feat(web-next): minimal authenticated shell home

Shell home for the platform-retrofit floor: a sign-in form (dev-seed
credentials) and a signed-in placeholder with sign-out. Both flows run
through the composed tRPC appRouter via server actions that own the
session cookie on the app side; the auth feature is untouched. Adds the
auth sign-in Playwright spec as the surviving e2e baseline and drops the
last demo-template metadata.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
This commit is contained in:
2026-07-12 20:20:37 +02:00
parent e1aa934153
commit f7b869bf67
6 changed files with 344 additions and 6 deletions

View File

@@ -0,0 +1,34 @@
import { test, expect } from "@playwright/test";
// Surviving e2e baseline (platform-retrofit PRD): the dev-seed shell must
// sign in with seeded credentials (see packages/auth/src/__seeds__/dev.ts)
// and sign back out. Runs against `pnpm dev` in dev-seed mode — no Payload.
test.describe("auth sign-in", () => {
test("signs in with dev-seed credentials and reaches the signed-in shell", async ({
page,
}) => {
await page.goto("/");
await page.getByLabel("Username").fill("alice");
await page.getByLabel("Password").fill("secret_alice");
await page.getByRole("button", { name: "Sign in" }).click();
await expect(page.getByText("You are signed in.")).toBeVisible();
await page.getByRole("button", { name: "Sign out" }).click();
await expect(page.getByRole("button", { name: "Sign in" })).toBeVisible();
});
test("rejects invalid credentials and keeps the sign-in form", async ({
page,
}) => {
await page.goto("/");
await page.getByLabel("Username").fill("alice");
await page.getByLabel("Password").fill("not-the-password");
await page.getByRole("button", { name: "Sign in" }).click();
await expect(page.getByText("Invalid username or password.")).toBeVisible();
await expect(page.getByRole("button", { name: "Sign in" })).toBeVisible();
});
});