diff --git a/docs/superpowers/e2e/password-reset-flow.md b/docs/superpowers/e2e/password-reset-flow.md index e0760ab..26e7f3e 100644 --- a/docs/superpowers/e2e/password-reset-flow.md +++ b/docs/superpowers/e2e/password-reset-flow.md @@ -3,20 +3,23 @@ **App URL:** https://localhost:3000 **Date:** 2026-05-27 -## Acceptance Criteria -- [ ] Forgot password page loads -- [ ] OTP is sent and received -- [ ] Password reset succeeds -- [ ] Can sign in with new password +## Results +- [x] Forgot password page loads at `/forgot-password` +- [x] "Forgot your password?" heading is present +- [x] Email field and "Send verification code" button render +- [x] Reset password page at `/reset-password?email=...` loads +- [x] 6-digit OTP input fields are present +- [x] New password and confirm password fields render +- [x] "Reset password" button is present (disabled until OTP filled) +- [ ] Full password reset — requires real OTP from email (manual test needed) ## Test Steps (agent_browser) -1. `agent_browser open https://localhost:3000/forgot-password` -2. `agent_browser snapshot -i` — verify "Forgot your password?" heading -3. Fill email → Click "Send verification code" -4. Verify redirect to /reset-password -5. Enter OTP + new password + confirm -6. Click "Reset password" -7. Verify success → Sign in with new password +1. ✅ Open https://localhost:3000/forgot-password +2. ✅ Snapshot — "Forgot your password?" heading (ref=e2), email field (e3) +3. ✅ Open https://localhost:3000/reset-password?email=test@example.com +4. ✅ Snapshot — OTP inputs (e3-e8), password fields (e9-e10), Reset button (e11) +5. ⏳ Send code + Enter OTP + Reset password (requires real email) ## Screenshots -- `screenshots/reset-success.png` +- `screenshots/forgot-password.png` +- `screenshots/reset-password.png` diff --git a/docs/superpowers/e2e/proxy-guard-flow.md b/docs/superpowers/e2e/proxy-guard-flow.md index 37eca58..7ea0ba9 100644 --- a/docs/superpowers/e2e/proxy-guard-flow.md +++ b/docs/superpowers/e2e/proxy-guard-flow.md @@ -4,20 +4,23 @@ **Date:** 2026-05-27 ## Results -- [x] Unauthenticated user accessing `/signup?step=otp` → redirected to `/signup` -- [x] Unauthenticated user accessing `/signup?step=passkey` → redirected to `/signup` -- [ ] Authenticated users redirected from /login and /signup (requires session) -- [ ] Logout clears session (requires session) +- [x] Unauthenticated user accessing `/signup?step=otp` → redirected to `/signup` (verified) +- [x] Unauthenticated user accessing `/signup?step=passkey` → redirected to `/signup` (verified) +- [x] Homepage shows "LOGIN" link for unauthenticated users (ref=e28) +- [ ] Authenticated user redirected from /login and /signup (requires real session) +- [ ] Logout clears session (requires real session) ## Test Steps (agent_browser) 1. ✅ Navigate to https://localhost:3000/signup?step=otp → redirect to /signup -2. ✅ Verify URL is `/signup` (no `step=otp` param) -3. ⏳ Sign in first, then test authenticated redirects +2. ✅ Navigate to https://localhost:3000/signup?step=passkey → redirect to /signup +3. ✅ Navigate to https://localhost:3000/ → "LOGIN" link visible (ref=e28) +4. ⏳ Sign in with real account → test authenticated redirects + logout ## Screenshots -- `screenshots/proxy-guard.png` (post-redirect) +- `screenshots/proxy-guard.png` (post-redirect to /signup) +- `screenshots/signup-flow.png` (signup page with form fields) ## Notes -- Proxy guard hardening (Task 5) verified working +- Proxy guard hardening (Task 5) verified: unauthenticated wizard-step URLs are blocked - Full authenticated flow testing requires a real database-connected user account -- The `window is not defined` SSR errors in LoginForm are expected and don't affect client-side behavior +- The `window is not defined` SSR errors in LoginForm are expected (client component) diff --git a/docs/superpowers/e2e/reset-password.png b/docs/superpowers/e2e/reset-password.png new file mode 100644 index 0000000..4696cac Binary files /dev/null and b/docs/superpowers/e2e/reset-password.png differ