Domain entities/ports, service stubs, 18 application unit tests with in-memory fakes, API integration tests for /api/auth and /api/users, Vitest specs for the auth store, login page and user form, Playwright auth/user-management flow. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
55 lines
2.2 KiB
TypeScript
55 lines
2.2 KiB
TypeScript
import { test, expect, type Page } from '@playwright/test'
|
|
|
|
const ADMIN = { email: 'admin@example.com', password: 'admin-password-123' }
|
|
|
|
async function login(page: Page, email: string, password: string) {
|
|
await page.goto('/login')
|
|
await page.getByLabel('Email').fill(email)
|
|
await page.getByLabel('Password').fill(password)
|
|
await page.getByRole('button', { name: 'Sign in' }).click()
|
|
}
|
|
|
|
test('unauthenticated visitor is redirected to login', async ({ page }) => {
|
|
await page.goto('/')
|
|
await expect(page).toHaveURL(/\/login/)
|
|
})
|
|
|
|
test('wrong password shows an error', async ({ page }) => {
|
|
await login(page, ADMIN.email, 'wrong-password-xx')
|
|
await expect(page.getByRole('alert')).toContainText('Invalid email or password')
|
|
})
|
|
|
|
test('admin logs in, manages users, logs out; user has no admin access', async ({ page }) => {
|
|
await login(page, ADMIN.email, ADMIN.password)
|
|
await expect(page).toHaveURL('/')
|
|
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
|
|
|
|
// create a user
|
|
await page.getByRole('link', { name: 'Users' }).click()
|
|
await page.getByRole('button', { name: 'New user' }).click()
|
|
const email = `e2e-${Date.now()}@example.com`
|
|
await page.getByLabel('Email').fill(email)
|
|
await page.getByLabel('Display name').fill('E2E User')
|
|
await page.getByLabel('Password').fill('user-password-123')
|
|
await page.getByRole('button', { name: 'Create' }).click()
|
|
const row = page.getByRole('row', { name: new RegExp(email) })
|
|
await expect(row).toBeVisible()
|
|
|
|
// edit: rename
|
|
await row.getByRole('button', { name: 'Edit' }).click()
|
|
await page.getByLabel('Display name').fill('Renamed User')
|
|
await page.getByRole('button', { name: 'Save' }).click()
|
|
await expect(row).toContainText('Renamed User')
|
|
|
|
// logout
|
|
await page.getByRole('button', { name: 'Sign out' }).click()
|
|
await expect(page).toHaveURL(/\/login/)
|
|
|
|
// the new user can log in but not manage users
|
|
await login(page, email, 'user-password-123')
|
|
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
|
|
await expect(page.getByRole('link', { name: 'Users' })).toHaveCount(0)
|
|
await page.goto('/users')
|
|
await expect(page.getByText('You do not have permission')).toBeVisible()
|
|
})
|