fix(ci): repair the chronically-failing nightly workflow (#624)

The scheduled Nightly had been red for over a week across nearly every job. This
root-causes and fixes each one. All were pre-existing: missing CI provisioning,
specs that drifted as the app grew, a job too heavy for its timeout, and a fuzz
that was never configured for file-upload endpoints. None came from the recent
security merge.

- Coverage + Docker Container E2E: install tesseract and its language packs so
  the built-in Fast OCR tests stop throwing spawn ENOENT; gate two repo-file and
  release-workflow tests that cannot run inside the slimmed container image.
- E2E (Full, Serial, Cross-Browser, Device Matrix): refresh specs that drifted
  behind the app (tool renames, the now admin-only Tools tab, dropped About copy,
  locator collisions scoped to the right region). One real product fix rode
  along: /config/auth was refetched six times per tool-page load, so cache it
  behind a single shared fetch, dropping the tool page from 13 to 8 API calls.
- Extended Matrix + Fuzz: shard the integration suite four ways so the full
  format x tool matrix plus property fuzz fits its budget instead of overrunning
  the 90-minute ceiling every night.
- Schemathesis: exclude the tools with bespoke handlers that process
  synchronously in-request (they hang the fuzz on adversarial input) and suppress
  Hypothesis's data-generation health checks, which fire because file-upload
  endpoints reject the fuzzer's random bytes. not_a_server_error still runs on
  every generated case (5000+ per run).
- Stabilize two long-tail flakes: raise the avif matrix per-test cap from 240s to
  600s, and assert toHaveCount(0) on the deleted user row so a transient success
  toast no longer trips a strict-mode violation.

Verified end to end: the full Nightly workflow is green on this branch (all 14
jobs), and PR CI is green.
This commit is contained in:
SnapOtter
2026-07-24 03:54:50 +08:00
committed by GitHub
parent 079fcd2631
commit 44f5aea326
20 changed files with 186 additions and 99 deletions
+5 -18
View File
@@ -1513,27 +1513,14 @@ base.describe("RBAC GUI - User tab content access", () => {
await expect(page.getByText("Password changed successfully")).toBeVisible({ timeout: 5_000 });
});
base.test("user can toggle tool visibility in Tools tab", async ({ page }) => {
base.test("user cannot access the Tools tab (requires settings:write)", async ({ page }) => {
await login(page, USER_GUI, USER_GUI_PASS);
await openSettings(page);
await page.getByRole("button", { name: /tools/i }).click();
await expect(page.getByRole("button", { name: /general/i })).toBeVisible();
await expect(page.getByText(/\d+ tools? disabled/)).toBeVisible({ timeout: 5_000 });
const counterText = page.getByText(/\d+ tools? disabled/);
const initialText = await counterText.textContent();
const initialCount = parseInt(initialText?.match(/(\d+)/)?.[1] || "0", 10);
// Toggle the first tool
const firstToggle = page.locator("button.w-11.h-6").first();
await firstToggle.click();
const updatedText = await counterText.textContent();
const updatedCount = parseInt(updatedText?.match(/(\d+)/)?.[1] || "0", 10);
expect(Math.abs(updatedCount - initialCount)).toBe(1);
// Revert
await firstToggle.click();
// The Tools tab writes the admin-only /v1/settings endpoint, so it is gated
// behind settings:write and hidden from the user role.
await expect(page.getByRole("button", { name: /tools/i })).not.toBeVisible();
});
base.test("user can generate API key from GUI", async ({ page }) => {