// Verifies the newest feature set end-to-end against the live backend: // per-member Insurance/Takaful policies, family-shared Liabilities, and // asset-ownership verification (proof document + dual-path confirm). const { chromium } = require('playwright'); const { signInFreshFamily, gotoTab } = require('./e2e-auth-helper.cjs'); const BASE = 'https://moslem04.falahos.my/'; const results = []; const consoleErrors = []; function record(name, pass, detail = '') { results.push({ name, pass, detail }); console.log(`${pass ? 'PASS' : 'FAIL'} ${name}${detail ? ' — ' + detail : ''}`); } async function main() { const browser = await chromium.launch(); const page = await browser.newPage({ viewport: { width: 390, height: 844 } }); page.on('console', m => { if (m.type() === 'error') consoleErrors.push(m.text()); }); page.on('pageerror', e => consoleErrors.push(e.message)); await signInFreshFamily(page, BASE, 'e2e-insurance'); // ── Insurance & Takaful tab ── await gotoTab(page, 'Insurance'); await page.waitForTimeout(600); await page.locator('.form-card .field:has-text("Type") select').selectOption('takaful'); await page.locator('.form-card .field:has-text("Provider") input').fill('Etiqa Takaful'); await page.locator('.form-card .field:has-text("Policy number") input').fill('TKF-00123'); await page.locator('.form-card .field:has-text("Sum assured") input').fill('250000'); await page.locator('.form-card .field:has-text("Beneficiary name") input').fill('Aisha binti Rahman'); await page.locator('.form-card .field:has-text("Beneficiary relation") input').fill('spouse'); await page.locator('.form-card button.btn-primary', { hasText: 'Add policy' }).click(); await page.waitForTimeout(1000); const policyRowVisible = await page.locator('.policy-row', { hasText: 'Etiqa Takaful' }).isVisible().catch(() => false); record('Insurance: policy added and listed', policyRowVisible); const totalCardVisible = await page.locator('.total-card strong', { hasText: '250,000' }).isVisible().catch(() => false); record('Insurance: total sum assured reflects the added policy', totalCardVisible); // Edit the policy await page.locator('.policy-row', { hasText: 'Etiqa Takaful' }).locator('button[aria-label="Edit"]').click(); await page.waitForTimeout(300); await page.locator('.form-card .field:has-text("Notes") input').fill('Renewed 2026'); await page.locator('.form-card button.btn-primary', { hasText: 'Update policy' }).click(); await page.waitForTimeout(800); record('Insurance: editing a policy succeeds without error', consoleErrors.length === 0, consoleErrors.join(' || ')); // ── Asset ownership verification (Assets tab) ── await gotoTab(page, 'Assets'); await page.waitForTimeout(600); await page.locator('.form-card .field:has-text("Description") input').fill('Family sedan'); await page.locator('.form-card .field:has-text("Estimated value") input').fill('45000'); await page.locator('.form-card select').first().selectOption('Vehicle'); await page.locator('.form-card button.btn-primary', { hasText: 'Add asset' }).click(); await page.waitForTimeout(1000); const unverifiedBadge = await page.locator('.verify-badge', { hasText: 'Unverified' }).isVisible().catch(() => false); record('Asset Verification: new asset starts unverified', unverifiedBadge); await page.locator('button.verify-toggle', { hasText: 'Confirm ownership' }).first().click(); await page.waitForTimeout(1000); const verifiedBadge = await page.locator('.verify-badge.verified', { hasText: 'Verified' }).isVisible().catch(() => false); record('Asset Verification: confirming ownership flips the badge to Verified', verifiedBadge); await page.locator('button.verify-toggle', { hasText: 'Unverify' }).first().click(); await page.waitForTimeout(1000); const revertedToUnverified = await page.locator('.verify-badge', { hasText: 'Unverified' }).isVisible().catch(() => false); record('Asset Verification: unverify reverts the badge', revertedToUnverified); // ── Liabilities (Assets tab, bottom section) ── await page.locator('.liabilities-section .field:has-text("Type") select').selectOption('mortgage'); await page.locator('.liabilities-section .field:has-text("Lender") input').fill('Maybank Islamic'); await page.locator('.liabilities-section .field:has-text("Outstanding balance") input').fill('180000'); await page.locator('.liabilities-section .field:has-text("Linked asset") select').selectOption({ label: 'Family sedan' }); await page.locator('.liabilities-section button.btn-primary', { hasText: 'Add liability' }).click(); await page.waitForTimeout(1000); const liabilityRowVisible = await page.locator('.liability-row', { hasText: 'Maybank Islamic' }).isVisible().catch(() => false); record('Liabilities: liability added and listed', liabilityRowVisible); const debtTotalVisible = await page.locator('.total-card.debt strong', { hasText: '180,000' }).isVisible().catch(() => false); record('Liabilities: total outstanding debt card shows the correct sum', debtTotalVisible); await page.locator('.liability-row', { hasText: 'Maybank Islamic' }).locator('button[aria-label="Remove"]').click(); await page.locator('.liability-row', { hasText: 'Maybank Islamic' }).waitFor({ state: 'detached', timeout: 10000 }).catch(() => {}); const liabilityRemoved = await page.locator('.liability-row', { hasText: 'Maybank Islamic' }).isVisible().catch(() => false); record('Liabilities: removing a liability removes it from the list', !liabilityRemoved); // ── Mutawalli dashboard should surface the insurance policy for this member (owner-only family: owner sees their own row) ── await gotoTab(page, 'Mutawalli'); await page.waitForTimeout(800); const mutawalliText = await page.locator('.module').innerText().catch(() => ''); const mutawalliGated = mutawalliText.includes('Only the mutawalli'); record('Mutawalli: owner-only family either sees the dashboard or the correct gate message', mutawalliGated || /INSURANCE/i.test(mutawalliText)); // ── Isolation: a second fresh family (same account) must not see this policy/liability/verification data ── const isolationPage = await browser.newPage({ viewport: { width: 390, height: 844 } }); await signInFreshFamily(isolationPage, BASE, 'e2e-insurance-isolation'); await gotoTab(isolationPage, 'Insurance'); await isolationPage.waitForTimeout(600); const leakedPolicy = await isolationPage.locator('.policy-row', { hasText: 'Etiqa Takaful' }).isVisible().catch(() => false); record('Isolation: a different family sees none of this insurance data', !leakedPolicy); await isolationPage.close(); record('No uncaught JS console errors during full session', consoleErrors.length === 0, consoleErrors.join(' || ')); await browser.close(); const passCount = results.filter(r => r.pass).length; const failCount = results.length - passCount; console.log(`\n${passCount} passed, ${failCount} failed, ${results.length} total`); if (failCount > 0) results.filter(r => !r.pass).forEach(r => console.log(` - ${r.name}: ${r.detail}`)); process.exit(failCount > 0 ? 1 : 0); } main().catch(e => { console.error('SCRIPT ERROR:', e); process.exit(2); });