mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
test: expand test coverage across unit, integration, e2e, and e2e-docker suites
Add ~210 new tests filling gaps identified by a comprehensive 14-agent coverage audit. Unit+integration tests go from 9,388 to 9,484 (all passing). Unit tests (+36): - AI bridge: OOM fallback path, custom tier option - Web lib: api-errors, format date/datetime, tool-i18n coverage Integration tests (+19): - Format matrix: ai-canvas-expand and find-duplicates added to cross-format matrix - Adversarial: SVG XXE attacks, SQL injection in settings, request body size limits, race conditions with identical filenames E2E Docker (+3): - ai-canvas-expand tool coverage with HEIC input and edge cases E2E GUI (~150+): - Navigation: login rate limiting, ai-canvas-expand in parameterized list - Responsive: dropzone visibility, text readability, dialog bounds at all viewports - Keyboard: shortcuts verified from automate, files, tool, and fullscreen pages - Tool UI: undo/state-reset for 16 tools, crop canvas drag handles, rotate/border live preview, linked aspect-ratio inputs for resize - Batch: per-image undo isolation, batch compress/convert/rotate (not just resize) - Pipeline: tool palette search, step collapse/expand visibility - Settings: audit log entry verification, system settings persistence, teams CRUD, role permission toggling - RBAC: user/editor 403 on roles/teams endpoints, privilege escalation prevention, cross-role tab parity documented as intentional - Accessibility: skip-to-content link (WCAG 2.4.1), comprehensive color contrast for all headings/body/buttons in both themes with DOM-walking background detection - Resilience: auth expiry 401 redirect, rate limit 429 handling - Performance: JS heap memory stability for tool navigation, dialog cycling, upload/clear cycles, rapid page navigation
This commit is contained in:
@@ -121,6 +121,31 @@ test.describe("Login Page", () => {
|
||||
|
||||
await expect(page.getByText("SnapOtter").first()).toBeVisible();
|
||||
});
|
||||
|
||||
test("after too many failed attempts, rate limiting kicks in", async ({ page }) => {
|
||||
await page.goto("/login");
|
||||
|
||||
// Submit several failed login attempts in rapid succession
|
||||
for (let i = 0; i < 10; i++) {
|
||||
await page.getByLabel("Username").fill(`wrong-user-${i}`);
|
||||
await page.getByLabel("Password").fill(`wrong-pass-${i}`);
|
||||
await page.getByRole("button", { name: /login/i }).click();
|
||||
|
||||
// Wait briefly for the response
|
||||
await page.waitForTimeout(300);
|
||||
}
|
||||
|
||||
// After many rapid failures, the UI should show a rate-limit or lockout message,
|
||||
// or the login button should become temporarily disabled
|
||||
const rateLimited = page.getByText(/too many|rate limit|try again|locked|slow down/i).first();
|
||||
const disabledBtn = page.getByRole("button", { name: /login/i });
|
||||
|
||||
// Either an error message about rate limiting appears, or the button is disabled
|
||||
const hasRateLimitMsg = await rateLimited.isVisible({ timeout: 5000 }).catch(() => false);
|
||||
const isDisabled = await disabledBtn.isDisabled();
|
||||
|
||||
expect(hasRateLimitMsg || isDisabled).toBe(true);
|
||||
});
|
||||
});
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
@@ -416,6 +441,7 @@ const DROPZONE_TOOLS = [
|
||||
{ id: "restore-photo", name: "Photo Restoration" },
|
||||
{ id: "passport-photo", name: "Passport Photo" },
|
||||
{ id: "content-aware-resize", name: "Content-Aware Resize" },
|
||||
{ id: "ai-canvas-expand", name: "AI Canvas Expand" },
|
||||
{ id: "transparency-fixer", name: "PNG Transparency Fixer" },
|
||||
// Watermark & Overlay
|
||||
{ id: "watermark-text", name: "Text Watermark" },
|
||||
|
||||
Reference in New Issue
Block a user