Files
Oxicloud/tests/e2e/spa/login.spec.ts
T
Bradley Nelson e3823ce470 test(e2e): Playwright + Vitest coverage harness and test instrumentation
Add an end-to-end and unit test suite for the SvelteKit frontend:

- Playwright e2e specs (tests/e2e/spa) with a throwaway container stack,
  codegen scenarios, and an Istanbul-based coverage report pipeline.
- Vitest unit tests across API endpoints, components, stores and composables.
- `data-testid` hooks on interactive elements (AppShell, FileViewer,
  ShareDialog, search, photos, files breadcrumbs, login/Nextcloud flows,
  public share pages) so the e2e suite can target them deterministically.
- Serve the SPA app-shell CSP from a <meta> policy (svelte.config.js) plus a
  middleware that skips the CSP header on HTML; move the Nextcloud Login Flow
  v2 grant page to the SvelteKit /nextcloud/login route.
- `just front-codegen` recipe and start-server-spa.sh harness.

Make the test environment robust and consistent:
- Install a deterministic in-memory localStorage/sessionStorage in the Vitest
  setup so storage behaves identically across Node versions (Node 26 ships a
  native Web Storage global that otherwise shadows jsdom's).
- Pin devenv to Node 26 + PostgreSQL 18 and pin every CI job to Node 26.3.0
  so the dev shell and CI run the same toolchain versions.

Repair the API/WebDAV (hurl) suite, which had drifted from the backend:
- Migrate the removed `/api/folders/{id}/listing` endpoint to `/resources`
  (cursor-paginated `{items:[{resource_type,resource}]}` shape) across the
  batch-copy, grants, nested-group, and WebDAV NC tests + the dav_helpers
  wipe routine.
- Stop photos_etag from uploading the dedup-tracked fixture so the dedup
  blob-lifecycle test can own its content-addressed blob exclusively.
- dedup_create now asserts the idempotent same-content re-upload (201 +
  existing file id) instead of the stale 409 expectation.

Generated coverage reports, nyc output and the e2e server runtime data dir
are gitignored rather than committed.
2026-06-22 00:05:06 -06:00

71 lines
3.1 KiB
TypeScript

import { test, expect } from './coverage-helpers';
/**
* Login route — register and magic-link flows (logged out). Exercises the
* register/magic submit handlers in the login page + auth endpoints.
*/
function uniq(p: string): string {
return `${p}-${Date.now()}-${Math.floor(Math.random() * 1e6)}`;
}
test('register a new account from the login page', async ({ page }) => {
const u = uniq('reg');
await page.goto('/login');
await page.getByTestId('login-to-register-btn').click();
await expect(page.getByTestId('login-register-form')).toBeVisible();
await page.getByTestId('login-register-username-input').fill(u);
await page.getByTestId('login-register-email-input').fill(`${u}@example.test`);
await page.getByTestId('login-register-password-input').fill('TestPassword1!');
await page.getByTestId('login-register-confirm-input').fill('TestPassword1!');
await page.getByTestId('login-register-submit-btn').click();
// Either we land in the app or a notice/error appears — both run onRegister.
await expect(
page
.getByTestId('appshell-logo-link')
.or(page.locator('.auth-error'))
.or(page.getByTestId('login-register-form'))
.first(),
).toBeVisible({ timeout: 15_000 });
});
// Note: the first-run setup panel is unreachable here — `login-to-setup-btn`
// only renders when no admin exists, but the test env always seeds one.
test('register with mismatched passwords shows a validation error', async ({ page }) => {
await page.goto('/login');
await page.getByTestId('login-to-register-btn').click();
await expect(page.getByTestId('login-register-form')).toBeVisible();
await page.getByTestId('login-register-username-input').fill(uniq('mm'));
await page.getByTestId('login-register-email-input').fill('mm@example.test');
await page.getByTestId('login-register-password-input').fill('TestPassword1!');
await page.getByTestId('login-register-confirm-input').fill('Different1!');
await page.getByTestId('login-register-submit-btn').click();
// Client-side validation rejects the mismatch before any request.
await expect(page.locator('.auth-error[role="alert"]')).toBeVisible({ timeout: 5_000 });
});
test('an oidc callback code is exchanged on load', async ({ page }) => {
// Landing with ?oidc_code triggers the SPA's OIDC code-exchange path; a bogus
// code fails and falls back to the login form (exercises the handler).
await page.goto('/login?oidc_code=fake-code-123');
await expect(
page.getByTestId('login-form').or(page.locator('.auth-error')).first(),
).toBeVisible({ timeout: 15_000 });
});
test('request a magic link from the login page', async ({ page }) => {
await page.goto('/login');
await page.getByTestId('login-magic-toggle-btn').click();
await expect(page.getByTestId('login-magic-form')).toBeVisible();
await page.getByTestId('login-magic-email-input').fill('someone@example.test');
await page.getByTestId('login-magic-send-btn').click();
// A status message resolves (success or error); give the request time to run.
await page.waitForTimeout(1_000);
await expect(page.getByTestId('login-magic-form').or(page.getByTestId('login-form')).first()).toBeVisible();
});