# Web Test Suite

This suite validates routing, controllers, and view contracts by executing the app entrypoint (`src/index.php`) in a separate PHP process per request.

## Why separate process?

- The app defines constants and global state during bootstrap.
- Some controllers call `exit` (for redirects/AJAX responses).
- Process isolation lets tests run multiple requests safely.

## Prerequisites

- Install dependencies:
  - `composer install`
- Ensure runtime config exists:
  - `src/settings/config.php`
- Configure DB/source in `config.php` (recommended reference source for web tests: `stream`).

## Commands

- Full web suite:
  - `composer test-web`
- Route smoke tests only:
  - `composer test-web-routes`
- Flow/controller tests only:
  - `composer test-web-flows`
- Security matrix tests only:
  - `composer test-web-security`
- CLI smoke tests only:
  - `composer test-web-cli`
- Direct PHPUnit invocation:
  - `php ./vendor/bin/phpunit --testdox --bootstrap ./tests/auto/integration-web/bootstrap.php tests/auto/integration-web --debug`

## Current coverage

- Route smoke checks for all routes declared in `src/pages/routes.php`.
- POST flow tests for login/register/chpass/store.
- Security matrix for admin routes (guest vs user vs admin).
- DOM/XPath view contracts for login/register/ranking/store/account-panel.
- CLI dispatch smoke tests for `src/cli.php`.

## Transaction model

- Each web request is executed in an isolated process.
- Requests run with `WEB_TEST_TRANSACTIONAL=1` in the child process.
- `src/settings/helpers.php` starts DB transactions on game/CMS connections in test mode.
- Rollback is executed in shutdown handlers, so DB state is reverted after every request.
- Registration/password/store operations are therefore safe to run repeatedly.

## Next expansion steps

- Add richer fixture builders for edge cases (missing products, disabled payment methods).
- Add assertions for JSON/AJAX contracts in more controllers.
- Add targeted snapshot contracts for stable HTML fragments.
