Skip to content

BE-M0-25 · One E2E login per system role

ID BE-M0-25 · Level L0 · Pack Pack E · Logins, types and the acceptance check · Run order row 22 · Issue #14

pnpm db:e2e-users makes one login per system role in the E2E organization, with that role at every pool, and writes what Playwright reads to the git-ignored .env.e2e (FE-R2, FE-R6). Committed on the branch tools/e2e-types-reference.

  • Timeline row 21 (pack D) is Done: pack D is merged into main, so the system roles and the E2E organization exist after a reset.
  • be-pack-e.zip, sent in the BE chat on 2026-10-07, is in ~/Downloads.
  • You are in ~/opleet-v2/opleet, git status --short prints nothing, and the stack is running.

1 · Check the zip, unzip it next to the repository, and check every file in it

Section titled “1 · Check the zip, unzip it next to the repository, and check every file in it”
Terminal window
shasum -a 256 ~/Downloads/be-pack-e.zip
unzip -q -o ~/Downloads/be-pack-e.zip -d ~/opleet-v2/packs
(cd ~/opleet-v2/packs/be-pack-e && shasum -a 256 -c SHA256SUMS)

2 · A branch for pack E, this step's file, and the root script that runs it

Section titled “2 · A branch for pack E, this step's file, and the root script that runs it”
Terminal window
cd ~/opleet-v2/opleet
git switch main && git pull
git switch -c tools/e2e-types-reference
cp -R ~/opleet-v2/packs/be-pack-e/BE-M0-25/. .
pnpm pkg set 'scripts["db:e2e-users"]=node tools/db/create-e2e-users.mjs'
git status --short

3 · Rebuild the local database, make the logins, then run the script again

Section titled “3 · Rebuild the local database, make the logins, then run the script again”

The second run must change nothing but the passwords, which it sets to the one already in .env.e2e. The script never prints the password.

Terminal window
pnpm supabase db reset
pnpm db:e2e-users
pnpm db:e2e-users

4 · Confirm .env.e2e is ignored, private and complete

Section titled “4 · Confirm .env.e2e is ignored, private and complete”
Terminal window
git check-ignore -v .env.e2e
stat -f '%Lp' .env.e2e
grep -c '^E2E_' .env.e2e
Terminal window
git add tools/db/create-e2e-users.mjs package.json
git commit -m "feat(tools): one E2E login per system role (FE-R2, FE-R6)"
  • Block 1: be-pack-e.zip's SHA-256 as written under Pack E, then 4 lines ending in “: OK”.
  • Block 2: “Switched to a new branch 'tools/e2e-types-reference'”, then M package.json and ?? tools/db/create-e2e-users.mjs.
  • Block 3: “Finished supabase db reset”; the first run prints eleven lines starting with “made”, one per role from super_admin to viewer with its address (e2e.super-admin@e2e.opleet.test and so on), then “11 logins in the E2E organization, all pools. .env.e2e updated (password not shown).” The second run prints the same lines with “kept” instead of “made”.
  • Block 4: .gitignore:44:.env.e2e .env.e2e, then 600, then 12.
  • Block 5: ✔️ biome and ✔️ commitlint, then the commit line with 2 files changed.

Sign in as the satpam login and ask the database what it may do. The token stays in the shell and is never printed.

Terminal window
eval "$(pnpm supabase status -o env)"
set -a; . ./.env.e2e; set +a
TOKEN=$(curl -s "$API_URL/auth/v1/token?grant_type=password" -H "apikey: $PUBLISHABLE_KEY" -H "Content-Type: application/json" -d "{\"email\":\"$E2E_SATPAM_EMAIL\",\"password\":\"$E2E_PASSWORD\"}" | python3 -c 'import json, sys; print(json.load(sys.stdin)["access_token"])')
curl -s -X POST "$API_URL/rest/v1/rpc/my_permissions" -H "apikey: $PUBLISHABLE_KEY" -H "Authorization: Bearer $TOKEN" | python3 -c 'import json, sys; [print(r["pool_code"], r["permission_code"]) for r in json.load(sys.stdin)]'
unset TOKEN E2E_PASSWORD

Four lines: E2A audit_log:read, E2A gate:read, E2B audit_log:read, E2B gate:read.

  • “the E2E organization is missing”: pack D's seed hasn't run. Run pnpm supabase db reset and block 3 again.
  • “system role … is missing”: pack D's system rows aren't in this database. Paste the output of pnpm supabase migration list --local.
  • “refusing …”: the script found a URL that isn't the local stack. Paste the line; don't change the script.
  • A 4xx or 5xx error with a path: paste the line. Running the script again is safe.
  • Block 4 prints no ignore rule: stop and don't commit. Paste the output of git status --short.
  • The check prints a KeyError for access_token: the sign-in failed. Paste the output of block 3, not the password.

Not committed yet: git checkout -- package.json, rm tools/db/create-e2e-users.mjs .env.e2e, then pnpm supabase db reset, which removes the logins. Committed: git reset --hard HEAD~1, then the same. Nothing has been pushed.

Not run yet. Log each run as a comment on #14.