Initial Playwright ERP UAT VAPT test suite v2.4.1 IMAP
This commit is contained in:
@@ -0,0 +1,84 @@
|
||||
/**
|
||||
* =============================================================================
|
||||
* UAT_FY_Lock_Backup -- Financial Year Lock & Backup UAT scaffolding
|
||||
* =============================================================================
|
||||
*
|
||||
* ⚠️ UNTESTED SCAFFOLDING -- READ BEFORE RUNNING ⚠️
|
||||
*
|
||||
* These 30 cases correspond to the UAT_FY_Lock_Backup sheet, which existed in
|
||||
* the checklist but was NOT part of the generated automation matrix. This file
|
||||
* was added in v2.4 to close that gap.
|
||||
*
|
||||
* It has NOT been executed or verified against a running ERP. The route paths,
|
||||
* selectors, and assertions below are best-effort guesses based on the ERP's
|
||||
* known routes (e.g. /system-settings/financial-years...). They are very likely
|
||||
* to need adjustment for your build. Every case is marked test.fixme() so the
|
||||
* suite does NOT report these as passing until a human has:
|
||||
* 1. Confirmed the real routes/selectors for each step,
|
||||
* 2. Implemented the assertion,
|
||||
* 3. Removed the test.fixme() wrapper for that case.
|
||||
*
|
||||
* DO NOT report these as automated coverage until that work is done.
|
||||
* Corresponding checklist rows remain "Not Started" / manual.
|
||||
* =============================================================================
|
||||
*/
|
||||
const { test, expect } = require('@playwright/test');
|
||||
require('dotenv').config();
|
||||
const { login } = require('../fixtures/auth');
|
||||
|
||||
const FY_BASE = '/system-settings/financial-years';
|
||||
const activeFY = process.env.ACTIVE_FY || process.env.DEFAULT_YEAR_CODE || '2025-26';
|
||||
|
||||
// Each entry maps to a checklist Test ID. status: 'fixme' until verified by a human.
|
||||
const FY_CASES = [
|
||||
['FY-001', 'Create financial year'],
|
||||
['FY-002', 'Duplicate FY prevention'],
|
||||
['FY-003', 'Mark current FY'],
|
||||
['FY-004', 'Header FY selector persistence'],
|
||||
['FY-005', 'Logout/login FY reset/default'],
|
||||
['FY-006', 'Staff tenant/branch from session'],
|
||||
['FY-007', 'Tenant switch updates session'],
|
||||
['FY-008', 'Branch switch updates session'],
|
||||
['FY-009', 'Engagement list active FY'],
|
||||
['FY-010', 'Direct URL cross-FY engagement'],
|
||||
['FY-011', 'Task list active FY'],
|
||||
['FY-012', 'Direct URL cross-FY task update'],
|
||||
['FY-013', 'Task/engagement document FY path'],
|
||||
['FY-014', 'Cross-FY document download'],
|
||||
['FY-015', 'Notice/case list active FY'],
|
||||
['FY-016', 'Notice engagement link same FY'],
|
||||
['FY-017', 'Invoice list active FY'],
|
||||
['FY-018', 'Client portal billing active FY'],
|
||||
['FY-019', 'Lock financial year'],
|
||||
['FY-020', 'Blocked writes in locked FY'],
|
||||
['FY-021', 'Unlock/reopen control'],
|
||||
['FY-022', 'Generate FY backup ZIP'],
|
||||
['FY-023', 'Backup export completeness'],
|
||||
['FY-024', 'Unauthorized backup access'],
|
||||
['FY-025', 'Backup not in static path'],
|
||||
['FY-026', 'Context switch auditability'],
|
||||
['FY-027', 'Fresh PostgreSQL upgrade'],
|
||||
['FY-028', 'Billing FY backfill'],
|
||||
['FY-029', 'Public header spoof ignored'],
|
||||
['FY-030', 'Trusted header requires secret'],
|
||||
];
|
||||
|
||||
test.describe('UAT_FY_Lock_Backup (UNTESTED SCAFFOLDING - all fixme)', () => {
|
||||
for (const [id, scenario] of FY_CASES) {
|
||||
// test.fixme keeps these visibly pending and NEVER green until implemented.
|
||||
test.fixme(`${id} :: ${scenario}`, async ({ page }) => {
|
||||
// TODO(human-verify): implement against real routes/selectors for this build.
|
||||
// Reference starting points (verify before trusting):
|
||||
// list: GET ${FY_BASE}
|
||||
// create: GET/POST ${FY_BASE}/new
|
||||
// lock: POST ${FY_BASE}/{fy_id}/lock
|
||||
// unlock: POST ${FY_BASE}/{fy_id}/unlock
|
||||
// backup: POST ${FY_BASE}/{fy_id}/backup/export
|
||||
// download: GET ${FY_BASE}/backups/{export_id}/download
|
||||
await login(page, 'System Admin');
|
||||
await page.goto(FY_BASE);
|
||||
// assertion intentionally omitted -- must be written per case before enabling.
|
||||
expect(true).toBeTruthy();
|
||||
});
|
||||
}
|
||||
});
|
||||
Reference in New Issue
Block a user