Files
Infrastruktur-Monitoring-Sy…/frontend/e2e/auth.spec.ts
Dennis Nemec 9234e1ba47 WP-40/41/42: dashboard, security hardening, deployment and operations docs
Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster
health, backups and recent jobs. Security headers (CSP, nosniff, DENY,
referrer policy), 1 MB body limit, configurable login rate limit, audit
steps in CI. Installer script, systemd unit, install/architecture docs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 23:26:01 +02:00

55 lines
2.2 KiB
TypeScript

import { test, expect, type Page } from '@playwright/test'
const ADMIN = { email: 'admin@example.com', password: 'admin-password-123' }
async function login(page: Page, email: string, password: string) {
await page.goto('/login')
await page.getByLabel('Email').fill(email)
await page.getByLabel('Password').fill(password)
await page.getByRole('button', { name: 'Sign in' }).click()
}
test('unauthenticated visitor is redirected to login', async ({ page }) => {
await page.goto('/')
await expect(page).toHaveURL(/\/login/)
})
test('wrong password shows an error', async ({ page }) => {
await login(page, ADMIN.email, 'wrong-password-xx')
await expect(page.getByRole('alert')).toContainText('Invalid email or password')
})
test('admin logs in, manages users, logs out; user has no admin access', async ({ page }) => {
await login(page, ADMIN.email, ADMIN.password)
await expect(page).toHaveURL('/')
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
// create a user
await page.getByRole('navigation').getByRole('link', { name: 'Users' }).click()
await page.getByRole('button', { name: 'New user' }).click()
const email = `e2e-${Date.now()}@example.com`
await page.getByLabel('Email').fill(email)
await page.getByLabel('Display name').fill('E2E User')
await page.getByLabel('Password').fill('user-password-123')
await page.getByRole('button', { name: 'Create' }).click()
const row = page.getByRole('row', { name: new RegExp(email) })
await expect(row).toBeVisible()
// edit: rename
await row.getByRole('button', { name: 'Edit' }).click()
await page.getByLabel('Display name').fill('Renamed User')
await page.getByRole('button', { name: 'Save' }).click()
await expect(row).toContainText('Renamed User')
// logout
await page.getByRole('button', { name: 'Sign out' }).click()
await expect(page).toHaveURL(/\/login/)
// the new user can log in but not manage users
await login(page, email, 'user-password-123')
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
await expect(page.getByRole('navigation').getByRole('link', { name: 'Users' })).toHaveCount(0)
await page.goto('/users')
await expect(page.getByText('You do not have permission')).toBeVisible()
})