# THIS BLOCK IS FOR HUMANS, SKIP THIS UNTIL THE NEXT TODO TITLE

- [ ] Create example docs in api-methods.md
- [ ] Check if can be splitted more the Testing docs
- [ ] Restore important information from other docs
- [ ] Check if other docs can be defragmented
- [ ] Add examples to create models
- [ ] Add example to create views + controllers
- [ ] Add example to create templates
- [ ] Current modules documentation:
  - [ ] payment + paypal
  - [ ] Shop


# TODO - Automated Web Testing

This document tracks pending items for the automated web testing infrastructure.

---

## Session Development Status

### Completed (Implemented)

- [x] Web test harness with isolated PHP process per request
- [x] Transaction-based DB isolation (begin/rollback per request)
- [x] Session injection support for authenticated test scenarios
- [x] FixtureLoader with account/product lookup helpers
- [x] HtmlAsserts trait with DOM/XPath assertions
- [x] WebTestCase base class with common helpers
- [x] Route smoke tests for all routes from `routes.php`
- [x] POST flow tests for login (invalid + valid + AJAX)
- [x] POST flow tests for register (validation + duplicate + success)
- [x] POST flow tests for store (quantity + payment method validation)
- [x] POST flow tests for change password (guest block + mismatch)
- [x] Admin access matrix (guest/user/admin per dynamic route list)
- [x] View contracts using DOM/XPath for key pages
- [x] CLI dispatch smoke tests
- [x] Composer scripts with PHPUnit groups

### Pending (To-Do List)

---

## Pending Items

### Phase 1: Enhanced Fixtures & Edge Cases

- [ ] Add richer fixture builders for edge cases (missing products, disabled payment methods)
- [ ] Add explicit fixture for GM account with known credentials (not just lookup)
- [ ] Add fixture for account with special characters in username/password
- [ ] Add deterministic DB snapshot seeding for ranking tests (avoid empty ranking pages)
- [ ] Add fixture cleanup utility for test-created accounts (register flow)

### Phase 2: Additional Flow Coverage

- [ ] Add AJAX login contract assertions (JSON structure validation)
- [ ] Add logout flow test (session destruction)
- [ ] Add forgot password flow test (email token path)
- [ ] Add profile page rendering test (authenticated user context)
- [ ] Add ranking page rendering test with mock/specific entities
- [ ] Add store purchase flow with valid product selection (payment redirect smoke)
- [ ] Add language switching flow test (account panel language change)

### Phase 3: Security & Permission Tests

- [ ] Add CSRF token validation on forms (where implemented)
- [ ] Add rate-limiting detection (if applicable in controllers)
- [ ] Add SQL injection prevention test cases on input fields
- [ ] Add XSS prevention test (reflected input in output)
- [ ] Add unauthorized access to other users' data (e.g., profile by ID)

### Phase 4: View Contract Expansion

- [ ] Add DOM assertions for ranking table structure
- [ ] Add snapshot contracts for stable HTML fragments (e.g., header/footer)
- [ ] Add assertions for translated string presence per language
- [ ] Add accessibility contract (basic ARIA roles, form labels)
- [ ] Add responsive/mobile viewport smoke (optional)

### Phase 5: Performance & Baseline

- [ ] Add response time budget assertions for core pages
- [ ] Add baseline memory usage check
- [ ] Add "no PHP notices/warnings" enforcement in test output

### Phase 6: CI/CD Integration

- [ ] Add GitLab CI stage for web tests
- [ ] Add test report generation (JUnit XML)
- [ ] Add coverage upload configuration
- [ ] Add PHP 8.2-specific test job
- [ ] Add parallel execution groups for speed

### Phase 7: Documentation & Maintenance

- [ ] Add troubleshooting guide for common fixture failures
- [ ] Add "how to add a new flow test" guide
- [ ] Add fixture naming conventions document
- [ ] Add README to each test subfolder

### Phase 8: Future Enhancements

- [ ] Consider static analysis integration (PHPStan level 1+)
- [ ] Consider browser-based testing for JS interactions (Playwright)
- [ ] Consider contract testing between API controllers and models
- [ ] Consider mutation testing for critical flows

---

## How to Contribute

1. Pick a pending item from the list above.
2. Create a test file in the appropriate `tests/auto/integration-web/` subfolder.
3. Follow existing patterns in `tests/auto/integration-web/controllers/`, `tests/auto/integration-web/security/`, etc.
4. Use `WebTestCase` base class and transaction isolation.
5. Run tests locally: `composer test-web-flows` (or specific group).
6. Update this document to mark the item as completed.

---

## Notes

- All web tests use **transaction isolation** via `src/settings/helpers.php`.
- Each request runs in an **isolated PHP process** to avoid global state pollution.
- Fixtures are **looked up** from the database at runtime; they are **not** pre-seeded.
- If a fixture is missing, tests are **skipped** with a clear message.
- PHPUnit groups: `web-routes`, `web-flows`, `web-security`, `web-cli`.

