Narrow the R1 coverage claim to the flow the suite measures

#2214's two TLS cases both sign in anonymously, so anonymous is the only one
of the three named flows exercised in a third-party frame. Email is covered
over http and never embedded, and Telegram is covered nowhere and cannot be
until #2208 makes the API base URL configurable. The expectation that all
three behave alike rests on the client-side writer keying off X-JWT and not
off the provider, which is an inference and now reads as one.
This commit is contained in:
Dmitry Verkhoturov
2026-08-24 01:09:05 +01:00
parent 33e93a427d
commit 864cde68c8
@@ -63,10 +63,19 @@ remaining gap for the flows named above.
The e2e suite covers the rendering half through `TestCrossOrigin_WidgetRendersOnAnotherOrigin`, which
proves the document loads on another origin and reports itself through postMessage across the
boundary, and `ALLOWED_HOSTS` refusal through `TestCrossOrigin_DisallowedHostNeverReportsInited`.
#2214 adds the authentication half over TLS, the reload included, and runs it once more against a
browser configured to block third-party cookies. That last case needs `IgnoreDefaultArgs`, because
Playwright's own `--disable-features` list switches partitioning off and beats the flags passed
through `Args`, which would leave the case asserting nothing.
The open #2214 adds the authentication half over TLS, the reload included, and runs it once more
against a browser configured to block third-party cookies. That second case needs
`IgnoreDefaultArgs`, because Playwright's own `--disable-features` list switches partitioning off and
beats the flags passed through `Args`, which would leave the case asserting nothing.
Both of its TLS cases sign in anonymously, so the anonymous flow is the only one of the three
measured in a third-party frame. Email is exercised over http by `TestAuth_EmailSignsIn` and never
embedded; Telegram is not exercised anywhere and cannot be until #2208 makes the Telegram API base
URL configurable, since without that the widget cannot be pointed at a stub. The expectation that all
three behave alike is an inference and should be read as one: the client-side writer keys off `X-JWT`
on any auth response and not off the provider, so nothing in it distinguishes them. Worth stating
plainly, because a criterion naming flows the suite cannot reach is a milder version of the defect
this section was rewritten to remove.
`ALLOWED_HOSTS` sets the CSP `frame-ancestors` and `AUTH_SAME_SITE=none` lets the server's auth
cookies be set from any embedding domain. Those server-set cookies carry no `Partitioned`, so they