Repository navigation
ci(e2e): back the stack's calendar and directory with the Microsoft 365 sandbox tenant - #553
Merged
Merged
Conversation
…65 sandbox tenant The tenant row carried placeholder credentials, so every calendar-backed route (the concierge day view, the staff directory, the rooms and attendance reports) died at Microsoft and their specs could only be guarded. With E2E_O365_TENANT, E2E_O365_CLIENT_ID and E2E_O365_CLIENT_SECRET set, the seed writes app-only credentials to the row, updating one left over from a placeholder run, and creates a local admin whose address is a mailbox in the tenant so staff-api can create events on its behalf. Without them nothing changes and the specs that need the tenant skip. CI takes the values from the repository variables and secret of the same names; they belong to the sandbox app "PlaceOS Bookings Visualiser".
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
|
Deployment failed for project frontend-templates with the following error: Learn More: https://vercel.com/placeos?upgradeToPro=build-rate-limit |
# Conflicts: # e2e/stack/SELF_HOSTED_RUNNER.md
- The seed names the tenant row after what it holds, and specs read it with calendarBacked(), so the test step needs no O365 secret. - The O365 vars move from the job env to the bring-up step only. - ensureTenant always writes the row back, so a reused stack goes back to placeholders. - ensureUser upserts users for staff and calendar roles and updates the password and sys_admin of an existing user. - calendar.env.ts loads e2e/.env itself and is the one source for the calendar user. - Fix the directory route in the docs and list the new vars in .env.example. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The e2e stack's calendar and directory can now be backed by the PlaceOS Microsoft 365 sandbox tenant, the one placeos-dev and HIO UAT use. Until now the tenant row carried placeholder credentials, so every calendar-backed concierge route (the day view, the staff directory, the rooms and attendance reports) died at Microsoft and their specs could only be guarded.
e2e/support/calendar/calendar.env.ts:E2E_O365_TENANT,E2E_O365_CLIENT_ID,E2E_O365_CLIENT_SECRETswitch it on;E2E_CALENDAR_USERandE2E_CALENDAR_ROOMname the mailbox identity and the room mailbox, with sandbox defaults.seed.ts: with the variables set the tenant row gets app-only credentials (no delegated access, no service account, so staff-api acts as the signed-in user), a row left over from a placeholder run is updated, and a local sys_admin is created whose address is a mailbox in the tenant (roleFor('calendar')). staff-api only lets a user host an event for themselves, so the identity that books through the calendar has to be a real mailbox; this keeps the ordinary admin and staff users local and unchanged.E2E_O365_TENANT,E2E_O365_CLIENT_IDand the secretE2E_O365_CLIENT_SECRET(set today). The app is "PlaceOS Bookings Visualiser", which already holds Calendars.ReadWrite, User.Read.All, GroupMember.Read.All and Place.Read.All; the secret is an additional one minted for this, named "user-interfaces e2e CI", expiring 2027-10-07.e2e/README.md, the runner's outbound hosts.Without the variables nothing changes: placeholders as before, and the specs that need the tenant skip rather than fail.
What uses it
On #497:
calendar.seed.tscreatesE2E Calendar Roomwith the sandbox room mailboxtestroom4@0cbfs.onmicrosoft.com(shared with placeos-dev's "Sydney Room 4"; the specs book days out and delete what they create), the concierge fixtures gain acalendarApi/calendarPageidentity, and the rows that were blocked by the placeholder run for real: CON-DAY-02/03/04 (a booking another user made appears on the day view, and moves with the day), CON-STAFF-01/02 (the directory lists and searches, and check-in from a row stores a staff booking), CON-REP-02 (the rooms report total matches the API). CON-DAY-05 (book from the day view) is not written yet; CON-DAY-06/07 need the approvals driver.Verified
/api/staff/v1/people?q=Adeleanswers 200; the calendar identity creates an event on the room (201), the admin's building listing returns it against the system, andDELETE /events/:id?system_id=removes it (202). The three concierge specs on that stack (concierge-dayview,concierge-staff,concierge-reports): CON-DAY-02/04, CON-DAY-03, CON-STAFF-01, CON-STAFF-02 and CON-REP-02 all pass, alongside the rows that never needed the tenant. CON-STAFF-02 needed a one second pause before check-out: the app stamps the end with the current second and staff-api refuses an end equal to the start, which a person cannot trigger and Playwright does.Stacked on #550 (same seed); the base moves when that merges.