import assert from "node:assert/strict"; import { chromium } from "playwright-core"; const password = process.env.E2E_PASSWORD; assert.ok(password, "E2E_PASSWORD must be set"); const browser = await chromium.launch({ executablePath: process.env.CHROME_BIN ?? "/usr/bin/google-chrome", headless: true, args: ["--no-sandbox"], }); try { const context = await browser.newContext(); const page = await context.newPage(); await page.goto("http://localhost:8082"); await page.locator("#login").click(); await page.waitForURL(/localhost:8080/u); await page.locator("#username").fill( process.env.E2E_USERNAME ?? "regular-user", ); await page.locator("#password").fill(password); await page.locator("#kc-login").click(); await page.waitForURL("http://localhost:8082/"); const boundaryResponsePromise = page.waitForResponse((response) => response.url().endsWith("/token/boundary"), ); await page.locator("#inspect").click(); const boundaryResponse = await boundaryResponsePromise; assert.equal(boundaryResponse.status(), 200); const boundary = await boundaryResponse.json(); assert.equal(boundary.accessTokenStored, true); assert.equal(boundary.refreshTokenStored, true); assert.equal(boundary.browserReceivesRefreshToken, false); assert.equal(JSON.stringify(boundary).includes("refresh_token"), false); const cookies = await context.cookies("http://localhost:8082/"); const sessionCookie = cookies.find((cookie) => cookie.name === "AP2_SESSION"); assert.ok(sessionCookie); assert.equal(sessionCookie.httpOnly, true); assert.equal(sessionCookie.sameSite, "Lax"); const storage = await page.evaluate(() => ({ localStorage: Object.values(localStorage), sessionStorage: Object.values(sessionStorage), })); assert.equal(JSON.stringify(storage).includes("refresh_token"), false); console.log( "pattern2 confidential client verified: server code exchange, server access/refresh custody, HttpOnly session", ); } finally { await browser.close(); }