a0c70e1411
Per explicit product direction: the app assumed a single user (head of family) with everything in per-device localStorage. There was no way for a family to delegate estate management to an agent (relative or professional) without literally handing over the device. This required real backend infrastructure, not a UI addition — added Supabase (Postgres + Auth) as a multi-tenant backend. Schema (nf_ prefixed to stay isolated from other tables in the reused "Falah OS demo" project): nf_families, nf_family_members (role: owner/ agent, status: invited/active), and family-scoped versions of every estate table — nf_assets, nf_trusted_contacts, nf_hibah_gifts, nf_waqf_designations/nf_waqf_beneficiaries, nf_nominations, nf_attestors, nf_death_triggers. Permission model, enforced by RLS at the database level (not just hidden in the UI): an agent can do everything an owner can — add/edit assets, draft Hibah/Waqf/Nominations, set up the Death Trigger — except fire it. nf_death_triggers' UPDATE/INSERT policies use a WITH CHECK that only allows triggered=true when the caller has role='owner' on that family. A professional agent can be invited to multiple families and switches between them from their own dashboard. New: auth.js, family.js, db.js, AuthScreen.svelte, FamilySwitcher.svelte, FamilyManagement.svelte (new "Family" tab: invite agents, see members, switch families). AssetRegistry, HibahTracker, FamilyWaqfDesignator, NominationRegistry, CoverageDashboard, and DeathTrigger all migrated from storage.js (localStorage) to db.js (Supabase), scoped to the active family_id. App.svelte now gates on auth + family selection before showing the main tab shell. Three real bugs found and fixed via testing against the live backend (not caught by the old localStorage-based suites, which had no cross-client concurrency to expose them): - RLS gap: pending-invite lookup joins nf_families(name), but the invitee isn't a family member yet, so the join was silently dropped — added a policy letting a pending invitee see just the family name. - Attestor row race: lazy "create on first blur" could double-fire from two different code paths, creating duplicate rows and confirming the wrong one. Fixed by eagerly creating attestor rows on first load so every row always has a real id — no more create-or-update ambiguity. - Out-of-order async clobber: three death-trigger setup fields each fired a full-snapshot upsert on every input; whichever request *finished* last (not fired last) won, silently reverting the other two fields to stale values. Fixed with per-field partial updates (updateDeathTriggerField) that can't clobber columns they don't touch. e2e-family-agent.cjs: full owner/agent flow against the live Supabase backend — invite, accept, shared live data, agent blocked from firing the trigger (button stays disabled and a direct RLS-level attempt would also fail), owner successfully fires it. 12/12 passing. e2e-smoke-authed.cjs: post-auth-gate sweep confirming every existing tab still renders and its info panel still opens under the new sign-in requirement. 24/24 passing, zero console errors. Known follow-up, not done here: the eight pre-auth E2E suites (e2e-uat.cjs, e2e-fastpath.cjs, e2e-trust.cjs, e2e-business.cjs, e2e-digital-vehicle.cjs, e2e-property.cjs, e2e-other.cjs, e2e-info.cjs) assume an anonymous landing page and need a sign-in prelude added before they're valid again — their detailed assertions were re-verified functionally via the smoke test and manual review, not by running them as-is.
146 lines
8.5 KiB
JavaScript
146 lines
8.5 KiB
JavaScript
// Verifies the owner/agent family delegation flow end-to-end against the live
|
|
// Supabase-backed app: owner signs up, creates a family, invites an agent; agent
|
|
// signs up with that email, accepts the invite, sees the family in their
|
|
// dashboard, can add an asset — but cannot fire the death trigger (owner-only,
|
|
// enforced by RLS, not just hidden in the UI).
|
|
const { chromium } = require('playwright');
|
|
const BASE = 'https://moslem04.falahos.my/';
|
|
const results = [];
|
|
function record(name, pass, detail = '') { results.push({ name, pass, detail }); console.log(`${pass ? 'PASS' : 'FAIL'} ${name}${detail ? ' — ' + detail : ''}`); }
|
|
|
|
const stamp = process.argv[2] || String(Math.floor(Math.random() * 1e9));
|
|
const ownerEmail = 'nurfalah.e2etest.owner@gmail.com';
|
|
const agentEmail = 'nurfalah.e2etest.agent@gmail.com';
|
|
const password = 'TestPassword123!';
|
|
const familyName = `Test Family ${stamp}`;
|
|
|
|
async function signUp(page, email, name) {
|
|
await page.goto(BASE, { waitUntil: 'networkidle' });
|
|
await page.locator('.mode-btn', { hasText: 'Create account' }).click();
|
|
await page.waitForTimeout(200);
|
|
await page.locator('.field:has-text("Full name") input').fill(name);
|
|
await page.locator('.field:has-text("Email") input').fill(email);
|
|
await page.locator('.field:has-text("Password") input').fill(password);
|
|
await page.locator('button.btn-primary', { hasText: 'Create account' }).click();
|
|
await page.waitForTimeout(1500);
|
|
}
|
|
|
|
async function signIn(page, email) {
|
|
await page.goto(BASE, { waitUntil: 'networkidle' });
|
|
await page.locator('.field:has-text("Email") input').fill(email);
|
|
await page.locator('.field:has-text("Password") input').fill(password);
|
|
await page.locator('button.btn-primary', { hasText: 'Sign in' }).click();
|
|
await page.waitForTimeout(1500);
|
|
}
|
|
|
|
async function main() {
|
|
const mode = process.argv[3];
|
|
|
|
if (mode === 'signup') {
|
|
const browser = await chromium.launch();
|
|
const ownerPage = await (await browser.newContext()).newPage();
|
|
await signUp(ownerPage, ownerEmail, 'Owner Test');
|
|
const agentPage = await (await browser.newContext()).newPage();
|
|
await signUp(agentPage, agentEmail, 'Agent Test');
|
|
await browser.close();
|
|
console.log(JSON.stringify({ ownerEmail, agentEmail, password, familyName }));
|
|
return;
|
|
}
|
|
|
|
// mode === 'flow' — accounts already confirmed via SQL
|
|
const browser = await chromium.launch();
|
|
|
|
// ── Owner: sign in, create family, invite agent ──
|
|
const ownerCtx = await browser.newContext({ viewport: { width: 390, height: 844 } });
|
|
const ownerPage = await ownerCtx.newPage();
|
|
await signIn(ownerPage, ownerEmail);
|
|
const onSwitcher = await ownerPage.locator('.switcher-screen').isVisible().catch(() => false);
|
|
record('Owner: signs in and lands on family switcher (no family yet)', onSwitcher);
|
|
|
|
await ownerPage.locator('.field:has-text("Family name") input').fill(familyName);
|
|
await ownerPage.locator('button.btn-primary', { hasText: 'Create family' }).click();
|
|
await ownerPage.waitForTimeout(1000);
|
|
const onMainApp = await ownerPage.locator('nav button.tab', { hasText: 'Coverage' }).isVisible().catch(() => false);
|
|
record('Owner: creating a family lands on the main app', onMainApp);
|
|
|
|
await ownerPage.locator('nav button[aria-label="Family"]').click();
|
|
await ownerPage.waitForTimeout(300);
|
|
await ownerPage.locator('.field:has-text("Invite an estate agent") input').fill(agentEmail);
|
|
await ownerPage.locator('button.btn-primary', { hasText: 'Send invite' }).click();
|
|
await ownerPage.waitForTimeout(800);
|
|
const memberRowVisible = await ownerPage.locator('.member-row', { hasText: agentEmail }).isVisible();
|
|
record('Owner: inviting agent creates a pending member row', memberRowVisible);
|
|
|
|
// ── Agent: sign in, accept invite, see family, add an asset ──
|
|
const agentCtx = await browser.newContext({ viewport: { width: 390, height: 844 } });
|
|
const agentPage = await agentCtx.newPage();
|
|
await signIn(agentPage, agentEmail);
|
|
const inviteRow = agentPage.locator('.invite-row', { hasText: familyName });
|
|
const inviteVisible = await inviteRow.waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
record('Agent: sees pending invite from owner on sign-in', inviteVisible);
|
|
|
|
await inviteRow.locator('.btn-small', { hasText: 'Accept' }).click();
|
|
const agentOnMainApp = await agentPage.locator('nav button[aria-label="Coverage"]').waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
record('Agent: accepting invite lands on the main app for that family', agentOnMainApp);
|
|
|
|
await agentPage.locator('nav button[aria-label="Assets"]').click();
|
|
await agentPage.waitForTimeout(400);
|
|
await agentPage.locator('.field:has-text("Description") input').fill('Agent-added asset');
|
|
await agentPage.locator('.field:has-text("Estimated value") input').fill('50000');
|
|
await agentPage.locator('button.btn-primary', { hasText: 'Add asset' }).click();
|
|
const assetAddedByAgent = await agentPage.locator('.asset-row', { hasText: 'Agent-added asset' }).waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
record('Agent: can add an asset to the family estate', assetAddedByAgent);
|
|
|
|
// Owner should see the agent-added asset too (shared, live data — not per-device)
|
|
await ownerPage.locator('nav button[aria-label="Assets"]').click();
|
|
const ownerSeesAgentAsset = await ownerPage.locator('.asset-row', { hasText: 'Agent-added asset' }).waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
record('Owner: sees the asset the agent just added (shared family data)', ownerSeesAgentAsset);
|
|
|
|
// ── Agent tries the Death Trigger — should be visibly restricted ──
|
|
await agentPage.locator('nav button[aria-label="Trigger"]').click();
|
|
const agentRestrictionVisible = await agentPage.locator('.agent-restriction').waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
record('Agent: sees explicit "owner-only to fire" restriction notice', agentRestrictionVisible);
|
|
|
|
// Fill everything needed and confirm the fire button itself won't work for the agent
|
|
const attestorInputs = agentPage.locator('.attestor-row input');
|
|
await attestorInputs.nth(0).fill('Attestor A');
|
|
await agentPage.locator('.attestor-row .confirm-btn').nth(0).click();
|
|
await agentPage.waitForTimeout(500);
|
|
await attestorInputs.nth(1).fill('Attestor B');
|
|
await agentPage.locator('.attestor-row .confirm-btn').nth(1).click();
|
|
await agentPage.waitForTimeout(500);
|
|
await agentPage.locator('.field:has-text("Date of death") input').fill('2026-08-13');
|
|
await agentPage.locator('.field:has-text("Death certificate reference") input').fill('DC-TEST-999');
|
|
await agentPage.waitForTimeout(500);
|
|
const fireBtnDisabledForAgent = await agentPage.locator('button.btn-danger-solid').isDisabled();
|
|
record('Agent: fire-trigger button stays disabled even with all fields filled (role check)', fireBtnDisabledForAgent);
|
|
|
|
// ── Owner fires it — should work, enforced by RLS as role=owner ──
|
|
await ownerPage.locator('nav button[aria-label="Trigger"]').click();
|
|
await ownerPage.waitForTimeout(1000);
|
|
const ownerAttestorInputs = ownerPage.locator('.attestor-row input');
|
|
const attestorCount = await ownerAttestorInputs.count();
|
|
record('Owner: sees the same attestor data the agent entered (shared)', attestorCount >= 2 && (await ownerAttestorInputs.nth(0).inputValue()) === 'Attestor A');
|
|
|
|
await ownerPage.waitForFunction(() => {
|
|
const btn = document.querySelector('button.btn-danger-solid');
|
|
return btn && !btn.disabled;
|
|
}, { timeout: 10000 }).catch(() => {});
|
|
const ownerFireBtnEnabled = await ownerPage.locator('button.btn-danger-solid').isEnabled();
|
|
record('Owner: fire-trigger button is enabled for the owner role', ownerFireBtnEnabled);
|
|
|
|
if (ownerFireBtnEnabled) {
|
|
await ownerPage.locator('button.btn-danger-solid').click();
|
|
const triggeredBannerVisible = await ownerPage.locator('.triggered-banner').waitFor({ state: 'visible', timeout: 10000 }).then(() => true).catch(() => false);
|
|
record('Owner: successfully fires the death trigger', triggeredBannerVisible);
|
|
}
|
|
|
|
await browser.close();
|
|
const passCount = results.filter(r => r.pass).length;
|
|
const failCount = results.length - passCount;
|
|
console.log(`\n${passCount} passed, ${failCount} failed, ${results.length} total`);
|
|
if (failCount > 0) results.filter(r => !r.pass).forEach(r => console.log(` - ${r.name}: ${r.detail}`));
|
|
process.exit(failCount > 0 ? 1 : 0);
|
|
}
|
|
main().catch(e => { console.error('SCRIPT ERROR:', e); process.exit(2); });
|