e2e.repos.test.ts
⎇
Raw
1import { describe, test, expect, beforeAll, afterAll } from 'bun:test';
2import { rmSync, writeFileSync } from 'node:fs';
3import { spawnSync } from 'node:child_process';
4import { chromium } from 'playwright';
5import type { Browser, BrowserContext } from 'playwright';
6import {
7 BASE,
8 ADMIN_PASS,
9 DATA_DIR,
10 setupTestEnv,
11 spawnServer,
12 killServer,
13 login,
14 seedRepo,
15 db,
16} from './helpers.ts';
17
18let browser: Browser;
19let server: Awaited<ReturnType<typeof spawnServer>>;
20
21beforeAll(async () => {
22 await setupTestEnv();
23 server = await spawnServer();
24 browser = await chromium.launch();
25
26 // Register alice
27 const ctx = await browser.newContext();
28 const page = await ctx.newPage();
29 try {
30 await page.goto(`${BASE}/register`);
31 await page.fill('[name=username]', 'alice');
32 await page.fill('[name=password]', 'password123');
33 await page.fill('[name=password2]', 'password123');
34 await page.click('button[type=submit]');
35 await page.waitForURL(BASE + '/');
36 } finally { await ctx.close(); }
37});
38
39afterAll(async () => {
40 await browser.close();
41 await killServer(server);
42});
43
44async function loggedInContext(username = 'admin', password = ADMIN_PASS) {
45 const ctx = await browser.newContext();
46 const page = await ctx.newPage();
47 await login(page, username, password);
48 await page.close();
49 return ctx;
50}
51
52// ─── Repos ────────────────────────────────────────────────────────────────────
53
54describe('repos', () => {
55 // Shared admin context — cookies persist across tests in this block.
56 let adminCtx: BrowserContext;
57 // Alice's context, created after alice is registered in auth tests.
58 let aliceCtx: BrowserContext;
59 // Set after 'commit log' test; used by all commit-detail tests below.
60 let commitUrl: string;
61
62 beforeAll(async () => {
63 adminCtx = await loggedInContext();
64 aliceCtx = await loggedInContext('alice', 'password123');
65 });
66
67 afterAll(async () => {
68 await adminCtx.close();
69 await aliceCtx.close();
70 });
71
72 test('non-admin gets 403 on /new', async () => {
73 const page = await aliceCtx.newPage();
74 try {
75 const resp = await page.request.get(`${BASE}/new`);
76 expect(resp.status()).toBe(403);
77 } finally { await page.close(); }
78 });
79
80 test('create repository', async () => {
81 const page = await adminCtx.newPage();
82 try {
83 await page.goto(`${BASE}/new`);
84 await page.fill('[name=name]', 'my-repo');
85 await page.fill('[name=description]', 'A test repo');
86 await page.click('form[action="/new"] button[type=submit]');
87 await page.waitForURL(`${BASE}/my-repo`);
88 expect(await page.locator('.empty-state').isVisible()).toBe(true);
89 } finally { await page.close(); }
90 });
91
92 test('repository appears in list', async () => {
93 const page = await adminCtx.newPage();
94 try {
95 await page.goto(BASE);
96 expect(await page.locator('.repo-name').allTextContents()).toContain('my-repo');
97 } finally { await page.close(); }
98 });
99
100 test('search finds matching repo', async () => {
101 const page = await adminCtx.newPage();
102 try {
103 await page.goto(BASE);
104 await page.fill('[name=q]', 'my-repo');
105 await page.click('.search-form button[type=submit]');
106 expect(await page.locator('.repo-name').allTextContents()).toContain('my-repo');
107 } finally { await page.close(); }
108 });
109
110 test('search returns empty for unknown term', async () => {
111 const page = await adminCtx.newPage();
112 try {
113 await page.goto(BASE);
114 await page.fill('[name=q]', 'zzz-nothing-here');
115 await page.click('.search-form button[type=submit]');
116 expect(await page.locator('.empty-state').isVisible()).toBe(true);
117 } finally { await page.close(); }
118 });
119
120 test('browse file tree after seeding content', async () => {
121 await seedRepo('my-repo');
122 const page = await adminCtx.newPage();
123 try {
124 await page.goto(`${BASE}/my-repo/tree/main`);
125 const files = await page.locator('.file-name a').allTextContents();
126 expect(files).toContain('README.md');
127 expect(files).toContain('index.js');
128 } finally { await page.close(); }
129 });
130
131 test('view file blob with syntax highlighting', async () => {
132 const page = await adminCtx.newPage();
133 try {
134 await page.goto(`${BASE}/my-repo/blob/main/index.js`);
135 expect(await page.locator('.file-blob-name').textContent()).toBe('index.js');
136 expect(await page.locator('.file-blob-body').isVisible()).toBe(true);
137 } finally { await page.close(); }
138 });
139
140 test('raw file download responds 200', async () => {
141 const page = await adminCtx.newPage();
142 try {
143 const resp = await page.request.get(`${BASE}/my-repo/raw/main/README.md`);
144 expect(resp.status()).toBe(200);
145 expect(resp.headers()['content-disposition']).toContain('README.md');
146 } finally { await page.close(); }
147 });
148
149 test('raw svg is served as an image under a sandbox policy', async () => {
150 const page = await adminCtx.newPage();
151 try {
152 const resp = await page.request.get(`${BASE}/my-repo/raw/main/logo.svg`);
153 expect(resp.status()).toBe(200);
154 expect(resp.headers()['content-type']).toContain('image/svg+xml');
155 expect(resp.headers()['content-security-policy']).toContain('sandbox;');
156 const txt = await page.request.get(`${BASE}/my-repo/raw/main/README.md`);
157 expect(txt.headers()['content-security-policy']).not.toContain('sandbox');
158 } finally { await page.close(); }
159 });
160
161 test('commit log shows initial commit', async () => {
162 const page = await adminCtx.newPage();
163 try {
164 await page.goto(`${BASE}/my-repo/commits/main`);
165 const subjects = await page.locator('.commit-subject').allTextContents();
166 expect(subjects.some(s => s.includes('Initial commit'))).toBe(true);
167 // Navigate to the commit page and capture the URL for subsequent tests
168 await page.locator('.commit-hash').first().click();
169 await page.waitForURL(/\/my-repo\/commit\//);
170 commitUrl = page.url();
171 } finally { await page.close(); }
172 });
173
174 test('commit detail shows metadata card', async () => {
175 const page = await adminCtx.newPage();
176 try {
177 await page.goto(commitUrl);
178 expect(await page.locator('.commit-card').isVisible()).toBe(true);
179 expect(await page.locator('.commit-card-subject').textContent()).toContain('Initial commit');
180 // Author, date and SHA rows are all present
181 const metaText = await page.locator('.commit-card-meta').textContent();
182 expect(metaText).toContain('Test'); // author name set by seedRepo
183 expect(metaText).toContain('Author'); // label (CSS uppercases visually)
184 expect(metaText).toContain('Date');
185 expect(metaText).toContain('Commit');
186 } finally { await page.close(); }
187 });
188
189 test('commit detail full SHA is shown', async () => {
190 const page = await adminCtx.newPage();
191 try {
192 await page.goto(commitUrl);
193 const sha = commitUrl.split('/commit/')[1] ?? null;
194 expect(await page.locator('.commit-sha-full').textContent()).toBe(sha);
195 } finally { await page.close(); }
196 });
197
198 test('commit detail shows file nav sidebar', async () => {
199 const page = await adminCtx.newPage();
200 try {
201 await page.goto(commitUrl);
202 expect(await page.locator('.file-nav-details').isVisible()).toBe(true);
203 const navItems = await page.locator('.file-nav-item').allTextContents();
204 // seedRepo adds README.md and index.js
205 expect(navItems.some(t => t.includes('README.md'))).toBe(true);
206 expect(navItems.some(t => t.includes('index.js'))).toBe(true);
207 } finally { await page.close(); }
208 });
209
210 test('commit detail file nav items are anchor links to diff sections', async () => {
211 const page = await adminCtx.newPage();
212 try {
213 await page.goto(commitUrl);
214 const hrefs = await page.locator('.file-nav-item').evaluateAll(
215 els => els.map(el => el.getAttribute('href') ?? ''),
216 );
217 expect(hrefs.every(h => h.startsWith('#'))).toBe(true);
218 } finally { await page.close(); }
219 });
220
221 test('commit detail shows diff table with added lines', async () => {
222 const page = await adminCtx.newPage();
223 try {
224 await page.goto(commitUrl);
225 // Initial commit only adds lines
226 expect(await page.locator('.diff-table').first().isVisible()).toBe(true);
227 expect(await page.locator('.diff-row-add').count()).toBeGreaterThan(0);
228 expect(await page.locator('.diff-row-del').count()).toBe(0);
229 } finally { await page.close(); }
230 });
231
232 test('commit detail diff table has line numbers', async () => {
233 const page = await adminCtx.newPage();
234 try {
235 await page.goto(commitUrl);
236 // New-side line numbers (column 2) on add rows start at 1
237 const firstNewLn = await page.locator('.diff-row-add .diff-ln-new').first().textContent();
238 expect(firstNewLn?.trim()).toBe('1');
239 } finally { await page.close(); }
240 });
241
242 test('commit detail shows added stats on file header', async () => {
243 const page = await adminCtx.newPage();
244 try {
245 await page.goto(commitUrl);
246 const addStats = await page.locator('.diff-stat-add').allTextContents();
247 expect(addStats.length).toBeGreaterThan(0);
248 expect(addStats.every(s => s.startsWith('+'))).toBe(true);
249 } finally { await page.close(); }
250 });
251
252 test('commit detail view-at-sha button links to blob at that commit', async () => {
253 const page = await adminCtx.newPage();
254 try {
255 await page.goto(commitUrl);
256 const sha = commitUrl.split('/commit/')[1];
257 const btn = page.locator('.btn-xs').first();
258 const href = await btn.getAttribute('href');
259 expect(href).toContain(`/blob/${sha}/`);
260 } finally { await page.close(); }
261 });
262
263 test('commit detail view-at-branch button links to blob at default branch', async () => {
264 const page = await adminCtx.newPage();
265 try {
266 await page.goto(commitUrl);
267 const btns = await page.locator('.btn-xs').allTextContents();
268 expect(btns.some(t => t.includes('@ main'))).toBe(true);
269 const branchBtns = await page.locator('.btn-xs').evaluateAll(
270 els => els.filter(el => el.textContent?.includes('@ main')).map(el => el.getAttribute('href') ?? ''),
271 );
272 expect(branchBtns.every(h => h.includes('/blob/main/'))).toBe(true);
273 } finally { await page.close(); }
274 });
275
276 test('commit detail file diff can be collapsed', async () => {
277 const page = await adminCtx.newPage();
278 try {
279 await page.goto(commitUrl);
280 // File body is visible when details is open
281 const diffFile = page.locator('.diff-file').first();
282 expect(await diffFile.getAttribute('open')).not.toBeNull();
283 // Click the summary to collapse
284 await diffFile.locator('.diff-file-header').click();
285 expect(await diffFile.getAttribute('open')).toBeNull();
286 } finally { await page.close(); }
287 });
288
289 test('commit detail file nav sidebar can be collapsed', async () => {
290 const page = await adminCtx.newPage();
291 try {
292 await page.goto(commitUrl);
293 const nav = page.locator('.file-nav-details');
294 expect(await nav.getAttribute('open')).not.toBeNull();
295 await nav.locator('.file-nav-toggle').click();
296 expect(await nav.getAttribute('open')).toBeNull();
297 } finally { await page.close(); }
298 });
299
300 test('readme renders on repo home', async () => {
301 const page = await adminCtx.newPage();
302 try {
303 await page.goto(`${BASE}/my-repo`);
304 expect(await page.locator('.readme-header').isVisible()).toBe(true);
305 expect(await page.locator('.readme-section .markdown-body').innerHTML()).toContain('my-repo');
306 } finally { await page.close(); }
307 });
308
309 test('private repo hidden from other users', async () => {
310 // Make private
311 const adminPage = await adminCtx.newPage();
312 try {
313 await adminPage.goto(`${BASE}/my-repo/settings`);
314 await adminPage.check('[name=is_private]');
315 await adminPage.click('form[action$="/settings"] button[type=submit]');
316 expect(await adminPage.locator('.form-success').isVisible()).toBe(true);
317 } finally { await adminPage.close(); }
318
319 // Alice should get 404
320 const alicePage = await aliceCtx.newPage();
321 try {
322 const resp = await alicePage.request.get(`${BASE}/my-repo`);
323 expect(resp.status()).toBe(404);
324 await alicePage.goto(BASE);
325 expect(await alicePage.locator('.repo-name').allTextContents()).not.toContain('my-repo');
326 } finally { await alicePage.close(); }
327
328 // Restore to public
329 const adminPage2 = await adminCtx.newPage();
330 try {
331 await adminPage2.goto(`${BASE}/my-repo/settings`);
332 await adminPage2.uncheck('[name=is_private]');
333 await adminPage2.click('form[action$="/settings"] button[type=submit]');
334 } finally { await adminPage2.close(); }
335 });
336
337 test('settings tab visible for admin, hidden for others', async () => {
338 const adminPage = await adminCtx.newPage();
339 try {
340 await adminPage.goto(`${BASE}/my-repo`);
341 expect(await adminPage.locator('.repo-tab[href$="/settings"]').isVisible()).toBe(true);
342 } finally { await adminPage.close(); }
343
344 const alicePage = await aliceCtx.newPage();
345 try {
346 await alicePage.goto(`${BASE}/my-repo`);
347 expect(await alicePage.locator('.repo-tab[href$="/settings"]').count()).toBe(0);
348 } finally { await alicePage.close(); }
349 });
350
351 test('create repository with invalid name shows error', async () => {
352 const resp = await adminCtx.request.post(`${BASE}/new`, {
353 form: { name: 'has spaces!', description: '', default_branch: 'main' },
354 maxRedirects: 0,
355 });
356 expect(resp.status()).toBe(200);
357 expect(await resp.text()).toContain('Invalid repository name');
358 });
359
360 test('auto-scanned repo is private by default', async () => {
361 const name = 'auto-private-repo';
362 const dir = `${process.cwd()}/${DATA_DIR}/repos/${name}.git`;
363
364 rmSync(dir, { recursive: true, force: true });
365 const tmp = `/tmp/hf-scan-${Date.now()}`;
366 try {
367 spawnSync('git', ['init', '--bare', dir], { stdio: 'ignore' });
368 spawnSync('git', ['clone', dir, tmp], { stdio: 'ignore' });
369 spawnSync('git', ['-C', tmp, 'commit', '--allow-empty', '-m', 'init'], { stdio: 'ignore' });
370 spawnSync('git', ['-C', tmp, 'push', 'origin', 'HEAD:main'], { stdio: 'ignore' });
371 } finally {
372 rmSync(tmp, { recursive: true, force: true });
373 }
374
375 // The Go server adopts repos found on disk at startup, not lazily per
376 // request, so restart it and read the row it created.
377 await killServer(server);
378 server = await spawnServer();
379 const repo = await db
380 .selectFrom('repositories')
381 .select(['name', 'is_private'])
382 .where('name', '=', name)
383 .executeTakeFirst();
384 expect(repo!.is_private).toBe(1);
385
386 await db.deleteFrom('repositories').where('name', '=', name).execute();
387 rmSync(dir, { recursive: true, force: true });
388 });
389
390 test('repo is registered even with a stale config.lock', async () => {
391 const name = 'stale-lock-repo';
392 const dir = `${process.cwd()}/${DATA_DIR}/repos/${name}.git`;
393
394 rmSync(dir, { recursive: true, force: true });
395 spawnSync('git', ['init', '--bare', dir], { stdio: 'ignore' });
396 // Drop core.bare so ensureBare has to attempt a write, then block it.
397 spawnSync('git', ['config', '--file', `${dir}/config`, '--unset', 'core.bare'], {
398 stdio: 'ignore',
399 });
400 writeFileSync(`${dir}/config.lock`, '');
401
402 await killServer(server);
403 server = await spawnServer();
404 const repo = await db
405 .selectFrom('repositories')
406 .select('name')
407 .where('name', '=', name)
408 .executeTakeFirst();
409 expect(repo!.name).toBe(name);
410
411 await db.deleteFrom('repositories').where('name', '=', name).execute();
412 rmSync(dir, { recursive: true, force: true });
413 });
414});
415