You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Playwright fixture never brought the host up: nothing supplied the issuemanagerdb connection string, so api-service failed to start, WebApp failed with it, and the fixture waited out its 3-minute timeout. Each of the 35 browser tests then skipped and the job passed.
PlaywrightFixture.InitializeAsync
+ start MongoDB test container- CreateAsync<AppHost>()+ CreateAsync<AppHost>(ConnectionStrings:issuemanagerdb = container, RandomizePorts = false)
StartAsync
- wait for WebApp Running (3 min), catch everything -> IsAvailable = false -> tests skip+ wait for WebApp healthy (throws as soon as a resource fails to start)+ no catch -> a host that can't start fails every test in the collection
Getting the host up surfaced bugs that the skips had hidden:
/admin declared twice (Pages/Admin.razor placeholder and Features/Admin/AdminPage.razor). The router threw on every interactive render and killed the circuit. The placeholder is deleted.
The Web called https+http://api, but the AppHost names the resource api-service, so every API call failed DNS. It now uses Constants.ApiService.
/auth/login was async void, so the response could end before the Auth0 challenge redirected. It now returns Task.
Random ports broke Auth0 login, because the callback URL wasn't on the allowed list. The fixture keeps the launchSettings ports (https://localhost:7176), and that callback is now allowed in Auth0.
Test credentials now come from configuration, Auth0:{Admin,Author,User}:{Username,Password}: user secrets locally, Auth0__{Role}__Username/Password in CI. The Api, Web and E2E projects share the 94491f6e-auth0-values-3ff40da38702 user-secrets store.
The 11 tests that now run and fail are skipped with Skip = "Fails: #246". #246 tracks their fixes.
Evidence
Before:AppHost.Tests.E2E: total 53, passed 18, skipped 35 (Fixture initialization failed: The operation has timed out.), 3m+ After: total 53, passed 42, skipped 11 (each Fails: #246), failed 0, ~2m. The pre-push gate passed.
With the old missing-connection-string config, the fixture now fails in ~20s with Stopped waiting for resource 'WebApp' to become healthy because it failed to start rather than skipping.
Revert restores the old fixture. Only the Auth0 callback URL lives outside the repo, and it's additive.
Blast Radius: E2E-and-Web
CI's E2E job needs TEST_ENV (ci: Standardize on the repo-ci-baseline Template #241) to carry Auth0__Domain, Auth0__ClientId, Auth0__ClientSecret, Auth0__Audience and the six Auth0__{Role}__Username/Password values. Without them, the host fails to start and the job now fails rather than skipping.
The E2E job needs Docker for the MongoDB container, which it already needs for Redis.
The Web changes (API base address, login endpoint, removed placeholder page) affect the running app. The API calls and login were broken before, so this should only fix them.
…t can't start
The Playwright fixture never brought the host up: the AppHost needs the
issuemanagerdb connection string (the Atlas URI), nothing supplied it, so
api-service failed to start, WebApp failed with it, and the fixture waited
out its 3-minute timeout. Each of the 35 tests then skipped, and the job passed.
The fixture now starts a MongoDB test container and hands its URI to the
AppHost, waits for WebApp's health check (which throws as soon as a resource
fails to start), and no longer catches its own failure, so a host that can't
start fails every test in the collection instead of skipping them.
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Pages/Admin.razor and Features/Admin/AdminPage.razor both declared /admin, so
the router threw on every interactive render and the circuit died.
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…enge
The API clients used https+http://api, but the AppHost names the resource
api-service, so every call failed DNS resolution. /auth/login was async void,
so the response ended before the Auth0 challenge could redirect.
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The helper read E2E_TEST_{ROLE}_EMAIL/PASSWORD environment variables. It now
reads configuration: the test project's user secrets locally, and environment
variables (Auth0__{Role}__Username/Password) in CI.
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The test project already uses 94491f6e-auth0-values-3ff40da38702; the Api and
Web read their Auth0 settings from the same store when run locally.
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
They never ran before #243 (the fixture timed out), and fail on stale selectors,
the login redirect path and the admin pages. Each skip names #246, which
tracks the fixes, so they show by name in every run rather than hiding.
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A crafted /auth/login?returnUrl= could send a user off-site after signing in.
Anything that isn't a local URL now falls back to /.
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/gate.sh writes TRX files there; left untracked, the next pre-push gate
refuses to run because the working tree isn't clean.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The five-minute startup timeout is created only after MongoDB has started, so a stalled image pull or container startup can still hang this fixture well beyond the intended bound. Pass a timeout token to StartAsync as well so every external startup step is bounded.
Moves the local-URL check into AuthExtensions.GetLocalReturnUrl and tests that
local paths pass through while absolute, protocol-relative, backslash, script
and empty values fall back to /.
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Documents the one store the Api, Web and E2E projects now share, how to move
values from the old per-project stores, the E2E test users and callback URL,
and the TEST_ENV lines CI needs. Drops a Client ID and secret that were
committed in plain text (the app no longer exists in the tenant).
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
On the runner the dev certificate is untrusted, so the AppHost's HTTPS health
check on the web app failed every attempt and the fixture timed out after five
minutes. prepare.sh now trusts it for AppHost.Tests.E2E and points
SSL_CERT_DIR at the exported certificate.
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
dotnet dev-certs https --trust exits 4 when OpenSSL trusts the certificate but
no browser store exists, which stopped prepare.sh under set -e. OpenSSL trust
is what the AppHost and web app need.
Refs #243
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The new startup path makes Auth0 mandatory, but NuGet Dependabot PRs still run this matrix without TEST_ENV (.github/workflows/ci.yml:366-375; only GitHub Actions bumps skip tests at lines 627-632). The API will therefore throw for missing Domain/Audience and every future NuGet update will fail here. Add a safe no-secret test-auth path for Dependabot, or explicitly omit this E2E project for those runs while retaining strict startup failure in normal CI.
Missing E2E role credentials silently skip CI tests
These optional lookups still return null, and every role test converts that result into SkipException. An incomplete TEST_ENV (for example, a missing admin password) therefore leaves the host healthy and the affected scenarios silently green, contrary to the stated requirement that missing E2E configuration fail CI. Fail on missing role credentials in CI while preserving optional local skips.
Update setup instructions to use the actual HTTPS launch-profile port
docs/build docs/auth0-setup.md:111
These new instructions conflict with step 5 above, which still tells users to configure only https://localhost:7001, while the current Web launch profile and E2E host use port 7176. Consolidate the callback, logout, and origin entries in the primary setup step around the actual launch-profile URL so following the guide does not leave local login misconfigured.
This new test omits the repository-required // Arrange marker. Add the marker even though the theory input is supplied by InlineData, so every test retains the mandated Arrange/Act/Assert structure.
This issue also appears on line 87 of the same file.
Matches the repo-ci-baseline Template (dotfiles #47); the shared settings are
in aspire.config.json.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Automated release blog posts for #247, opened by the release workflow.
It holds every Release whose post isn't on main yet, rebuilt from main
on each run. The [skip-release] title marker keeps its merge from
starting another release.
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #243
Summary
The Playwright fixture never brought the host up: nothing supplied the
issuemanagerdbconnection string, soapi-servicefailed to start,WebAppfailed with it, and the fixture waited out its 3-minute timeout. Each of the 35 browser tests then skipped and the job passed.Getting the host up surfaced bugs that the skips had hidden:
/admindeclared twice (Pages/Admin.razorplaceholder andFeatures/Admin/AdminPage.razor). The router threw on every interactive render and killed the circuit. The placeholder is deleted.https+http://api, but the AppHost names the resourceapi-service, so every API call failed DNS. It now usesConstants.ApiService./auth/loginwasasync void, so the response could end before the Auth0 challenge redirected. It now returnsTask.https://localhost:7176), and that callback is now allowed in Auth0.Test credentials now come from configuration,
Auth0:{Admin,Author,User}:{Username,Password}: user secrets locally,Auth0__{Role}__Username/Passwordin CI. The Api, Web and E2E projects share the94491f6e-auth0-values-3ff40da38702user-secrets store.The 11 tests that now run and fail are skipped with
Skip = "Fails: #246". #246 tracks their fixes.Evidence
AppHost.Tests.E2E: total 53, passed 18, skipped 35 (Fixture initialization failed: The operation has timed out.), 3m+After: total 53, passed 42, skipped 11 (each
Fails: #246), failed 0, ~2m. The pre-push gate passed.Stopped waiting for resource 'WebApp' to become healthy because it failed to startrather than skipping.Merge Danger
Door: two-way
Revert restores the old fixture. Only the Auth0 callback URL lives outside the repo, and it's additive.
Blast Radius: E2E-and-Web
TEST_ENV(ci: Standardize on the repo-ci-baseline Template #241) to carryAuth0__Domain,Auth0__ClientId,Auth0__ClientSecret,Auth0__Audienceand the sixAuth0__{Role}__Username/Passwordvalues. Without them, the host fails to start and the job now fails rather than skipping.🤖 Generated with Claude Code