Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .changeset/ci-security-audit-and-thunder-e2e.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
---

Dependency and CI maintenance: resolve all high/critical `pnpm audit` advisories, remove the Thunder E2E suite, pin the CI pnpm version. No runtime changes.
90 changes: 4 additions & 86 deletions .github/workflows/e2e-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,9 @@ on:
workflow_dispatch:
inputs:
idp_target:
description: 'IDP target (is, thunder, both)'
description: 'IDP target (is)'
required: false
default: 'both'
default: 'is'

env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Expand All @@ -24,14 +24,13 @@ jobs:
name: 🧪 E2E (WSO2 IS)
if: >-
github.event_name == 'pull_request' ||
github.event.inputs.idp_target == 'is' ||
github.event.inputs.idp_target == 'both'
github.event.inputs.idp_target == 'is'
runs-on: ubuntu-latest
timeout-minutes: 30
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [10.33.4]
steps:
- name: ⬇️ Checkout
uses: actions/checkout@v4
Expand Down Expand Up @@ -100,84 +99,3 @@ jobs:
- name: 🐳 Stop Docker containers
if: always()
run: pnpm e2e:docker:down

e2e-thunder:
name: 🧪 E2E (Thunder)
if: >-
github.event_name == 'pull_request' ||
github.event.inputs.idp_target == 'thunder' ||
github.event.inputs.idp_target == 'both'
runs-on: ubuntu-latest
timeout-minutes: 20
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
steps:
- name: ⬇️ Checkout
uses: actions/checkout@v4

- name: 🟢 Setup node
uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node-version }}

- name: 🥡 Setup pnpm
uses: pnpm/action-setup@v4
with:
version: ${{ matrix.pnpm-version }}
run_install: false

- name: 🎈 Get pnpm store directory
id: get-pnpm-cache-dir
run: echo "pnpm_cache_dir=$(pnpm store path)" >> $GITHUB_OUTPUT

- name: 🔆 Cache pnpm modules
uses: actions/cache@v4
with:
path: ${{ steps.get-pnpm-cache-dir.outputs.pnpm_cache_dir }}
key: ${{ runner.os }}-pnpm-store-${{ hashFiles('**/pnpm-lock.yaml') }}
restore-keys: |
${{ runner.os }}-pnpm-store-

- name: 🧩 Install Dependencies
run: pnpm install --frozen-lockfile

- name: 🏗️ Build SDK packages
run: pnpm build

- name: 🎭 Install Playwright browsers
run: pnpm e2e:install

- name: 🐳 Start Thunder
run: pnpm e2e:docker:up:thunder

- name: 🧪 Run E2E redirect tests against Thunder
run: pnpm e2e -- --idp thunder --mode redirect
env:
CI: true

- name: 🧪 Run E2E embedded tests against Thunder
run: pnpm e2e -- --idp thunder --mode embedded
env:
CI: true

- name: 📊 Upload redirect test report
uses: actions/upload-artifact@v4
if: always()
with:
name: e2e-thunder-redirect-report
path: e2e/playwright-report/
retention-days: 14

- name: 📊 Upload embedded test report
uses: actions/upload-artifact@v4
if: always()
with:
name: e2e-thunder-embedded-report
path: e2e/playwright-report-embedded/
retention-days: 14

- name: 🐳 Stop Docker containers
if: always()
run: pnpm e2e:docker:down
2 changes: 1 addition & 1 deletion .github/workflows/npm-audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ jobs:
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [10.33.4]
steps:
- name: ⬇️ Checkout
id: checkout
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/pr-builder.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [10.33.4]
steps:
- name: ⬇️ Checkout
id: checkout
Expand Down Expand Up @@ -76,7 +76,7 @@ jobs:
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [10.33.4]
steps:
- name: ⬇️ Checkout
id: checkout
Expand Down Expand Up @@ -135,7 +135,7 @@ jobs:
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [10.33.4]
steps:
- name: ⬇️ Checkout
id: checkout
Expand Down Expand Up @@ -189,7 +189,7 @@ jobs:
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [10.33.4]
steps:
- name: ⬇️ Checkout
id: checkout
Expand Down
81 changes: 29 additions & 52 deletions e2e/README.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# E2E Tests

End-to-end tests for the `@asgardeo/react` SDK using [Playwright](https://playwright.dev). Tests run against two
identity providers (IDPs) and cover both redirect-based OAuth and embedded `<SignIn />` component flows.
End-to-end tests for the `@asgardeo/react` SDK using [Playwright](https://playwright.dev). Tests run against WSO2 Identity
Server and cover both redirect-based OAuth and embedded `<SignIn />` component flows.

## Prerequisites

Expand All @@ -27,12 +27,12 @@ pnpm e2e -- --idp is
All e2e tests are run via a single script:

```bash
pnpm e2e -- [--idp is|thunder|all] [--mode redirect|embedded|all] [--headed]
pnpm e2e -- [--idp is] [--mode redirect|embedded|all] [--headed]
```

| Flag | Values | Default | Description |
| ---------- | ----------------------------- | ---------- | -------------------------- |
| `--idp` | `is`, `thunder`, `all` | `is` | Which IDP to test against |
| `--idp` | `is` | `is` | Which IDP to test against |
| `--mode` | `redirect`, `embedded`, `all` | `redirect` | Sign-in mode to test |
| `--headed` | _(flag)_ | off | Run in headed browser mode |

Expand All @@ -42,11 +42,8 @@ pnpm e2e -- [--idp is|thunder|all] [--mode redirect|embedded|all] [--headed]
# IS redirect tests (default)
pnpm e2e

# Thunder embedded tests
pnpm e2e -- --idp thunder --mode embedded

# All tests, all IDPs, headed
pnpm e2e -- --idp all --mode all --headed
# All modes, headed
pnpm e2e -- --mode all --headed

# IS both modes
pnpm e2e -- --idp is --mode all
Expand All @@ -55,10 +52,9 @@ pnpm e2e -- --idp is --mode all
### Docker Commands

```bash
pnpm e2e:docker:up # Start all IDP containers
pnpm e2e:docker:up # Start the IDP container
pnpm e2e:docker:down # Stop and remove all containers + volumes
pnpm e2e:docker:up:is # Start only WSO2 IS
pnpm e2e:docker:up:thunder # Start only Thunder
```

## Sign-In Modes
Expand Down Expand Up @@ -89,60 +85,41 @@ e2e/
│ ├── global-teardown.ts # Cleanup after test run
│ ├── wait-for-idp.ts # Health-check poller
│ ├── http-utils.ts # HTTP helpers for setup APIs
│ ├── is/
│ │ ├── constants.ts # IS-specific config
│ │ ├── app-registration.ts # DCR + Application Management API
│ │ └── user-provisioning.ts # SCIM2 test user creation
│ └── thunder/
│ ├── constants.ts # Thunder-specific config
│ ├── app-registration.ts # App client ID + redirect URI patching
│ └── user-provisioning.ts # Thunder test user creation
│ └── is/
│ ├── constants.ts # IS-specific config
│ ├── app-registration.ts # DCR + Application Management API
│ └── user-provisioning.ts # SCIM2 test user creation
├── fixtures/
│ └── base.fixture.ts # Shared Playwright test fixture
├── helpers/
│ ├── auth-helpers.ts # IDP-agnostic sign-in/sign-out helpers
│ ├── selectors.ts # Shared UI selectors (SDK components, dashboard)
│ ├── is/
│ │ ├── auth-helpers.ts # IS login page interaction
│ │ └── selectors.ts # IS-specific selectors
│ └── thunder/
│ ├── auth-helpers.ts # Thunder Gate login page interaction
│ └── selectors.ts # Thunder-specific selectors
│ └── is/
│ ├── auth-helpers.ts # IS login page interaction
│ └── selectors.ts # IS-specific selectors
├── tests/
│ ├── is/
│ │ ├── redirect/
│ │ │ ├── sign-in.spec.ts # IS redirect sign-in tests
│ │ │ ├── sign-out.spec.ts # IS sign-out tests
│ │ │ └── user-profile.spec.ts
│ │ └── embedded/
│ │ └── sign-in.spec.ts # IS embedded sign-in tests
│ └── thunder/
│ └── is/
│ ├── redirect/
│ │ ├── sign-in.spec.ts # Thunder redirect sign-in tests
│ │ ├── sign-in.spec.ts # IS redirect sign-in tests
│ │ ├── sign-out.spec.ts # IS sign-out tests
│ │ └── user-profile.spec.ts
│ └── embedded/
│ └── sign-in.spec.ts # Thunder embedded sign-in tests
├── thunder-bootstrap/
│ └── 02-sample-resources.sh # Thunder bootstrap: registers sample app
└── thunder-config/
└── deployment.yaml # Thunder server configuration
│ └── sign-in.spec.ts # IS embedded sign-in tests
```

## Test Coverage

| Test | IS | Thunder |
| ----------------------------------------- | --- | ------- |
| Redirect to IDP login page | Yes | Yes |
| Sign in with valid credentials (redirect) | Yes | Yes |
| Redirect unauthenticated users to IDP | Yes | Yes |
| Sign out and redirect to landing page | Yes | — |
| Block protected routes after sign out | Yes | — |
| Render embedded `<SignIn />` component | Yes | Yes |
| Sign in via embedded component | Yes | Yes |
| Display user profile | Yes | Yes |
| Navigate back from profile | Yes | Yes |

> Thunder does not support OIDC logout, so sign-out tests are IS-only.
| Test | IS |
| ----------------------------------------- | --- |
| Redirect to IDP login page | Yes |
| Sign in with valid credentials (redirect) | Yes |
| Redirect unauthenticated users to IDP | Yes |
| Sign out and redirect to landing page | Yes |
| Block protected routes after sign out | Yes |
| Render embedded `<SignIn />` component | Yes |
| Sign in via embedded component | Yes |
| Display user profile | Yes |
| Navigate back from profile | Yes |

## How It Works

Expand Down
58 changes: 0 additions & 58 deletions e2e/docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,64 +19,6 @@ services:
networks:
- e2e-network

# ============================================================================
# Asgardeo Thunder (3-stage setup: db-init -> setup -> server)
# ============================================================================

# Stage 1: Initialize the database from the image
thunder-db-init:
image: ghcr.io/asgardeo/thunder:latest
container_name: asgardeo-e2e-thunder-db-init
command: sh -c "cp -r /opt/thunder/repository/database/* /data/"
volumes:
- thunder-db:/data
restart: "no"
networks:
- e2e-network

# Stage 2: Run setup (creates admin user, default app, flows, etc.)
# Mounts custom 02-sample-resources.sh to register the app with
# redirect_uris pointing to https://localhost:5173 (Vite dev server).
thunder-setup:
image: ghcr.io/asgardeo/thunder:latest
container_name: asgardeo-e2e-thunder-setup
command: ./setup.sh
volumes:
- thunder-db:/opt/thunder/repository/database
- ./thunder-bootstrap/02-sample-resources.sh:/opt/thunder/bootstrap/02-sample-resources.sh:ro
- ./thunder-config/deployment.yaml:/opt/thunder/repository/conf/deployment.yaml:ro
depends_on:
thunder-db-init:
condition: service_completed_successfully
restart: "no"
networks:
- e2e-network

# Stage 3: Run the Thunder server
thunder:
image: ghcr.io/asgardeo/thunder:latest
container_name: asgardeo-e2e-thunder
depends_on:
thunder-setup:
condition: service_completed_successfully
ports:
- "8090:8090"
volumes:
- thunder-db:/opt/thunder/repository/database
- ./thunder-config/deployment.yaml:/opt/thunder/repository/conf/deployment.yaml:ro
healthcheck:
test: ["CMD", "curl", "-k", "-f", "https://localhost:8090/health/readiness"]
interval: 10s
timeout: 5s
retries: 15
start_period: 30s
networks:
- e2e-network

volumes:
thunder-db:
driver: local

networks:
e2e-network:
driver: bridge
Loading
Loading