Files
Oxicloud/tests/e2e/spa/auth.spec.ts
T
Bradley Nelson e3823ce470 test(e2e): Playwright + Vitest coverage harness and test instrumentation
Add an end-to-end and unit test suite for the SvelteKit frontend:

- Playwright e2e specs (tests/e2e/spa) with a throwaway container stack,
  codegen scenarios, and an Istanbul-based coverage report pipeline.
- Vitest unit tests across API endpoints, components, stores and composables.
- `data-testid` hooks on interactive elements (AppShell, FileViewer,
  ShareDialog, search, photos, files breadcrumbs, login/Nextcloud flows,
  public share pages) so the e2e suite can target them deterministically.
- Serve the SPA app-shell CSP from a <meta> policy (svelte.config.js) plus a
  middleware that skips the CSP header on HTML; move the Nextcloud Login Flow
  v2 grant page to the SvelteKit /nextcloud/login route.
- `just front-codegen` recipe and start-server-spa.sh harness.

Make the test environment robust and consistent:
- Install a deterministic in-memory localStorage/sessionStorage in the Vitest
  setup so storage behaves identically across Node versions (Node 26 ships a
  native Web Storage global that otherwise shadows jsdom's).
- Pin devenv to Node 26 + PostgreSQL 18 and pin every CI job to Node 26.3.0
  so the dev shell and CI run the same toolchain versions.

Repair the API/WebDAV (hurl) suite, which had drifted from the backend:
- Migrate the removed `/api/folders/{id}/listing` endpoint to `/resources`
  (cursor-paginated `{items:[{resource_type,resource}]}` shape) across the
  batch-copy, grants, nested-group, and WebDAV NC tests + the dav_helpers
  wipe routine.
- Stop photos_etag from uploading the dedup-tracked fixture so the dedup
  blob-lifecycle test can own its content-addressed blob exclusively.
- dedup_create now asserts the idempotent same-content re-upload (201 +
  existing file id) instead of the stale 409 expectation.

Generated coverage reports, nyc output and the e2e server runtime data dir
are gitignored rather than committed.
2026-06-22 00:05:06 -06:00

54 lines
2.4 KiB
TypeScript

import { test, expect, uiLogin, TEST_ADMIN } from './coverage-helpers';
test.describe('SPA · authentication', () => {
test('login page renders the sign-in form', async ({ page }) => {
await page.goto('/login');
await expect(page.getByTestId('login-form')).toBeVisible();
await expect(page.getByTestId('login-username-input')).toBeVisible();
await expect(page.getByTestId('login-password-input')).toBeVisible();
await expect(page.getByTestId('login-submit-btn')).toBeVisible();
await expect(page).toHaveTitle(/OxiCloud/i);
});
test('wrong password is rejected with an error', async ({ page }) => {
await page.goto('/login');
await page.getByTestId('login-username-input').fill(TEST_ADMIN.username);
await page.getByTestId('login-password-input').fill('definitely-wrong-password');
await page.getByTestId('login-submit-btn').click();
await expect(page.locator('.auth-error[role="alert"]')).toBeVisible();
// Still on the login page — no redirect into the app.
await expect(page.getByTestId('login-form')).toBeVisible();
});
test('register and setup panels are reachable from login', async ({ page }) => {
await page.goto('/login');
await page.getByTestId('login-to-register-btn').click();
await expect(page.getByTestId('login-register-form')).toBeVisible();
await page.getByTestId('login-register-to-login-btn').click();
await expect(page.getByTestId('login-form')).toBeVisible();
});
test('magic-link panel toggles open', async ({ page }) => {
await page.goto('/login');
await page.getByTestId('login-magic-toggle-btn').click();
await expect(page.getByTestId('login-magic-form')).toBeVisible();
await expect(page.getByTestId('login-magic-email-input')).toBeVisible();
});
test('successful login reaches the files app shell', async ({ page }) => {
await uiLogin(page);
await expect(page).toHaveURL(/\/files/);
await expect(page.getByTestId('appshell-logo-link')).toBeVisible();
await expect(page.getByTestId('appshell-user-menu-btn')).toBeVisible();
});
test('logout returns to the login page', async ({ page }) => {
await uiLogin(page);
await page.getByTestId('appshell-user-menu-btn').click();
await page.getByTestId('appshell-user-menu-logout-btn').click();
await page.waitForURL('**/login**', { timeout: 15_000 });
await expect(page.getByTestId('login-form')).toBeVisible();
});
});