5adbad6d53
Per explicit direction to use existing VPS/Bitwarden/Gitea infrastructure instead of waiting on a Resend signup. Bitwarden's MCP unlock/list both hung (server-side issue, confirmed via direct CLI retry too — not something to keep retrying), so this used the VPS and Gitea directly. Found real, working infrastructure already in place: a documented but never-deployed falah-ibaas email connector (SMTP wrapper) at /opt/falah-ibaas/connectors/email, backed by a local Postfix relay that Ghost already uses successfully in production on the same VPS (mail__options__host=172.17.0.1:25, no auth needed internally). Built nf-mail-relay: a small HTTP wrapper (Python stdlib, no deps) around that connector, deployed as a Docker Swarm service on the existing Traefik network at https://nfmailrelay.falahos.my, bind-mounting the connector code read-only so it stays in sync with any future updates to it. Shared-secret bearer auth (X-Relay-Secret) — verified a wrong secret gets rejected with 401. notify-heirs Edge Function rewired to call this relay instead of Resend. Two real bugs found and fixed via actual testing, not code review: - The function only took memberId, but a person can belong to multiple families — .maybeSingle() against multiple trigger rows failed closed (correctly, but silently, as "not triggered"). Function and both call sites (db.js notifyHeirs, MutawalliDashboard) now require and pass familyId too, matching the same composite-key fix already applied to the trigger tables themselves. - No CORS/OPTIONS handling: a browser's preflight OPTIONS request has no body, and calling req.json() on it crashed the function before any headers were sent — surfaced in the browser as a generic "Failed to send a request" with no detail. Added an OPTIONS short-circuit and CORS headers on every response path. Verified with a real send to a live inbox through the full chain (browser -> Edge Function -> VPS relay -> Postfix -> SMTP), not just a connectivity check. Also fixed a stale e2e-trust.cjs assertion using the same instant-isVisible()-after-fixed-wait pattern already fixed elsewhere in this session — real app behavior was correct, only the test's timing assumption was wrong. e2e-per-member.cjs's heir-notification check now asserts an actual "Sent" result via the real relay instead of accepting either Sent or a not-configured failure. Full sweep: e2e-uat 32/32 (stable across 3 runs, one earlier run's failure was a one-off network blip under heavy parallel test load), e2e-fastpath 16/16, e2e-trust 12/12 (stable across 3 runs), e2e-business 10/10, e2e-digital-vehicle 10/10, e2e-property 9/9, e2e-other 4/4, e2e-info 31/31, e2e-per-member 11/11 — 165/165 total.
151 lines
9.4 KiB
JavaScript
151 lines
9.4 KiB
JavaScript
// Verifies the per-member estate model end-to-end against the live backend:
|
|
// owner invites a plain "member" and an agent (mutawalli); the member authors
|
|
// their own Wassiyah, private to them; the mutawalli sees it on their
|
|
// dashboard and can fire the member's trigger; the member cannot fire their
|
|
// own trigger; the owner's own separate Wassiyah is not visible to the
|
|
// member as "theirs" (proves per-author isolation, not just per-family).
|
|
const { chromium } = require('playwright');
|
|
const BASE = 'https://moslem04.falahos.my/';
|
|
const results = [];
|
|
function record(name, pass, detail = '') { results.push({ name, pass, detail }); console.log(`${pass ? 'PASS' : 'FAIL'} ${name}${detail ? ' — ' + detail : ''}`); }
|
|
|
|
const OWNER = 'nurfalah.e2etest.owner@gmail.com';
|
|
const AGENT = 'nurfalah.e2etest.agent@gmail.com';
|
|
const MEMBER = 'nurfalah.e2etest.member@gmail.com';
|
|
const PASSWORD = 'TestPassword123!';
|
|
const familyName = `PerMember ${Date.now()}-${Math.floor(Math.random() * 1e6)}`;
|
|
|
|
async function signIn(page, email) {
|
|
await page.goto(BASE, { waitUntil: 'networkidle' });
|
|
await page.locator('.field:has-text("Email") input').fill(email);
|
|
await page.locator('.field:has-text("Password") input').fill(PASSWORD);
|
|
await page.locator('button.btn-primary', { hasText: 'Sign in' }).click();
|
|
await page.waitForTimeout(1500);
|
|
}
|
|
|
|
async function main() {
|
|
const browser = await chromium.launch();
|
|
|
|
// ── Owner: create family, invite member + agent ──
|
|
const ownerCtx = await browser.newContext({ viewport: { width: 390, height: 844 } });
|
|
const ownerPage = await ownerCtx.newPage();
|
|
await signIn(ownerPage, OWNER);
|
|
await ownerPage.locator('.field:has-text("Family name") input').fill(familyName);
|
|
await ownerPage.locator('button.btn-primary', { hasText: 'Create family' }).click();
|
|
await ownerPage.waitForTimeout(1200);
|
|
|
|
await ownerPage.locator('nav button[aria-label="Family"]').click();
|
|
await ownerPage.waitForTimeout(500);
|
|
await ownerPage.locator('.field:has-text("Invite by email") input').fill(MEMBER);
|
|
await ownerPage.locator('.field:has-text("Role") select').selectOption('member');
|
|
await ownerPage.locator('button.btn-primary', { hasText: 'Send invite' }).click();
|
|
await ownerPage.waitForTimeout(600);
|
|
await ownerPage.locator('.field:has-text("Invite by email") input').fill(AGENT);
|
|
await ownerPage.locator('.field:has-text("Role") select').selectOption('agent');
|
|
await ownerPage.locator('button.btn-primary', { hasText: 'Send invite' }).click();
|
|
const bothInvited = await ownerPage.locator('.member-row', { hasText: MEMBER }).waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
record('Owner: invites both a member and an agent', bothInvited);
|
|
|
|
// Owner writes their OWN wassiyah bequest (should stay private to owner)
|
|
await ownerPage.locator('nav button[aria-label="Wassiyah"]').click();
|
|
await ownerPage.waitForTimeout(600);
|
|
await ownerPage.locator('.form-card .field:has-text("Recipient name") input').fill('Owner Charity');
|
|
await ownerPage.locator('.form-card .field:has-text("Relation to you") input').fill('charity');
|
|
await ownerPage.locator('.form-card .field:has-text("Description") input').fill('Owner personal bequest');
|
|
await ownerPage.locator('.form-card .field:has-text("Value") input').fill('5000');
|
|
await ownerPage.locator('.form-card button.btn-primary', { hasText: 'Add bequest' }).click();
|
|
await ownerPage.waitForTimeout(600);
|
|
|
|
// ── Member: accept, author own Wassiyah (should NOT see owner's bequest) ──
|
|
const memberCtx = await browser.newContext({ viewport: { width: 390, height: 844 } });
|
|
const memberPage = await memberCtx.newPage();
|
|
await signIn(memberPage, MEMBER);
|
|
const inviteRow = memberPage.locator('.invite-row', { hasText: familyName });
|
|
const inviteVisible = await inviteRow.waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
record('Member: sees pending invite', inviteVisible);
|
|
await inviteRow.locator('.btn-small', { hasText: 'Accept' }).click();
|
|
await memberPage.locator('nav button[aria-label="Coverage"]').waitFor({ state: 'visible', timeout: 10000 });
|
|
|
|
await memberPage.locator('nav button[aria-label="Wassiyah"]').click();
|
|
await memberPage.waitForTimeout(600);
|
|
const ownerBequestVisibleToMember = await memberPage.locator('.bequest-row', { hasText: 'Owner Charity' }).isVisible().catch(() => false);
|
|
record('Member: does NOT see owner\'s private bequest (per-author isolation)', !ownerBequestVisibleToMember);
|
|
|
|
await memberPage.locator('.form-card .field:has-text("Recipient name") input').fill('My Nephew');
|
|
await memberPage.locator('.form-card .field:has-text("Relation to you") input').fill('nephew');
|
|
await memberPage.locator('.form-card .field:has-text("Description") input').fill('Member personal bequest');
|
|
await memberPage.locator('.form-card .field:has-text("Value") input').fill('3000');
|
|
await memberPage.locator('.form-card .field:has-text("Recipient email") input').fill('wanjauhari@gmail.com');
|
|
await memberPage.locator('.form-card button.btn-primary', { hasText: 'Add bequest' }).click();
|
|
const memberBequestSaved = await memberPage.locator('.bequest-row', { hasText: 'My Nephew' }).waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
record('Member: authors their own Wassiyah bequest with heir email', memberBequestSaved);
|
|
|
|
// ── Agent (mutawalli): accept, see member's doc on dashboard, cannot fire own trigger ──
|
|
const agentCtx = await browser.newContext({ viewport: { width: 390, height: 844 } });
|
|
const agentPage = await agentCtx.newPage();
|
|
await signIn(agentPage, AGENT);
|
|
const agentInviteRow = agentPage.locator('.invite-row', { hasText: familyName });
|
|
const agentInviteVisible = await agentInviteRow.waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
if (agentInviteVisible) {
|
|
await agentInviteRow.locator('.btn-small', { hasText: 'Accept' }).click();
|
|
await agentPage.locator('nav button[aria-label="Coverage"]').waitFor({ state: 'visible', timeout: 10000 });
|
|
} else {
|
|
// Agent may already belong to many families from prior test runs — switch to this one via Family tab
|
|
await agentPage.locator('nav button[aria-label="Family"]').click().catch(() => {});
|
|
}
|
|
record('Agent: accepts mutawalli invite', agentInviteVisible);
|
|
|
|
await agentPage.locator('nav button[aria-label="Mutawalli"]').click();
|
|
await agentPage.waitForTimeout(800);
|
|
const memberChipVisible = await agentPage.locator('.member-chip', { hasText: MEMBER }).isVisible().catch(() => false);
|
|
record('Mutawalli dashboard: shows the member in the chip list', memberChipVisible);
|
|
|
|
if (memberChipVisible) {
|
|
await agentPage.locator('.member-chip', { hasText: MEMBER }).click();
|
|
await agentPage.waitForTimeout(600);
|
|
const memberDocVisible = await agentPage.locator('.doc-row', { hasText: 'My Nephew' }).isVisible().catch(() => false);
|
|
record('Mutawalli dashboard: sees the member\'s Wassiyah bequest (read access)', memberDocVisible);
|
|
|
|
// Set up and fire the member's trigger
|
|
await agentPage.locator('.attestor-row input').nth(0).fill('Attestor One');
|
|
await agentPage.locator('.attestor-row .confirm-btn').nth(0).click();
|
|
await agentPage.waitForTimeout(400);
|
|
await agentPage.locator('.attestor-row input').nth(1).fill('Attestor Two');
|
|
await agentPage.locator('.attestor-row .confirm-btn').nth(1).click();
|
|
await agentPage.waitForTimeout(400);
|
|
await agentPage.locator('.field:has-text("Date of death") input').fill('2026-08-14');
|
|
await agentPage.locator('.field:has-text("Death certificate reference") input').fill('DC-MEMBER-001');
|
|
await agentPage.waitForTimeout(600);
|
|
const fireEnabled = await agentPage.locator('button.btn-danger-solid').isEnabled();
|
|
record('Mutawalli: fire button enabled for the member (not self)', fireEnabled);
|
|
|
|
if (fireEnabled) {
|
|
await agentPage.locator('button.btn-danger-solid').click();
|
|
const triggeredVisible = await agentPage.locator('.triggered-banner').waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
record('Mutawalli: successfully fires the member\'s trigger', triggeredVisible);
|
|
|
|
const notifyBtn = agentPage.locator('button.btn-secondary', { hasText: 'Notify heirs' });
|
|
if (await notifyBtn.isVisible().catch(() => false)) {
|
|
await notifyBtn.click();
|
|
await agentPage.locator('.notify-status', { hasText: /Sent|Failed/ }).waitFor({ state: 'visible', timeout: 15000 }).catch(() => {});
|
|
const statusText = await agentPage.locator('.notify-status').textContent().catch(() => '');
|
|
record('Mutawalli: heir notification actually sends via the real SMTP relay', statusText.includes('Sent'), statusText);
|
|
}
|
|
}
|
|
|
|
// Now check the agent CANNOT fire their own trigger
|
|
await agentPage.locator('.member-chip', { hasText: AGENT }).click().catch(() => {});
|
|
await agentPage.waitForTimeout(600);
|
|
const selfNoteVisible = await agentPage.locator('.self-note').isVisible().catch(() => false);
|
|
record('Mutawalli: sees "cannot fire own trigger" note when selecting self', selfNoteVisible);
|
|
}
|
|
|
|
const passCount = results.filter(r => r.pass).length;
|
|
const failCount = results.length - passCount;
|
|
console.log(`\n${passCount} passed, ${failCount} failed, ${results.length} total`);
|
|
if (failCount > 0) results.filter(r => !r.pass).forEach(r => console.log(` - ${r.name}: ${r.detail}`));
|
|
await browser.close();
|
|
process.exit(failCount > 0 ? 1 : 0);
|
|
}
|
|
main().catch(e => { console.error('SCRIPT ERROR:', e); process.exit(2); });
|