Adds the referential models, the first database-backed settings screens, and the register the compliance matrix requires before any parameter is enforceable. The register is the point of the lot. The matrix is explicit that copying another product's configuration is not enough — each parameter must carry its value, source, effective date, population and an approver. Approval records the session's actor, never a form field: a signature you can type yourself is worth nothing. The screen names the domains that have no approved parameter yet, so the gap is visible rather than assumed closed. Two bugs of the same family, both now structurally impossible: - The Prisma scoping extension read a hand-written list of models carrying accountId. The four models added here were missing from it, so writes failed with an opaque Prisma error — and a read would have silently returned every account's rows. The list is now derived from the schema itself. - The RLS policies were likewise per-table. A new integration test fails if any table with an accountId column lacks forced RLS and both policies, which is the failure mode that hides best: nobody writes a wrong rule, someone forgets to write one. An end-to-end test signs in as a manager and confirms the settings screens refuse to render — the sidebar hiding them is a convenience, the server check is the control. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
74 lines
2.3 KiB
TypeScript
74 lines
2.3 KiB
TypeScript
import { defineConfig, devices } from '@playwright/test';
|
|
|
|
import { STORAGE_STATE } from './tests/e2e/storage';
|
|
|
|
/**
|
|
* Certains environnements fournissent déjà un Chromium dont la révision ne
|
|
* correspond pas à celle qu'attend cette version de Playwright.
|
|
* PLAYWRIGHT_CHROMIUM_PATH permet de le réutiliser plutôt que d'en télécharger
|
|
* un second.
|
|
*/
|
|
const chromiumOverride = process.env.PLAYWRIGHT_CHROMIUM_PATH
|
|
? { launchOptions: { executablePath: process.env.PLAYWRIGHT_CHROMIUM_PATH } }
|
|
: {};
|
|
|
|
const PORT = Number(process.env.E2E_PORT ?? 3100);
|
|
const baseURL = `http://127.0.0.1:${PORT}`;
|
|
|
|
export default defineConfig({
|
|
testDir: './tests/e2e',
|
|
fullyParallel: true,
|
|
forbidOnly: Boolean(process.env.CI),
|
|
retries: process.env.CI ? 2 : 0,
|
|
// Serial in CI so the single Postgres service is not raced.
|
|
...(process.env.CI ? { workers: 1 } : {}),
|
|
reporter: process.env.CI ? [['github'], ['html', { open: 'never' }]] : 'list',
|
|
|
|
use: {
|
|
baseURL,
|
|
trace: 'on-first-retry',
|
|
},
|
|
|
|
projects: [
|
|
// Ouvre une session et enregistre le cookie ; les autres projets
|
|
// le réutilisent.
|
|
{
|
|
name: 'setup',
|
|
testMatch: /auth\.setup\.ts/,
|
|
use: { ...devices['Desktop Chrome'], ...chromiumOverride },
|
|
},
|
|
// Parcours d'authentification : doit partir d'un navigateur vierge.
|
|
{
|
|
name: 'anonyme',
|
|
testMatch: /(auth|reglages)\.spec\.ts/,
|
|
use: { ...devices['Desktop Chrome'], ...chromiumOverride },
|
|
},
|
|
{
|
|
name: 'chromium',
|
|
testIgnore: /(auth\.setup|auth\.spec|reglages\.spec)\.ts/,
|
|
dependencies: ['setup'],
|
|
use: {
|
|
...devices['Desktop Chrome'],
|
|
...chromiumOverride,
|
|
storageState: STORAGE_STATE,
|
|
},
|
|
},
|
|
],
|
|
|
|
webServer: {
|
|
// Exercise the standalone server, which is what the Docker image runs.
|
|
// `next start` is not compatible with `output: standalone`, and testing a
|
|
// different server than the one deployed defeats the purpose of this suite.
|
|
command: [
|
|
'pnpm build',
|
|
'cp -r .next/static .next/standalone/.next/static',
|
|
'cp -r public .next/standalone/public',
|
|
`node .next/standalone/server.js`,
|
|
].join(' && '),
|
|
url: baseURL,
|
|
env: { PORT: String(PORT), HOSTNAME: '127.0.0.1' },
|
|
reuseExistingServer: !process.env.CI,
|
|
timeout: 180_000,
|
|
},
|
|
});
|