Assignment 6: CI and Testing
CI & Testing Foundations
Submitted files
- GitHub Actions
- Backend (FastAPI)
- app/services/api/pyproject.toml
- Tests & fixtures: app/services/api/tests/
(e.g.,conftest.py,test_auth_*.py,test_health_*.py)
- Frontend (Next.js)
- Component test: app/web/src/test/components/ProtectedRoute.test.tsx
- Test setup: app/web/src/test/setup.ts
- Playwright config & e2e specs: app/web/e2e/ and app/web/playwright.config.ts
Progress:
This release establishes our end-to-end testing and continuous integration for both the API (FastAPI) and Web App (Next.js). We added unit/integration tests for the API’s auth and health endpoints using pytest and FastAPI’s TestClient, with Supabase calls safely mocked to avoid network/secret coupling. On the frontend, we added Vitest + React Testing Library coverage for ProtectedRoute, including loading state, redirect on unauthenticated access, and rendering on authenticated sessions, alongside a JSDOM test setup to mock browser APIs required by Mantine (matchMedia, ResizeObserver). We also added Playwright e2e smoke tests and an artifact upload step for the HTML report. Two GitHub Actions workflows now run on push/PR to master: API CI (ruff lint, pytest, import/startup smoke) and Web App CI (lint, typecheck, unit tests, e2e). CI injects required Supabase env vars via repository secrets. Collectively, this gives us a reproducible, automated signal for regressions, validates our auth flows at multiple layers, and unblocks future work like coverage gating and preview deployments.
Roadmap update
- Scope delivered in this assignment: green CI for API & Web; backend auth/health tests;
ProtectedRouteunit tests; Playwright e2e smoke; cached, deterministic Node/Python installs (pnpm store cache;uv syncfor Python); artifact upload for e2e reports. - What this enables next: coverage thresholds and PR gating; adding API contract tests; expanding e2e to real CUJs; per-PR ephemeral previews.
Issue summaries (opened/closed since last release)
- [Closed] CI/CD Pipeline (Lint, Test, Typecheck) — Set up GitHub Actions to run linting, type-checking, and test suites on pull requests.
- [Closed] Authentication & Session Management — Implement secure user authentication and session management using NextAuth (email/password or OAuth). Required for all CUJs.
Architecture / UI-UX / Research (3+ components)
Architecture
- Split workflows: api-ci and web-ci to parallelize and isolate failures.
- Python uses
uvfor fast lockfile-driven installs; Node uses pnpm with cached store keyed bypnpm-lock.yaml. - Secrets are injected only where needed (
SUPABASE_URL/KEY/JWT_SECRETfor API;NEXT_PUBLIC_*for Web), reducing blast radius.
Research & Decisions
- Testing libraries:
- API:
pytest+TestClientfor speed and fixture ergonomics. - Web: Vitest + RTL to test behavior over implementation details.
- E2E: Playwright chosen for reliability and auto-installable browsers in CI.
- API:
- Key challenges & resolutions:
- Supabase client initialization during tests → patched before import to avoid side effects.
- Mantine requires browser APIs not present in JSDOM → mocked
matchMediaandResizeObserverin test setup.
Decisions log
- Standardized on Node 20 and Python 3.11 in CI for consistency with local dev.
- Added a lightweight API import/startup smoke step to catch import/config errors early (faster failure than full test run).
- Uploaded Playwright HTML report as an artifact to simplify debugging flaky e2e runs.
Milestone update
- ✅ CI green on push/PR to
masterfor API & Web - ✅ Unit/Integration tests for auth & health (API) and
ProtectedRoute(Web) - ✅ E2E smoke running and report uploaded
- ⏳ Add coverage gates & PR status checks
- ⏳ Expand e2e to cover core CUJs (auth + protected flows)
JTBD (testing angle)
- When pushing code, we want fast, reliable CI signals so we can merge confidently without breaking auth flows or protected routes.
- When changing auth or routing, we want unit tests + e2e smoke that fail loudly if redirects, loading, or rendering regress.
How to run tests locally
API
cd app/services/api
uv sync --extra dev
uv run pytest -vWeb
cd app/web
pnpm install --frozen-lockfile
pnpm test:run # unit tests
pnpm test:coverage # coverage
pnpm build && pnpm test:e2e # e2e (Playwright)Ensure local env vars mirror CI:
API →SUPABASE_URL,SUPABASE_KEY,SUPABASE_JWT_SECRET
Web →NEXT_PUBLIC_SUPABASE_URL,NEXT_PUBLIC_SUPABASE_ANON_KEY