Files
Oxicloud/frontend/src/routes/profile/page.test.ts
T
Bradley Nelson e3823ce470 test(e2e): Playwright + Vitest coverage harness and test instrumentation
Add an end-to-end and unit test suite for the SvelteKit frontend:

- Playwright e2e specs (tests/e2e/spa) with a throwaway container stack,
  codegen scenarios, and an Istanbul-based coverage report pipeline.
- Vitest unit tests across API endpoints, components, stores and composables.
- `data-testid` hooks on interactive elements (AppShell, FileViewer,
  ShareDialog, search, photos, files breadcrumbs, login/Nextcloud flows,
  public share pages) so the e2e suite can target them deterministically.
- Serve the SPA app-shell CSP from a <meta> policy (svelte.config.js) plus a
  middleware that skips the CSP header on HTML; move the Nextcloud Login Flow
  v2 grant page to the SvelteKit /nextcloud/login route.
- `just front-codegen` recipe and start-server-spa.sh harness.

Make the test environment robust and consistent:
- Install a deterministic in-memory localStorage/sessionStorage in the Vitest
  setup so storage behaves identically across Node versions (Node 26 ships a
  native Web Storage global that otherwise shadows jsdom's).
- Pin devenv to Node 26 + PostgreSQL 18 and pin every CI job to Node 26.3.0
  so the dev shell and CI run the same toolchain versions.

Repair the API/WebDAV (hurl) suite, which had drifted from the backend:
- Migrate the removed `/api/folders/{id}/listing` endpoint to `/resources`
  (cursor-paginated `{items:[{resource_type,resource}]}` shape) across the
  batch-copy, grants, nested-group, and WebDAV NC tests + the dav_helpers
  wipe routine.
- Stop photos_etag from uploading the dedup-tracked fixture so the dedup
  blob-lifecycle test can own its content-addressed blob exclusively.
- dedup_create now asserts the idempotent same-content re-upload (201 +
  existing file id) instead of the stale 409 expectation.

Generated coverage reports, nyc output and the e2e server runtime data dir
are gitignored rather than committed.
2026-06-22 00:05:06 -06:00

129 lines
4.5 KiB
TypeScript

import { it, expect, vi, beforeEach } from 'vitest';
import { render, screen, fireEvent, waitFor } from '@testing-library/svelte';
const { session, ui } = vi.hoisted(() => ({
session: {
loaded: true,
load: vi.fn(),
user: {
id: '1',
username: 'admin',
email: 'a@x.test',
given_name: 'A',
family_name: 'B',
role: 'admin',
storage_used_bytes: 100,
storage_quota_bytes: 1000,
is_external: false
}
},
ui: { notify: vi.fn() }
}));
vi.mock('$lib/stores/session.svelte', () => ({ session }));
vi.mock('$lib/stores/ui.svelte', () => ({ ui }));
vi.mock('$lib/stores/dialogs.svelte', () => ({ confirmDialog: vi.fn() }));
vi.mock('$lib/utils/errors', () => ({ errorToast: vi.fn() }));
vi.mock('$lib/api/endpoints/auth', () => ({ getOidcProviders: vi.fn() }));
vi.mock('$lib/api/endpoints/profile', () => ({
changePassword: vi.fn(),
createAppPassword: vi.fn(),
isAutoAppPassword: () => false,
listAppPasswords: vi.fn(),
revokeAppPassword: vi.fn(),
updateAvatar: vi.fn(),
updateProfile: vi.fn()
}));
import * as profile from '$lib/api/endpoints/profile';
import { getOidcProviders } from '$lib/api/endpoints/auth';
import { confirmDialog } from '$lib/stores/dialogs.svelte';
import ProfilePage from './+page.svelte';
const m = (fn: unknown) => fn as ReturnType<typeof vi.fn>;
beforeEach(() => {
vi.clearAllMocks();
// Reset the shared session each test (handlers may mutate session.user).
session.loaded = true;
session.user = {
id: '1',
username: 'admin',
email: 'a@x.test',
given_name: 'A',
family_name: 'B',
role: 'admin',
storage_used_bytes: 100,
storage_quota_bytes: 1000,
is_external: false
};
m(profile.listAppPasswords).mockResolvedValue([]);
m(profile.updateProfile).mockResolvedValue(undefined);
m(getOidcProviders).mockResolvedValue({ password_login_enabled: true });
});
it('renders and saves the profile form', async () => {
m(profile.updateProfile).mockResolvedValue(undefined);
render(ProfilePage);
await screen.findByTestId('profile-edit-form');
await fireEvent.input(screen.getByTestId('profile-given-name-input'), {
target: { value: 'New' }
});
await fireEvent.click(screen.getByTestId('profile-save-btn'));
await waitFor(() => expect(profile.updateProfile).toHaveBeenCalled());
});
it('generates an app password', async () => {
m(profile.createAppPassword).mockResolvedValue({ id: 'ap1', secret: 'xyz', label: 'tok' });
render(ProfilePage);
await screen.findByTestId('profile-app-pw-label-input');
await fireEvent.input(screen.getByTestId('profile-app-pw-label-input'), {
target: { value: 'tok' }
});
await fireEvent.click(screen.getByTestId('profile-app-pw-generate-btn'));
await waitFor(() => expect(profile.createAppPassword).toHaveBeenCalledWith('tok'));
});
it('rejects a mismatched password change without calling the API', async () => {
render(ProfilePage);
await screen.findByTestId('profile-password-form');
await fireEvent.input(screen.getByTestId('profile-current-password-input'), {
target: { value: 'old' }
});
await fireEvent.input(screen.getByTestId('profile-new-password-input'), {
target: { value: 'new1' }
});
await fireEvent.input(screen.getByTestId('profile-confirm-password-input'), {
target: { value: 'new2' }
});
await fireEvent.click(screen.getByTestId('profile-update-password-btn'));
expect(profile.changePassword).not.toHaveBeenCalled();
});
it('changes the password when the confirmation matches', async () => {
m(profile.changePassword).mockResolvedValue(undefined);
render(ProfilePage);
await screen.findByTestId('profile-password-form');
await fireEvent.input(screen.getByTestId('profile-current-password-input'), {
target: { value: 'OldPassword1!' }
});
await fireEvent.input(screen.getByTestId('profile-new-password-input'), {
target: { value: 'NewPassword1!' }
});
await fireEvent.input(screen.getByTestId('profile-confirm-password-input'), {
target: { value: 'NewPassword1!' }
});
await fireEvent.click(screen.getByTestId('profile-update-password-btn'));
await waitFor(() => expect(profile.changePassword).toHaveBeenCalled());
});
it('revokes an existing app password after confirmation', async () => {
m(profile.listAppPasswords).mockResolvedValue([
{ id: 'ap1', label: 'CLI token', created_at: '2024-01-01T00:00:00Z' }
]);
m(confirmDialog).mockResolvedValue(true);
m(profile.revokeAppPassword).mockResolvedValue(undefined);
render(ProfilePage);
await fireEvent.click(await screen.findByTestId('profile-app-pw-revoke-ap1'));
await waitFor(() => expect(profile.revokeAppPassword).toHaveBeenCalledWith('ap1'));
});