|
||||
match NextcloudLoginTemplate.render() {
|
||||
Ok(html) => html_with_csp(html),
|
||||
Err(e) => {
|
||||
tracing::error!(error = %e, "Login Flow v2: login page template render failed");
|
||||
StatusCode::INTERNAL_SERVER_ERROR.into_response()
|
||||
}
|
||||
}
|
||||
// The grant-access page is now owned by the SvelteKit SPA at
|
||||
// /nextcloud/login; redirect the client's browser there with the flow
|
||||
// token. The page POSTs back to /login/v2/flow/{token} (handle_login_submit).
|
||||
Redirect::to(&format!("/nextcloud/login?token={token}")).into_response()
|
||||
}
|
||||
|
||||
pub async fn handle_login_submit(
|
||||
|
||||
+53
-12
@@ -59,7 +59,7 @@ use common::di::AppServiceFactory;
|
||||
use infrastructure::db::create_database_pools;
|
||||
use interfaces::{
|
||||
create_api_routes, create_health_routes, create_public_api_routes,
|
||||
web::{content_security_policy, create_web_routes, resolve_static_path},
|
||||
web::{create_web_routes, resolve_static_path},
|
||||
};
|
||||
|
||||
fn parse_addr(host: &str, port: u16) -> Result<SocketAddr, String> {
|
||||
@@ -804,18 +804,59 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
|
||||
use axum::http::HeaderValue;
|
||||
use axum::http::header::HeaderName;
|
||||
|
||||
// Content-Security-Policy is content-type-aware.
|
||||
//
|
||||
// HTML documents are served by the SvelteKit SPA, which emits its OWN
|
||||
// strict, hash-based CSP via a <meta> tag (see `kit.csp` in
|
||||
// frontend/svelte.config.js). SvelteKit's inline bootstrap script is
|
||||
// hashed per build, so a static `script-src 'self'` header here would
|
||||
// block it and blank the app. We therefore do NOT send a CSP header on
|
||||
// text/html responses and let the SPA's meta policy govern them.
|
||||
//
|
||||
// Every other response (API JSON, DAV XML, static JS/CSS/img) gets the
|
||||
// strict header below. Notes:
|
||||
// • style-src 'unsafe-inline': the frontend sets inline styles at
|
||||
// runtime (e.g. element.style.display); hashes can't cover those.
|
||||
// • frame-src '*': only matches network schemes, so 'blob:' is listed
|
||||
// explicitly for inline PDF/document viewers.
|
||||
// • media-src 'blob:': needed for blob: video/audio playback.
|
||||
// • form-action 'https:': the WOPI office editor is launched by POSTing a
|
||||
// token form to a cross-origin, admin-configured Collabora/OnlyOffice
|
||||
// host. Mirrors the SPA meta policy in frontend/svelte.config.js.
|
||||
async fn content_security_policy(
|
||||
req: axum::extract::Request,
|
||||
next: axum::middleware::Next,
|
||||
) -> axum::response::Response {
|
||||
let mut res = next.run(req).await;
|
||||
let is_html = res
|
||||
.headers()
|
||||
.get(axum::http::header::CONTENT_TYPE)
|
||||
.and_then(|v| v.to_str().ok())
|
||||
.is_some_and(|v| v.starts_with("text/html"));
|
||||
if !is_html {
|
||||
res.headers_mut().insert(
|
||||
axum::http::header::CONTENT_SECURITY_POLICY,
|
||||
HeaderValue::from_static(
|
||||
"default-src 'self'; \
|
||||
script-src 'self'; \
|
||||
worker-src 'self'; \
|
||||
style-src 'self' 'unsafe-inline'; \
|
||||
img-src 'self' data: blob: https:; \
|
||||
media-src 'self' blob:; \
|
||||
connect-src 'self'; \
|
||||
font-src 'self' data:; \
|
||||
frame-src * blob:; \
|
||||
frame-ancestors 'none'; \
|
||||
base-uri 'self'; \
|
||||
form-action 'self' https:",
|
||||
),
|
||||
);
|
||||
}
|
||||
res
|
||||
}
|
||||
|
||||
app = app
|
||||
.layer(SetResponseHeaderLayer::overriding(
|
||||
HeaderName::from_static("content-security-policy"),
|
||||
// Built at startup: script-src is 'self' plus a SHA-256 hash for
|
||||
// every inline <script> in the served HTML, so the policy stays
|
||||
// strict (no 'unsafe-inline' for scripts) while the SvelteKit SPA's
|
||||
// inline bootstrap can still run. The full directive set, and why
|
||||
// style-src/frame-src/media-src look the way they do, live in
|
||||
// interfaces::web::content_security_policy.
|
||||
HeaderValue::from_str(&content_security_policy(&config))
|
||||
.expect("CSP header value contains only ASCII"),
|
||||
))
|
||||
.layer(axum::middleware::from_fn(content_security_policy))
|
||||
.layer(SetResponseHeaderLayer::overriding(
|
||||
HeaderName::from_static("x-content-type-options"),
|
||||
HeaderValue::from_static("nosniff"),
|
||||
|
||||
Reference in New Issue
Block a user