test: timing budgets + CI hardening (artifact v3 pin, npm cache retry)
CI / skip-ci-check (pull_request) Successful in 5s
CI / docker-ci (pull_request) Successful in 7s
CI / secret-scan (pull_request) Successful in 12s
CI / viewer-unit (pull_request) Successful in 1m29s
CI / e2e (pull_request) Successful in 4m8s
CI / admin-unit (pull_request) Successful in 4m24s

Closes three items from the outstanding e2e/CI gap list:

- Timing budgets: timings.measure() only ever recorded durations for the
  (still-unwired) Pushgateway export — nothing failed CI when a step got
  slow. Add e2e/timing-budgets.ts (expectWithinBudget + shared BUDGET_MS
  buckets) and wire it into every measure() call site across the suite.
  Mail-wait steps are deliberately left unbudgeted (external mail-trap
  delivery latency, not a code performance signal).

- actions/upload-artifact@v4 doesn't work against this Gitea/act runner's
  artifact backend — pin to v3 for the e2e failure-report upload.

- Shared act_runner npm cache has corrupted platform-native tarballs before
  (@next/swc-linux-x64-musl) and reds viewer-unit/admin-unit/e2e with no
  product bug involved. All three npm ci steps now retry once after
  `npm cache clean --force` on first failure.

Verified: full local suite green against DEV (37 passed, 6 skipped, no
budget assertion failures) before wiring into CI.
This commit is contained in:
2026-07-15 08:56:31 -04:00
parent 96351288f0
commit c0c997f796
22 changed files with 155 additions and 6 deletions
+3
View File
@@ -1,5 +1,6 @@
import path from 'node:path';
import { test, expect } from '../fixtures';
import { BUDGET_MS, expectWithinBudget } from '../timing-budgets';
/**
* NextAuth (browser-session) write gates — `session.user.hasWriteAccess`
@@ -32,6 +33,7 @@ test.describe('viewer write gates (NextAuth, viewer) @smoke', () => {
data: { firstName: 'Test', lastName: 'Viewer' },
}),
);
expectWithinBudget(timings, 'viewer_identify', BUDGET_MS.api);
expect(res.status()).toBe(403);
const body = await res.json();
expect(body).toMatchObject({ error: expect.stringMatching(/write access/i) });
@@ -51,6 +53,7 @@ test.describe('viewer write gates (NextAuth, admin) @smoke', () => {
data: { firstName: 'Test', lastName: 'Admin' },
}),
);
expectWithinBudget(timings, 'admin_identify', BUDGET_MS.api);
// Admin clears the write-access gate; a nonexistent face id then 404s —
// proves the gate didn't block a legitimate write-access user.
expect(res.status()).toBe(404);