V8 Central — Product & Technical Spec
  1. Docs
  2. Delivery
  3. Testing strategy

#Testing strategy

#Layers

LayerToolWhereCovers
Backend unit + featurePest (V8 rule: a test for every endpoint), Http::fake for OSS/providers/gatewayssa-central-api-2Validation, policies (allow and deny), organization isolation, plan limits, payment verification, OSS error mapping
Frontend unitVitest (to be scaffolded)frontend-2API client (error normalisation, retry rules), formatters, permission map, zod schemas, stores
ComponentVitest + Testing Libraryfrontend-2Forms, tables, states (loading/empty/error)
End-to-endPlaywright (to be scaffolded)frontend-2 + a test backendUser flows, mobile/desktop, themes, locales
Accessibilityaxe (Playwright)every pageWCAG 2.2 AA, both themes
ContractRecorded OSS responses (fixtures from API_REFERENCE.md / a test panel)backendThe OSS client keeps working as OSS changes
Live smokeA real OSS test panel (e.g. the .79 test server)stagingConnect / health / details / disconnect with a real key

#Per-module checklist

Each module is tested for: happy path · validation · permission (allowed + denied) · API error · loading · empty · network failure · mobile · desktop · dark mode · language · session expiration.

ModuleKey scenarios
AuthenticationRegister → verify → login. Unverified / banned / wrong password. 2FA (all 3 methods, 5-try limit, resend). IP approval. OAuth new/existing/linked. Reset logs out devices. Refresh rotation. Logout clears everything
OrganizationsCreate first (owner + roles). Rename. Delete refusals (main, only, has servers). Switch reloads every scoped list. Two tabs. Removed while viewing
PlansCatalog only from the API (no hard-coded values: a test fails if a price constant appears in the bundle Assumption). Current plan. Ineligible plans disabled
SubscriptionEach state's UI (trial, active, pending, cancelled, expired, failed, lifetime). Cancel/resume. Renew. Expired blocks actions except delete
BillingTop-up redirect + return with success/failure/pending (gateway mocked). Never shows success before backend confirmation. Invoices list/download. Auto-recharge form
RolesCreate (≥ 1 permission). System roles read-only. Delete rules. Matrix none/view/manage
MembersInvite existing/new email. Duplicate. Resend. Cancel. Accept. Change role. Remove (owner only, not self)
DashboardEach widget's loading/empty/error alone. One server offline doesn't break the page. Charts in both themes. No fake data
ServersConnect: valid, invalid key, offline, duplicate, version, limit. Status changes (revoked key → unauthorized). Disconnect message about revoking on the panel
Server detailsEach section with a live OSS fixture. Permission per OSS area. Offline state. Polling stops when hidden
ProvidersOAuth + token connect. Regions/sizes. Create VPS job states. Installer gets --stack + CENTRAL_TOKEN
BlueprintsCRUD. Deploy run polling. completed:false with failed steps. Add-on missing/no licence
Audit logEntry written for every mutation (backend). Filters. Deleted actor still readable. Server actions attributed to the person

#Matrix for E2E

DimensionValues
Viewports320, 375, 768, 1024, 1280, 1440 (+1920 smoke)
Themeslight, dark
Localesen (full), de + ja (layout/overflow), all 8 (smoke on key pages)
Rolesowner, admin, custom read-only
BrowsersChromium (all), WebKit + Firefox (smoke)
  1. auth.spec: login states + session expiry redirect with next.
  2. org-switch.spec: switching changes every list. Detail pages go back to the list.
  3. permissions.spec: menu visibility + 403 states for a read-only role.
  4. server-connect.spec: all connect failure codes (backend faked).
  5. billing-return.spec: pending → success polling, failure, tampered query parameters ignored.
  6. i18n.spec: no missing keys, no hard-coded strings (lint rule), locale switch keeps the path.
  7. a11y.spec: axe on every route in both themes.
  8. responsive.spec: no horizontal scroll at 320 px on every route.

Definition of done per feature (project rule): build passes, lint passes, tests green, i18n keys only, no secrets, diff re-read.

ServerAvatar V8 Central · prepared by central-app-2 (Pair 2 frontend) for Bhavik Jethwa · nothing in this spec is implemented yet · Built 2026-10-03 12:35 UTC