A comprehensive role-based E2E audit (guest/host/admin, across browser sessions) surfaced one critical and several smaller issues; this addresses them and hardens the tests that missed them. Critical - The client upload pipeline was fully broken: the IndexedDB v1->v2 upgrade opened a *new* transaction inside the upgrade callback, which throws during a version-change transaction and aborted the whole upgrade, leaving the queue object store uncreated -- so no UI upload ever fired. Reuse the version-change transaction the callback provides, and bump the DB to v3 with a contains() guard so installs already corrupted by the shipped bug self-heal on next load. Re-enabled the previously-fixme'd UI upload E2E test. High / Medium - Event lock is uploads-only again: likes, comments and browsing stay open while the event is locked (USER_JOURNEYS 9.3 / FEATURES) -- it was wrongly freezing social interaction. Updated the event-lock spec accordingly. - get_original now excludes soft-deleted and ban-hidden uploads, and direct /media/originals/** serving is blocked, so a hidden user's originals can no longer be pulled by UUID (all originals go through the checked alias). - The upload handler reads the file field with an early-abort size cap chosen from the declared content-type, instead of buffering the entire body before the size check. Low - unban_user mirrors the ban role guard (a host can no longer unban a host/admin banned by an admin). - reset_user_pin's UPDATE is event-scoped. - Admin login returns and stores a real identity (user_id + display name) instead of a blank session. - The host user list no longer renders target-actions (ban/promote/demote/PIN) on the caller's own row, where the backend always rejected them. - /diashow gains a client-side auth guard like the other protected routes. - The join page shows the event name via a new public GET /api/v1/event. Verified: backend cargo build clean, frontend svelte-check 0 errors, full Playwright E2E suite 144 passed / 1 skipped. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
82 lines
3.4 KiB
TypeScript
82 lines
3.4 KiB
TypeScript
/**
|
|
* USER_JOURNEYS.md §9 — host locks/unlocks the event. We use the API for
|
|
* the host action so the test isn't blocked on the host dashboard UI being
|
|
* complete, but assert the SSE-driven "uploads gesperrt" banner appears
|
|
* for a guest who's already viewing the feed.
|
|
*/
|
|
import { test, expect } from '../../fixtures/test';
|
|
|
|
test.describe('Host — event lock', () => {
|
|
test('closing the event via API sets uploads_locked_at; opening clears it', async ({ host, api }) => {
|
|
// The frontend doesn't (yet) render a per-guest "uploads locked" banner on
|
|
// the feed — that's the journey §9 banner, currently a UX gap. We assert
|
|
// the API + DB contract here and leave the banner check for once it ships.
|
|
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
|
|
|
|
await api.closeEvent(host.jwt);
|
|
const evRes = await fetch(`${BASE}/api/v1/host/event`, {
|
|
headers: { Authorization: `Bearer ${host.jwt}` },
|
|
});
|
|
expect(evRes.status).toBe(200);
|
|
const body: any = await evRes.json();
|
|
expect(body.uploads_locked).toBe(true);
|
|
|
|
await api.openEvent(host.jwt);
|
|
const evRes2 = await fetch(`${BASE}/api/v1/host/event`, {
|
|
headers: { Authorization: `Bearer ${host.jwt}` },
|
|
});
|
|
const body2: any = await evRes2.json();
|
|
expect(body2.uploads_locked).toBe(false);
|
|
});
|
|
|
|
test.fixme('event-closed SSE renders a "uploads gesperrt" banner in the feed (planned UX)', async () => {
|
|
// Currently no UI consumes the event-closed SSE on /feed. Add this banner
|
|
// and flip fixme to test once it lands.
|
|
});
|
|
|
|
// Locking is uploads-only: likes, comments and browsing stay open on a closed
|
|
// event (USER_JOURNEYS §9.3, FEATURES capability matrix). Only new uploads are
|
|
// rejected. (An earlier revision froze social interaction too; that contradicted
|
|
// the documented behavior and was reverted.)
|
|
test('a closed event still allows likes and comments, but blocks new uploads', async ({ api, host, guest }) => {
|
|
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
|
|
const g = await guest('SocialLocked');
|
|
|
|
// Upload while still open so there's a target to interact with.
|
|
const { uploadRaw } = await import('../../helpers/upload-client');
|
|
const { readFileSync } = await import('node:fs');
|
|
const { join } = await import('node:path');
|
|
const sample = join(process.cwd(), 'fixtures', 'media', 'sample.jpg');
|
|
const upRes = await uploadRaw(g.jwt, readFileSync(sample), {
|
|
filename: 'x.jpg',
|
|
contentType: 'image/jpeg',
|
|
});
|
|
expect(upRes.status).toBe(201);
|
|
const { id } = await upRes.json();
|
|
|
|
await api.closeEvent(host.jwt);
|
|
|
|
// Likes stay open on a locked event.
|
|
const likeRes = await fetch(`${BASE}/api/v1/upload/${id}/like`, {
|
|
method: 'POST',
|
|
headers: { Authorization: `Bearer ${g.jwt}` },
|
|
});
|
|
expect(likeRes.status).toBe(204);
|
|
|
|
// Comments stay open on a locked event.
|
|
const commentRes = await fetch(`${BASE}/api/v1/upload/${id}/comments`, {
|
|
method: 'POST',
|
|
headers: { Authorization: `Bearer ${g.jwt}`, 'Content-Type': 'application/json' },
|
|
body: JSON.stringify({ body: 'darf durchgehen' }),
|
|
});
|
|
expect(commentRes.status).toBe(201);
|
|
|
|
// New uploads, however, are rejected while locked.
|
|
const blockedUpload = await uploadRaw(g.jwt, readFileSync(sample), {
|
|
filename: 'y.jpg',
|
|
contentType: 'image/jpeg',
|
|
});
|
|
expect(blockedUpload.status).toBe(403);
|
|
});
|
|
});
|