from pathlib import Path def test_discovery_page_uses_cookie_session_not_user_id(): """The browser session is a server-set cookie, so the page must not mint or carry a client-side user id, and all calls go through authedFetch.""" html = Path("app/static/discovery.html").read_text(encoding="utf-8") assert "impactflow_user_id" not in html assert "createUserId" not in html assert "user_id" not in html assert "authedFetch" in html assert '/static/auth.js' in html def test_profile_page_uses_me_endpoints_and_authed_fetch(): """Profile reads/confirms via the user-scoped /me routes, authenticated by the session cookie through authedFetch — not the old user_id-in-URL paths.""" html = Path("app/static/profile.html").read_text(encoding="utf-8") assert "/discovery/profile/me" in html assert "/discovery/profile/me/confirm" in html assert "user_id" not in html assert "authedFetch" in html def test_profile_page_has_edit_affordance(): """The read/edit/affirm DoD: an Edit control that PATCHes the profile.""" html = Path("app/static/profile.html").read_text(encoding="utf-8") assert "renderEdit" in html assert 'method: "PATCH"' in html assert "Edit my words" in html def test_reflect_page_uses_reflection_endpoints(): """Phase 2 reflection page drives the coach loop via authedFetch.""" html = Path("app/static/reflect.html").read_text(encoding="utf-8") assert "/discovery/profile/me/reflect" in html assert "/discovery/profile/me/reflection" in html assert "authedFetch" in html assert "user_id" not in html def test_profile_page_links_to_reflection(): html = Path("app/static/profile.html").read_text(encoding="utf-8") assert "/static/reflect.html" in html def test_coaching_page_uses_coaching_endpoints(): """Phase 3 coaching page drives preferences + check-ins via authedFetch.""" html = Path("app/static/coaching.html").read_text(encoding="utf-8") assert "/discovery/coaching/preferences" in html assert "/discovery/coaching/checkins" in html assert "authedFetch" in html assert "user_id" not in html def test_profile_page_links_to_coaching(): html = Path("app/static/profile.html").read_text(encoding="utf-8") assert "/static/coaching.html" in html def test_dashboard_page_uses_work_patterns_endpoint(): """Phase 4 dashboard reads work patterns via authedFetch.""" html = Path("app/static/dashboard.html").read_text(encoding="utf-8") assert "/discovery/integration/work-patterns" in html assert "authedFetch" in html assert "user_id" not in html def test_profile_page_links_to_dashboard(): html = Path("app/static/profile.html").read_text(encoding="utf-8") assert "/static/dashboard.html" in html def test_auth_helper_sends_credentials_and_refreshes(): js = Path("app/static/auth.js").read_text(encoding="utf-8") assert 'credentials: "include"' in js assert "/api/auth/refresh" in js assert "/api/auth/login" in js