66 lines
3.5 KiB
Markdown
66 lines
3.5 KiB
Markdown
# Task 6 — Frontend identity and administrator UX report
|
|
|
|
## RED
|
|
|
|
- Added API tests for the `/me` principal call and `mine`/`all` session-list scopes.
|
|
- Added component tests for regular-user scope, admin scope switching, owner labels,
|
|
administrator banner, foreign-owner delete confirmation, and foreign-owner archive
|
|
confirmation.
|
|
- Initial focused run: 7 expected failures (missing `getMe`, missing scope query,
|
|
missing owner label/admin controls, and missing foreign-action confirmation).
|
|
- The archive-confirmation regression was also run separately before its implementation
|
|
and failed because `window.confirm` was not called.
|
|
|
|
## GREEN
|
|
|
|
- `npx vitest run src/api/sessions.test.ts src/shell/NavSessions.test.tsx src/shell/AppShell.session-mgmt.test.tsx`
|
|
— passed (47 tests before the archive follow-up; the focused archive regression then passed).
|
|
- `npm test` — passed: 44 files / 305 tests.
|
|
- `npx tsc -b` — passed.
|
|
- `npm run build` — passed.
|
|
- `git diff --check` — passed.
|
|
- `npm run e2e` reached Playwright but could not run: the environment has no Chromium
|
|
executable at Playwright's configured cache path. No application test failure was reported.
|
|
|
|
## Files changed
|
|
|
|
- `frontend/src/api/types.ts`: typed principal and session scope contracts.
|
|
- `frontend/src/api/sessions.ts`: typed `/me` API call; scoped listing defaults to `mine`.
|
|
- `frontend/src/shell/AppShell.tsx`: identity query, admin-only session scope selector and
|
|
banner, owner-aware destructive action confirmations.
|
|
- `frontend/src/shell/NavSessions.tsx`: owner labels in the all-sessions view.
|
|
- `frontend/src/api/sessions.test.ts`, `frontend/src/shell/NavSessions.test.tsx`, and
|
|
`frontend/src/shell/AppShell.session-mgmt.test.tsx`: contract and UX coverage.
|
|
|
|
## Self-review
|
|
|
|
- Regular users remain fail-closed on `mine`; no administrator control renders without
|
|
`principal.isAdmin`.
|
|
- The all-sessions view includes owner labels (including `Unknown` for legacy records).
|
|
- Delete confirmation preserves the pre-existing select-all behavior and adds confirmation
|
|
for foreign/unknown owners. Foreign archive now also requires an explicit browser
|
|
confirmation; existing Stop & save already has its confirmation dialog.
|
|
- A read-only review found no critical, important, or minor issues. The archive guard was
|
|
added after that review in response to the requirement to cover every destructive rail
|
|
action, and has its own RED/GREEN regression plus the final full verification above.
|
|
|
|
## Concerns
|
|
|
|
- E2E remains environment-blocked until the Playwright Chromium browser is installed.
|
|
- Existing Vitest runs emit pre-existing MSW unmatched-request and dialog-ref warnings; all
|
|
assertions pass and this task does not modify those shared test/UI primitives.
|
|
|
|
## Review remediation
|
|
|
|
- A post-commit review correctly identified that matching `displayName` must never establish
|
|
ownership. The predicate now skips confirmation only when `session.author` exactly equals
|
|
`principal.subject`; all display-name matches and missing authors are conservative
|
|
cross-owner actions.
|
|
- Added RED/GREEN regressions where two principals share display name `Alice` but have distinct
|
|
subjects: both delete (with another session present, so select-all cannot mask the guard) and
|
|
archive require confirmation.
|
|
- Added `aria-pressed` to the My sessions / All sessions controls and asserts their selected state
|
|
before and after switching.
|
|
- Remediation verification: focused regressions passed; full frontend Vitest (44 files / 305
|
|
tests), `npx tsc -b`, `npm run build`, and `git diff --check` all passed.
|