feature(nitrate): sso tests - #884
Merged
Merged
Conversation
tdelatorre
force-pushed
the
tdelatorre/feature/enterprise-sso-tests
branch
from
September 25, 2026 08:47
19ef6a2 to
bf97325
Compare
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical CI configuration and test setup issues must be resolved before approval.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 3
Open (3)
What changed in this PR
Automates the enterprise Organization SSO scenarios with shared setup, page-object coverage, Gmail validation, and environment configuration.
Changes:
- Adds SSO activation, cutoff, and deactivation coverage.
- Adds SSO page object, fixture, redirect assertion, and Gmail helpers.
- Documents required SSO credentials.
Unresolved findings include missing CI secret mappings, invitee context setup, invite-flow settling, and stale fixture documentation.
| File | Description |
|---|---|
tests/enterprise/fixtures/enterprise-fixtures.ts |
Registers the SSO page fixture. |
tests/enterprise/admin-console/organization-sso.spec.ts |
Automates the three SSO scenarios. |
README.md |
Documents SSO environment variables. |
pages/dashboard/organization-page.ts |
Adds SSO redirect validation. |
pages/admin-console/organization-sso-page.ts |
Adds SSO configuration interactions and assertions. |
helpers/gmail.js |
Adds SSO email helpers and checks. |
.env.example |
Documents SSO environment variables. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
tdelatorre
force-pushed
the
tdelatorre/feature/enterprise-sso-tests
branch
from
September 25, 2026 09:00
bf97325 to
2dff984
Compare
tdelatorre
marked this pull request as ready for review
September 25, 2026 09:38
tdelatorre
force-pushed
the
tdelatorre/feature/enterprise-sso-tests
branch
from
September 25, 2026 09:38
2dff984 to
b5c19be
Compare
tdelatorre
force-pushed
the
tdelatorre/feature/enterprise-sso-tests
branch
from
September 25, 2026 09:48
b5c19be to
ecf660a
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Done Definition Checks
Description
This PR resolves the automation of the 3 Qase cases under Admin Console > Sidebar Menu > Organization SSO (PENPOT-3527, PENPOT-3535, PENPOT-3587), which existed only as
test.skipstubs with no locators or page object.What problem are you trying to solve?
organization-sso.spec.tshad 3 manual test cases sitting as unimplemented stubs, and there was no page object for the Admin Console's SSO Config screen at all. The 3 cases also share a real dependency chain — both "existing session cutoff" (3535) and "deactivate SSO" (3587) require SSO to already be active, which PENPOT-3527 sets up — so automating them independently would mean paying 3x for the same expensive setup (Stripe checkout, a real Gmail-alias invitee, a live Auth0 test-connection).Solution
How did you solve the problem?
pages/admin-console/organization-sso-page.ts, a new page object covering the SSO Config tab: provider selection (Generic OpenID Connect / Azure AD / Google), the config form, activate/deactivate + their confirmation dialogs, and the resulting toast notifications. Includes self-healing retries for a couple of hydration races confirmed live (the config form occasionally lagging behind the provider radio's checked state, and anActivate SSOlocator accidentally substring-matchingDeactivate SSO).ssoPagefixture intotests/enterprise/fixtures/enterprise-fixtures.ts.qase([3527, 3535, 3587], ...)) usingownerAndInviteeTest— a real Gmail-alias invitee is required (not a demo account) since accepting a team invite needs a readable inbox, and the invitee must be an actual signed-in team member for their session to be the one that gets cut off.isRedirectedToSsoLogin()topages/dashboard/organization-page.tsto assert the live-push redirect to the identity provider's login page.getMessageText(),checkSsoActivatedEmailSubject(), andcheckSsoActivatedEmailText()tohelpers/gmail.jsto verify the "SSO enabled" notification email sent to the invitee.ENTERPRISE_SSO_ISSUER_URL/ENTERPRISE_SSO_CLIENT_ID/ENTERPRISE_SSO_CLIENT_SECRETenv vars, documented in.env.exampleandREADME.md.How to test
Screenshots 📸