// Verifies the per-member estate model end-to-end against the live backend: // owner invites a plain "member" and an agent (mutawalli); the member authors // their own Wassiyah, private to them; the mutawalli sees it on their // dashboard and can fire the member's trigger; the member cannot fire their // own trigger; the owner's own separate Wassiyah is not visible to the // member as "theirs" (proves per-author isolation, not just per-family). const { chromium } = require('playwright'); const { gotoTab } = require('./e2e-auth-helper.cjs'); const BASE = 'https://moslem04.falahos.my/'; const results = []; function record(name, pass, detail = '') { results.push({ name, pass, detail }); console.log(`${pass ? 'PASS' : 'FAIL'} ${name}${detail ? ' — ' + detail : ''}`); } const OWNER = 'nurfalah.e2etest.owner@gmail.com'; const AGENT = 'nurfalah.e2etest.agent@gmail.com'; const MEMBER = 'nurfalah.e2etest.member@gmail.com'; const PASSWORD = 'TestPassword123!'; const familyName = `PerMember ${Date.now()}-${Math.floor(Math.random() * 1e6)}`; async function signIn(page, email) { await page.goto(BASE, { waitUntil: 'networkidle' }); await page.locator('.field:has-text("Email") input').fill(email); await page.locator('.field:has-text("Password") input').fill(PASSWORD); await page.locator('button.btn-primary', { hasText: 'Sign in' }).click(); await page.waitForTimeout(1500); } async function main() { const browser = await chromium.launch(); // ── Owner: create family, invite member + agent ── const ownerCtx = await browser.newContext({ viewport: { width: 390, height: 844 } }); const ownerPage = await ownerCtx.newPage(); await signIn(ownerPage, OWNER); await ownerPage.locator('.field:has-text("Family name") input').fill(familyName); await ownerPage.locator('button.btn-primary', { hasText: 'Create family' }).click(); await ownerPage.waitForTimeout(1200); await gotoTab(ownerPage, 'Manage'); await ownerPage.waitForTimeout(500); await ownerPage.locator('.field:has-text("Invite by email") input').fill(MEMBER); await ownerPage.locator('.field:has-text("Role") select').selectOption('member'); await ownerPage.locator('button.btn-primary', { hasText: 'Send invite' }).click(); await ownerPage.waitForTimeout(600); await ownerPage.locator('.field:has-text("Invite by email") input').fill(AGENT); await ownerPage.locator('.field:has-text("Role") select').selectOption('agent'); await ownerPage.locator('button.btn-primary', { hasText: 'Send invite' }).click(); const bothInvited = await ownerPage.locator('.member-row', { hasText: MEMBER }).waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false); record('Owner: invites both a member and an agent', bothInvited); // Owner writes their OWN wassiyah bequest (should stay private to owner) await gotoTab(ownerPage, 'Wassiyah'); await ownerPage.waitForTimeout(600); await ownerPage.locator('.form-card .field:has-text("Recipient name") input').fill('Owner Charity'); await ownerPage.locator('.form-card .field:has-text("Relation to you") input').fill('charity'); await ownerPage.locator('.form-card .field:has-text("Description") input').fill('Owner personal bequest'); await ownerPage.locator('.form-card .field:has-text("Value") input').fill('5000'); await ownerPage.locator('.form-card button.btn-primary', { hasText: 'Add bequest' }).click(); await ownerPage.waitForTimeout(600); // ── Member: accept, author own Wassiyah (should NOT see owner's bequest) ── const memberCtx = await browser.newContext({ viewport: { width: 390, height: 844 } }); const memberPage = await memberCtx.newPage(); await signIn(memberPage, MEMBER); const inviteRow = memberPage.locator('.invite-row', { hasText: familyName }); const inviteVisible = await inviteRow.waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false); record('Member: sees pending invite', inviteVisible); await inviteRow.locator('.btn-small', { hasText: 'Accept' }).click(); await memberPage.locator('.hub-tab[aria-label="Home"]').waitFor({ state: 'visible', timeout: 10000 }); await gotoTab(memberPage, 'Wassiyah'); await memberPage.waitForTimeout(600); const ownerBequestVisibleToMember = await memberPage.locator('.bequest-row', { hasText: 'Owner Charity' }).isVisible().catch(() => false); record('Member: does NOT see owner\'s private bequest (per-author isolation)', !ownerBequestVisibleToMember); await memberPage.locator('.form-card .field:has-text("Recipient name") input').fill('My Nephew'); await memberPage.locator('.form-card .field:has-text("Relation to you") input').fill('nephew'); await memberPage.locator('.form-card .field:has-text("Description") input').fill('Member personal bequest'); await memberPage.locator('.form-card .field:has-text("Value") input').fill('3000'); await memberPage.locator('.form-card .field:has-text("Recipient email") input').fill('wanjauhari@gmail.com'); await memberPage.locator('.form-card button.btn-primary', { hasText: 'Add bequest' }).click(); const memberBequestSaved = await memberPage.locator('.bequest-row', { hasText: 'My Nephew' }).waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false); record('Member: authors their own Wassiyah bequest with heir email', memberBequestSaved); // ── Agent (mutawalli): accept, see member's doc on dashboard, cannot fire own trigger ── const agentCtx = await browser.newContext({ viewport: { width: 390, height: 844 } }); const agentPage = await agentCtx.newPage(); await signIn(agentPage, AGENT); const agentInviteRow = agentPage.locator('.invite-row', { hasText: familyName }); const agentInviteVisible = await agentInviteRow.waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false); if (agentInviteVisible) { await agentInviteRow.locator('.btn-small', { hasText: 'Accept' }).click(); await agentPage.locator('.hub-tab[aria-label="Home"]').waitFor({ state: 'visible', timeout: 10000 }); } else { // Agent may already belong to many families from prior test runs — switch to this one via Family tab await gotoTab(agentPage, 'Manage').catch(() => {}); } record('Agent: accepts mutawalli invite', agentInviteVisible); await gotoTab(agentPage, 'Mutawalli'); await agentPage.waitForTimeout(800); const memberChipVisible = await agentPage.locator('.member-chip', { hasText: MEMBER }).isVisible().catch(() => false); record('Mutawalli dashboard: shows the member in the chip list', memberChipVisible); if (memberChipVisible) { await agentPage.locator('.member-chip', { hasText: MEMBER }).click(); await agentPage.waitForTimeout(600); const memberDocVisible = await agentPage.locator('.doc-row', { hasText: 'My Nephew' }).isVisible().catch(() => false); record('Mutawalli dashboard: sees the member\'s Wassiyah bequest (read access)', memberDocVisible); // Set up and fire the member's trigger await agentPage.locator('.attestor-row input').nth(0).fill('Attestor One'); await agentPage.locator('.attestor-row .confirm-btn').nth(0).click(); await agentPage.waitForTimeout(400); await agentPage.locator('.attestor-row input').nth(1).fill('Attestor Two'); await agentPage.locator('.attestor-row .confirm-btn').nth(1).click(); await agentPage.waitForTimeout(400); await agentPage.locator('.field:has-text("Date of death") input').fill('2026-08-14'); await agentPage.locator('.field:has-text("Death certificate reference") input').fill('DC-MEMBER-001'); await agentPage.waitForTimeout(600); const fireEnabled = await agentPage.locator('button.btn-danger-solid').isEnabled(); record('Mutawalli: fire button enabled for the member (not self)', fireEnabled); if (fireEnabled) { await agentPage.locator('button.btn-danger-solid').click(); const triggeredVisible = await agentPage.locator('.triggered-banner').waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false); record('Mutawalli: successfully fires the member\'s trigger', triggeredVisible); const notifyBtn = agentPage.locator('button.btn-secondary', { hasText: 'Notify heirs' }); if (await notifyBtn.isVisible().catch(() => false)) { await notifyBtn.click(); await agentPage.locator('.heir-notify-status', { hasText: /Sent|Failed/ }).waitFor({ state: 'visible', timeout: 15000 }).catch(() => {}); const statusText = await agentPage.locator('.heir-notify-status').textContent().catch(() => ''); record('Mutawalli: heir notification actually sends via the real SMTP relay', statusText.includes('Sent'), statusText); } } // Now check the agent CANNOT fire their own trigger await agentPage.locator('.member-chip', { hasText: AGENT }).click().catch(() => {}); await agentPage.waitForTimeout(600); const selfNoteVisible = await agentPage.locator('.self-note').isVisible().catch(() => false); record('Mutawalli: sees "cannot fire own trigger" note when selecting self', selfNoteVisible); } const passCount = results.filter(r => r.pass).length; const failCount = results.length - passCount; console.log(`\n${passCount} passed, ${failCount} failed, ${results.length} total`); if (failCount > 0) results.filter(r => !r.pass).forEach(r => console.log(` - ${r.name}: ${r.detail}`)); await browser.close(); process.exit(failCount > 0 ? 1 : 0); } main().catch(e => { console.error('SCRIPT ERROR:', e); process.exit(2); });