All 11 issues from 4-player simulation of The Hunt for Fabius Bile: 1. Roll feed visible to all players (no GM auth guard) 2. Scene text gated by revealed flag; GM explicit reveal per scene 3. GM can add NPC/enemy entries to initiative tracker 4. Round counter synced to Dice Roller via localStorage + custom event 5. Check reward text hidden until player has rolled 6. Checks assignable to specific player via Scene Secrets ⚙ options 7. Fear test quick-roll panel with WP input appears when fearRating > 0 8. Decision checks show textarea/Declare instead of d100 roll button 9. Fate point re-roll: one per check per scene, resets on scene advance 10. Player poll reduced from 8s to 4s, combined mission + roll feed poll 11. Mission complete banner with scene stats and GM outcome notes field 4 follow-up findings from second simulation run: - Finding #1: Activate mission now initialises revealed:false on all scenes so players never see scene text before the GM narrates - Finding #2: Fear penalty auto-applied to WP display; button shows effective (penalised) target rather than raw WP input - Finding #3: RollFeedRow moved outside component to avoid re-mount on every render; onDelete passed as prop - Finding #4: Removed duplicate "Open for Players" quick-button from Scene Checks left panel — Scene Secrets is the sole entry point New files: - src/tests/missionPlaythrough.test.js — full GM+4-player simulation test suite covering all 11 issues and 4 findings (39 test cases) - src/tests/missionTab.test.js — player/GM view isolation tests - src/utils/diceRoller.js — shared d100/degrees/clampTarget utilities - tests/missionRoutes.test.js — backend mission route unit tests - tests/playerRoutesLogin.test.js — player login route tests - tests/sessionRoutes.test.js — session validation tests Note: React unit tests require jsdom; segfaults on ARM64 (Raspberry Pi) due to a known jsdom/Node 20 incompatibility on aarch64. Tests pass on x86 CI. Backend integration tests (tests/) run normally. Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
124 lines
3.5 KiB
JavaScript
124 lines
3.5 KiB
JavaScript
const express = require('express');
|
|
const fetch = require('node-fetch');
|
|
const bcrypt = require('bcrypt');
|
|
|
|
jest.mock('../database/mariadb', () => ({
|
|
playerHelpers: {
|
|
getByName: jest.fn(),
|
|
getAll: jest.fn(),
|
|
},
|
|
logToFile: jest.fn(),
|
|
}));
|
|
|
|
jest.mock('../database/sessionModel', () => ({
|
|
createSession: jest.fn(),
|
|
}));
|
|
|
|
const { playerHelpers } = require('../database/mariadb');
|
|
const { createSession } = require('../database/sessionModel');
|
|
const playerRoutes = require('../database/routes/playerRoutes');
|
|
|
|
describe('player login route', () => {
|
|
let server;
|
|
let baseUrl;
|
|
const originalPlayerPassword = process.env.PLAYER_PASSWORD;
|
|
|
|
beforeEach((done) => {
|
|
jest.clearAllMocks();
|
|
delete process.env.PLAYER_PASSWORD;
|
|
createSession.mockResolvedValue(undefined);
|
|
|
|
const app = express();
|
|
app.use(express.json());
|
|
app.use('/api/players', playerRoutes);
|
|
|
|
server = app.listen(0, () => {
|
|
baseUrl = `http://127.0.0.1:${server.address().port}`;
|
|
done();
|
|
});
|
|
});
|
|
|
|
afterEach((done) => {
|
|
if (originalPlayerPassword === undefined) {
|
|
delete process.env.PLAYER_PASSWORD;
|
|
} else {
|
|
process.env.PLAYER_PASSWORD = originalPlayerPassword;
|
|
}
|
|
server.close(done);
|
|
});
|
|
|
|
test('logs in a regular player with their stored plain password', async () => {
|
|
playerHelpers.getByName.mockResolvedValue({
|
|
name: 'anders',
|
|
pw: 'stored-player-password',
|
|
pwHash: '',
|
|
});
|
|
|
|
const res = await fetch(`${baseUrl}/api/players/login`, {
|
|
method: 'POST',
|
|
headers: { 'Content-Type': 'application/json' },
|
|
body: JSON.stringify({ name: 'anders', password: 'stored-player-password' }),
|
|
});
|
|
const body = await res.json();
|
|
|
|
expect(res.status).toBe(200);
|
|
expect(body.success).toBe(true);
|
|
expect(body.player).toEqual({ name: 'anders' });
|
|
expect(body.sessionId).toMatch(/^session_anders_/);
|
|
});
|
|
|
|
test('logs in a regular player with their stored hashed password', async () => {
|
|
const hash = await bcrypt.hash('hashed-player-password', 4);
|
|
playerHelpers.getByName.mockResolvedValue({
|
|
name: 'claes',
|
|
pw: '',
|
|
pwHash: hash,
|
|
});
|
|
|
|
const res = await fetch(`${baseUrl}/api/players/login`, {
|
|
method: 'POST',
|
|
headers: { 'Content-Type': 'application/json' },
|
|
body: JSON.stringify({ name: 'claes', password: 'hashed-player-password' }),
|
|
});
|
|
|
|
expect(res.status).toBe(200);
|
|
await expect(res.json()).resolves.toMatchObject({
|
|
success: true,
|
|
player: { name: 'claes' },
|
|
});
|
|
});
|
|
|
|
test('uses the player UI default when no stored or environment password exists', async () => {
|
|
playerHelpers.getByName.mockResolvedValue({
|
|
name: 'phillip',
|
|
pw: '',
|
|
pwHash: '',
|
|
});
|
|
|
|
const res = await fetch(`${baseUrl}/api/players/login`, {
|
|
method: 'POST',
|
|
headers: { 'Content-Type': 'application/json' },
|
|
body: JSON.stringify({ name: 'phillip', password: '1234' }),
|
|
});
|
|
|
|
expect(res.status).toBe(200);
|
|
});
|
|
|
|
test('rejects an incorrect regular player password', async () => {
|
|
playerHelpers.getByName.mockResolvedValue({
|
|
name: 'christoffer',
|
|
pw: 'stored-player-password',
|
|
pwHash: '',
|
|
});
|
|
|
|
const res = await fetch(`${baseUrl}/api/players/login`, {
|
|
method: 'POST',
|
|
headers: { 'Content-Type': 'application/json' },
|
|
body: JSON.stringify({ name: 'christoffer', password: 'wrong-password' }),
|
|
});
|
|
|
|
expect(res.status).toBe(401);
|
|
await expect(res.json()).resolves.toEqual({ error: 'Invalid username or password' });
|
|
});
|
|
});
|