From 828fe4829e5327e0de353f2aa590a52cc4440611 Mon Sep 17 00:00:00 2001 From: Bretton <36870434+BrettM86@users.noreply.github.com> Date: Sun, 19 Jul 2026 21:18:23 -0700 Subject: [PATCH] test(maestro): cover the OAuth cancel redirect (a4) and update a3 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit a3's cancel branch asserted the old backend dead-end ("OAuth callback failed" page + manual Close tab); the backend now redirects the error back into the app, so assert the quiet "Sign in cancelled." snackbar on the login screen instead. New a4_oauth_cancel denies the authorization on the PDS consent page ("Deny access") and asserts the same graceful return. Runs last in the suite (starts and ends signed out, after a3). Quirk documented in the flow: Chrome's "Save password?" sheet floats over the consent page but does not cover the buttons — tap through it, never BACK (closes the tab). Co-Authored-By: Claude Fable 5 --- .maestro/a3_wrong_password.yaml | 11 +++---- .maestro/a4_oauth_cancel.yaml | 57 +++++++++++++++++++++++++++++++++ .maestro/config.yaml | 1 + 3 files changed, 63 insertions(+), 6 deletions(-) create mode 100644 .maestro/a4_oauth_cancel.yaml diff --git a/.maestro/a3_wrong_password.yaml b/.maestro/a3_wrong_password.yaml index 23912c1..16757d7 100644 --- a/.maestro/a3_wrong_password.yaml +++ b/.maestro/a3_wrong_password.yaml @@ -31,15 +31,14 @@ appId: social.coves.dev visible: "Wrong identifier or password" timeout: 30000 - assertVisible: "Password" -# Cancel: the backend currently renders a raw "OAuth callback failed" page in -# the tab instead of redirecting back to the app (known backend issue), so -# close the tab manually and confirm the app survived without a crash. +# Cancel: the backend redirects back to the app with error=access_denied +# (Coves cc98f26); the app closes the tab and shows a quiet "Sign in +# cancelled." snackbar on the login screen. - tapOn: "Cancel" - extendedWaitUntil: - visible: "OAuth callback failed.*" + visible: "Sign in cancelled.*" timeout: 30000 -- tapOn: "Close tab" - extendedWaitUntil: visible: "Welcome back" - timeout: 30000 + timeout: 15000 - takeScreenshot: build/maestro/a_wrong_password diff --git a/.maestro/a4_oauth_cancel.yaml b/.maestro/a4_oauth_cancel.yaml new file mode 100644 index 0000000..5f0360c --- /dev/null +++ b/.maestro/a4_oauth_cancel.yaml @@ -0,0 +1,57 @@ +# Section A — OAuth cancel handling: denying the authorization request on +# the PDS consent page redirects back into the app with error=access_denied +# (Coves backend cc98f26). The app must treat it as a user cancel — no +# crash, no stuck "signing in" state, a quiet "Sign in cancelled." snackbar +# on the login screen (regression for the SignInCancelledException path in +# coves_auth_service.dart). The sign-in-page Cancel variant of the same +# redirect is covered by a3_wrong_password. +# PRECONDITION: app signed out (run after a2_signout_landing / a3). +# Leaves the app signed out on the login screen. +# QUIRK: Chrome's "Save password?" sheet may float over the consent page; +# it does not cover the Deny/Authorize buttons — tap through it. Do NOT +# press BACK to dismiss it: BACK closes the whole custom tab. +appId: social.coves.dev +--- +- launchApp +- extendedWaitUntil: + visible: "Sign in|Welcome back" + timeout: 30000 +# launchApp normally resets to the landing screen; tolerate starting on the +# login screen too. +- runFlow: + when: + notVisible: "Welcome back" + commands: + - tapOn: "Sign in" + - extendedWaitUntil: + visible: "Welcome back" + timeout: 15000 +- tapOn: "alice.bsky.social" +- inputText: "mari.local.coves.dev" +- hideKeyboard +- tapOn: "Sign in" +# Chrome custom tab: PDS OAuth password page (localhost:3001) +- extendedWaitUntil: + visible: "Password" + timeout: 30000 +- tapOn: "Password" +- inputText: "password" +- hideKeyboard +# The web page has a "Sign in" heading and a "Sign in" button; the button is +# the last match in the tree. +- tapOn: + text: "Sign in" + index: 1 +# Consent page: deny instead of authorize +- extendedWaitUntil: + visible: "Authorize" + timeout: 30000 +- tapOn: "Deny access" +# Back in the app: quiet cancel message, login screen intact, no crash +- extendedWaitUntil: + visible: "Sign in cancelled.*" + timeout: 30000 +- extendedWaitUntil: + visible: "Welcome back" + timeout: 15000 +- takeScreenshot: build/maestro/a_oauth_cancel_deny diff --git a/.maestro/config.yaml b/.maestro/config.yaml index a09cad5..2cbf7a0 100644 --- a/.maestro/config.yaml +++ b/.maestro/config.yaml @@ -46,3 +46,4 @@ executionOrder: - a2_signout_landing - d4_discovery_guest - a3_wrong_password + - a4_oauth_cancel -- 2.51.2