Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .changeset/ci-security-audit-and-thunder-e2e.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
---

Dependency and CI maintenance: resolve all high/critical `pnpm audit` advisories, remove the Thunder E2E suite, pin the CI pnpm version. No runtime changes.
90 changes: 4 additions & 86 deletions .github/workflows/e2e-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,9 @@ on:
workflow_dispatch:
inputs:
idp_target:
description: 'IDP target (is, thunder, both)'
description: 'IDP target (is)'
required: false
default: 'both'
default: 'is'

env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Expand All @@ -24,14 +24,13 @@ jobs:
name: 🧪 E2E (WSO2 IS)
if: >-
github.event_name == 'pull_request' ||
github.event.inputs.idp_target == 'is' ||
github.event.inputs.idp_target == 'both'
github.event.inputs.idp_target == 'is'
runs-on: ubuntu-latest
timeout-minutes: 30
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [11.17.0]
steps:
- name: ⬇️ Checkout
uses: actions/checkout@v4
Expand Down Expand Up @@ -100,84 +99,3 @@ jobs:
- name: 🐳 Stop Docker containers
if: always()
run: pnpm e2e:docker:down

e2e-thunder:
name: 🧪 E2E (Thunder)
if: >-
github.event_name == 'pull_request' ||
github.event.inputs.idp_target == 'thunder' ||
github.event.inputs.idp_target == 'both'
runs-on: ubuntu-latest
timeout-minutes: 20
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
steps:
- name: ⬇️ Checkout
uses: actions/checkout@v4

- name: 🟢 Setup node
uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node-version }}

- name: 🥡 Setup pnpm
uses: pnpm/action-setup@v4
with:
version: ${{ matrix.pnpm-version }}
run_install: false

- name: 🎈 Get pnpm store directory
id: get-pnpm-cache-dir
run: echo "pnpm_cache_dir=$(pnpm store path)" >> $GITHUB_OUTPUT

- name: 🔆 Cache pnpm modules
uses: actions/cache@v4
with:
path: ${{ steps.get-pnpm-cache-dir.outputs.pnpm_cache_dir }}
key: ${{ runner.os }}-pnpm-store-${{ hashFiles('**/pnpm-lock.yaml') }}
restore-keys: |
${{ runner.os }}-pnpm-store-

- name: 🧩 Install Dependencies
run: pnpm install --frozen-lockfile

- name: 🏗️ Build SDK packages
run: pnpm build

- name: 🎭 Install Playwright browsers
run: pnpm e2e:install

- name: 🐳 Start Thunder
run: pnpm e2e:docker:up:thunder

- name: 🧪 Run E2E redirect tests against Thunder
run: pnpm e2e -- --idp thunder --mode redirect
env:
CI: true

- name: 🧪 Run E2E embedded tests against Thunder
run: pnpm e2e -- --idp thunder --mode embedded
env:
CI: true

- name: 📊 Upload redirect test report
uses: actions/upload-artifact@v4
if: always()
with:
name: e2e-thunder-redirect-report
path: e2e/playwright-report/
retention-days: 14

- name: 📊 Upload embedded test report
uses: actions/upload-artifact@v4
if: always()
with:
name: e2e-thunder-embedded-report
path: e2e/playwright-report-embedded/
retention-days: 14

- name: 🐳 Stop Docker containers
if: always()
run: pnpm e2e:docker:down
2 changes: 1 addition & 1 deletion .github/workflows/npm-audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ jobs:
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [11.17.0]
Comment thread
DonOmalVindula marked this conversation as resolved.
Outdated
steps:
- name: ⬇️ Checkout
id: checkout
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/pr-builder.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [11.17.0]
steps:
- name: ⬇️ Checkout
id: checkout
Expand Down Expand Up @@ -76,7 +76,7 @@ jobs:
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [11.17.0]
steps:
- name: ⬇️ Checkout
id: checkout
Expand Down Expand Up @@ -135,7 +135,7 @@ jobs:
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [11.17.0]
steps:
- name: ⬇️ Checkout
id: checkout
Expand Down Expand Up @@ -189,7 +189,7 @@ jobs:
strategy:
matrix:
node-version: [lts/*]
pnpm-version: [latest]
pnpm-version: [11.17.0]
steps:
- name: ⬇️ Checkout
id: checkout
Expand Down
81 changes: 29 additions & 52 deletions e2e/README.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# E2E Tests

End-to-end tests for the `@asgardeo/react` SDK using [Playwright](https://playwright.dev). Tests run against two
identity providers (IDPs) and cover both redirect-based OAuth and embedded `<SignIn />` component flows.
End-to-end tests for the `@asgardeo/react` SDK using [Playwright](https://playwright.dev). Tests run against WSO2 Identity
Server and cover both redirect-based OAuth and embedded `<SignIn />` component flows.

## Prerequisites

Expand All @@ -27,12 +27,12 @@ pnpm e2e -- --idp is
All e2e tests are run via a single script:

```bash
pnpm e2e -- [--idp is|thunder|all] [--mode redirect|embedded|all] [--headed]
pnpm e2e -- [--idp is] [--mode redirect|embedded|all] [--headed]
```

| Flag | Values | Default | Description |
| ---------- | ----------------------------- | ---------- | -------------------------- |
| `--idp` | `is`, `thunder`, `all` | `is` | Which IDP to test against |
| `--idp` | `is` | `is` | Which IDP to test against |
| `--mode` | `redirect`, `embedded`, `all` | `redirect` | Sign-in mode to test |
| `--headed` | _(flag)_ | off | Run in headed browser mode |

Expand All @@ -42,11 +42,8 @@ pnpm e2e -- [--idp is|thunder|all] [--mode redirect|embedded|all] [--headed]
# IS redirect tests (default)
pnpm e2e

# Thunder embedded tests
pnpm e2e -- --idp thunder --mode embedded

# All tests, all IDPs, headed
pnpm e2e -- --idp all --mode all --headed
# All modes, headed
pnpm e2e -- --mode all --headed

# IS both modes
pnpm e2e -- --idp is --mode all
Expand All @@ -55,10 +52,9 @@ pnpm e2e -- --idp is --mode all
### Docker Commands

```bash
pnpm e2e:docker:up # Start all IDP containers
pnpm e2e:docker:up # Start the IDP container
pnpm e2e:docker:down # Stop and remove all containers + volumes
pnpm e2e:docker:up:is # Start only WSO2 IS
pnpm e2e:docker:up:thunder # Start only Thunder
```

## Sign-In Modes
Expand Down Expand Up @@ -89,60 +85,41 @@ e2e/
│ ├── global-teardown.ts # Cleanup after test run
│ ├── wait-for-idp.ts # Health-check poller
│ ├── http-utils.ts # HTTP helpers for setup APIs
│ ├── is/
│ │ ├── constants.ts # IS-specific config
│ │ ├── app-registration.ts # DCR + Application Management API
│ │ └── user-provisioning.ts # SCIM2 test user creation
│ └── thunder/
│ ├── constants.ts # Thunder-specific config
│ ├── app-registration.ts # App client ID + redirect URI patching
│ └── user-provisioning.ts # Thunder test user creation
│ └── is/
│ ├── constants.ts # IS-specific config
│ ├── app-registration.ts # DCR + Application Management API
│ └── user-provisioning.ts # SCIM2 test user creation
├── fixtures/
│ └── base.fixture.ts # Shared Playwright test fixture
├── helpers/
│ ├── auth-helpers.ts # IDP-agnostic sign-in/sign-out helpers
│ ├── selectors.ts # Shared UI selectors (SDK components, dashboard)
│ ├── is/
│ │ ├── auth-helpers.ts # IS login page interaction
│ │ └── selectors.ts # IS-specific selectors
│ └── thunder/
│ ├── auth-helpers.ts # Thunder Gate login page interaction
│ └── selectors.ts # Thunder-specific selectors
│ └── is/
│ ├── auth-helpers.ts # IS login page interaction
│ └── selectors.ts # IS-specific selectors
├── tests/
│ ├── is/
│ │ ├── redirect/
│ │ │ ├── sign-in.spec.ts # IS redirect sign-in tests
│ │ │ ├── sign-out.spec.ts # IS sign-out tests
│ │ │ └── user-profile.spec.ts
│ │ └── embedded/
│ │ └── sign-in.spec.ts # IS embedded sign-in tests
│ └── thunder/
│ └── is/
│ ├── redirect/
│ │ ├── sign-in.spec.ts # Thunder redirect sign-in tests
│ │ ├── sign-in.spec.ts # IS redirect sign-in tests
│ │ ├── sign-out.spec.ts # IS sign-out tests
│ │ └── user-profile.spec.ts
│ └── embedded/
│ └── sign-in.spec.ts # Thunder embedded sign-in tests
├── thunder-bootstrap/
│ └── 02-sample-resources.sh # Thunder bootstrap: registers sample app
└── thunder-config/
└── deployment.yaml # Thunder server configuration
│ └── sign-in.spec.ts # IS embedded sign-in tests
```

## Test Coverage

| Test | IS | Thunder |
| ----------------------------------------- | --- | ------- |
| Redirect to IDP login page | Yes | Yes |
| Sign in with valid credentials (redirect) | Yes | Yes |
| Redirect unauthenticated users to IDP | Yes | Yes |
| Sign out and redirect to landing page | Yes | — |
| Block protected routes after sign out | Yes | — |
| Render embedded `<SignIn />` component | Yes | Yes |
| Sign in via embedded component | Yes | Yes |
| Display user profile | Yes | Yes |
| Navigate back from profile | Yes | Yes |

> Thunder does not support OIDC logout, so sign-out tests are IS-only.
| Test | IS |
| ----------------------------------------- | --- |
| Redirect to IDP login page | Yes |
| Sign in with valid credentials (redirect) | Yes |
| Redirect unauthenticated users to IDP | Yes |
| Sign out and redirect to landing page | Yes |
| Block protected routes after sign out | Yes |
| Render embedded `<SignIn />` component | Yes |
| Sign in via embedded component | Yes |
| Display user profile | Yes |
| Navigate back from profile | Yes |

## How It Works

Expand Down
58 changes: 0 additions & 58 deletions e2e/docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,64 +19,6 @@ services:
networks:
- e2e-network

# ============================================================================
# Asgardeo Thunder (3-stage setup: db-init -> setup -> server)
# ============================================================================

# Stage 1: Initialize the database from the image
thunder-db-init:
image: ghcr.io/asgardeo/thunder:latest
container_name: asgardeo-e2e-thunder-db-init
command: sh -c "cp -r /opt/thunder/repository/database/* /data/"
volumes:
- thunder-db:/data
restart: "no"
networks:
- e2e-network

# Stage 2: Run setup (creates admin user, default app, flows, etc.)
# Mounts custom 02-sample-resources.sh to register the app with
# redirect_uris pointing to https://localhost:5173 (Vite dev server).
thunder-setup:
image: ghcr.io/asgardeo/thunder:latest
container_name: asgardeo-e2e-thunder-setup
command: ./setup.sh
volumes:
- thunder-db:/opt/thunder/repository/database
- ./thunder-bootstrap/02-sample-resources.sh:/opt/thunder/bootstrap/02-sample-resources.sh:ro
- ./thunder-config/deployment.yaml:/opt/thunder/repository/conf/deployment.yaml:ro
depends_on:
thunder-db-init:
condition: service_completed_successfully
restart: "no"
networks:
- e2e-network

# Stage 3: Run the Thunder server
thunder:
image: ghcr.io/asgardeo/thunder:latest
container_name: asgardeo-e2e-thunder
depends_on:
thunder-setup:
condition: service_completed_successfully
ports:
- "8090:8090"
volumes:
- thunder-db:/opt/thunder/repository/database
- ./thunder-config/deployment.yaml:/opt/thunder/repository/conf/deployment.yaml:ro
healthcheck:
test: ["CMD", "curl", "-k", "-f", "https://localhost:8090/health/readiness"]
interval: 10s
timeout: 5s
retries: 15
start_period: 30s
networks:
- e2e-network

volumes:
thunder-db:
driver: local

networks:
e2e-network:
driver: bridge
Loading
Loading