ab63da8324
* test: add real-Postgres smoke gate (pg-real) Mocked Supabase tests cannot exercise triggers, RPCs, or RLS policies — a migration that drops enforce_period_lock, mangles user_company_ids(), or weakens an RLS policy ships green today. Closes that gap with a small Vitest project `pg-real` running 5 smoke tests against a real supabase/postgres:15 container in CI. Covers: closed-period INSERT rejection, commit_journal_entry voucher atomicity under concurrency, posted-entry immutability, RLS tenant isolation on journal_entries, and audit_log UPDATE/DELETE rejection. Also lands the bankid anonymization migration that was sitting untracked from a prior task. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * test(pg-real): fix storage schema bootstrap + de-scope + PR review fixes - Drop bankid anonymization migration from this PR. That change is separate scope (and has open compliance questions flagged by the Swedish review bot on #357); it will land in its own PR. - Add tests/pg/bootstrap.sql to align storage.buckets/objects/foldername with what migrations expect before the replay loop. The supabase/postgres image ships only a partial storage schema; the rest comes from the storage-api service at runtime, which CI does not run. First pg-real run failed at migration 24 on "column public of relation buckets does not exist". - Add concurrency group to the workflow so stacked PR commits cancel in-progress runs instead of queueing. - Gate the pg-real vitest project on DATABASE_URL so a bare `vitest run` with no DB configured runs only the unit project. npm run test:pg is the opt-in entry point. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * test(pg-real): widen JWT claim setup so auth.uid() resolves under RLS The rls.pg test came back with 0 rows instead of 1 — user_company_ids() returned empty because auth.uid() didn't resolve to the seeded user. Two fixes: - Set both request.jwt.claims (whole object) and request.jwt.claim.sub (individual claim). Different Supabase auth.uid() versions read one or the other. - Assert auth.uid() = expected userId immediately after the context switch, so the next failure points at the right layer instead of an unrelated empty-result assertion. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
47 lines
1.1 KiB
TypeScript
47 lines
1.1 KiB
TypeScript
import { defineConfig } from 'vitest/config'
|
|
import path from 'path'
|
|
|
|
const alias = { '@': path.resolve(__dirname, '.') }
|
|
|
|
const unitProject = {
|
|
resolve: { alias },
|
|
test: {
|
|
name: 'unit',
|
|
globals: true,
|
|
environment: 'node' as const,
|
|
include: ['**/*.test.ts'],
|
|
exclude: ['**/node_modules/**', '**/*.pg.test.ts'],
|
|
},
|
|
}
|
|
|
|
const pgRealProject = {
|
|
resolve: { alias },
|
|
test: {
|
|
name: 'pg-real',
|
|
globals: true,
|
|
environment: 'node' as const,
|
|
include: ['**/*.pg.test.ts'],
|
|
exclude: ['**/node_modules/**'],
|
|
setupFiles: ['tests/pg/setup.ts'],
|
|
// One-connection-at-a-time to avoid cross-file DB contention.
|
|
fileParallelism: false,
|
|
testTimeout: 15000,
|
|
},
|
|
}
|
|
|
|
// Only register the pg-real project when DATABASE_URL is set. Local devs
|
|
// running a bare `vitest run` would otherwise hit the schema sanity check
|
|
// against a non-existent DB. `npm run test:pg` is the opt-in entry point.
|
|
const projects = process.env.DATABASE_URL
|
|
? [unitProject, pgRealProject]
|
|
: [unitProject]
|
|
|
|
export default defineConfig({
|
|
resolve: { alias },
|
|
test: {
|
|
globals: true,
|
|
environment: 'node',
|
|
projects,
|
|
},
|
|
})
|