test(e2e): journal↔planner save handoff covers Phase A + Phase B
New \`e2e/journal-planner-save.test.ts\` exercises the full save flow: 1. Seed a routeId + JWT via \`/api/e2e/seed\` (journal). 2. POST to \`/api/sessions\` on the planner with \`callbackUrl\` + \`callbackToken\` — mirrors what the journal's \`edit-in-planner\` action does server-to-server. 3. Open the planner session in a real browser. 4. Click \"Save to Journal\". The button POSTs sessionId+GPX to the planner's \`/api/save-to-journal\` action (Phase A); the action forwards to the journal callback with the Bearer. Test 1 asserts: - The journal's route ends up with geometry (round-trip works). - The exact JWT string is **never** present in any browser-issued request body or \`Authorization\` header — i.e. Phase A correctly keeps the token server-side. Test 2 asserts: - A second click on Save reuses the same stored JWT, the journal's jti consumer rejects it, and the planner UI surfaces the error. This is the Phase B replay guard exercised end-to-end through the UI rather than just the API. Added \`journal-planner-save\` Playwright project (no baseURL — the test navigates both apps using absolute URLs). Full repo: pnpm typecheck / lint / test all green (cached). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
11edcbccb3
commit
be64e2df5c
2 changed files with 120 additions and 0 deletions
|
|
@ -62,6 +62,15 @@ export default defineConfig({
|
|||
...devices["Desktop Chrome"],
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "journal-planner-save",
|
||||
testMatch: "journal-planner-save.test.ts",
|
||||
use: {
|
||||
// No baseURL — the test navigates between both apps using
|
||||
// absolute URLs.
|
||||
...devices["Desktop Chrome"],
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "notifications",
|
||||
testMatch: "notifications.test.ts",
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue