Pre-launch — Gluecron is in final validation. Public signups and git hosting for non-owner users open after launch review.
CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
claude/adoring-hopper-5x74bqclaude/affectionate-feynman-ykrf1hclaude/architecture-audit-design-wxprenclaude/build-status-update-3MXsfclaude/charming-meitner-mllb5rclaude/compare-gate-gluecron-s4mFQclaude/confident-faraday-tikcwbclaude/continue-work-XMTlIclaude/crontech-gluecron-deploy-7MIECclaude/crontech-platform-setup-SeKfwclaude/design-2026claude/ecstatic-ptolemy-jMdigclaude/enhance-github-integration-QNHdGclaude/fix-aa-loop-issue-PonMQclaude/fix-actions-and-processclaude/fix-desktop-errors-XqoW8claude/fix-red-workflowsclaude/fix-website-access-6FKJNclaude/gatetest-integration-hardeningclaude/github-audit-improvements-bDFr9claude/gluecron-launch-status-FoMRlclaude/hopeful-lamport-olfCTclaude/issue-to-pr-and-protectionsclaude/jolly-heisenberg-2sg1Qclaude/launch-preparation-QmTb6claude/new-session-xk1l7claude/plan-platform-architecture-kkN4yclaude/platform-analysis-roadmap-1nUGLclaude/platform-launch-assessment-8dWV8claude/polish-platform-release-AeDrUclaude/resume-previous-work-KzyLwclaude/review-crontech-handoff-qYEVqclaude/review-project-completeness-lHhS2claude/review-readme-docs-ulqPKclaude/serene-edison-rj87weclaude/setup-multi-repo-dev-BCwNQclaude/ship-fixes-and-tests-Jvz1cclaude/site-audit-competitive-pctlwgclaude/site-migration-vercel-XstpKclaude/standalone-product-repos-XHFTDcopilot/feat-smart-empty-states-keyboard-first-enhancementcopilot/feat-smart-morning-digest-review-context-restorecopilot/fix-and-process-workflowscopilot/update-ai-powered-code-reviewfeat/debt-mapfeat/push-policy-codeowners-hardeningfeat/smart-digest-contextfeat/stage-impactfeat/t1-secret-migrationfeat/u-polishfeat/w-self-hostfeat/w2-claude-configfix/agent-journey-orphan-sweepgatetest/auto-fix-1776586424172gatetest/auto-fix-1776586534814gatetest/auto-fix-1776590685143gatetest/auto-fix-1776590808199mainops/redeploy-retriggerstyle/dxt-cta-themeworktree-agent-a3377aad30d55da26worktree-agent-a7ef607b7ee1d6c74
auth.spec.ts6.0 KB · 167 lines
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
/**
 * E2E — Auth flows
 *
 * Covers: registration, login, logout, wrong password.
 * Each test creates its own isolated user to avoid cross-test state.
 */

import { test, expect } from "@playwright/test";
import { uid, TEST_PASSWORD } from "./fixtures";

// ---------------------------------------------------------------------------
// Register
// ---------------------------------------------------------------------------

test.describe("Registration", () => {
  test("happy path — new user registers and lands on dashboard", async ({ page }) => {
    const username = uid("reg");
    const email = `${username}@test.example`;

    await page.goto("/register");
    await page.fill('input[name="username"]', username);
    await page.fill('input[name="email"]', email);
    await page.fill('input[name="password"]', TEST_PASSWORD);
    await page.click('button[type="submit"]');

    // Expect redirect away from /register
    await expect(page).not.toHaveURL(/\/register/);

    // Should surface the username somewhere on the page (nav, dashboard, etc.)
    await expect(page.locator("body")).toContainText(username, { timeout: 8_000 });
  });

  test("duplicate username — shows error message", async ({ page }) => {
    const username = uid("dup");
    const email = `${username}@test.example`;

    // Register once
    await page.goto("/register");
    await page.fill('input[name="username"]', username);
    await page.fill('input[name="email"]', email);
    await page.fill('input[name="password"]', TEST_PASSWORD);
    await page.click('button[type="submit"]');
    await page.waitForURL(/\/(dashboard|[a-z])/);

    // Navigate away, then try registering again with same username
    await page.goto("/register");
    await page.fill('input[name="username"]', username);
    await page.fill('input[name="email"]', `other-${email}`);
    await page.fill('input[name="password"]', TEST_PASSWORD);
    await page.click('button[type="submit"]');

    // Should stay on /register (or show an error URL) with an error message
    const body = page.locator("body");
    await expect(body).toContainText(/already|taken|exists/i, { timeout: 5_000 });
  });

  test("missing fields — stays on register page", async ({ page }) => {
    await page.goto("/register");
    // Submit with no data — browser or server should block/redirect back
    await page.click('button[type="submit"]');

    // We either stay on /register or get an error param
    const url = page.url();
    const onRegisterOrError =
      url.includes("/register") ||
      url.includes("error") ||
      (await page.locator(".auth-error, [role=alert]").count()) > 0;
    expect(onRegisterOrError).toBeTruthy();
  });
});

// ---------------------------------------------------------------------------
// Login
// ---------------------------------------------------------------------------

test.describe("Login", () => {
  test("happy path — existing user logs in", async ({ page }) => {
    const username = uid("login");
    const email = `${username}@test.example`;

    // Pre-register
    await page.goto("/register");
    await page.fill('input[name="username"]', username);
    await page.fill('input[name="email"]', email);
    await page.fill('input[name="password"]', TEST_PASSWORD);
    await page.click('button[type="submit"]');
    await page.waitForURL(/\/(dashboard|[a-z])/);

    // Logout then log back in
    await page.goto("/logout");
    await page.waitForURL(/\/(login|register|)/);

    await page.goto("/login");
    await page.fill('input[name="username"]', username);
    await page.fill('input[name="password"]', TEST_PASSWORD);
    await page.click('button[type="submit"]');

    await expect(page).not.toHaveURL(/\/login/);
    await expect(page.locator("body")).toContainText(username, { timeout: 8_000 });
  });

  test("wrong password — shows error, stays on login page", async ({ page }) => {
    const username = uid("badpw");
    const email = `${username}@test.example`;

    // Pre-register
    await page.goto("/register");
    await page.fill('input[name="username"]', username);
    await page.fill('input[name="email"]', email);
    await page.fill('input[name="password"]', TEST_PASSWORD);
    await page.click('button[type="submit"]');
    await page.waitForURL(/\/(dashboard|[a-z])/);

    // Logout
    await page.goto("/logout");

    // Try wrong password
    await page.goto("/login");
    await page.fill('input[name="username"]', username);
    await page.fill('input[name="password"]', "WrongPassword999!");
    await page.click('button[type="submit"]');

    // Should stay on login or get an error
    const body = page.locator("body");
    await expect(body).toContainText(/invalid|incorrect|wrong|failed/i, {
      timeout: 5_000,
    });
  });

  test("unknown username — shows error", async ({ page }) => {
    await page.goto("/login");
    await page.fill('input[name="username"]', "totally_nonexistent_xyz_abc");
    await page.fill('input[name="password"]', TEST_PASSWORD);
    await page.click('button[type="submit"]');

    const body = page.locator("body");
    await expect(body).toContainText(/invalid|not found|incorrect/i, {
      timeout: 5_000,
    });
  });
});

// ---------------------------------------------------------------------------
// Logout
// ---------------------------------------------------------------------------

test.describe("Logout", () => {
  test("logged-in user can log out and is redirected", async ({ page }) => {
    const username = uid("lgout");
    const email = `${username}@test.example`;

    await page.goto("/register");
    await page.fill('input[name="username"]', username);
    await page.fill('input[name="email"]', email);
    await page.fill('input[name="password"]', TEST_PASSWORD);
    await page.click('button[type="submit"]');
    await page.waitForURL(/\/(dashboard|[a-z])/);

    // Logout
    await page.goto("/logout");
    await page.waitForURL(/\/(login|register|)/);

    // Accessing a protected route should redirect to login
    await page.goto("/settings");
    await expect(page).toHaveURL(/\/login/);
  });
});