e3823ce470
Add an end-to-end and unit test suite for the SvelteKit frontend:
- Playwright e2e specs (tests/e2e/spa) with a throwaway container stack,
codegen scenarios, and an Istanbul-based coverage report pipeline.
- Vitest unit tests across API endpoints, components, stores and composables.
- `data-testid` hooks on interactive elements (AppShell, FileViewer,
ShareDialog, search, photos, files breadcrumbs, login/Nextcloud flows,
public share pages) so the e2e suite can target them deterministically.
- Serve the SPA app-shell CSP from a <meta> policy (svelte.config.js) plus a
middleware that skips the CSP header on HTML; move the Nextcloud Login Flow
v2 grant page to the SvelteKit /nextcloud/login route.
- `just front-codegen` recipe and start-server-spa.sh harness.
Make the test environment robust and consistent:
- Install a deterministic in-memory localStorage/sessionStorage in the Vitest
setup so storage behaves identically across Node versions (Node 26 ships a
native Web Storage global that otherwise shadows jsdom's).
- Pin devenv to Node 26 + PostgreSQL 18 and pin every CI job to Node 26.3.0
so the dev shell and CI run the same toolchain versions.
Repair the API/WebDAV (hurl) suite, which had drifted from the backend:
- Migrate the removed `/api/folders/{id}/listing` endpoint to `/resources`
(cursor-paginated `{items:[{resource_type,resource}]}` shape) across the
batch-copy, grants, nested-group, and WebDAV NC tests + the dav_helpers
wipe routine.
- Stop photos_etag from uploading the dedup-tracked fixture so the dedup
blob-lifecycle test can own its content-addressed blob exclusively.
- dedup_create now asserts the idempotent same-content re-upload (201 +
existing file id) instead of the stale 409 expectation.
Generated coverage reports, nyc output and the e2e server runtime data dir
are gitignored rather than committed.
71 lines
3.1 KiB
TypeScript
71 lines
3.1 KiB
TypeScript
import { test, expect } from './coverage-helpers';
|
|
|
|
/**
|
|
* Login route — register and magic-link flows (logged out). Exercises the
|
|
* register/magic submit handlers in the login page + auth endpoints.
|
|
*/
|
|
function uniq(p: string): string {
|
|
return `${p}-${Date.now()}-${Math.floor(Math.random() * 1e6)}`;
|
|
}
|
|
|
|
test('register a new account from the login page', async ({ page }) => {
|
|
const u = uniq('reg');
|
|
await page.goto('/login');
|
|
await page.getByTestId('login-to-register-btn').click();
|
|
await expect(page.getByTestId('login-register-form')).toBeVisible();
|
|
|
|
await page.getByTestId('login-register-username-input').fill(u);
|
|
await page.getByTestId('login-register-email-input').fill(`${u}@example.test`);
|
|
await page.getByTestId('login-register-password-input').fill('TestPassword1!');
|
|
await page.getByTestId('login-register-confirm-input').fill('TestPassword1!');
|
|
await page.getByTestId('login-register-submit-btn').click();
|
|
|
|
// Either we land in the app or a notice/error appears — both run onRegister.
|
|
await expect(
|
|
page
|
|
.getByTestId('appshell-logo-link')
|
|
.or(page.locator('.auth-error'))
|
|
.or(page.getByTestId('login-register-form'))
|
|
.first(),
|
|
).toBeVisible({ timeout: 15_000 });
|
|
});
|
|
|
|
// Note: the first-run setup panel is unreachable here — `login-to-setup-btn`
|
|
// only renders when no admin exists, but the test env always seeds one.
|
|
|
|
test('register with mismatched passwords shows a validation error', async ({ page }) => {
|
|
await page.goto('/login');
|
|
await page.getByTestId('login-to-register-btn').click();
|
|
await expect(page.getByTestId('login-register-form')).toBeVisible();
|
|
|
|
await page.getByTestId('login-register-username-input').fill(uniq('mm'));
|
|
await page.getByTestId('login-register-email-input').fill('mm@example.test');
|
|
await page.getByTestId('login-register-password-input').fill('TestPassword1!');
|
|
await page.getByTestId('login-register-confirm-input').fill('Different1!');
|
|
await page.getByTestId('login-register-submit-btn').click();
|
|
|
|
// Client-side validation rejects the mismatch before any request.
|
|
await expect(page.locator('.auth-error[role="alert"]')).toBeVisible({ timeout: 5_000 });
|
|
});
|
|
|
|
test('an oidc callback code is exchanged on load', async ({ page }) => {
|
|
// Landing with ?oidc_code triggers the SPA's OIDC code-exchange path; a bogus
|
|
// code fails and falls back to the login form (exercises the handler).
|
|
await page.goto('/login?oidc_code=fake-code-123');
|
|
await expect(
|
|
page.getByTestId('login-form').or(page.locator('.auth-error')).first(),
|
|
).toBeVisible({ timeout: 15_000 });
|
|
});
|
|
|
|
test('request a magic link from the login page', async ({ page }) => {
|
|
await page.goto('/login');
|
|
await page.getByTestId('login-magic-toggle-btn').click();
|
|
await expect(page.getByTestId('login-magic-form')).toBeVisible();
|
|
|
|
await page.getByTestId('login-magic-email-input').fill('someone@example.test');
|
|
await page.getByTestId('login-magic-send-btn').click();
|
|
// A status message resolves (success or error); give the request time to run.
|
|
await page.waitForTimeout(1_000);
|
|
await expect(page.getByTestId('login-magic-form').or(page.getByTestId('login-form')).first()).toBeVisible();
|
|
});
|