Files
rfc-app/testing
Ben Stull 2fc7029bd9 test(e2e): §22-current Tier-1 harness + metadata E2E (SLICE-3/4/5)
Modernize the Tier-1 stack to the three-tier app and add browser coverage for
the §22.4a metadata UI, closing the E2E gap deferred across SLICE-3/4/5:
- seed-gitea.sh: create a REGISTRY_REPO with projects.yaml + a faceted named
  collection (.collection.yaml fields: priority enum + tags) seeded with three
  metadata-bearing entries; register content+registry webhooks; self-guarding
  (skip if a prior token still works) so a dependency-triggered re-run can't
  remint and invalidate the backend's token.
- .env.tier1: REGISTRY_REPO/DEFAULT_PROJECT_ID; disable OTC cooldown + lift the
  per-IP auth limiter for the single-IP test runner.
- docker-compose: pin backend image; backend-seed inserts a granted owner the
  OTC path can sign in as (write paths need contributor+).
- Makefile: two-phase tier1-up (seed to completion, then create backend so it
  reads the populated token env); robust down; e2e-fresh = down+up+e2e (the
  canonical run, since the edit/bulk specs mutate the seeded corpus).
- metadata.spec.js: SLICE-3 faceted filter (anon), SLICE-4 edit panel (owner),
  SLICE-5 bulk bar (owner). 4 passed against a fresh stack.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 22:29:11 -07:00
..

Test harness (handbook §10.3 two-tier testing)

One environment-agnostic suite, two targets.

Tier 1 — local Docker (every PR)

make e2e-install     # one-time: install Playwright + chromium (cold checkout)
make tier1-up        # build + start: gitea(seeded) + backend + web(nginx) + mailpit
make e2e             # run Playwright against http://localhost:8080
make fe-unit         # run Vitest frontend unit tests
make tier1-down      # stop + wipe volumes

The stack is hermetic and disposable — fresh SQLite + fresh seeded Gitea each tier1-up. e2e signs in via the email OTC flow, reading the code back from Mailpit, so no real OAuth provider is needed.

CI note: the backend enforces a per-IP OTC request limiter (5 requests / 300s, backend/app/ratelimit.py). A single make e2e run uses exactly one OTC request, so the normal "fresh tier1-up then one e2e" flow is well clear of it. Do not retry make e2e more than ~4 times in a 5-minute window against the same running stack, or the 6th OTC request will 429. Restarting the backend container (or tier1-down/tier1-up) resets the in-process limiter. Note: this is distinct from the per-email 60s OTC cooldown (OTC_REQUEST_COOLDOWN_SECONDS, backend/app/otc.py); the smoke spec handles that separately by using a unique email address per run.

Tier 2 — PPE (deploy gate)

The SAME suite, pointed at the PPE instance (once rfc-app-ppe.<base> is stood up via flotilla — see the engineering handbook §10.1/§10.3):

cd e2e && BASE_URL=https://rfc-app-ppe.<base> MAILSINK_URL=<ppe-mailpit-api> npm run e2e

PPE provides the real nginx/systemd/SQLite topology + its own isolated Gitea + always-pass Turnstile keys. Standing up the PPE VM is an operator task, not part of this repo.