Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 10 additions & 9 deletions web/src/routes/UsersPage.test.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -526,7 +526,7 @@ describe("UsersPage dismissed step-up continuations (#360)", () => {
target: { value: "dismissed@farm.test" },
});
fireEvent.change(within(dialog()).getAllByLabelText(/Password/)[0], {
target: { value: `pw-${crypto.randomUUID()}` },
target: { value: crypto.randomUUID() },
});
fireEvent.change(within(dialog()).getByLabelText(/Your current password/), {
target: { value: OWNER_STEP_UP_PASSWORD },
Expand All @@ -537,11 +537,12 @@ describe("UsersPage dismissed step-up continuations (#360)", () => {

fireEvent.click(within(dialog()).getByRole("button", { name: "Cancel" }));
openCreate();
const reopenedPassword = crypto.randomUUID();
fireEvent.change(within(dialog()).getByLabelText("Email *"), {
target: { value: "current@farm.test" },
});
fireEvent.change(within(dialog()).getAllByLabelText(/Password/)[0], {
target: { value: "current form value" },
target: { value: reopenedPassword },
});

await act(async () => {
Expand All @@ -550,7 +551,7 @@ describe("UsersPage dismissed step-up continuations (#360)", () => {

expect(mockCreateUser).not.toHaveBeenCalled();
expect(within(dialog()).getByLabelText("Email *")).toHaveValue("current@farm.test");
expect(within(dialog()).getAllByLabelText(/Password/)[0]).toHaveValue("current form value");
expect(within(dialog()).getAllByLabelText(/Password/)[0]).toHaveValue(reopenedPassword);
});

it("does not let a dismissed password-reset continuation write", async () => {
Expand All @@ -561,7 +562,7 @@ describe("UsersPage dismissed step-up continuations (#360)", () => {

fireEvent.click(within(screen.getByRole("row", { name: /worker@farm.test/ }))
.getByRole("button", { name: "password" }));
const newPassword = `Aa1!${crypto.randomUUID()}`;
const newPassword = crypto.randomUUID();
fireEvent.change(within(dialog()).getByLabelText(/New password/), {
target: { value: newPassword },
});
Expand All @@ -578,7 +579,7 @@ describe("UsersPage dismissed step-up continuations (#360)", () => {
fireEvent.click(within(dialog()).getByRole("button", { name: "Cancel" }));
fireEvent.click(within(screen.getByRole("row", { name: /worker@farm.test/ }))
.getByRole("button", { name: "password" }));
const reopenedPassword = `Aa1!${crypto.randomUUID()}`;
const reopenedPassword = crypto.randomUUID();
const reopenedProof = crypto.randomUUID();
fireEvent.change(within(dialog()).getByLabelText(/New password/), {
target: { value: reopenedPassword },
Expand Down Expand Up @@ -644,7 +645,7 @@ describe("UsersPage dismissed step-up continuations (#360)", () => {
target: { value: "pending-create@farm.test" },
});
fireEvent.change(within(dialog()).getAllByLabelText(/Password/)[0], {
target: { value: `pw-${crypto.randomUUID()}` },
target: { value: crypto.randomUUID() },
});
fireEvent.change(within(dialog()).getByLabelText("Name"), {
target: { value: "Pending Create" },
Expand All @@ -660,7 +661,7 @@ describe("UsersPage dismissed step-up continuations (#360)", () => {

fireEvent.click(within(dialog()).getByRole("button", { name: "Cancel" }));
openCreate();
const reopenedPassword = `pw-${crypto.randomUUID()}`;
const reopenedPassword = crypto.randomUUID();
const reopenedProof = crypto.randomUUID();
fireEvent.change(within(dialog()).getByLabelText("Email *"), {
target: { value: "reopened-create@farm.test" },
Expand Down Expand Up @@ -698,7 +699,7 @@ describe("UsersPage dismissed step-up continuations (#360)", () => {
.getByRole("button", { name: "password" }),
);
openPassword();
const pendingPassword = `Aa1!${crypto.randomUUID()}`;
const pendingPassword = crypto.randomUUID();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use a policy-compliant pending reset password

When this test models a password-reset write that later succeeds, crypto.randomUUID() contains lowercase hexadecimal characters and hyphens but no uppercase character, while AddIdentityCore retains Identity's default uppercase requirement. A real SetUserPassword call would therefore reject this value rather than enter the deferred-success path, making the race asserted by this guard unreachable in production; generate a runtime-only value that still satisfies every password-policy class.

AGENTS.md reference: AGENTS.md:L137-L142

Useful? React with 👍 / 👎.

fireEvent.change(within(dialog()).getByLabelText(/New password/), {
target: { value: pendingPassword },
});
Expand All @@ -715,7 +716,7 @@ describe("UsersPage dismissed step-up continuations (#360)", () => {

fireEvent.click(within(dialog()).getByRole("button", { name: "Cancel" }));
openPassword();
const reopenedPassword = `Aa1!${crypto.randomUUID()}`;
const reopenedPassword = crypto.randomUUID();
const reopenedProof = crypto.randomUUID();
fireEvent.change(within(dialog()).getByLabelText(/New password/), {
target: { value: reopenedPassword },
Expand Down
Loading