The e2e suite names its own origins, and refuses a live instance
Playwright Tests / test-playwright (1, 2) (push) Canceled after 0s
Playwright Tests / test-playwright (2, 2) (push) Canceled after 0s
pre-commit / pre-commit (push) Canceled after 0s
Compose Smoke Test / test-compose (push) Canceled after 0s
Playwright Tests / merge-reports (push) Canceled after 0s

`tests/utils/api.ts` took the API origin from `VITE_API_URL`, which
`tests/config.ts` loads out of `app/.env`. In a checkout configured for a
deployment that names the deployment — so the browser went to the local stack
while every setup and teardown call, `deleteAll` included, went to the live
one. `privateApi.ts` had the same reading, and it creates users.

Both origins now come from one place: `PLAYWRIGHT_BASE_URL`, with the API
derived from it (`app.<domain>` → `api.<domain>`) or named outright by
`PLAYWRIGHT_API_URL`, which is what CI and the compose service set. Nothing in
the suite reads `VITE_API_URL` any more.

Belt and braces, since a stack served under a real domain answers to the same
names its production instance does: a global setup resolves both origins and
refuses anything that is not loopback or a private range, before a test runs.
`PLAYWRIGHT_ALLOW_PUBLIC=1` says you meant it.

`make test-frontend` is now that safe run — the Playwright image on the proxy
network with both names mapped onto Traefik by address, as the host user so it
does not leave root-owned results behind.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NUb8YpL2s3gmN9WTACTt4q
This commit is contained in:
2026-08-20 20:46:04 +02:00
co-authored by Claude Opus 5
parent 032c2e3ae6
commit a2e11b61cf
10 changed files with 142 additions and 12 deletions
+13 -2
View File
@@ -1,5 +1,6 @@
import { defineConfig, devices } from '@playwright/test';
import 'dotenv/config'
import { appUrl } from './tests/config.ts'
/**
* Read environment variables from file.
@@ -21,12 +22,22 @@ export default defineConfig({
workers: process.env.CI ? 1 : undefined,
/* Reporter to use. See https://playwright.dev/docs/test-reporters */
reporter: process.env.CI ? 'blob' : 'html',
/* Nothing runs until the target is known not to be a live instance. */
globalSetup: './tests/guard.ts',
/* Shared settings for all the projects below. See https://playwright.dev/docs/api/class-testoptions. */
use: {
/* Base URL to use in actions like `await page.goto('/')`. Defaults to the
integrated stack (`make dev`), the only origin the API allows CORS from.
Point PLAYWRIGHT_BASE_URL elsewhere to test another running server. */
baseURL: process.env.PLAYWRIGHT_BASE_URL || 'http://app.localhost',
Point PLAYWRIGHT_BASE_URL elsewhere to test another running server; the
API origin follows it (see tests/config.ts). */
baseURL: appUrl,
/* Chromium pins *.localhost to loopback whatever /etc/hosts says, so a
containerised run maps the names here as well as through --add-host. */
launchOptions: process.env.HOST_RESOLVER_RULES
? { args: [`--host-resolver-rules=${process.env.HOST_RESOLVER_RULES}`] }
: {},
/* Collect trace when retrying the failed test. See https://playwright.dev/docs/trace-viewer */
trace: 'on-first-retry',