fix(ci): align PAYLOAD_SECRET for post-deploy cleanup and enhance diagnostics
Some checks failed
Build & Deploy / 🔍 Prepare (push) Successful in 7s
Build & Deploy / 🧪 QA (push) Successful in 1m18s
Build & Deploy / 🏗️ Build (push) Successful in 3m53s
Build & Deploy / 🚀 Deploy (push) Successful in 21s
Build & Deploy / 🧪 Post-Deploy Verification (push) Failing after 5m33s
Build & Deploy / 🔔 Notify (push) Successful in 2s

This commit is contained in:
2026-04-27 13:58:26 +02:00
parent 263640bce5
commit de0089f068
3 changed files with 36 additions and 24 deletions

View File

@@ -532,7 +532,7 @@ jobs:
env:
NEXT_PUBLIC_BASE_URL: ${{ needs.prepare.outputs.next_public_url }}
GATEKEEPER_PASSWORD: ${{ secrets.GATEKEEPER_PASSWORD || 'klz2026' }}
PAYLOAD_SECRET: ${{ secrets.PAYLOAD_SECRET || vars.PAYLOAD_SECRET }}
PAYLOAD_SECRET: ${{ secrets.PAYLOAD_SECRET || vars.PAYLOAD_SECRET || 'you-need-to-set-a-payload-secret' }}
PUPPETEER_EXECUTABLE_PATH: /usr/bin/chromium
run: pnpm run check:forms

View File

@@ -139,7 +139,7 @@
"prepare": "husky",
"preinstall": "npx only-allow pnpm"
},
"version": "2.3.22-rc.2",
"version": "2.3.22-rc.3",
"pnpm": {
"onlyBuiltDependencies": [
"@parcel/watcher",

View File

@@ -115,8 +115,10 @@ async function main() {
// Intercept Next.js chunks and data to bypass Varnish 404-caching
// Includes standard /_next/ and subpath /gatekeeper/_next/
if (
(url.includes('/_next/static/') || url.includes('/_next/data/') || url.includes('/gatekeeper/_next/')) &&
!url.includes('?cb=') &&
(url.includes('/_next/static/') ||
url.includes('/_next/data/') ||
url.includes('/gatekeeper/_next/')) &&
!url.includes('?cb=') &&
!url.includes('&cb=')
) {
const buster = `cb=${Date.now()}`;
@@ -154,10 +156,10 @@ async function main() {
const navigateWithRetry = async (url: string, label: string) => {
chunkErrorsDetected = false;
console.log(`\n🧪 Testing ${label} on: ${url}`);
// First attempt: Wait for network to be relatively idle
await page.goto(url, { waitUntil: 'networkidle2', timeout: 30000 });
// REDIRECTION CHECK: Logging redirected landing page
const finalUrl = page.url();
if (finalUrl !== url && !finalUrl.includes(url)) {
@@ -167,7 +169,9 @@ async function main() {
if (chunkErrorsDetected) {
const buster = `cb=${Date.now()}`;
const cbUrl = finalUrl.includes('?') ? `${finalUrl}&${buster}` : `${finalUrl}?${buster}`;
console.warn(` ⚠️ Assets failed to load (Varnish staleness suspected). Retrying with cache-buster: ${cbUrl}`);
console.warn(
` ⚠️ Assets failed to load (Varnish staleness suspected). Retrying with cache-buster: ${cbUrl}`,
);
chunkErrorsDetected = false;
await page.goto(cbUrl, { waitUntil: 'networkidle2', timeout: 30000 });
}
@@ -266,10 +270,10 @@ async function main() {
console.log(` 🔔 Alert text: ${alertText}`);
// Detection robust for both English and German versions
const isError =
alertText?.toLowerCase().includes('failed') ||
const isError =
alertText?.toLowerCase().includes('failed') ||
alertText?.toLowerCase().includes('wrong') ||
alertText?.toLowerCase().includes('fehlgeschlagen') ||
alertText?.toLowerCase().includes('fehlgeschlagen') ||
alertText?.toLowerCase().includes('schief gelaufen') ||
alertText?.toLowerCase().includes('fehler');
@@ -329,10 +333,10 @@ async function main() {
const alertText = await page.$eval('[role="alert"]', (el) => el.textContent);
console.log(` 🔔 Alert text: ${alertText}`);
const isError =
alertText?.toLowerCase().includes('failed') ||
const isError =
alertText?.toLowerCase().includes('failed') ||
alertText?.toLowerCase().includes('wrong') ||
alertText?.toLowerCase().includes('fehlgeschlagen') ||
alertText?.toLowerCase().includes('fehlgeschlagen') ||
alertText?.toLowerCase().includes('schief gelaufen') ||
alertText?.toLowerCase().includes('fehler');
@@ -349,9 +353,15 @@ async function main() {
// 5. Cleanup: Delete test submissions from Payload CMS
console.log(`\n🧹 Starting cleanup of test submissions...`);
const payloadSecret = process.env.PAYLOAD_SECRET;
if (!payloadSecret) {
console.warn(` ⚠️ PAYLOAD_SECRET not found in environment. Cleanup will likely fail with 403.`);
console.warn(
` ⚠️ PAYLOAD_SECRET not found in environment. Cleanup will likely fail with 403 if the server expects a secret.`,
);
} else {
console.log(
` 🔐 PAYLOAD_SECRET found (${payloadSecret.substring(0, 3)}...). Sending x-e2e-secret header.`,
);
}
try {
@@ -361,7 +371,7 @@ async function main() {
// Fetch test submissions with bypass header
const searchResponse = await axios.get(searchUrl, {
headers: {
headers: {
Cookie: `klz_gatekeeper_session=${gatekeeperPassword}`,
'x-e2e-secret': payloadSecret || '',
},
@@ -373,29 +383,31 @@ async function main() {
for (const doc of testSubmissions) {
try {
await axios.delete(`${apiUrl}/${doc.id}`, {
headers: {
headers: {
Cookie: `klz_gatekeeper_session=${gatekeeperPassword}`,
'x-e2e-secret': payloadSecret || '',
},
});
console.log(` ✅ Deleted submission: ${doc.id} (${doc.name})`);
} catch (delErr: any) {
console.warn(
` ⚠️ Cleanup attempt on ${doc.id} failed: ${delErr.message}`,
);
console.warn(` ⚠️ Cleanup attempt on ${doc.id} failed: ${delErr.message}`);
}
}
if (testSubmissions.length > 0) {
console.log(`✅ Cleanup completed successfully.`);
}
} catch (err: any) {
if (err.response?.status === 403) {
console.error(
` ❌ Cleanup failed with 403 Forbidden. Ensure FormSubmissions access control and PAYLOAD_SECRET are aligned.`,
);
console.error(` ❌ Cleanup failed with 403 Forbidden.`);
console.error(` Detail: The server rejected the x-e2e-secret header.`);
console.error(` Server Response: ${JSON.stringify(err.response.data)}`);
} else {
console.error(` ❌ Cleanup fetch failed: ${err.message}`);
if (err.response) {
console.error(` Status: ${err.response.status}`);
console.error(` Body: ${JSON.stringify(err.response.data)}`);
}
}
}