- Standard email/password login
- Registering a new account
- Logging out
- Email verification
- Resending email verification
- Verifying 2FA code
- Login/register via Google OAuth
¶ 1. Standard Login:
Purpose: Ensuring a standard user (no 2FA or OAuth) can login.
Steps:
- Navigate to login
- Enter correct email/password combination
- Submit login form
- Expect:
- User is logged in
- Session token is granted
Edge Cases:
- Invalid email or password:
- User not found
- Ensure input is properly sanitized for prevention against SQL injection
Purpose: Ensuring a user is able to register.
Steps:
- Navigate to registration page
- Enter a valid email and password combination
- Submit registration form
- Expect:
- User is created
- User is logged in
- User is requested to verify their email
Edge Cases:
- Duplicate email: "Account Already Exists" error -> Submitting form is blocked
- Missing password: Submitting form is blocked
- Ensure input is properly sanitized for prevention against SQL injection
Purpose: Ensuring a user can log out.
Steps:
- Log in as a user
- Navigate to the log out button
- Log out
- Expect:
- JWT token is invalidated
- User is logged out
- Redirect to the login page
Edge Cases:
Purpose: Ensuring email can be properly verified for a newly created user.
Steps:
- Log into newly created account without verified status
- Visit email of account
- Find code for verification
- Enter code into verfication form
- Expect:
- Account becomes verified
- Redirects to home page
Edge Cases:
- Invalid or expired code: User is prompted to resend verification email
Purpose: Ensuring user can resend verification email if needed.
Steps:
- Log into newly created (unverified) account
- Request a resend of the verification email
- Try the new code
- Expect:
- Account becomes verified
- Redirects to home page
Edge Cases:
Purpose: Ensuring user with 2FA enabled is able to properly login.
Steps:
- Log into account with 2FA enabled
- Get 2FA code from email of account
- Enter 2FA code as prompted
- Expect:
- User is logged in
- Redirects to home page
Edge Cases:
- Expired 2FA code:
401 -> New 2FA code gets sent
- Wrong code:
401 -> User is prompted to re-enter code
Purpose: Ensuring Google OAuth flow works.
Steps:
- Log in using the "Login via Google" button
- Expect:
- User is logged in
- Redirects to home page
Edge Cases:
- Invalid Google ID:
401 -> User is prompted to retry
- DB error:
500 -> Internal server error is displayed
- Need multiple accounts for testing purposes:
- One without 2FA
- One with 2FA
- One Google OAuth account