phase-6: the staff console, and a log that says who did what
Flow H, three screens behind a role check: find an account, work the ingestion error queue, read and export the audit log. Superadmins can change a role, never their own. The error queue merges ingest errors and dead jobs into one table with a cursor that pages both sources; only a job can be retried and only an ingest row resolved, with a note that migration 003 gives it somewhere to live. writeAudit no longer defaults a missing subject to the actor, which had been recording a user search as staff looking themselves up. Omitting the subject still means acting on yourself; null now means the action has no subject, which is what a search, a retry and an export are. Reading the log is not audited. Exporting it is: a copy leaving the building is a different act from looking. e2e/global-setup.ts asks for every screen once before the suite starts, so a dev server's first-request compile is paid before the first test rather than by it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
6620650e9e
commit
4c39926483
@@ -0,0 +1,100 @@
|
||||
import { es } from '@impuestos/i18n';
|
||||
import { expect, test, type Page } from '@playwright/test';
|
||||
import { readAuditActions } from './db';
|
||||
|
||||
async function signIn(page: Page, email: string, password: string): Promise<void> {
|
||||
await page.goto('/es/login');
|
||||
await page.getByLabel(es['auth.register.email']).fill(email);
|
||||
await page.getByLabel(es['auth.login.password']).fill(password);
|
||||
await page.getByRole('button', { name: es['auth.login.submit'] }).click();
|
||||
// Staff accounts have no taxpayer profile, so they land on setup rather than the
|
||||
// dashboard. Either way, leaving the login screen is what says the session took.
|
||||
// Generous, because the first visit to a route in a dev server compiles it.
|
||||
await expect(page).not.toHaveURL(/\/login$/, { timeout: 20_000 });
|
||||
}
|
||||
|
||||
async function openMaria(page: Page): Promise<void> {
|
||||
await page.goto('/es/usuarios');
|
||||
await page.getByLabel(es['admin.users.searchLabel']).fill('maria@demo.local');
|
||||
await page.getByRole('button', { name: es['common.search'] }).click();
|
||||
await page.getByRole('link', { name: 'maria@demo.local' }).click();
|
||||
}
|
||||
|
||||
/** Golden path 5 (SPEC.md section 13): admin lookup, then the audit row it wrote. */
|
||||
test.describe('admin console', () => {
|
||||
test('staff look a user up and the lookup lands in the audit log', async ({ page }) => {
|
||||
await signIn(page, 'staff@demo.local', 'demo-staff-1');
|
||||
|
||||
await page.goto('/es/usuarios');
|
||||
await expect(page.getByRole('heading', { name: es['admin.users.title'] })).toBeVisible();
|
||||
// The reminder is on the screen before anyone searches anything.
|
||||
await expect(page.getByText(es['admin.users.auditBanner'])).toBeVisible();
|
||||
|
||||
const before = readAuditActions('maria@demo.local').filter(
|
||||
(action) => action === 'admin.user_lookup',
|
||||
).length;
|
||||
// How many rows one view writes is pinned against the API in admin.test.ts, where it
|
||||
// is exactly one. It cannot be pinned here: React strict mode mounts a client
|
||||
// component twice in development, so the browser asks for the overview twice.
|
||||
|
||||
await page.getByLabel(es['admin.users.searchLabel']).fill('maria@demo.local');
|
||||
await page.getByRole('button', { name: es['common.search'] }).click();
|
||||
|
||||
const row = page.getByRole('link', { name: 'maria@demo.local' });
|
||||
await expect(row).toBeVisible();
|
||||
await row.click();
|
||||
|
||||
await expect(page.getByRole('heading', { name: 'Maria Gonzalez' })).toBeVisible();
|
||||
await expect(page.getByText(es['admin.users.counts.documents'])).toBeVisible();
|
||||
|
||||
await expect(async () => {
|
||||
const after = readAuditActions('maria@demo.local').filter(
|
||||
(action) => action === 'admin.user_lookup',
|
||||
).length;
|
||||
expect(after).toBeGreaterThan(before);
|
||||
}).toPass({ timeout: 10_000 });
|
||||
|
||||
// And the row is visible on the audit screen, which is where staff would look.
|
||||
await page.goto('/es/auditoria');
|
||||
await page.getByLabel(es['admin.audit.filterAction']).fill('admin.user_lookup');
|
||||
await page.getByRole('button', { name: es['admin.audit.apply'] }).click();
|
||||
await expect(page.locator('tbody tr').first()).toContainText('staff@demo.local');
|
||||
await expect(page.locator('tbody tr').first()).toContainText('maria@demo.local');
|
||||
});
|
||||
|
||||
test('the error queue shows both sources and expands a row', async ({ page }) => {
|
||||
await signIn(page, 'staff@demo.local', 'demo-staff-1');
|
||||
await page.goto('/es/errores');
|
||||
|
||||
await expect(page.getByRole('heading', { name: es['admin.errors.title'] })).toBeVisible();
|
||||
|
||||
const rows = page.locator('tbody tr');
|
||||
await expect(rows.first()).toBeVisible();
|
||||
|
||||
// Expanding a row shows what the failure captured, rather than a stack trace.
|
||||
await rows.first().getByRole('button').click();
|
||||
await expect(page.locator('pre').first()).toBeVisible();
|
||||
});
|
||||
|
||||
test('a plain user cannot reach the console', async ({ page }) => {
|
||||
await signIn(page, 'maria@demo.local', 'demo-maria-1');
|
||||
|
||||
for (const path of ['/es/usuarios', '/es/errores', '/es/auditoria']) {
|
||||
await page.goto(path);
|
||||
await expect(page.getByText(es['admin.forbidden'])).toBeVisible();
|
||||
}
|
||||
});
|
||||
|
||||
test('staff are not offered role management', async ({ page }) => {
|
||||
await signIn(page, 'staff@demo.local', 'demo-staff-1');
|
||||
await openMaria(page);
|
||||
await expect(page.getByRole('heading', { name: 'Maria Gonzalez' })).toBeVisible();
|
||||
await expect(page.getByRole('button', { name: es['admin.role.change'] })).toHaveCount(0);
|
||||
});
|
||||
|
||||
test('a superadmin is offered role management', async ({ page }) => {
|
||||
await signIn(page, 'superadmin@demo.local', 'demo-superadmin-1');
|
||||
await openMaria(page);
|
||||
await expect(page.getByRole('button', { name: es['admin.role.change'] })).toBeVisible();
|
||||
});
|
||||
});
|
||||
@@ -61,7 +61,9 @@ test.describe('golden path 4: review, approve, download, file', () => {
|
||||
// The official layout, in Spanish, marked as a draft until it is approved.
|
||||
await expect(page.getByRole('heading', { name: es['decl.preview.title'] })).toBeVisible();
|
||||
await expect(page.getByText(es['decl.preview.spanishNote'])).toBeVisible();
|
||||
await expect(page.getByText('Debito fiscal')).toBeVisible();
|
||||
// The cell, not any text: the summary above it names the debito too, and this line is
|
||||
// about the form laying out its casillas.
|
||||
await expect(page.getByRole('cell', { name: 'Debito fiscal', exact: true })).toBeVisible();
|
||||
await expect(page.getByText(es['decl.preview.draftMark'])).toBeVisible();
|
||||
|
||||
// D3: approving asks once, restating the number.
|
||||
|
||||
@@ -0,0 +1,46 @@
|
||||
import { request } from '@playwright/test';
|
||||
|
||||
/**
|
||||
* Asks for every screen once before the suite starts.
|
||||
*
|
||||
* Against `pnpm dev` a route is compiled the first time it is requested, and whichever test
|
||||
* happens to be first pays for it: a sign in navigation runs past the five seconds
|
||||
* Playwright waits by default and fails for a reason that has nothing to do with the
|
||||
* product. Against a built stack these are cheap 200s and 307s.
|
||||
*/
|
||||
const ROUTES = [
|
||||
'/es',
|
||||
'/en',
|
||||
'/es/login',
|
||||
'/es/registro',
|
||||
'/es/verificar',
|
||||
'/es/inicio',
|
||||
'/es/bandeja',
|
||||
'/es/comprobantes',
|
||||
'/es/comprobantes/nuevo',
|
||||
'/es/declaraciones',
|
||||
'/es/vencimientos',
|
||||
'/es/escanear',
|
||||
'/es/perfil',
|
||||
'/es/configuracion',
|
||||
'/es/consentimiento',
|
||||
'/es/usuarios',
|
||||
'/es/errores',
|
||||
'/es/auditoria',
|
||||
'/en/login',
|
||||
];
|
||||
|
||||
export default async function globalSetup(): Promise<void> {
|
||||
const baseURL = process.env['E2E_BASE_URL'] ?? 'http://localhost:3005';
|
||||
const context = await request.newContext({ baseURL });
|
||||
try {
|
||||
for (const route of ROUTES) {
|
||||
// A redirect to sign in is a compiled route, which is all this is after.
|
||||
await context
|
||||
.get(route, { failOnStatusCode: false, timeout: 120_000 })
|
||||
.catch(() => undefined);
|
||||
}
|
||||
} finally {
|
||||
await context.dispose();
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user