Follow-ups from the code review of the test-quality batches: - Consolidate duplicated helpers into e2e/helpers/: seed.ts (seedUpload, seedComment, listComments, findFeedRow) and sse.ts (mintSseTicket, openStream, trackStreamOpens). Refactor authorization-deep, xss-injection, like-comment, sse-ticket-abuse, ddos, sse-realtime, multi-tab, and SseListener to use them — the upload/comment/ticket-flow contracts now live in one place each instead of being re-inlined across 3–7 specs. - xss-injection display-name loop: it navigated to /feed (which renders uploader names, not the viewer's) so "nothing fired" passed vacuously — the payload was never rendered. Now navigate to /account (the actual sink) and add a render guard asserting the payload reached the DOM as escaped text before checking __xssFired. - sse-realtime reconnect: snapshot the stream-open count AFTER backgrounding, so the "new connection" assertion is attributable to the foreground event and can't be satisfied by a spurious native/error reconnect before the toggle. - recover-page: correct the comment (auto-submit is the onPinInput handler, not an $effect). 44 affected specs verified green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
36 lines
1.2 KiB
TypeScript
36 lines
1.2 KiB
TypeScript
import type { Page, Locator } from '@playwright/test';
|
|
|
|
export class RecoverPage {
|
|
readonly page: Page;
|
|
readonly nameInput: Locator;
|
|
readonly pinInput: Locator;
|
|
readonly submitButton: Locator;
|
|
readonly errorMessage: Locator;
|
|
|
|
constructor(page: Page) {
|
|
this.page = page;
|
|
this.nameInput = page.getByTestId('recover-name-input');
|
|
this.pinInput = page.getByTestId('recover-pin-input');
|
|
this.submitButton = page.getByTestId('recover-submit');
|
|
this.errorMessage = page.getByTestId('recover-error');
|
|
}
|
|
|
|
async goto() {
|
|
await this.page.goto('/recover');
|
|
}
|
|
|
|
async recover(name: string, pin: string) {
|
|
await this.nameInput.fill(name);
|
|
// Filling the 4th digit fires the form's auto-submit (the onPinInput handler
|
|
// calls handleRecover once pin.length === 4, see pin-auto-submit.spec). An explicit
|
|
// submit click would race the ensuing navigation and detach mid-click, so only click
|
|
// as a fallback if the button is still around (e.g. a partial / failed PIN).
|
|
await this.pinInput.fill(pin);
|
|
if (await this.submitButton.isEnabled().catch(() => false)) {
|
|
await this.submitButton.click().catch(() => {
|
|
/* auto-submit already navigated — nothing to click */
|
|
});
|
|
}
|
|
}
|
|
}
|