test: expand test coverage across unit, integration, e2e, and e2e-docker suites

Add ~210 new tests filling gaps identified by a comprehensive 14-agent
coverage audit. Unit+integration tests go from 9,388 to 9,484 (all passing).

Unit tests (+36):
- AI bridge: OOM fallback path, custom tier option
- Web lib: api-errors, format date/datetime, tool-i18n coverage

Integration tests (+19):
- Format matrix: ai-canvas-expand and find-duplicates added to cross-format matrix
- Adversarial: SVG XXE attacks, SQL injection in settings, request body size
  limits, race conditions with identical filenames

E2E Docker (+3):
- ai-canvas-expand tool coverage with HEIC input and edge cases

E2E GUI (~150+):
- Navigation: login rate limiting, ai-canvas-expand in parameterized list
- Responsive: dropzone visibility, text readability, dialog bounds at all viewports
- Keyboard: shortcuts verified from automate, files, tool, and fullscreen pages
- Tool UI: undo/state-reset for 16 tools, crop canvas drag handles, rotate/border
  live preview, linked aspect-ratio inputs for resize
- Batch: per-image undo isolation, batch compress/convert/rotate (not just resize)
- Pipeline: tool palette search, step collapse/expand visibility
- Settings: audit log entry verification, system settings persistence, teams CRUD,
  role permission toggling
- RBAC: user/editor 403 on roles/teams endpoints, privilege escalation prevention,
  cross-role tab parity documented as intentional
- Accessibility: skip-to-content link (WCAG 2.4.1), comprehensive color contrast
  for all headings/body/buttons in both themes with DOM-walking background detection
- Resilience: auth expiry 401 redirect, rate limit 429 handling
- Performance: JS heap memory stability for tool navigation, dialog cycling,
  upload/clear cycles, rapid page navigation
This commit is contained in:
SnapOtter
2026-05-15 21:35:02 +08:00
parent d38621d7b9
commit 3b181dd1ac
24 changed files with 3398 additions and 0 deletions
+26
View File
@@ -121,6 +121,31 @@ test.describe("Login Page", () => {
await expect(page.getByText("SnapOtter").first()).toBeVisible();
});
test("after too many failed attempts, rate limiting kicks in", async ({ page }) => {
await page.goto("/login");
// Submit several failed login attempts in rapid succession
for (let i = 0; i < 10; i++) {
await page.getByLabel("Username").fill(`wrong-user-${i}`);
await page.getByLabel("Password").fill(`wrong-pass-${i}`);
await page.getByRole("button", { name: /login/i }).click();
// Wait briefly for the response
await page.waitForTimeout(300);
}
// After many rapid failures, the UI should show a rate-limit or lockout message,
// or the login button should become temporarily disabled
const rateLimited = page.getByText(/too many|rate limit|try again|locked|slow down/i).first();
const disabledBtn = page.getByRole("button", { name: /login/i });
// Either an error message about rate limiting appears, or the button is disabled
const hasRateLimitMsg = await rateLimited.isVisible({ timeout: 5000 }).catch(() => false);
const isDisabled = await disabledBtn.isDisabled();
expect(hasRateLimitMsg || isDisabled).toBe(true);
});
});
// ---------------------------------------------------------------------------
@@ -416,6 +441,7 @@ const DROPZONE_TOOLS = [
{ id: "restore-photo", name: "Photo Restoration" },
{ id: "passport-photo", name: "Passport Photo" },
{ id: "content-aware-resize", name: "Content-Aware Resize" },
{ id: "ai-canvas-expand", name: "AI Canvas Expand" },
{ id: "transparency-fixer", name: "PNG Transparency Fixer" },
// Watermark & Overlay
{ id: "watermark-text", name: "Text Watermark" },