Files
SnapOtter/tests/e2e-docker/auth.setup.ts
T
SnapOtter b00ef20667 fix: close SVG sanitization gap on upload routes and fix OCR/extension bugs
Security:
- Apply sanitizeSvg() to all file upload routes (files.ts, user-files.ts)
  preventing SSRF and script injection via SVG uploads to file library

Functional:
- Handle PaddleOCR-VL 1.5 markdown_texts output format in ocr.py
- Add empty-text fallback in OCR tier chain (ocr.ts) so higher tiers
  that return empty text fall back to the next tier automatically
- Fix SVG->PNG filename extension mismatch in tool-factory.ts so
  download endpoint serves correct Content-Type
- Report original upload size (not decoded size) in API response

Test infrastructure:
- Move Playwright auth state from test-results/ to .playwright/ to
  prevent mid-run cleanup deleting auth files
- Fix auth.setup.ts navigation race with waitForURL
- Fix gui-batch.spec.ts regex matching "Presets" instead of "reset"
- Fix pipeline-advanced.spec.ts crop bounds and resize assertions
- Broaden pipeline cleanup to include all E2E-prefixed pipelines
2026-04-30 16:11:33 +08:00

32 lines
1.2 KiB
TypeScript

import { mkdirSync } from "node:fs";
import path from "node:path";
import { expect, test as setup } from "@playwright/test";
const authFile = path.join(__dirname, "..", "..", ".playwright", ".auth", "analytics-user.json");
setup("authenticate", async ({ page }) => {
await page.goto("/login");
await page.getByLabel("Username").fill("admin");
await page.getByLabel("Password").fill("admin");
await page.getByRole("button", { name: /login/i }).click();
// Wait for login to complete — page leaves "/login"
await page.waitForURL((url) => !url.pathname.startsWith("/login"), {
timeout: 30_000,
});
// If we landed on the consent page, accept or decline it
if (page.url().includes("/analytics-consent")) {
const acceptBtn = page.getByRole("button", { name: /sure, sounds good/i });
await acceptBtn.waitFor({ state: "visible", timeout: 15_000 });
await acceptBtn.click();
// Consent page does window.location.href = "/" (full reload)
await page.waitForURL("/", { timeout: 30_000 });
}
// At this point we should be on the home page
await expect(page).toHaveURL("/");
mkdirSync(path.dirname(authFile), { recursive: true });
await page.context().storageState({ path: authFile });
});