## Summary - Fix a chain of QA CI issues: Docker build/health-check flakiness, NuGet vuln pins, then adds the post-deploy integration + Playwright smoke suite and works through everything needed to make it actually run on the self-hosted `qa` runner (musl/Alpine job container, no node/dotnet/curl preinstalled, docker-outside-of-docker networking). - Adds a fixed dev/QA seed admin user + fixed Development environment API key so integration tests and e2e specs have a stable target. - Pins Aspire's `AppHost.cs` ports/credentials to match the docker-compose local dev defaults. - Adds `tests/api/MicCheck.Api.Tests.Integration` coverage for disabled flags, environment-document bootstrap, identity override precedence, auth login, and unauthorized access; adds a Playwright e2e suite under `src/admin/e2e` (login, nav, context selection, features CRUD/toggle). - Adds a `smoke-qa` CI job that runs both suites against the just-deployed QA stack, working around: no curl/node/dotnet on the bare runner, musl vs glibc (Playwright browsers run via the official `mcr.microsoft.com/playwright` image instead), and the runner's job-container network isolation (reach the QA stack via the docker bridge gateway IP; `docker cp` instead of a bind mount to get files into the playwright container, since paths don't cross the docker-outside-of-docker boundary). ## Test plan - [x] Unit tests pass (dotnet test tests/api/MicCheck.Api.Tests.Unit, 243 passed) - [x] API integration suite passes against the real QA stack in CI - [x] Playwright e2e suite passes against the real QA stack in CI (verified 3/3 locally against a real dev API + vite server for the flakiest spec) - [x] Full CI pipeline (build → deploy-qa → smoke-qa) green end to end on the qa runner Reviewed-on: #3
31 lines
1.3 KiB
TypeScript
31 lines
1.3 KiB
TypeScript
import { chromium, type FullConfig } from '@playwright/test';
|
|
import path from 'node:path';
|
|
|
|
/**
|
|
* Deterministic dev/QA seed admin credentials — see DatabaseSeeder.SeedAdminEmail /
|
|
* SeedAdminPassword in src/api/MicCheck.Api/Data/DatabaseSeeder.cs. Seeding only ever runs in
|
|
* Development, which is what both local dev and the QA deployment run as.
|
|
*/
|
|
const ADMIN_EMAIL = process.env.E2E_ADMIN_EMAIL ?? 'admin@miccheck.local';
|
|
const ADMIN_PASSWORD = process.env.E2E_ADMIN_PASSWORD ?? 'MicCheckQa!2026';
|
|
|
|
export const authFile = path.join(__dirname, '.auth', 'admin.json');
|
|
|
|
export default async function globalSetup(config: FullConfig): Promise<void> {
|
|
const baseURL = config.projects[0]?.use?.baseURL ?? 'http://localhost:5173';
|
|
|
|
const browser = await chromium.launch();
|
|
const page = await browser.newPage({ baseURL });
|
|
|
|
await page.goto('/login');
|
|
await page.getByTestId('email-input').locator('input').fill(ADMIN_EMAIL);
|
|
await page.getByTestId('password-input').locator('input').fill(ADMIN_PASSWORD);
|
|
await page.getByTestId('login-submit').click();
|
|
|
|
// A successful login redirects off /login onto the authenticated shell.
|
|
await page.waitForURL((url) => !url.pathname.startsWith('/login'), { timeout: 15_000 });
|
|
|
|
await page.context().storageState({ path: authFile });
|
|
await browser.close();
|
|
}
|