Files
nur-falah-prevention/e2e-per-member.cjs
T
wmj 2549e9de0c feat: add Khairat, emergency-contact auto-notify, and 5 lifestyle-companion tabs
Big round covering two different asks: Khairat/emergency infrastructure
(tightly coupled to what's already built) and a Muslim-lifestyle
companion surface (a genuinely different product, added at the user's
explicit request after being offered a smaller scope).

Khairat & emergency contacts:
- nf_khairat_memberships (per-member scheme membership) + nf_emergency_fund
  (per-family shared reserve tracker) — records intent/contacts only,
  never holds or moves real money.
- nf_trusted_contacts gains category (mosque/police/ambulance/hospital/
  khairat/family/other) and email columns.
- New notify-emergency-contacts Edge Function, auto-invoked the moment a
  mutawalli fires a member's death trigger (the one place in this app
  where auto-send-on-trigger is actually correct), alongside — not
  instead of — the existing heir notification. Verified with a live fire
  end-to-end (e2e-emergency-notify.cjs, 5/5).

Lifestyle-companion tabs — all computed/searched live, nothing fabricated:
- Qibla: pure great-circle bearing math to the Kaaba from geolocation,
  no API/key. Verified against Kuala Lumpur (293°, matches expected ~292°).
- Prayer Times: client-side astronomical calculation (single-pass solar
  position, MWL angles), sanity-checked against known KL/London times
  before shipping.
- Locate: mosque/halal/cemetery search via the free, keyless OpenStreetMap
  Overpass API — real community-sourced results only, honest empty state
  when nothing's mapped nearby.
- Quran: Surah list + Arabic/translation via the free alquran.cloud API,
  fetched fresh each time, nothing stored in this app's own database.
- Neighbourhood: a join-by-code community announcement board — a
  genuinely separate multi-tenant concept from the estate-planning family
  structure, scoped to the user account. Found and fixed a real UX gap
  during testing: the create/join form was only reachable with zero
  existing neighbourhoods, with no way to join a second one.

Also found and fixed a real bug: the heir-notify and emergency-notify
status messages shared the same CSS class, breaking any script (including
the pre-existing e2e-per-member.cjs) that targeted '.notify-status'
without further filtering — gave each its own distinguishing class.

Covered by e2e-khairat-lifestyle.cjs (13/13) and e2e-emergency-notify.cjs
(5/5). Full regression: 316/316 across all suites (several transient
flakes under heavy mail-relay load during the sweep, all confirmed clean
on rerun — one led to the real class-collision fix above).
2026-08-14 14:25:26 +08:00

151 lines
9.4 KiB
JavaScript

// Verifies the per-member estate model end-to-end against the live backend:
// owner invites a plain "member" and an agent (mutawalli); the member authors
// their own Wassiyah, private to them; the mutawalli sees it on their
// dashboard and can fire the member's trigger; the member cannot fire their
// own trigger; the owner's own separate Wassiyah is not visible to the
// member as "theirs" (proves per-author isolation, not just per-family).
const { chromium } = require('playwright');
const BASE = 'https://moslem04.falahos.my/';
const results = [];
function record(name, pass, detail = '') { results.push({ name, pass, detail }); console.log(`${pass ? 'PASS' : 'FAIL'} ${name}${detail ? ' — ' + detail : ''}`); }
const OWNER = 'nurfalah.e2etest.owner@gmail.com';
const AGENT = 'nurfalah.e2etest.agent@gmail.com';
const MEMBER = 'nurfalah.e2etest.member@gmail.com';
const PASSWORD = 'TestPassword123!';
const familyName = `PerMember ${Date.now()}-${Math.floor(Math.random() * 1e6)}`;
async function signIn(page, email) {
await page.goto(BASE, { waitUntil: 'networkidle' });
await page.locator('.field:has-text("Email") input').fill(email);
await page.locator('.field:has-text("Password") input').fill(PASSWORD);
await page.locator('button.btn-primary', { hasText: 'Sign in' }).click();
await page.waitForTimeout(1500);
}
async function main() {
const browser = await chromium.launch();
// ── Owner: create family, invite member + agent ──
const ownerCtx = await browser.newContext({ viewport: { width: 390, height: 844 } });
const ownerPage = await ownerCtx.newPage();
await signIn(ownerPage, OWNER);
await ownerPage.locator('.field:has-text("Family name") input').fill(familyName);
await ownerPage.locator('button.btn-primary', { hasText: 'Create family' }).click();
await ownerPage.waitForTimeout(1200);
await ownerPage.locator('nav button[aria-label="Family"]').click();
await ownerPage.waitForTimeout(500);
await ownerPage.locator('.field:has-text("Invite by email") input').fill(MEMBER);
await ownerPage.locator('.field:has-text("Role") select').selectOption('member');
await ownerPage.locator('button.btn-primary', { hasText: 'Send invite' }).click();
await ownerPage.waitForTimeout(600);
await ownerPage.locator('.field:has-text("Invite by email") input').fill(AGENT);
await ownerPage.locator('.field:has-text("Role") select').selectOption('agent');
await ownerPage.locator('button.btn-primary', { hasText: 'Send invite' }).click();
const bothInvited = await ownerPage.locator('.member-row', { hasText: MEMBER }).waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
record('Owner: invites both a member and an agent', bothInvited);
// Owner writes their OWN wassiyah bequest (should stay private to owner)
await ownerPage.locator('nav button[aria-label="Wassiyah"]').click();
await ownerPage.waitForTimeout(600);
await ownerPage.locator('.form-card .field:has-text("Recipient name") input').fill('Owner Charity');
await ownerPage.locator('.form-card .field:has-text("Relation to you") input').fill('charity');
await ownerPage.locator('.form-card .field:has-text("Description") input').fill('Owner personal bequest');
await ownerPage.locator('.form-card .field:has-text("Value") input').fill('5000');
await ownerPage.locator('.form-card button.btn-primary', { hasText: 'Add bequest' }).click();
await ownerPage.waitForTimeout(600);
// ── Member: accept, author own Wassiyah (should NOT see owner's bequest) ──
const memberCtx = await browser.newContext({ viewport: { width: 390, height: 844 } });
const memberPage = await memberCtx.newPage();
await signIn(memberPage, MEMBER);
const inviteRow = memberPage.locator('.invite-row', { hasText: familyName });
const inviteVisible = await inviteRow.waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
record('Member: sees pending invite', inviteVisible);
await inviteRow.locator('.btn-small', { hasText: 'Accept' }).click();
await memberPage.locator('nav button[aria-label="Coverage"]').waitFor({ state: 'visible', timeout: 10000 });
await memberPage.locator('nav button[aria-label="Wassiyah"]').click();
await memberPage.waitForTimeout(600);
const ownerBequestVisibleToMember = await memberPage.locator('.bequest-row', { hasText: 'Owner Charity' }).isVisible().catch(() => false);
record('Member: does NOT see owner\'s private bequest (per-author isolation)', !ownerBequestVisibleToMember);
await memberPage.locator('.form-card .field:has-text("Recipient name") input').fill('My Nephew');
await memberPage.locator('.form-card .field:has-text("Relation to you") input').fill('nephew');
await memberPage.locator('.form-card .field:has-text("Description") input').fill('Member personal bequest');
await memberPage.locator('.form-card .field:has-text("Value") input').fill('3000');
await memberPage.locator('.form-card .field:has-text("Recipient email") input').fill('wanjauhari@gmail.com');
await memberPage.locator('.form-card button.btn-primary', { hasText: 'Add bequest' }).click();
const memberBequestSaved = await memberPage.locator('.bequest-row', { hasText: 'My Nephew' }).waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
record('Member: authors their own Wassiyah bequest with heir email', memberBequestSaved);
// ── Agent (mutawalli): accept, see member's doc on dashboard, cannot fire own trigger ──
const agentCtx = await browser.newContext({ viewport: { width: 390, height: 844 } });
const agentPage = await agentCtx.newPage();
await signIn(agentPage, AGENT);
const agentInviteRow = agentPage.locator('.invite-row', { hasText: familyName });
const agentInviteVisible = await agentInviteRow.waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
if (agentInviteVisible) {
await agentInviteRow.locator('.btn-small', { hasText: 'Accept' }).click();
await agentPage.locator('nav button[aria-label="Coverage"]').waitFor({ state: 'visible', timeout: 10000 });
} else {
// Agent may already belong to many families from prior test runs — switch to this one via Family tab
await agentPage.locator('nav button[aria-label="Family"]').click().catch(() => {});
}
record('Agent: accepts mutawalli invite', agentInviteVisible);
await agentPage.locator('nav button[aria-label="Mutawalli"]').click();
await agentPage.waitForTimeout(800);
const memberChipVisible = await agentPage.locator('.member-chip', { hasText: MEMBER }).isVisible().catch(() => false);
record('Mutawalli dashboard: shows the member in the chip list', memberChipVisible);
if (memberChipVisible) {
await agentPage.locator('.member-chip', { hasText: MEMBER }).click();
await agentPage.waitForTimeout(600);
const memberDocVisible = await agentPage.locator('.doc-row', { hasText: 'My Nephew' }).isVisible().catch(() => false);
record('Mutawalli dashboard: sees the member\'s Wassiyah bequest (read access)', memberDocVisible);
// Set up and fire the member's trigger
await agentPage.locator('.attestor-row input').nth(0).fill('Attestor One');
await agentPage.locator('.attestor-row .confirm-btn').nth(0).click();
await agentPage.waitForTimeout(400);
await agentPage.locator('.attestor-row input').nth(1).fill('Attestor Two');
await agentPage.locator('.attestor-row .confirm-btn').nth(1).click();
await agentPage.waitForTimeout(400);
await agentPage.locator('.field:has-text("Date of death") input').fill('2026-08-14');
await agentPage.locator('.field:has-text("Death certificate reference") input').fill('DC-MEMBER-001');
await agentPage.waitForTimeout(600);
const fireEnabled = await agentPage.locator('button.btn-danger-solid').isEnabled();
record('Mutawalli: fire button enabled for the member (not self)', fireEnabled);
if (fireEnabled) {
await agentPage.locator('button.btn-danger-solid').click();
const triggeredVisible = await agentPage.locator('.triggered-banner').waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
record('Mutawalli: successfully fires the member\'s trigger', triggeredVisible);
const notifyBtn = agentPage.locator('button.btn-secondary', { hasText: 'Notify heirs' });
if (await notifyBtn.isVisible().catch(() => false)) {
await notifyBtn.click();
await agentPage.locator('.heir-notify-status', { hasText: /Sent|Failed/ }).waitFor({ state: 'visible', timeout: 15000 }).catch(() => {});
const statusText = await agentPage.locator('.heir-notify-status').textContent().catch(() => '');
record('Mutawalli: heir notification actually sends via the real SMTP relay', statusText.includes('Sent'), statusText);
}
}
// Now check the agent CANNOT fire their own trigger
await agentPage.locator('.member-chip', { hasText: AGENT }).click().catch(() => {});
await agentPage.waitForTimeout(600);
const selfNoteVisible = await agentPage.locator('.self-note').isVisible().catch(() => false);
record('Mutawalli: sees "cannot fire own trigger" note when selecting self', selfNoteVisible);
}
const passCount = results.filter(r => r.pass).length;
const failCount = results.length - passCount;
console.log(`\n${passCount} passed, ${failCount} failed, ${results.length} total`);
if (failCount > 0) results.filter(r => !r.pass).forEach(r => console.log(` - ${r.name}: ${r.detail}`));
await browser.close();
process.exit(failCount > 0 ? 1 : 0);
}
main().catch(e => { console.error('SCRIPT ERROR:', e); process.exit(2); });