e2e/mrweb_test.go
333 lines · 13631 bytes
1package e2e
2
3import (
4 "encoding/json"
5 "net/http"
6 "net/url"
7 "os"
8 "path/filepath"
9 "regexp"
10 "strconv"
11 "strings"
12 "testing"
13)
14
15// login returns a browser holding a session for the given key's account.
16func (i *instance) login(t *testing.T, key string) *http.Client {
17 t.Helper()
18 out, errOut, code := i.ssh(t, key, "", "web", "login", "--json")
19 if code != 0 {
20 t.Fatalf("web login: %s", errOut)
21 }
22 var env struct {
23 Data struct {
24 URL string `json:"url"`
25 } `json:"data"`
26 }
27 json.Unmarshal([]byte(out), &env)
28 c := newBrowser(t)
29 path := env.Data.URL[strings.Index(env.Data.URL, "/login"):]
30 if status, _ := browserGet(t, c, i.base()+path); status != 200 {
31 t.Fatalf("login landed: %d", status)
32 }
33 return c
34}
35
36// TestMRWebReviewLoop drives review, thread resolution, and merge from the
37// browser. Every action runs the same control command the CLI runs, so the
38// test also proves the merge gates apply to web merges.
39func TestMRWebReviewLoop(t *testing.T) {
40 inst := startInstanceWith(t, "[web]\nmode = \"accounts\"\n")
41 aliceKey := inst.newKey(t, "alice")
42 bobKey := inst.newKey(t, "bob")
43 inst.admin(t, "admin", "user", "create", "alice",
44 "--key", aliceKey+".pub", "--email", "alice@example.test", "--verified")
45 inst.admin(t, "admin", "user", "create", "bob",
46 "--key", bobKey+".pub", "--email", "bob@example.test", "--verified")
47
48 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "create", "alice/lib"); code != 0 {
49 t.Fatalf("repo create: %s", errOut)
50 }
51 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "access", "grant", "alice/lib", "bob", "write"); code != 0 {
52 t.Fatalf("grant: %s", errOut)
53 }
54 // Unresolved review threads block merges, so the gate is observable.
55 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "settings", "require-resolved", "alice/lib", "on"); code != 0 {
56 t.Fatalf("require-resolved: %s", errOut)
57 }
58
59 env := inst.gitEnv(aliceKey)
60 work := t.TempDir()
61 mustGit(t, work, env, "clone", inst.sshURL("alice/lib"), "w")
62 dir := filepath.Join(work, "w")
63 os.WriteFile(filepath.Join(dir, "lib.txt"), []byte("v1\n"), 0o644)
64 mustGit(t, dir, env, "checkout", "-q", "-b", "main")
65 mustGit(t, dir, env, "add", ".")
66 mustGit(t, dir, env, "commit", "-q", "-m", "base")
67 mustGit(t, dir, env, "push", "-q", "origin", "main")
68
69 // Bob proposes a change and leaves a review thread on it.
70 bobEnv := inst.gitEnv(bobKey)
71 bobWork := t.TempDir()
72 mustGit(t, bobWork, bobEnv, "clone", inst.sshURL("alice/lib"), "w")
73 bobDir := filepath.Join(bobWork, "w")
74 mustGit(t, bobDir, bobEnv, "checkout", "-q", "-b", "feature", "origin/main")
75 os.WriteFile(filepath.Join(bobDir, "feature.txt"), []byte("bob's work\n"), 0o644)
76 mustGit(t, bobDir, bobEnv, "add", ".")
77 mustGit(t, bobDir, bobEnv, "commit", "-q", "-m", "add feature")
78 mustGit(t, bobDir, bobEnv, "push", "-q", "origin", "feature")
79 if _, errOut, code := inst.ssh(t, bobKey, "", "mr", "create", "alice/lib",
80 "--source", "feature", "--target", "main", "--title", "'add feature'"); code != 0 {
81 t.Fatalf("mr create: %s", errOut)
82 }
83 if _, errOut, code := inst.ssh(t, bobKey, "", "mr", "diff-comment", "alice/lib", "1",
84 "--path", "feature.txt", "--line", "1", "--message", "'is this right?'"); code != 0 {
85 t.Fatalf("diff-comment: %s", errOut)
86 }
87
88 mrURL := inst.base() + "/alice/lib/mrs/1"
89 alice := inst.login(t, aliceKey)
90
91 // The controls are on the page, and carry the thread to resolve.
92 _, body := browserGet(t, alice, mrURL)
93 for _, want := range []string{`value="approve"`, `action="/alice/lib/mrs/1/merge"`} {
94 if !strings.Contains(body, want) {
95 t.Fatalf("MR page missing %q", want)
96 }
97 }
98 // Review threads live on the diff view, where their lines are.
99 _, diffBody := browserGet(t, alice, mrURL+"?view=diff")
100 m := regexp.MustCompile(`name="thread" value="(\d+)"`).FindStringSubmatch(diffBody)
101 if m == nil {
102 t.Fatalf("no thread control on the diff view:\n%s", diffBody)
103 }
104 threadID := m[1]
105
106 // Approve from the browser; the CLI sees the review.
107 if status, _ := browserPost(t, alice, mrURL+"/review", url.Values{"verdict": {"approve"}}); status != 200 {
108 t.Fatalf("review post: %d", status)
109 }
110 show := inst.mrShow(t, aliceKey, "alice/lib", "1")
111 if len(show.Reviews) != 1 || show.Reviews[0].Reviewer != "alice" || show.Reviews[0].Verdict != "approve" {
112 t.Fatalf("review not recorded: %+v", show.Reviews)
113 }
114
115 // Merging is refused while the thread is open, and the page says why.
116 _, body = browserPost(t, alice, mrURL+"/merge", url.Values{"strategy": {"auto"}})
117 if !strings.Contains(body, "unresolved") {
118 t.Fatalf("merge gate not surfaced:\n%s", body)
119 }
120 if st := inst.mrShow(t, aliceKey, "alice/lib", "1").State; st != "open" {
121 t.Fatalf("blocked merge changed state to %s", st)
122 }
123
124 // Resolve the thread, then merge.
125 if status, _ := browserPost(t, alice, mrURL+"/thread",
126 url.Values{"thread": {threadID}, "action": {"resolve"}}); status != 200 {
127 t.Fatalf("resolve post: %d", status)
128 }
129 out, _, _ := inst.ssh(t, aliceKey, "", "mr", "threads", "alice/lib", "1")
130 if !strings.Contains(out, "resolved") {
131 t.Fatalf("thread not resolved:\n%s", out)
132 }
133 if status, _ := browserPost(t, alice, mrURL+"/merge", url.Values{"strategy": {"auto"}}); status != 200 {
134 t.Fatalf("merge post: %d", status)
135 }
136 if st := inst.mrShow(t, aliceKey, "alice/lib", "1").State; st != "merged" {
137 t.Fatalf("MR state after web merge: %s", st)
138 }
139 mustGit(t, dir, env, "pull", "-q", "origin", "main")
140 if _, err := os.Stat(filepath.Join(dir, "feature.txt")); err != nil {
141 t.Fatal("merged content missing from main")
142 }
143
144 // Readers get no controls, and a forged POST is refused by the command.
145 _, anon := browserGet(t, newBrowser(t), mrURL)
146 if strings.Contains(anon, `value="approve"`) {
147 t.Fatal("anonymous visitor sees review controls")
148 }
149 carol := inst.newKey(t, "carol")
150 inst.admin(t, "admin", "user", "create", "carol", "--key", carol+".pub")
151 if _, errOut, code := inst.ssh(t, carol, "", "repo", "create", "carol/own"); code != 0 {
152 t.Fatalf("carol repo: %s", errOut)
153 }
154 _, denied := browserPost(t, inst.login(t, carol), mrURL+"/close", url.Values{})
155 if !strings.Contains(denied, `class="error"`) || !strings.Contains(denied, "write access") {
156 t.Fatalf("reader was not refused:\n%s", denied)
157 }
158}
159
160// TestMRWebCreate opens a merge request from the browser and checks the
161// form survives a refusal with the draft intact.
162func TestMRWebCreate(t *testing.T) {
163 inst := startInstanceWith(t, "[web]\nmode = \"accounts\"\n")
164 aliceKey := inst.newKey(t, "alice")
165 inst.admin(t, "admin", "user", "create", "alice",
166 "--key", aliceKey+".pub", "--email", "alice@example.test", "--verified")
167 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "create", "alice/lib"); code != 0 {
168 t.Fatalf("repo create: %s", errOut)
169 }
170 env := inst.gitEnv(aliceKey)
171 work := t.TempDir()
172 mustGit(t, work, env, "clone", inst.sshURL("alice/lib"), "w")
173 dir := filepath.Join(work, "w")
174 os.WriteFile(filepath.Join(dir, "a.txt"), []byte("a\n"), 0o644)
175 mustGit(t, dir, env, "checkout", "-q", "-b", "main")
176 mustGit(t, dir, env, "add", ".")
177 mustGit(t, dir, env, "commit", "-q", "-m", "base")
178 mustGit(t, dir, env, "push", "-q", "origin", "main")
179 mustGit(t, dir, env, "checkout", "-q", "-b", "topic")
180 os.WriteFile(filepath.Join(dir, "b.txt"), []byte("b\n"), 0o644)
181 mustGit(t, dir, env, "add", ".")
182 mustGit(t, dir, env, "commit", "-q", "-m", "topic work")
183 mustGit(t, dir, env, "push", "-q", "origin", "topic")
184
185 alice := inst.login(t, aliceKey)
186 base := inst.base() + "/alice/lib"
187
188 // The list links to the form, and the form offers the pushed branches.
189 if _, body := browserGet(t, alice, base+"/mrs"); !strings.Contains(body, "/alice/lib/mrs/new") {
190 t.Fatalf("no create link on the list:\n%s", body)
191 }
192 _, form := browserGet(t, alice, base+"/mrs/new")
193 for _, want := range []string{`name="source"`, `value="topic"`, `value="main"`} {
194 if !strings.Contains(form, want) {
195 t.Fatalf("form missing %q:\n%s", want, form)
196 }
197 }
198
199 // A refusal keeps the draft: the branch does not exist.
200 _, retry := browserPost(t, alice, base+"/mrs/new", url.Values{
201 "source": {"nope"}, "target": {"main"}, "title": {"my title"}, "body": {"my body"}})
202 if !strings.Contains(retry, `class="error"`) || !strings.Contains(retry, "my title") ||
203 !strings.Contains(retry, "my body") {
204 t.Fatalf("refusal lost the draft:\n%s", retry)
205 }
206
207 // A real one lands on the merge request it created.
208 status, created := browserPost(t, alice, base+"/mrs/new", url.Values{
209 "source": {"topic"}, "target": {"main"}, "title": {"topic into main"}, "body": {"please review"}})
210 if status != 200 || !strings.Contains(created, "topic into main") {
211 t.Fatalf("create failed: %d\n%s", status, created)
212 }
213 show := inst.mrShow(t, aliceKey, "alice/lib", "1")
214 if show.State != "open" || show.Source != "topic" {
215 t.Fatalf("created MR wrong: %+v", show)
216 }
217}
218
219// TestMRWebDiffThreads opens a review thread on a diff line and replies to
220// it from the browser. The CLI's view of the threads afterwards is what
221// proves the page dispatched mr diff-comment rather than writing its own
222// rows.
223func TestMRWebDiffThreads(t *testing.T) {
224 inst := startInstanceWith(t, "[web]\nmode = \"accounts\"\n")
225 aliceKey := inst.newKey(t, "alice")
226 inst.admin(t, "admin", "user", "create", "alice",
227 "--key", aliceKey+".pub", "--email", "alice@example.test", "--verified")
228
229 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "create", "alice/lib"); code != 0 {
230 t.Fatalf("repo create: %s", errOut)
231 }
232 env := inst.gitEnv(aliceKey)
233 work := t.TempDir()
234 mustGit(t, work, env, "clone", inst.sshURL("alice/lib"), "w")
235 dir := filepath.Join(work, "w")
236 os.WriteFile(filepath.Join(dir, "main.go"), []byte("package main\n\nfunc main() {\n}\n"), 0o644)
237 mustGit(t, dir, env, "checkout", "-q", "-b", "main")
238 mustGit(t, dir, env, "add", ".")
239 mustGit(t, dir, env, "commit", "-q", "-m", "base")
240 mustGit(t, dir, env, "push", "-q", "origin", "main")
241 mustGit(t, dir, env, "checkout", "-q", "-b", "feat")
242 os.WriteFile(filepath.Join(dir, "main.go"),
243 []byte("package main\n\nimport \"fmt\"\n\nfunc main() {\n\tfmt.Println(\"hi\")\n}\n"), 0o644)
244 mustGit(t, dir, env, "add", ".")
245 mustGit(t, dir, env, "commit", "-q", "-m", "add greeting")
246 mustGit(t, dir, env, "push", "-q", "origin", "feat")
247 if _, errOut, code := inst.ssh(t, aliceKey, "", "mr", "create", "alice/lib",
248 "--source", "feat", "--target", "main", "--title", "'greeting'"); code != 0 {
249 t.Fatalf("mr create: %s", errOut)
250 }
251
252 mrURL := inst.base() + "/alice/lib/mrs/1"
253 alice := inst.login(t, aliceKey)
254
255 // The gutter carries the handle, and following it renders the form
256 // anchored to that line. There is no JavaScript, so the anchor has to
257 // survive a round trip in the query.
258 _, body := browserGet(t, alice, mrURL+"?view=diff")
259 if !strings.Contains(body, "cpath=main.go&cline=6&cside=new") {
260 t.Fatalf("no comment handle in the diff gutter:\n%s", body)
261 }
262 _, body = browserGet(t, alice, mrURL+"?view=diff&cpath=main.go&cline=6&cside=new")
263 if !strings.Contains(body, `id="compose"`) || !strings.Contains(body, `name="line" value="6"`) {
264 t.Fatalf("compose form not rendered:\n%s", body)
265 }
266
267 if status, _ := browserPost(t, alice, mrURL+"/diff-comment", url.Values{
268 "path": {"main.go"}, "line": {"6"}, "side": {"new"},
269 "body": {"use log instead of fmt"}}); status != 200 {
270 t.Fatalf("open thread: %d", status)
271 }
272 threads := inst.mrThreads(t, aliceKey, "alice/lib", "1")
273 if len(threads) != 1 || threads[0].Path != "main.go" || threads[0].Line != 6 {
274 t.Fatalf("thread not anchored: %+v", threads)
275 }
276 if len(threads[0].Comments) != 1 || threads[0].Comments[0].Body != "use log instead of fmt" {
277 t.Fatalf("comment body not stored: %+v", threads[0].Comments)
278 }
279
280 // The rendered thread offers reply and resolve to its author.
281 _, body = browserGet(t, alice, mrURL+"?view=diff")
282 if !strings.Contains(body, `name="reply" value="`+strconv.FormatInt(threads[0].ID, 10)+`"`) {
283 t.Fatalf("no reply form on the thread:\n%s", body)
284 }
285 if !strings.Contains(body, `value="resolve"`) {
286 t.Fatalf("no resolve control on the thread:\n%s", body)
287 }
288
289 if status, _ := browserPost(t, alice, mrURL+"/diff-comment", url.Values{
290 "reply": {strconv.FormatInt(threads[0].ID, 10)}, "body": {"agreed, switching"}}); status != 200 {
291 t.Fatalf("reply: %d", status)
292 }
293 threads = inst.mrThreads(t, aliceKey, "alice/lib", "1")
294 if len(threads) != 1 || len(threads[0].Comments) != 2 ||
295 threads[0].Comments[1].Body != "agreed, switching" {
296 t.Fatalf("reply not on the thread: %+v", threads)
297 }
298
299 // An empty body is refused, and says so on the page it returns to.
300 _, body = browserPost(t, alice, mrURL+"/diff-comment", url.Values{
301 "reply": {strconv.FormatInt(threads[0].ID, 10)}, "body": {" "}})
302 if !strings.Contains(body, "empty comment") {
303 t.Fatalf("empty reply not refused:\n%s", body)
304 }
305}
306
307// mrThread is one review thread as mr threads --json reports it.
308type mrThread struct {
309 ID int64 `json:"id"`
310 Path string `json:"path"`
311 Side string `json:"side"`
312 Line int64 `json:"line"`
313 Comments []struct {
314 Author string `json:"author"`
315 Body string `json:"body"`
316 } `json:"comments"`
317}
318
319// mrThreads reads the review threads on a merge request over SSH.
320func (i *instance) mrThreads(t *testing.T, key, repo, n string) []mrThread {
321 t.Helper()
322 out, errOut, code := i.ssh(t, key, "", "mr", "threads", repo, n, "--json")
323 if code != 0 {
324 t.Fatalf("mr threads: %s", errOut)
325 }
326 var env struct {
327 Data []mrThread `json:"data"`
328 }
329 if err := json.Unmarshal([]byte(out), &env); err != nil {
330 t.Fatalf("mr threads json: %v", err)
331 }
332 return env.Data
333}