Repository navigation
test(web): use runtime-only credentials in step-up race tests - #608
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0209d6b816
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| ); | ||
| openPassword(); | ||
| const pendingPassword = `Aa1!${crypto.randomUUID()}`; | ||
| const pendingPassword = crypto.randomUUID(); |
There was a problem hiding this comment.
Use a policy-compliant pending reset password
When this test models a password-reset write that later succeeds, crypto.randomUUID() contains lowercase hexadecimal characters and hyphens but no uppercase character, while AddIdentityCore retains Identity's default uppercase requirement. A real SetUserPassword call would therefore reject this value rather than enter the deferred-success path, making the race asserted by this guard unreachable in production; generate a runtime-only value that still satisfies every password-policy class.
AGENTS.md reference: AGENTS.md:L137-L142
Useful? React with 👍 / 👎.
Summary
Verification
npm test -- --run src/routes/UsersPage.test.tsx -t "dismissed step-up continuations"— 6 passednpm run typecheckFollow-up to #607 and #360.