pediatric-ai-scribe-v3/scripts/e2e.sh
Daniel 79c329ceda
Some checks failed
Forgejo Android APK / Root app tests (push) Successful in 55s
Forgejo Docker Build / Root app tests (push) Successful in 48s
Forgejo Android APK / Build signed APK (push) Successful in 2m0s
Forgejo Docker Build / Build Docker image (push) Successful in 16s
Forgejo Docker Build / Deploy to the host (push) Failing after 0s
test(e2e): seed an admin account, and fix the sign-in that broke the browser suite
Adds the admin fixture the Search Sources screen needed, and repairs the reason
no browser-driving e2e test could log in at all.

The sign-in failure first. The suite drove the app over http on a container
hostname, which is not a secure context, so the browser provides no
crypto.randomUUID. AccountBoundary calls it to mint a session generation on
every sign-in; the call threw, the boot handler's catch swallowed it, and every
test landed on the login screen holding a perfectly valid session. Measured:
isSecureContext false and randomUUID undefined on
http://pediatric-ai-scribe-e2e:3000, both true on http://127.0.0.1:3553, where
boundary.enter() returns true and the app enters.

Chrome's --unsafely-treat-insecure-origin-as-secure was tried first and does not
work: Playwright rejects the --user-data-dir it must be paired with, and the
flag alone leaves isSecureContext false. Loopback needs no flags, so the runner
now uses the host network and the published port.

The seed is new. The e2e user was a registration someone did by hand once that
the shared Postgres happened to keep — enough to log in and no more. There was
no admin account, so nothing under /api/admin could be tested through a real
request, which is how the Search Sources card came to be verified by reading its
markup. e2e/seed.js creates both accounts and reconciles an existing one, so a
leftover with the wrong role cannot fail the suite for a reason unrelated to the
code. It resets passwords and grants admin, so it refuses any address outside
@ped-ai.test. The runner seeds before it tests.

The new spec covers what markup-reading could not: that an ordinary account is
refused the settings and never offered the Admin menu item, that no API key
comes back readable, that the Test button reports each source separately, and
that every control the save handler reads exists in a real render. Each account
gets its own browser context, because AccountBoundary allows one owner per
document and freezing the page on a second is the behaviour, not a bug.

10/10 pass on both projects. Two unit tests pin the loopback requirement and the
seed's domain guard so neither can be undone quietly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Dv6sqaY6Vq3ChZHMem3cnU
2026-09-11 17:24:32 +02:00

45 lines
1.8 KiB
Bash
Executable file

#!/usr/bin/env bash
# Runs Playwright smoke tests inside the official Playwright container against
# the running PedScribe app. Usage: npm run e2e (or ./scripts/e2e.sh)
set -euo pipefail
cd "$(dirname "$0")/.."
IMAGE="mcr.microsoft.com/playwright:v1.50.0-noble"
# --- PREFLIGHT: static reference linter ---
# Catches the class of bug where a JS file reaches for an id that no
# HTML element (or dynamic id assignment anywhere in the repo) ever
# produces — the lightbox + adminMilestones dead-code bugs were both
# this shape and both went undetected until someone tripped over them
# in the real app. Fails the build before tests even start.
echo "==> Static reference lint"
docker run --rm -v "$PWD:/work" -w /work node:20-alpine \
node scripts/lint-references.js
# --- SEED: the accounts the fixtures log in as ---
# Idempotent, and the only place the admin account comes from. Run inside the
# app container because that is where the database credentials are: the
# entrypoint exports them from OpenBao into the Node process and nowhere else.
# Non-fatal, so a run against a stack that is already seeded is not blocked by
# a container that happens not to be up.
E2E_CONTAINER="${E2E_CONTAINER:-pediatric-ai-scribe-e2e}"
echo "==> Seeding e2e accounts"
if docker exec "$E2E_CONTAINER" node e2e/seed.js; then
:
else
echo " seed skipped ($E2E_CONTAINER not running or not seedable); tests will fail on login if the accounts are missing" >&2
fi
# Host network and a loopback URL, because the browser only treats loopback as
# a secure context over plain http, and the app cannot sign in without one.
BASE_URL="${BASE_URL:-http://127.0.0.1:3553}"
docker run --rm --ipc=host \
--network=host \
-v "$PWD/e2e":/work \
-w /work \
-e BASE_URL="$BASE_URL" \
-e CI=true \
"$IMAGE" \
sh -c "npm install --no-audit --no-fund --silent && npx playwright test"