Files
authforge/gui/TESTING.md
michael 25eed8ff94 docs(gui): smoke-test recipes for Policy and Recovery tabs
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 11:18:50 -07:00

2.9 KiB

Testing the AuthForge GUI

Automated gate

cargo build -p authforge-gui
cargo clippy -p authforge-gui --all-targets -- -D warnings
cargo test -p authforge-gui            # 4 error-classifier tests

CI runs all three on every push (libgtk-4-dev / libadwaita-1-dev are installed in the workflow image).

The GUI requires libadwaita 1.5 (Ubuntu 24.04+) for adw::AlertDialog and the v1_5 feature gate enabled in gui/Cargo.toml. Older distros need the plan's MessageDialog fallback (not implemented in v1).

Manual smoke

Requires a USB FIDO2 device (Yubikey 5, Solo, etc.) and a built daemon.

# Terminal 1 — daemon (permissive polkit so you don't get prompted).
AUTHFORGE_POLKIT_BYPASS=1 \
  AUTHFORGE_POLICY_DIR=/tmp/af/policy.d \
  AUTHFORGE_PENDING_DIR=/tmp/af/pending \
  AUTHFORGE_USERDB=/tmp/af/users.db \
  target/release/authforged

# Terminal 2 — GUI.
target/release/authforge

Walk-through:

  1. Window opens, Keys tab visible. Empty list with hint text "No keys enrolled yet."
  2. Click "Enroll a new key" → modal opens with spinner + "Touch your security key now". Touch the device.
  3. Modal closes, the list re-renders with one row showing the key's short id.
  4. Click the trash icon on the row → row vanishes immediately.
  5. Pull the security key, click Enroll → modal opens, swaps to error text ("authenticator: no FIDO2 device found") with a Close button.
  6. Kill the daemon (pkill authforged), click Enroll → toast appears with the disconnected message; Retry on the page reconnects after restart.

Policy tab smoke

  1. Daemon running (same setup as Keys tab smoke).
  2. Open the GUI → Policy tab. Three rows: gdm-password, sudo, sshd. All start at "Disabled" on a clean system.
  3. Set sudo to "Required" → Apply. With no enrolled keys you'll see an inline banner "Would lock users out — sudo: : no fido2 enrolled" and a "Force apply" button.
  4. Click "Force apply" → toast "Policy applied".
  5. Switch to Keys tab → enroll a Yubikey → switch back. Apply again with sudo=Required → toast "Policy applied" without the banner.
  6. In another terminal: authforgectl policy show should reflect the change.
  7. Run authforgectl policy set sshd disabled --methods fido2 externally → Policy tab refreshes within ~1s (PolicyChanged signal).
  8. Expand "Advanced" — any non-master stack the daemon discovered shows here with the same Disabled/Optional/Required combo.

Recovery tab smoke

  1. Open Recovery tab. Empty list with hint text.
  2. Type "alice" in the username row, click "Generate code". Modal opens showing the 8-digit code with a Copy button. Click Copy → paste somewhere to verify clipboard worked.
  3. Close the modal. List now shows alice with "expires in 7 day(s)".
  4. Click "Revoke" on alice's row → row vanishes, toast confirms.
  5. Generate again, then run authforgectl recovery list externally — should show alice with the same expiry.