Closes three items from the outstanding e2e/CI gap list:
- Timing budgets: timings.measure() only ever recorded durations for the
(still-unwired) Pushgateway export — nothing failed CI when a step got
slow. Add e2e/timing-budgets.ts (expectWithinBudget + shared BUDGET_MS
buckets) and wire it into every measure() call site across the suite.
Mail-wait steps are deliberately left unbudgeted (external mail-trap
delivery latency, not a code performance signal).
- actions/upload-artifact@v4 doesn't work against this Gitea/act runner's
artifact backend — pin to v3 for the e2e failure-report upload.
- Shared act_runner npm cache has corrupted platform-native tarballs before
(@next/swc-linux-x64-musl) and reds viewer-unit/admin-unit/e2e with no
product bug involved. All three npm ci steps now retry once after
`npm cache clean --force` on first failure.
Verified: full local suite green against DEV (37 passed, 6 skipped, no
budget assertion failures) before wiring into CI.
- Wire E2E_API_USERNAME/PASSWORD (admin) + E2E_API_VIEWER_USERNAME/PASSWORD
(viewer) into the Gitea Actions e2e job so FastAPI-authed specs run in CI.
- Add api.role-permissions.spec.ts: viewer 403 vs admin 200/200/200 on
/api/v1/users, /api/v1/role-permissions, and /api/v1/photos/bulk-delete
(safe no-op via a non-existent photo id — proves the gate, not deletion).
- Add gallery.search-filters.spec.ts: tag_id and person_id filters on the
public /api/search route return correct subsets, combined filters narrow
results, and the /search UI tag-filter interaction updates the URL/count.
- Update ROADMAP/README/.env.example for the new env vars and coverage.