Comprehensive user-flow review across guest/host/admin roles, then fixes with
e2e regression guards. Highlights:
- Offline upload queue auto-resumes on reconnect: network errors keep items
pending (not error), 4xx are terminal (no infinite retry), quota exhaustion
returns a distinct 413; queue cap + dedup.
- Export lifecycle: release atomically locks uploads; reopen invalidates and
re-release regenerates the keepsake; workers claim their job atomically so a
reopen->re-release can't corrupt the ZIP; startup re-spawns interrupted
exports.
- Sessions slide on activity (no 30-day cliff); JWT expiry deferred to the
revocable session row; sign-out-everywhere + revoke-on-PIN-reset.
- Ban always hides content (v_feed / find_visible_media / export filter
is_banned) but stays a read-only ban per USER_JOURNEYS §10 — sessions are
not revoked, read access + keepsake download preserved.
- Realtime: server-clock SSE delta cursor; event-closed/opened drive the UI
live; feed_delta rate-limited; like returns {liked, like_count} to fix
multi-device drift; lightbox live comments; diashow delta backfill.
- Forgotten-PIN in-app request flow; simultaneous same-name join returns 409;
quota increment is transactional; operator floor.
Adds e2e/specs/10-flow-review/ (offline resume, export integrity, deterministic
anti-race guard) and updates existing specs for the new contracts.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
82 lines
3.4 KiB
TypeScript
82 lines
3.4 KiB
TypeScript
/**
|
|
* USER_JOURNEYS.md §9 — host locks/unlocks the event. We use the API for
|
|
* the host action so the test isn't blocked on the host dashboard UI being
|
|
* complete, but assert the SSE-driven "uploads gesperrt" banner appears
|
|
* for a guest who's already viewing the feed.
|
|
*/
|
|
import { test, expect } from '../../fixtures/test';
|
|
|
|
test.describe('Host — event lock', () => {
|
|
test('closing the event via API sets uploads_locked_at; opening clears it', async ({ host, api }) => {
|
|
// The frontend doesn't (yet) render a per-guest "uploads locked" banner on
|
|
// the feed — that's the journey §9 banner, currently a UX gap. We assert
|
|
// the API + DB contract here and leave the banner check for once it ships.
|
|
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
|
|
|
|
await api.closeEvent(host.jwt);
|
|
const evRes = await fetch(`${BASE}/api/v1/host/event`, {
|
|
headers: { Authorization: `Bearer ${host.jwt}` },
|
|
});
|
|
expect(evRes.status).toBe(200);
|
|
const body: any = await evRes.json();
|
|
expect(body.uploads_locked).toBe(true);
|
|
|
|
await api.openEvent(host.jwt);
|
|
const evRes2 = await fetch(`${BASE}/api/v1/host/event`, {
|
|
headers: { Authorization: `Bearer ${host.jwt}` },
|
|
});
|
|
const body2: any = await evRes2.json();
|
|
expect(body2.uploads_locked).toBe(false);
|
|
});
|
|
|
|
test.fixme('event-closed SSE renders a "uploads gesperrt" banner in the feed (planned UX)', async () => {
|
|
// Currently no UI consumes the event-closed SSE on /feed. Add this banner
|
|
// and flip fixme to test once it lands.
|
|
});
|
|
|
|
// Locking is uploads-only: likes, comments and browsing stay open on a closed
|
|
// event (USER_JOURNEYS §9.3, FEATURES capability matrix). Only new uploads are
|
|
// rejected. (An earlier revision froze social interaction too; that contradicted
|
|
// the documented behavior and was reverted.)
|
|
test('a closed event still allows likes and comments, but blocks new uploads', async ({ api, host, guest }) => {
|
|
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
|
|
const g = await guest('SocialLocked');
|
|
|
|
// Upload while still open so there's a target to interact with.
|
|
const { uploadRaw } = await import('../../helpers/upload-client');
|
|
const { readFileSync } = await import('node:fs');
|
|
const { join } = await import('node:path');
|
|
const sample = join(process.cwd(), 'fixtures', 'media', 'sample.jpg');
|
|
const upRes = await uploadRaw(g.jwt, readFileSync(sample), {
|
|
filename: 'x.jpg',
|
|
contentType: 'image/jpeg',
|
|
});
|
|
expect(upRes.status).toBe(201);
|
|
const { id } = await upRes.json();
|
|
|
|
await api.closeEvent(host.jwt);
|
|
|
|
// Likes stay open on a locked event.
|
|
const likeRes = await fetch(`${BASE}/api/v1/upload/${id}/like`, {
|
|
method: 'POST',
|
|
headers: { Authorization: `Bearer ${g.jwt}` },
|
|
});
|
|
expect(likeRes.status).toBe(200);
|
|
|
|
// Comments stay open on a locked event.
|
|
const commentRes = await fetch(`${BASE}/api/v1/upload/${id}/comments`, {
|
|
method: 'POST',
|
|
headers: { Authorization: `Bearer ${g.jwt}`, 'Content-Type': 'application/json' },
|
|
body: JSON.stringify({ body: 'darf durchgehen' }),
|
|
});
|
|
expect(commentRes.status).toBe(201);
|
|
|
|
// New uploads, however, are rejected while locked.
|
|
const blockedUpload = await uploadRaw(g.jwt, readFileSync(sample), {
|
|
filename: 'y.jpg',
|
|
contentType: 'image/jpeg',
|
|
});
|
|
expect(blockedUpload.status).toBe(403);
|
|
});
|
|
});
|