AI Page Import — Test Cases
| Area | Required assertion | Current automated coverage |
|---|---|---|
| Queue schema | Required fields, positive tenant IDs, HTTP(S), viewport, attempt 1, unknown-field rejection | Service/schema tests |
| Public URL policy | Reject credentials, nonstandard ports, loopback, private, link-local, IPv6 loopback | test_security.py |
| Redirect security | Validate each asset redirect; reject a public URL redirecting to metadata/private IP | test_security.py |
| Browser evidence | CSS filter normalization and SVG rasterization selection | test_browser.py |
| Success path | Capture, assets, screenshot, immutable capture/result/manifest, success webhook | test_service.py |
| Failure path | Safe failure artifact/manifest and failed webhook | Required component/E2E coverage |
| Idempotency | Identical immutable writes are reusable; backend duplicate callback does not re-enqueue | Backend webhook unit tests |
| Database isolation | Worker imports no PostgreSQL/DocumentDB client | Architecture/static review |
| SQS batch behavior | Only failed record IDs are returned in batchItemFailures |
Handler component coverage |
| Uploaded source | Reject wrong tenant/prefix/hash/length; persist capture without opening local URL | test_service.py |
| Asset limits | Skip public video/oversized assets; reject oversized uploaded assets | test_security.py, test_service.py |
Local E2E acceptance
For a representative public page, create Page Import through REST and verify that the row reaches completed and capture.json, screenshot, and asset keys exist under the tenant prefix without any Code2Des row being created. Then select that import in the plugin, verify a new Code2Des row completes, and materialize it. Repeat generation from the same Page Import and confirm a distinct Code2Des row and Figma frame are retained. Compare source and Figma output for geometry, stacking, backgrounds/SVG, text wrapping, image color/filter, and missing layers.
Network-dependent E2E fixtures must use explicitly approved public targets and bounded timeouts. They are not part of the deterministic unit suite.