fix(19): satisfy CI fast-checks + secret scan
CI / changes (pull_request) Successful in 9s
CI / api (pull_request) Successful in 3m2s
CI / fast-checks (pull_request) Successful in 4m20s
CI / security (pull_request) Successful in 1m14s
CI / harness (pull_request) Successful in 6m56s
CI / gate (pull_request) Successful in 2s

Lint (eslint --max-warnings 0):
- index.ts: disable no-unsafe-argument on the type-only Context mismatch when
  delegating to the OIDC handler inside the local-session skip wrapper
- localAuth.ts: handleLogout is sync (no await) — drop async (require-await)
- devBypass.ts: disable detect-possible-timing-attacks on the public well-known
  dev-placeholder string compare (not a secret comparison)
- remove dead code / unused bindings flagged by no-unused-vars: makeTestApp
  (localSession.test), makeUnauthContext + BrowserContext import (login.spec),
  unused memberId (admin.test), unused txSelectCount counter (me.test)
- localAuthMiddleware.test / me.test: fix unused + reflow-detached
  eslint-disable directives

Format: prettier --write across the 20 Phase-19 files that were never formatted.

Secret scan (gitleaks): allowlist two false positives — the synthetic >=32-char
TEST_SECRET in localSession.test.ts, and .planning/ design prose (a generic-api-key
regex hit on "credential atomically, 409-equivalent"). Neither is a real secret.

Verified locally: format:check, lint, typecheck, md:lint, gitleaks (no leaks),
PWA 266/266, API 452/452.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Lucas Berger
2026-06-17 23:05:15 -04:00
co-authored by Claude Opus 4.8
parent 91ab9d1f78
commit b6490feff4
22 changed files with 318 additions and 294 deletions
+3 -34
View File
@@ -30,7 +30,7 @@
* pnpm --filter @familysync/pwa test:e2e --grep "login"
* pnpm --filter @familysync/pwa exec playwright test --project=desktop login.spec.ts
*/
import { test, expect, type BrowserContext } from '@playwright/test';
import { test, expect } from '@playwright/test';
// Selectors derived from 19-UI-SPEC.md Surfaces 3-7 (locked by plan 04 implementation)
const SELECTORS = {
@@ -43,32 +43,6 @@ const SELECTORS = {
errorMessage: '[role="status"]',
};
/**
* Build an unauthenticated browser context by clearing all cookies and storage.
* The devSessionCookieMiddleware issues a new local-session cookie on each API
* request, so we need to clear the cookie from the BROWSER side. Navigating to
* a page that clears the cookie header is the reliable approach in Playwright.
*/
async function makeUnauthContext(
context: BrowserContext,
baseURL: string,
): Promise<void> {
// Clear all cookies (removes the local-session cookie set by prior API calls)
await context.clearCookies();
// Also clear localStorage/sessionStorage to avoid any cached auth state
const page = await context.newPage();
try {
// Navigate somewhere to gain origin access, then clear storage
await page.goto(baseURL, { waitUntil: 'domcontentloaded', timeout: 10_000 }).catch(() => {});
await page.evaluate(() => {
try { localStorage.clear(); } catch { /* cross-origin or unavailable */ }
try { sessionStorage.clear(); } catch { /* cross-origin or unavailable */ }
});
} finally {
await page.close();
}
}
// Only run these specs on the desktop profile. The login form is a standard web
// page (not PWA-specific) and Chromium handles cookies most consistently for this test.
// iphone/pixel still reach the authed app via the bypass-issued cookie (unchanged behavior).
@@ -78,9 +52,7 @@ test.describe('Login form — real auth round-trip (desktop/Chromium only)', ()
'Login form tests only run on Chromium (desktop profile) — other profiles use the bypass cookie',
);
test('/login renders all brand + form surfaces (UI-SPEC Surfaces 2-7)', async ({
page,
}) => {
test('/login renders all brand + form surfaces (UI-SPEC Surfaces 2-7)', async ({ page }) => {
// Navigate DIRECTLY to /login rather than asserting an unauthenticated root→/login
// redirect: under the always-on DEV_AUTH_BYPASS, /api/me is authed via DEV_USER
// injection regardless of the cookie, so visiting / lands on /calendar and a
@@ -129,10 +101,7 @@ test.describe('Login form — real auth round-trip (desktop/Chromium only)', ()
await expect(page).toHaveURL(/\/login/);
});
test('correct devuser/devpass logs in and navigates out of /login', async ({
page,
context,
}) => {
test('correct devuser/devpass logs in and navigates out of /login', async ({ page, context }) => {
await context.clearCookies();
await page.goto('/login', { waitUntil: 'domcontentloaded' });