test: expand test coverage across unit, integration, e2e, and e2e-docker suites

Add ~210 new tests filling gaps identified by a comprehensive 14-agent
coverage audit. Unit+integration tests go from 9,388 to 9,484 (all passing).

Unit tests (+36):
- AI bridge: OOM fallback path, custom tier option
- Web lib: api-errors, format date/datetime, tool-i18n coverage

Integration tests (+19):
- Format matrix: ai-canvas-expand and find-duplicates added to cross-format matrix
- Adversarial: SVG XXE attacks, SQL injection in settings, request body size
  limits, race conditions with identical filenames

E2E Docker (+3):
- ai-canvas-expand tool coverage with HEIC input and edge cases

E2E GUI (~150+):
- Navigation: login rate limiting, ai-canvas-expand in parameterized list
- Responsive: dropzone visibility, text readability, dialog bounds at all viewports
- Keyboard: shortcuts verified from automate, files, tool, and fullscreen pages
- Tool UI: undo/state-reset for 16 tools, crop canvas drag handles, rotate/border
  live preview, linked aspect-ratio inputs for resize
- Batch: per-image undo isolation, batch compress/convert/rotate (not just resize)
- Pipeline: tool palette search, step collapse/expand visibility
- Settings: audit log entry verification, system settings persistence, teams CRUD,
  role permission toggling
- RBAC: user/editor 403 on roles/teams endpoints, privilege escalation prevention,
  cross-role tab parity documented as intentional
- Accessibility: skip-to-content link (WCAG 2.4.1), comprehensive color contrast
  for all headings/body/buttons in both themes with DOM-walking background detection
- Resilience: auth expiry 401 redirect, rate limit 429 handling
- Performance: JS heap memory stability for tool navigation, dialog cycling,
  upload/clear cycles, rapid page navigation
This commit is contained in:
SnapOtter
2026-05-15 21:35:02 +08:00
parent d38621d7b9
commit 3b181dd1ac
24 changed files with 3398 additions and 0 deletions
+197
View File
@@ -560,4 +560,201 @@ base.describe("RBAC Settings Visibility - User", () => {
await expect(page.locator("h3").filter({ hasText: "API Keys" })).toBeVisible();
await expect(page.getByRole("button", { name: /generate api key/i })).toBeVisible();
});
base.test("user gets 403 on roles endpoint", async ({ page }) => {
await login(page, USER_USER, USER_PASS);
const token = await page.evaluate(() => localStorage.getItem("snapotter-token"));
expect(token).toBeTruthy();
const bearerToken = token as string;
// GET /api/v1/roles requires users:manage
const rolesRes = await fetch(`${API}/api/v1/roles`, {
headers: { Authorization: `Bearer ${bearerToken}` },
});
expect(rolesRes.status).toBe(403);
});
base.test("user cannot register new users via API", async ({ page }) => {
await login(page, USER_USER, USER_PASS);
const token = await page.evaluate(() => localStorage.getItem("snapotter-token"));
expect(token).toBeTruthy();
const bearerToken = token as string;
// POST /api/auth/register requires users:manage
const registerRes = await fetch(`${API}/api/auth/register`, {
method: "POST",
headers: {
Authorization: `Bearer ${bearerToken}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
username: "hacked-user",
password: "HackedPass1",
role: "admin",
}),
});
expect(registerRes.status).toBe(403);
});
});
// ---------------------------------------------------------------------------
// RBAC -- additional cross-role endpoint verification
// ---------------------------------------------------------------------------
base.describe("RBAC API Endpoints - Editor (extended)", () => {
let adminToken: string;
const EDITOR_EXT = `guieditorext-${UID}`;
const EDITOR_EXT_PASS = "EditorExtPass1";
base.beforeAll(async () => {
adminToken = await getAdminToken();
await createReadyUser(adminToken, EDITOR_EXT, EDITOR_EXT_PASS, "editor");
});
base.afterAll(async () => {
await deleteUser(adminToken, EDITOR_EXT);
});
base.test("editor gets 403 on teams endpoint", async ({ page }) => {
await login(page, EDITOR_EXT, EDITOR_EXT_PASS);
const token = await page.evaluate(() => localStorage.getItem("snapotter-token"));
expect(token).toBeTruthy();
const bearerToken = token as string;
// GET /api/v1/teams requires teams:manage
const teamsRes = await fetch(`${API}/api/v1/teams`, {
headers: { Authorization: `Bearer ${bearerToken}` },
});
expect(teamsRes.status).toBe(403);
});
base.test("editor gets 403 on roles endpoint", async ({ page }) => {
await login(page, EDITOR_EXT, EDITOR_EXT_PASS);
const token = await page.evaluate(() => localStorage.getItem("snapotter-token"));
expect(token).toBeTruthy();
const bearerToken = token as string;
// GET /api/v1/roles requires users:manage
const rolesRes = await fetch(`${API}/api/v1/roles`, {
headers: { Authorization: `Bearer ${bearerToken}` },
});
expect(rolesRes.status).toBe(403);
});
base.test("editor cannot register new users via API", async ({ page }) => {
await login(page, EDITOR_EXT, EDITOR_EXT_PASS);
const token = await page.evaluate(() => localStorage.getItem("snapotter-token"));
expect(token).toBeTruthy();
const bearerToken = token as string;
const registerRes = await fetch(`${API}/api/auth/register`, {
method: "POST",
headers: {
Authorization: `Bearer ${bearerToken}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
username: "hacked-editor-user",
password: "HackedPass1",
role: "user",
}),
});
expect(registerRes.status).toBe(403);
});
base.test("editor can read own settings via API", async ({ page }) => {
await login(page, EDITOR_EXT, EDITOR_EXT_PASS);
const token = await page.evaluate(() => localStorage.getItem("snapotter-token"));
expect(token).toBeTruthy();
const bearerToken = token as string;
// GET /api/v1/config/auth is public, but session should work
const sessionRes = await fetch(`${API}/api/auth/session`, {
headers: { Authorization: `Bearer ${bearerToken}` },
});
expect(sessionRes.status).toBe(200);
const session = await sessionRes.json();
expect(session.user.role).toBe("editor");
});
base.test("editor About tab shows correct role", async ({ page }) => {
await login(page, EDITOR_EXT, EDITOR_EXT_PASS);
await openSettings(page);
await page.getByRole("button", { name: /about/i }).click();
await expect(page.locator("h3").filter({ hasText: "About" })).toBeVisible();
await expect(page.getByText("Version:")).toBeVisible();
});
});
base.describe("RBAC -- Editor and User see identical tabs (intentional)", () => {
let adminToken: string;
const RBAC_EDITOR = `rbaceditor-${UID}`;
const RBAC_EDITOR_PASS = "RbacEditorPass1";
const RBAC_USER = `rbacuser-${UID}`;
const RBAC_USER_PASS = "RbacUserPass1";
base.beforeAll(async () => {
adminToken = await getAdminToken();
await createReadyUser(adminToken, RBAC_EDITOR, RBAC_EDITOR_PASS, "editor");
await createReadyUser(adminToken, RBAC_USER, RBAC_USER_PASS, "user");
});
base.afterAll(async () => {
await deleteUser(adminToken, RBAC_EDITOR);
await deleteUser(adminToken, RBAC_USER);
});
base.test(
"editor and user see the same 6 tabs (correct behavior, not a bug)",
async ({ page }) => {
// Verify editor tab count
await login(page, RBAC_EDITOR, RBAC_EDITOR_PASS);
await openSettings(page);
await expect(page.getByRole("button", { name: /general/i })).toBeVisible();
const editorNavButtons = page.locator(".w-48 button");
const editorCount = await editorNavButtons.count();
// Close and switch to user
await page.keyboard.press("Escape");
await page.goto("/login");
await login(page, RBAC_USER, RBAC_USER_PASS);
await openSettings(page);
await expect(page.getByRole("button", { name: /general/i })).toBeVisible();
const userNavButtons = page.locator(".w-48 button");
const userCount = await userNavButtons.count();
// Both should see exactly 6 tabs
expect(editorCount).toBe(6);
expect(userCount).toBe(6);
expect(editorCount).toBe(userCount);
},
);
base.test("editor and user both see the same set of tab labels", async ({ page }) => {
const expectedTabs = ["General", "Security", "API Keys", "Tools", "Product Analytics", "About"];
// Check editor
await login(page, RBAC_EDITOR, RBAC_EDITOR_PASS);
await openSettings(page);
for (const label of expectedTabs) {
await expect(page.getByRole("button", { name: new RegExp(label, "i") })).toBeVisible();
}
// Close and check user
await page.keyboard.press("Escape");
await page.goto("/login");
await login(page, RBAC_USER, RBAC_USER_PASS);
await openSettings(page);
for (const label of expectedTabs) {
await expect(page.getByRole("button", { name: new RegExp(label, "i") })).toBeVisible();
}
});
});