WP-01: domain contract and failing tests for auth and user management
Domain entities/ports, service stubs, 18 application unit tests with in-memory fakes, API integration tests for /api/auth and /api/users, Vitest specs for the auth store, login page and user form, Playwright auth/user-management flow. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
54
frontend/e2e/auth.spec.ts
Normal file
54
frontend/e2e/auth.spec.ts
Normal file
@ -0,0 +1,54 @@
|
||||
import { test, expect, type Page } from '@playwright/test'
|
||||
|
||||
const ADMIN = { email: 'admin@example.com', password: 'admin-password-123' }
|
||||
|
||||
async function login(page: Page, email: string, password: string) {
|
||||
await page.goto('/login')
|
||||
await page.getByLabel('Email').fill(email)
|
||||
await page.getByLabel('Password').fill(password)
|
||||
await page.getByRole('button', { name: 'Sign in' }).click()
|
||||
}
|
||||
|
||||
test('unauthenticated visitor is redirected to login', async ({ page }) => {
|
||||
await page.goto('/')
|
||||
await expect(page).toHaveURL(/\/login/)
|
||||
})
|
||||
|
||||
test('wrong password shows an error', async ({ page }) => {
|
||||
await login(page, ADMIN.email, 'wrong-password-xx')
|
||||
await expect(page.getByRole('alert')).toContainText('Invalid email or password')
|
||||
})
|
||||
|
||||
test('admin logs in, manages users, logs out; user has no admin access', async ({ page }) => {
|
||||
await login(page, ADMIN.email, ADMIN.password)
|
||||
await expect(page).toHaveURL('/')
|
||||
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
|
||||
|
||||
// create a user
|
||||
await page.getByRole('link', { name: 'Users' }).click()
|
||||
await page.getByRole('button', { name: 'New user' }).click()
|
||||
const email = `e2e-${Date.now()}@example.com`
|
||||
await page.getByLabel('Email').fill(email)
|
||||
await page.getByLabel('Display name').fill('E2E User')
|
||||
await page.getByLabel('Password').fill('user-password-123')
|
||||
await page.getByRole('button', { name: 'Create' }).click()
|
||||
const row = page.getByRole('row', { name: new RegExp(email) })
|
||||
await expect(row).toBeVisible()
|
||||
|
||||
// edit: rename
|
||||
await row.getByRole('button', { name: 'Edit' }).click()
|
||||
await page.getByLabel('Display name').fill('Renamed User')
|
||||
await page.getByRole('button', { name: 'Save' }).click()
|
||||
await expect(row).toContainText('Renamed User')
|
||||
|
||||
// logout
|
||||
await page.getByRole('button', { name: 'Sign out' }).click()
|
||||
await expect(page).toHaveURL(/\/login/)
|
||||
|
||||
// the new user can log in but not manage users
|
||||
await login(page, email, 'user-password-123')
|
||||
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
|
||||
await expect(page.getByRole('link', { name: 'Users' })).toHaveCount(0)
|
||||
await page.goto('/users')
|
||||
await expect(page.getByText('You do not have permission')).toBeVisible()
|
||||
})
|
||||
Reference in New Issue
Block a user