Skip to content

Commit 007932a

Browse files
Tsvetan StoychevTsvetan Stoychev
authored andcommitted
Add browser tests for JavaScript loaders
1 parent b7632cf commit 007932a

17 files changed

Lines changed: 540 additions & 19 deletions

‎.github/dependabot.yml‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,15 @@
11
version: 2
22

33
updates:
4+
- package-ecosystem: npm
5+
directory: /
6+
schedule:
7+
interval: weekly
8+
day: monday
9+
time: "04:30"
10+
timezone: Europe/Berlin
11+
open-pull-requests-limit: 5
12+
413
- package-ecosystem: composer
514
directory: /plugins/basicrum
615
schedule:

‎.github/workflows/ci.yml‎

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -64,6 +64,31 @@ jobs:
6464
- name: Check for stale translation artifacts
6565
run: git diff --exit-code -- plugins/basicrum/languages
6666

67+
javascript:
68+
name: JavaScript loader behavior
69+
runs-on: ubuntu-latest
70+
timeout-minutes: 15
71+
72+
steps:
73+
- name: Checkout
74+
uses: actions/checkout@v7
75+
76+
- name: Setup Node.js
77+
uses: actions/setup-node@v6
78+
with:
79+
node-version-file: .nvmrc
80+
cache: npm
81+
cache-dependency-path: package-lock.json
82+
83+
- name: Install JavaScript dependencies
84+
run: npm ci
85+
86+
- name: Install Chromium
87+
run: npx playwright install --with-deps chromium
88+
89+
- name: Test JavaScript loaders
90+
run: npm run test:js
91+
6792
unit:
6893
name: Unit (PHP ${{ matrix.php }})
6994
runs-on: ubuntu-latest
@@ -164,6 +189,7 @@ jobs:
164189
needs:
165190
- quality
166191
- translations
192+
- javascript
167193
- unit
168194
- integration
169195

‎.gitignore‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,9 @@
1212

1313
# Node
1414
/node_modules/
15+
/playwright-report/
16+
/test-results/
17+
/blob-report/
1518

1619
# PHPUnit
1720
.phpunit.result.cache

‎.nvmrc‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
24

‎AGENTS.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,7 @@ make analyse
4040
make composer-validate
4141
make composer-audit
4242
make unit
43+
make js-test
4344
make integration-setup
4445
make integration
4546
make translations

‎Makefile‎

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@ PHP_SERVICE = php
33
WP_SERVICE = wordpress
44
DB_SERVICE = db
55
WPCLI_SERVICE = wpcli
6+
JS_SERVICE = javascript
67
WPCLI_PLUGIN_WORKDIR = /var/www/html/wp-content/plugins/basicrum
78
PLUGIN_DIR = plugins/basicrum
89
PLUGIN_WORKDIR = /workspace
@@ -12,7 +13,7 @@ TEST_DB_PASS = root
1213
TEST_DB_HOST = db
1314
WP_TEST_VERSION ?= latest
1415

15-
.PHONY: help build up down restart logs shell composer-install wp-install lint lint-fix lint-php analyse composer-validate composer-audit translations integration-setup integration test package package-verify package-smoke clean
16+
.PHONY: help build up down restart logs shell composer-install wp-install lint lint-fix lint-php analyse composer-validate composer-audit translations js-install js-test integration-setup integration test package package-verify package-smoke clean
1617

1718
help:
1819
@echo "Targets:"
@@ -31,6 +32,8 @@ help:
3132
@echo " composer-validate Validate Composer metadata and lock file"
3233
@echo " composer-audit Audit locked Composer dependencies"
3334
@echo " translations Update POT, PO, and MO translation catalogs"
35+
@echo " js-install Install locked JavaScript test dependencies"
36+
@echo " js-test Run loader behavior tests in Chromium"
3437
@echo " unit Run unit tests"
3538
@echo " integration-setup Install WordPress test suite inside containers"
3639
@echo " integration Run integration tests"
@@ -85,6 +88,12 @@ composer-audit:
8588
translations:
8689
$(COMPOSE) run --rm --no-deps --user "$$(id -u):$$(id -g)" -e HOME=/tmp -w $(WPCLI_PLUGIN_WORKDIR) $(WPCLI_SERVICE) sh /tools/update-translations.sh .
8790

91+
js-install:
92+
$(COMPOSE) run --rm --no-deps --user "$$(id -u):$$(id -g)" -e HOME=/tmp $(JS_SERVICE) npm ci --no-audit --no-fund
93+
94+
js-test: js-install
95+
$(COMPOSE) run --rm --no-deps --user "$$(id -u):$$(id -g)" -e HOME=/tmp $(JS_SERVICE) npm run test:js
96+
8897
unit:
8998
$(COMPOSE) run --rm -w $(PLUGIN_WORKDIR) $(PHP_SERVICE) composer unit
9099

@@ -95,7 +104,7 @@ integration-setup:
95104
integration:
96105
$(COMPOSE) run --rm -w $(PLUGIN_WORKDIR) $(PHP_SERVICE) composer integration
97106

98-
test: unit integration
107+
test: unit integration js-test
99108

100109
package:
101110
$(COMPOSE) run --rm --no-deps -w /repo $(PHP_SERVICE) sh /tools/build-release.sh /repo/$(PLUGIN_DIR) /repo/release

‎README.md‎

Lines changed: 16 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@ make analyse
2626
make composer-validate
2727
make composer-audit
2828
make translations
29+
make js-test
2930
make package
3031
make package-smoke
3132
```
@@ -72,13 +73,25 @@ both files to the GitHub release.
7273

7374
## Automated Quality Controls
7475

76+
`make js-test` installs the locked root-level Node dependencies and runs the
77+
standard and consent loader behavior suites in Chromium. The tests execute the
78+
actual minified and unminified files from `plugins/basicrum/assets/js/loaders/`,
79+
intercept the synthetic Boomerang request, and block every unexpected network
80+
request. They cover consent gating, repeated opt-in, opt-out cleanup, and cookie
81+
behavior on HTTP, HTTPS, localhost, and subdomains.
82+
83+
The JavaScript package, Playwright configuration, and browser tests live at the
84+
repository root. The release builder copies only `plugins/basicrum/`, and the
85+
release verifier also rejects Node or Playwright development files if they ever
86+
appear in the plugin ZIP.
87+
7588
`make analyse` runs PHPStan level 5 with WordPress-aware stubs. The enforced
7689
configuration is stored in `plugins/basicrum/phpstan.neon.dist`.
7790

7891
`make composer-validate` checks Composer metadata and lock-file consistency in
7992
strict mode. `make composer-audit` checks the complete lock file against current
8093
security advisories. CI runs all three checks on every push and pull request.
8194

82-
Dependabot checks Composer dependencies and GitHub Actions weekly. CI workflows
83-
use a read-only `GITHUB_TOKEN`; release and pre-release workflows receive only
84-
the `contents: write` permission required to attach release assets.
95+
Dependabot checks npm, Composer dependencies, and GitHub Actions weekly. CI
96+
workflows use a read-only `GITHUB_TOKEN`; release and pre-release workflows
97+
receive only the `contents: write` permission required to attach release assets.

‎checklist.md‎

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -36,22 +36,22 @@ Acceptance criteria:
3636

3737
## 3. Add JavaScript consent and loader tests
3838

39-
- [ ] Add a JavaScript test runner and a documented test command.
40-
- [ ] Test that Boomerang does not load before consent is granted.
41-
- [ ] Test that opt-in loads Boomerang exactly once.
42-
- [ ] Test that repeated opt-in calls do not load duplicate scripts.
43-
- [ ] Test that opt-out disables Boomerang when it is already loaded.
44-
- [ ] Test removal of Boomerang cookies during opt-out.
45-
- [ ] Test consent cookie behavior on HTTP and HTTPS.
46-
- [ ] Test consent cookie behavior for normal hostnames, localhost, and relevant
39+
- [x] Add a JavaScript test runner and a documented test command.
40+
- [x] Test that Boomerang does not load before consent is granted.
41+
- [x] Test that opt-in loads Boomerang exactly once.
42+
- [x] Test that repeated opt-in calls do not load duplicate scripts.
43+
- [x] Test that opt-out disables Boomerang when it is already loaded.
44+
- [x] Test removal of Boomerang cookies during opt-out.
45+
- [x] Test consent cookie behavior on HTTP and HTTPS.
46+
- [x] Test consent cookie behavior for normal hostnames, localhost, and relevant
4747
subdomain cases.
48-
- [ ] Run the same behavioral assertions against minified and unminified loaders.
49-
- [ ] Add JavaScript tests to CI.
48+
- [x] Run the same behavioral assertions against minified and unminified loaders.
49+
- [x] Add JavaScript tests to CI.
5050

5151
Acceptance criteria:
5252

53-
- [ ] Privacy-critical loader behavior is covered independently of PHP tests.
54-
- [ ] Minified and unminified loaders pass the same behavior suite.
53+
- [x] Privacy-critical loader behavior is covered independently of PHP tests.
54+
- [x] Minified and unminified loaders pass the same behavior suite.
5555

5656
## 4. Make installation and release artifacts resilient
5757

@@ -152,7 +152,7 @@ Acceptance criteria:
152152
- [ ] PHPCS passes.
153153
- [ ] PHP unit tests pass across the supported PHP matrix.
154154
- [ ] WordPress integration tests pass across the supported WordPress matrix.
155-
- [ ] JavaScript tests pass.
155+
- [x] JavaScript tests pass.
156156
- [x] Static analysis passes.
157157
- [x] Composer validation and audit pass.
158158
- [ ] Generated asset checks pass.

‎docker-compose.yml‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -77,6 +77,15 @@ services:
7777
- wp_core:/tmp/wordpress
7878
tty: true
7979

80+
javascript:
81+
image: mcr.microsoft.com/playwright:v1.61.1-noble
82+
working_dir: /workspace
83+
environment:
84+
HOME: /tmp
85+
volumes:
86+
- ./:/workspace
87+
ipc: host
88+
8089
volumes:
8190
db_data:
8291
wordpress_data:

‎package-lock.json‎

Lines changed: 79 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)