name: CI on: push: branches: [main] pull_request: concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true env: # Test-only values. Real secrets never live in CI configuration. # Compte applicatif, **pas** le superutilisateur d'amorçage : un # superutilisateur contourne la row-level security, et la suite passerait sans # jamais éprouver la seconde couche d'isolation — présente en base, absente # des faits. DATABASE_URL: postgresql://planflow_app:planflow_app@localhost:5432/planflow_test # Le harnais de tests fabrique des états que l'interface ne pose pas ; il lui # faut une connexion qui traverse les comptes, comme un exploitant. ADMIN_DATABASE_URL: postgresql://planflow:planflow@localhost:5432/planflow_test ENCRYPTION_KEY: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA= APP_URL: http://127.0.0.1:3100 jobs: verify: runs-on: ubuntu-latest services: postgres: image: postgres:16-alpine env: POSTGRES_USER: planflow POSTGRES_PASSWORD: planflow POSTGRES_DB: planflow_test ports: ['5432:5432'] options: >- --health-cmd "pg_isready -U planflow" --health-interval 5s --health-timeout 5s --health-retries 10 steps: - uses: actions/checkout@v4 - uses: pnpm/action-setup@v4 - uses: actions/setup-node@v4 with: node-version: 22 cache: pnpm - run: pnpm install --frozen-lockfile - name: Créer le rôle applicatif, soumis à la RLS run: | PGPASSWORD=planflow psql -h localhost -U planflow -d planflow_test -v ON_ERROR_STOP=1 <<'SQL' CREATE ROLE planflow_app LOGIN PASSWORD 'planflow_app' NOSUPERUSER NOCREATEDB NOCREATEROLE NOBYPASSRLS; ALTER DATABASE planflow_test OWNER TO planflow_app; ALTER SCHEMA public OWNER TO planflow_app; GRANT ALL ON SCHEMA public TO planflow_app; SQL - run: pnpm db:generate - name: Appliquer les migrations run: pnpm db:deploy - name: Installer le jeu de démonstration (Playwright) run: pnpm db:seed:demo - run: pnpm typecheck - run: pnpm lint - run: pnpm test - run: pnpm build - name: Installer le navigateur Playwright run: pnpm exec playwright install --with-deps chromium - run: pnpm test:e2e - uses: actions/upload-artifact@v4 if: failure() with: name: playwright-report path: playwright-report/ retention-days: 7