chore(e2e): add ESLint + Prettier; fix real findings; dedupe BASE

The Playwright suite had no linter and no formatter — only tsc. Add flat-config ESLint
(typescript-eslint, type-aware) and Prettier (2-space, matching the suite's style).

Rules keep the ones that catch real TEST bugs and drop the noise:
  - no-floating-promises KEPT — an un-awaited request/assertion can let a test end before it runs,
    passing vacuously. It caught one: the SSE reader loop in sse-listener is now explicitly `void`.
  - no-unused-vars KEPT — caught three dead bindings (an unused adminToken fixture arg, an unused
    `api` arg, an unused JPEG_MAGIC import), all removed.
  - no-explicit-any OFF — all test code; `any` is the honest type for an untyped res.json() body or
    a page.evaluate() return.
  - no-empty-pattern OFF — Playwright's dependency-free fixtures are `async ({}, use) => {}`.

Refactor: `const BASE = process.env.E2E_FRONTEND_URL ?? '...'` was redeclared verbatim in 23
files — extracted to helpers/env.ts and imported, so a port/scheme change is one edit not a sweep.

Then `prettier --write`. Verified: eslint clean, tsc clean, prettier clean, desktop suite 210
passed / 1 skipped. (One mobile spec flaked once under retries:0 — a pre-existing cross-test
reflow-timing vector from the flakiness audit, not this change: the each-key edit is stable across
16 isolated runs and a clean full mobile re-run.)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
fabi
2026-07-15 20:45:59 +02:00
parent f8cba95e49
commit bbdfae09a0
67 changed files with 2441 additions and 396 deletions

View File

@@ -26,7 +26,7 @@ test.describe('Auth — admin login', () => {
};
return {
sessionRole: decodeRole(sessionStorage.getItem('eventsnap_jwt')),
localToken: localStorage.getItem('eventsnap_jwt')
localToken: localStorage.getItem('eventsnap_jwt'),
};
});
expect(stores.sessionRole).toBe('admin');

View File

@@ -6,7 +6,9 @@
import { test, expect } from '../../fixtures/test';
test.describe('Navigation — back chevrons', () => {
test('/recover back chevron navigates to /feed (which redirects to /join when unauth)', async ({ page }) => {
test('/recover back chevron navigates to /feed (which redirects to /join when unauth)', async ({
page,
}) => {
await page.goto('/recover');
const back = page.getByTestId('recover-back');
await expect(back).toBeVisible();
@@ -15,7 +17,11 @@ test.describe('Navigation — back chevrons', () => {
await page.waitForURL(/\/(join|feed)$/);
});
test('/export back chevron returns the authenticated guest to /feed', async ({ page, guest, signIn }) => {
test('/export back chevron returns the authenticated guest to /feed', async ({
page,
guest,
signIn,
}) => {
const g = await guest('ExportBack');
await signIn(page, g);
await page.goto('/export');

View File

@@ -41,7 +41,10 @@ test.describe('Auth — join flow', () => {
await page.waitForURL('**/feed', { timeout: 5_000 });
});
test('returning guest, new device: same name shows the inline recovery form', async ({ page, guest }) => {
test('returning guest, new device: same name shows the inline recovery form', async ({
page,
guest,
}) => {
const original = await guest('Charlie');
// Brand-new browser context (cleared storage) — landing on /join with same name

View File

@@ -7,7 +7,11 @@ import { AccountPage } from '../../page-objects';
import { readStorage } from '../../helpers/storage-helpers';
test.describe('Auth — leave event', () => {
test('leave event clears localStorage and redirects to /join', async ({ page, guest, signIn }) => {
test('leave event clears localStorage and redirects to /join', async ({
page,
guest,
signIn,
}) => {
const h = await guest('Jens');
await signIn(page, h);

View File

@@ -5,14 +5,13 @@
* revoked token must stop authenticating.
*/
import { test, expect } from '../../fixtures/test';
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
import { BASE } from '../../helpers/env';
const ctx = (jwt: string) =>
fetch(`${BASE}/api/v1/me/context`, { headers: { Authorization: `Bearer ${jwt}` } });
test.describe('Auth — sign out everywhere', () => {
test('DELETE /sessions revokes ALL of the caller\'s sessions, not just the current one', async ({
test("DELETE /sessions revokes ALL of the caller's sessions, not just the current one", async ({
api,
guest,
db,
@@ -41,7 +40,7 @@ test.describe('Auth — sign out everywhere', () => {
expect(await db.countSessionsForUser(g.userId)).toBe(0);
});
test('one user signing out everywhere does not touch another user\'s sessions', async ({
test("one user signing out everywhere does not touch another user's sessions", async ({
guest,
}) => {
const a = await guest('SignsOut');

View File

@@ -13,7 +13,10 @@ import { JoinPage, RecoverPage } from '../../page-objects';
import { clearAllStorage } from '../../helpers/storage-helpers';
test.describe('Auth — PIN auto-submit', () => {
test('inline recovery: 4th digit auto-submits and navigates to /feed', async ({ page, guest }) => {
test('inline recovery: 4th digit auto-submits and navigates to /feed', async ({
page,
guest,
}) => {
const original = await guest('AutoInline');
await clearAllStorage(page);
@@ -30,7 +33,10 @@ test.describe('Auth — PIN auto-submit', () => {
await page.waitForURL('**/feed', { timeout: 5_000 });
});
test('/recover: 4th digit auto-submits when the name is already filled in', async ({ page, guest }) => {
test('/recover: 4th digit auto-submits when the name is already filled in', async ({
page,
guest,
}) => {
const original = await guest('AutoRecover');
await clearAllStorage(page);

View File

@@ -9,8 +9,7 @@
* - a host reset REVOKES the target's sessions (the forgotten/compromised device is logged out)
*/
import { test, expect } from '../../fixtures/test';
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
import { BASE } from '../../helpers/env';
const requestReset = (displayName: string) =>
fetch(`${BASE}/api/v1/recover/request`, {
@@ -59,9 +58,8 @@ test.describe('PIN reset — in-app request lifecycle', () => {
api,
host,
db,
adminToken,
}) => {
// The admin user exists (adminToken logged them in). Their display name is "Admin" by
// The admin user exists (the host fixture logs an admin in to create it). Its display name is "Admin" by
// convention; request a reset for it and confirm the queue stays empty — the INSERT filters
// `role <> 'admin'`, so queuing a reset for an admin would be a privilege-relevant leak.
const admin = (await api.listUsers(host.jwt)).find((u: any) => u.role === 'admin');