Files
penguin-harness/packages/web/e2e/auth.mjs
T
Yaowei Zheng d4faee3a1e Changelog, dev startup, README, AgentHub 0.4.0, model catalog, and landing site (#7)
Branch-length batch covering tooling, the model layer, the Web App and the public
surfaces. Highlights:

- Changelog: a per-release `changelog/<version>/` tree, grouped by the surface each
  change touches, with a root CHANGELOG.md holding one line per release.
- Dev startup: `scripts/dev-prebuild.mjs` serializes the skills+core prebuild behind a
  lock and keeps `pnpm install` current; `pnpm dev` runs server+web together.
- AgentHub 0.3.3 -> 0.4.0: OmniMessage complete payloads carry one opaque `fidelity`
  object in place of item-level `signature`/`phase`, threaded verbatim through Trace,
  replay and resume; malformed classification adapted to the new error types.
- Model layer: a model is always referenced by an explicit `(provider, model_id)` pair.
  The provider is never inferred, guessed or defaulted -- both the catalog inference and
  the unique-match config resolution are gone, and CLI, SDK, server routes and
  run_subagent all require the complete pair. Catalog gains the Qwen Token Plan, Qwen
  Pay-As-You-Go and Fireworks AI gateways, plus an expanded OpenRouter group.
- Web App: catalog preset sync and per-group speed test on the Models page, positional
  slash commands, a markdown renderer, skill-library update reminders, and a vertically
  centred draft page whose upward menus size themselves to the room available.
- Public surfaces: restructured READMEs, the penguin.ooo landing site and blog, refreshed
  benchmark results for both suites, and the demo videos playing on the landing page.

Includes the fixes from a full review of the branch: 23 confirmed findings, among them a
provider-inference bug that could send one vendor's API key to another vendor's endpoint,
and an Escape handler that destroyed the composer's contents unrecoverably.

Verified on the branch head: pnpm test (1127 passing, 7 packages), pnpm typecheck and
pnpm format:check clean, Playwright e2e 14/14.
2026-07-21 17:43:31 +08:00

39 lines
1.6 KiB
JavaScript

/**
* e2e auth helper: with signup disabled, test users are always provisioned via
* the built-in admin account, then logged in. The server seeds an admin
* (admin / penguin-2026) on startup; a single e2e run shares one data root, and
* provisioning is idempotent (reuses the user if it already exists) so a
* single spec can be rerun on its own.
*/
import { request } from "@playwright/test";
const BASE = process.env.BASE_URL;
export const ADMIN_ID = "admin";
export const ADMIN_PASSWORD = "penguin-2026";
/** Log in: the cookie lands in the given request context (page.request is the browser context); returns user. */
export async function login(ctx, userId, password) {
const res = await ctx.post(`${BASE}/api/auth/login`, { data: { userId, password } });
if (!res.ok()) {
throw new Error(`login ${userId} failed: ${res.status()} ${await res.text()}`);
}
return (await res.json()).user;
}
/** Admin creates the user (409 is treated as already-exists, idempotent). */
export async function provisionUser(userId, password) {
const adminCtx = await request.newContext();
await login(adminCtx, ADMIN_ID, ADMIN_PASSWORD);
const created = await adminCtx.post(`${BASE}/api/admin/users`, { data: { userId, password } });
if (!created.ok() && created.status() !== 409) {
throw new Error(`create user ${userId} failed: ${created.status()} ${await created.text()}`);
}
await adminCtx.dispose();
}
/** Provision the user and log ctx in as them; returns user. */
export async function provisionAndLogin(ctx, userId, password) {
await provisionUser(userId, password);
return login(ctx, userId, password);
}