Files
Louis King 94dd4c9b42 test(e2e): replace Python e2e suite with Playwright (headless Chromium)
Replaces the httpx-based smoke tests in tests/e2e/ with a browser E2E suite
under e2e/, running against a self-contained throwaway stack that never
touches the local development database.

Stack & data isolation (e2e/docker-compose.test.yml):
- Own ephemeral Postgres 17 (schema via the `migrate` service / Alembic),
  distinct project name + named volumes, no host DB port, no \${VAR}
  interpolation. `make e2e-down` destroys everything.
- OIDC enabled with a known session secret; WEB_AUTO_REFRESH_SECONDS=2 so
  polling is assertable; CONTENT_HOME mounts a test markdown page.
- Deterministic seeder (e2e/seed_data.py) run via global setup inside the
  collector container: nodes/observers with `area` tags, adverts, messages
  on the public (17) + a custom channel, raw packets + path hops keyed to
  node prefixes, a route + health/history, profiles + adoptions, and
  event_observers rows so the observer filter/badges resolve.

Auth & tests:
- Forged signed `meshcore-session` cookies (e2e/mint_session.py,
  itsdangerous) for admin/member identities -> storageState; no real IdP
  needed. 31 specs across 12 files cover global nav/theme, profile
  menu+edit, home hero, dashboard widgets, list filters/auto-refresh/row
  actions, observer toggles, the path-node overlay, map filters +
  show-labels, members, markdown pages, and routes add/edit/delete
  (persistence, validation, confirm dialog). workers:1 / fullyParallel:false
  against the single shared backend; targeted data-testids added to React
  components for stable selectors.

Fixes surfaced while running the suite on fresh Postgres:
- Migration 5e3b712ccf10 aborted on Postgres: its route-health backfill
  queries the live Route model (which now has max_path_length) before that
  column exists. The swallowed error left the transaction aborted, killing
  the subsequent alembic_version stamp. Wrapped the backfill in a SAVEPOINT
  so a failure rolls back cleanly without blocking the migration.
- Restored the full ABUSE_* env set required by the MQTT broker, and set
  the web service's API_KEY to the admin key (admin writes go through the
  proxy as a Bearer token).

31/31 passing; tsc (frontend+e2e), pytest (1460), and pre-commit green.
2026-07-22 10:41:53 +01:00

54 lines
1.6 KiB
Python

"""Mint a signed ``meshcore-session`` cookie for Playwright e2e tests.
Reproduces Starlette's SessionMiddleware signing scheme (an
``itsdangerous.TimestampSigner`` over the base64-encoded session JSON) so the
forged cookie is accepted by the web tier exactly like a real OIDC login -
populating ``window.__APP_CONFIG__`` (user + roles) and driving the API proxy's
``X-User-Id`` / ``X-User-Roles`` injection. No IdP round-trip is performed.
The secret must match the stack's ``OIDC_SESSION_SECRET``
(``test-session-secret`` in ``e2e/docker-compose.test.yml``).
Usage:
python e2e/mint_session.py <secret> <sub> <name> <email> <roles_csv>
Prints the cookie value to stdout.
"""
from __future__ import annotations
import base64
import json
import sys
import itsdangerous
def mint(secret: str, sub: str, name: str, email: str, roles_csv: str) -> str:
"""Return a signed session-cookie value for the given identity/roles."""
session = {
"user": {
"sub": sub,
"name": name,
"email": email,
"picture": None,
"roles": [r.strip() for r in roles_csv.split(",") if r.strip()],
}
}
data = base64.b64encode(json.dumps(session).encode("utf-8"))
signed = itsdangerous.TimestampSigner(secret).sign(data).decode("utf-8")
return str(signed)
def main() -> None:
if len(sys.argv) != 6:
raise SystemExit(
"usage: mint_session.py <secret> <sub> <name> <email> <roles_csv>"
)
secret, sub, name, email, roles_csv = sys.argv[1:6]
print(mint(secret, sub, name, email, roles_csv))
if __name__ == "__main__":
main()