feat(playwright): add durable settings browser test suite#5773
feat(playwright): add durable settings browser test suite#5773BillLeoutsakosvl346 wants to merge 14 commits into
Conversation
Allow focused child PRs to receive normal CI before the completed suite returns to staging.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
* test(e2e): add reusable Playwright foundation Establish a hermetic full-stack browser harness so settings and future surfaces can exercise real authentication, APIs, and isolated database state safely. * test(e2e): harden runner lifecycle and artifacts Fail closed on stale processes, preserve cleanup during interruption, and keep credentials and personal fixture data out of uploaded diagnostics. * test(e2e): tighten isolation and shutdown guards Make destructive database operations and service bindings strictly local while ensuring interrupted runs fully stop managed children before cleanup. * test(e2e): finalize harness safety boundaries Close the remaining lifecycle, credential-isolation, and CLI escape hatches so future persona and settings suites can build on a fail-closed foundation. * test(e2e): harden interrupted-run cleanup Use a detached cleanup supervisor so repeated signals cannot interrupt process-group shutdown or forced removal of the guarded run database. * test(e2e): guard signal cleanup edge cases Prevent empty process-group targets and verify forced-drop retries against final database state so interrupted runs cannot self-signal or report false cleanup failures. * test(e2e): require exact host and race-safe signals Reject dual-stack host mappings that cannot reach IPv4-only services and tolerate child exit races during process-group signal fallback. * test(e2e): force IPv4 for hosted test origin Accept safe dual-stack loopback resolution while pinning Chromium and Node traffic to 127.0.0.1 so CI reaches IPv4-only services reliably. * test(e2e): settle readiness exit race Mark successful readiness before the managed process completion branch can reject, preventing later normal shutdown from surfacing an abandoned promise failure. * test(e2e): propagate IPv4 preference to probes Keep Node-based Playwright requests on the same IPv4 path as Chromium and use direct loopback for orchestrator probes under dual-stack CI DNS. --------- Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local>
* Add safe E2E build reuse and environment isolation Separate build-time inputs from per-run services so verified artifacts can accelerate local iteration without weakening fresh database or provider boundaries. * Add validated E2E persona world model Model settings personas as deterministic, serializable resource graphs and provide production-first factories with exact-ID cleanup so impossible or cross-world fixture states fail before browser tests run. Co-authored-by: Cursor <cursoragent@cursor.com> * Seed and verify E2E settings personas Provision the validated world through real product boundaries, capture isolated sessions through the login UI, and assert persona contracts plus two-worker cross-world isolation without exposing credentials to Playwright. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden E2E persona orchestration and remove deferred cleanup Generate runtime secrets per run, fail closed when diagnostics cannot be scanned, and harden cache and process cleanup while removing the unused exact-ID cleanup module until retained-stack support has a real consumer. * Fix CI option policy assertions Make local-only parser scenarios explicit so the safety suite tests the intended policy instead of inheriting the GitHub runner environment. * Fix organization invitation fixture semantics Match production organization invitations even when workspace grants are attached, and remove an unused cookie-reset method from the E2E client. --------- Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local> Co-authored-by: Cursor <cursoragent@cursor.com>
* Harden Playwright lifecycle and persona fidelity Close production-state and cleanup gaps so the settings E2E platform fails closed without sacrificing useful diagnostics. * Serialize E2E signal cleanup ownership Prevent opposite signals and normal finalization from racing detached cleanup or releasing its run lock. * Preserve browser fixture failures Report network isolation violations without masking the original Playwright test or fixture error. * Make E2E signal handoff resilient Keep cleanup single-flight across repeated signals and retain lock ownership when supervisor logging or startup fails. * fix(e2e): preserve replacement org coverage Co-authored-by: Cursor <cursoragent@cursor.com> * fix(e2e): derive usage from entitled coverage Co-authored-by: Cursor <cursoragent@cursor.com> * fix(e2e): serialize cleanup lock ownership Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ci): detect safe E2E diagnostics directly Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local> Co-authored-by: Cursor <cursoragent@cursor.com>
* Add settings navigation acceptance contracts Co-authored-by: Cursor <cursoragent@cursor.com> * Support IPv6 loopback in E2E database guard Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local> Co-authored-by: Cursor <cursoragent@cursor.com>
* Add settings authorization acceptance contracts Co-authored-by: Cursor <cursoragent@cursor.com> * Clarify authorization readiness states Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local> Co-authored-by: Cursor <cursoragent@cursor.com>
* test(e2e): cover credential settings workflows Co-authored-by: Cursor <cursoragent@cursor.com> * fix(e2e): address credential review findings Co-authored-by: Cursor <cursoragent@cursor.com> * style(e2e): format credential helper Co-authored-by: Cursor <cursoragent@cursor.com> * fix(settings): prioritize API key load errors Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local> Co-authored-by: Cursor <cursoragent@cursor.com>
* test(e2e): add enterprise workflow coverage Co-authored-by: Cursor <cursoragent@cursor.com> * fix(e2e): harden workflow readiness invariants Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local> Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
* test(e2e): cover enterprise integrations Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sso): preserve uniqueness during migration replay Co-authored-by: Cursor <cursoragent@cursor.com> * fix settings e2e and sso route contracts Co-authored-by: Cursor <cursoragent@cursor.com> * serialize sso provider mutations Co-authored-by: Cursor <cursoragent@cursor.com> * close sso account link races Co-authored-by: Cursor <cursoragent@cursor.com> * normalize sso overlap comparisons Co-authored-by: Cursor <cursoragent@cursor.com> * serialize sso domain verification Co-authored-by: Cursor <cursoragent@cursor.com> * allow sso cleanup after plan loss Co-authored-by: Cursor <cursoragent@cursor.com> * refresh sso provider inside mutation lock Co-authored-by: Cursor <cursoragent@cursor.com> * harden sso update and delete concurrency Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sso): avoid long-held callback mutation locks Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sso): release mutation lock during DNS verification Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sso): normalize audited domain overlaps Co-authored-by: Cursor <cursoragent@cursor.com> * fix(e2e): override auth endpoint rate limits Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local> Co-authored-by: Cursor <cursoragent@cursor.com>
* test(e2e): finalize settings suite stabilization Co-authored-by: Cursor <cursoragent@cursor.com> * fix(helm): tolerate retired SSO preflight keys Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Bill Leoutsakos <billleoutsakos@Mac.localdomain> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
|
@cursor review |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit e60658d. Configure here.
Greptile SummaryThis PR establishes durable settings browser coverage and the supporting production hardening.
Confidence Score: 5/5The PR appears safe to merge based on the reviewed migration, authentication, realtime, CI, and diagnostics paths. The changed paths preserve organization authorization and provider integrity, use guarded and replay-aware migration handling, isolate browser-test infrastructure, accept the configured browser origin, and gate diagnostic uploads on successful secret-leak scanning. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart LR
CI[Settings E2E CI job] --> PG[(Isolated pgvector/Postgres)]
CI --> Runner[E2E orchestrator]
Runner --> Migration[Migration and SSO rehearsal]
Runner --> Stripe[Fake Stripe service]
Runner --> MCP[Fake MCP service]
Runner --> Realtime[Realtime service]
Runner --> App[Production Next.js app]
Runner --> Seed[Deterministic personas and scenarios]
Seed --> PG
Runner --> Browser[Playwright Chromium projects]
Browser --> App
Browser --> Realtime
App --> PG
App --> Stripe
App --> MCP
Browser --> Diagnostics[Reports, traces, screenshots]
Diagnostics --> LeakScan[Leak-canary gate]
LeakScan --> Artifacts[Conditional CI artifact upload]
Reviews (1): Last reviewed commit: "chore(ci): update API validation route b..." | Re-trigger Greptile |
|
Too many files changed for review. ( Bypass the limit by tagging |

Summary
Delivery plan
Test plan
This is the draft integration PR. Each delivery step will be reviewed in a focused PR targeting
e2e/settings-playwrightbefore this PR is made ready for final review.Made with Cursor