test(e2e): Playwright + Vitest coverage harness and test instrumentation

Add an end-to-end and unit test suite for the SvelteKit frontend:

- Playwright e2e specs (tests/e2e/spa) with a throwaway container stack,
  codegen scenarios, and an Istanbul-based coverage report pipeline.
- Vitest unit tests across API endpoints, components, stores and composables.
- `data-testid` hooks on interactive elements (AppShell, FileViewer,
  ShareDialog, search, photos, files breadcrumbs, login/Nextcloud flows,
  public share pages) so the e2e suite can target them deterministically.
- Serve the SPA app-shell CSP from a <meta> policy (svelte.config.js) plus a
  middleware that skips the CSP header on HTML; move the Nextcloud Login Flow
  v2 grant page to the SvelteKit /nextcloud/login route.
- `just front-codegen` recipe and start-server-spa.sh harness.

Make the test environment robust and consistent:
- Install a deterministic in-memory localStorage/sessionStorage in the Vitest
  setup so storage behaves identically across Node versions (Node 26 ships a
  native Web Storage global that otherwise shadows jsdom's).
- Pin devenv to Node 26 + PostgreSQL 18 and pin every CI job to Node 26.3.0
  so the dev shell and CI run the same toolchain versions.

Repair the API/WebDAV (hurl) suite, which had drifted from the backend:
- Migrate the removed `/api/folders/{id}/listing` endpoint to `/resources`
  (cursor-paginated `{items:[{resource_type,resource}]}` shape) across the
  batch-copy, grants, nested-group, and WebDAV NC tests + the dav_helpers
  wipe routine.
- Stop photos_etag from uploading the dedup-tracked fixture so the dedup
  blob-lifecycle test can own its content-addressed blob exclusively.
- dedup_create now asserts the idempotent same-content re-upload (201 +
  existing file id) instead of the stale 409 expectation.

Generated coverage reports, nyc output and the e2e server runtime data dir
are gitignored rather than committed.
This commit is contained in:
Bradley Nelson
2026-06-21 20:03:32 -06:00
parent 0c40c69f9b
commit e3823ce470
162 changed files with 13213 additions and 554 deletions
+11 -5
View File
@@ -104,15 +104,21 @@ jsonpath "$.successful[0].files_copied" == 1
# ─────────────────────────────────────────────────────────────
# Step 6 – Verify the copied folder is inside the target folder
# ─────────────────────────────────────────────────────────────
GET {{base_url}}/api/folders/{{target_folder_id}}/listing
GET {{base_url}}/api/folders/{{target_folder_id}}/resources?resource_types=folder
Authorization: Bearer {{token}}
HTTP 200
[Asserts]
jsonpath "$.folders" count == 1
jsonpath "$.folders[0].id" == "{{new_root_folder_id}}"
jsonpath "$.folders[0].name" == "hurl-copy-source"
jsonpath "$.files" count == 0
jsonpath "$.items" count == 1
jsonpath "$.items[0].resource.id" == "{{new_root_folder_id}}"
jsonpath "$.items[0].resource.name" == "hurl-copy-source"
GET {{base_url}}/api/folders/{{target_folder_id}}/resources?resource_types=file
Authorization: Bearer {{token}}
HTTP 200
[Asserts]
jsonpath "$.items" count == 0
# ─────────────────────────────────────────────────────────────
+13 -6
View File
@@ -78,11 +78,15 @@ jsonpath "$.content_hash" == "b2208c5dc33ff951227bd0c139f5eccb04105d6da6a7519ee2
# ─────────────────────────────────────────────────────────────
# Step 4 — Duplicate-name probe (incidental but useful): try
# uploading the same fixture again, same name, same
# folder → 409 Conflict. This catches the (folder_id,
# name, user_id) WHERE NOT is_trashed unique index in
# `storage.files`.
# Step 4 — Idempotent re-upload: re-POSTing the same fixture (same
# folder, same name, IDENTICAL content/BLAKE3) is a no-op
# that returns the EXISTING file row, not a 409. See the
# idempotency branch in save_file_with_blob
# (file_blob_write_repository.rs): a (folder_id, name)
# unique clash whose content hash matches resolves to the
# existing file so re-uploading a partially-transferred
# folder is clean; only a same-name upload with DIFFERENT
# content still returns 409.
# ─────────────────────────────────────────────────────────────
POST {{base_url}}/api/files/upload
Authorization: Bearer {{token}}
@@ -90,7 +94,10 @@ Authorization: Bearer {{token}}
folder_id: {{home_folder_id}}
file: file,fixtures/hello-copy.txt; text/plain
HTTP 409
HTTP 201
[Asserts]
jsonpath "$.id" == "{{seed_file_id}}"
jsonpath "$.content_hash" == "{{seed_content_hash}}"
# ─────────────────────────────────────────────────────────────
+2 -2
View File
@@ -424,7 +424,7 @@ Authorization: Bearer {{adam_token}}
HTTP 404
GET {{base_url}}/api/folders/{{perm_folder_id}}/listing
GET {{base_url}}/api/folders/{{perm_folder_id}}/resources
Authorization: Bearer {{adam_token}}
HTTP 404
@@ -547,7 +547,7 @@ Authorization: Bearer {{adam_token}}
HTTP 200
GET {{base_url}}/api/folders/{{perm_folder_id}}/listing
GET {{base_url}}/api/folders/{{perm_folder_id}}/resources
Authorization: Bearer {{adam_token}}
HTTP 200
+2 -2
View File
@@ -164,7 +164,7 @@ Authorization: Bearer {{henry_token}}
HTTP 404
GET {{base_url}}/api/folders/{{perm_folder_id}}/listing
GET {{base_url}}/api/folders/{{perm_folder_id}}/resources
Authorization: Bearer {{henry_token}}
HTTP 404
@@ -303,7 +303,7 @@ Authorization: Bearer {{henry_token}}
HTTP 200
GET {{base_url}}/api/folders/{{perm_folder_id}}/listing
GET {{base_url}}/api/folders/{{perm_folder_id}}/resources
Authorization: Bearer {{henry_token}}
HTTP 200
+6 -2
View File
@@ -37,13 +37,17 @@ home_folder_id: jsonpath "$[0].id"
# ─────────────────────────────────────────────────────────────
# Step 3 – Upload an image so the photos timeline is non-empty
# Step 3 – Upload an image so the photos timeline is non-empty.
# Uses oxicloud-logo.jpg (not dedup-test.jpg): the dedup
# blob-lifecycle test asserts an exact ref_count on the
# dedup-test.jpg blob and must own it exclusively, and
# blobs are content-addressed (shared across the suite).
# ─────────────────────────────────────────────────────────────
POST {{base_url}}/api/files/upload
Authorization: Bearer {{token}}
[MultipartFormData]
folder_id: {{home_folder_id}}
file: file,fixtures/dedup-test.jpg; image/jpeg
file: file,fixtures/oxicloud-logo.jpg; image/jpeg
HTTP 201