3.5 KiB
3.5 KiB
Task 6 — Frontend identity and administrator UX report
RED
- Added API tests for the
/meprincipal call andmine/allsession-list scopes. - Added component tests for regular-user scope, admin scope switching, owner labels, administrator banner, foreign-owner delete confirmation, and foreign-owner archive confirmation.
- Initial focused run: 7 expected failures (missing
getMe, missing scope query, missing owner label/admin controls, and missing foreign-action confirmation). - The archive-confirmation regression was also run separately before its implementation
and failed because
window.confirmwas not called.
GREEN
npx vitest run src/api/sessions.test.ts src/shell/NavSessions.test.tsx src/shell/AppShell.session-mgmt.test.tsx— passed (47 tests before the archive follow-up; the focused archive regression then passed).npm test— passed: 44 files / 305 tests.npx tsc -b— passed.npm run build— passed.git diff --check— passed.npm run e2ereached Playwright but could not run: the environment has no Chromium executable at Playwright's configured cache path. No application test failure was reported.
Files changed
frontend/src/api/types.ts: typed principal and session scope contracts.frontend/src/api/sessions.ts: typed/meAPI call; scoped listing defaults tomine.frontend/src/shell/AppShell.tsx: identity query, admin-only session scope selector and banner, owner-aware destructive action confirmations.frontend/src/shell/NavSessions.tsx: owner labels in the all-sessions view.frontend/src/api/sessions.test.ts,frontend/src/shell/NavSessions.test.tsx, andfrontend/src/shell/AppShell.session-mgmt.test.tsx: contract and UX coverage.
Self-review
- Regular users remain fail-closed on
mine; no administrator control renders withoutprincipal.isAdmin. - The all-sessions view includes owner labels (including
Unknownfor legacy records). - Delete confirmation preserves the pre-existing select-all behavior and adds confirmation for foreign/unknown owners. Foreign archive now also requires an explicit browser confirmation; existing Stop & save already has its confirmation dialog.
- A read-only review found no critical, important, or minor issues. The archive guard was added after that review in response to the requirement to cover every destructive rail action, and has its own RED/GREEN regression plus the final full verification above.
Concerns
- E2E remains environment-blocked until the Playwright Chromium browser is installed.
- Existing Vitest runs emit pre-existing MSW unmatched-request and dialog-ref warnings; all assertions pass and this task does not modify those shared test/UI primitives.
Review remediation
- A post-commit review correctly identified that matching
displayNamemust never establish ownership. The predicate now skips confirmation only whensession.authorexactly equalsprincipal.subject; all display-name matches and missing authors are conservative cross-owner actions. - Added RED/GREEN regressions where two principals share display name
Alicebut have distinct subjects: both delete (with another session present, so select-all cannot mask the guard) and archive require confirmation. - Added
aria-pressedto the My sessions / All sessions controls and asserts their selected state before and after switching. - Remediation verification: focused regressions passed; full frontend Vitest (44 files / 305
tests),
npx tsc -b,npm run build, andgit diff --checkall passed.