Summary
frontend/src/__tests__/recommendations-lookback.test.ts fails on the base branch feat/multicloud-web-frontend itself (the frontend-build-sentinel workflow that runs Run frontend tests is red on the latest base tip eb85a507b and the prior commit f3920e426). Because the failure lives on base, every feature branch rebased on top inherits a red Build frontend (push) / frontend-build-sentinel check and cannot reach a CLEAN merge state through CI on its own.
Surfaced while running the pr-iterate loop on PR #924 (which does not touch this file; the file is byte-identical between base and the PR branch).
Root cause
The test's mockUser helper still uses the pre-#917 legacy role field:
const mockUser = (role: string | null) => {
(state.getCurrentUser as jest.Mock).mockReturnValue(
role === null ? null : { id: 'u', email: 'u@example.com', role },
);
};
After the group-membership authorization migration (#912 / #917), permissions.ts isAdmin() derives admin status from user.groups.includes(ADMINISTRATORS_GROUP_ID) and ignores role entirely. canAccess('update', 'config') falls back to isAdmin() when effectivePermissions is absent. In recommendations.ts::renderLookbackToolbar() the lookback <select> change listener is only attached when canEdit === canAccess('update', 'config') is true:
const canEdit = canAccess('update', 'config');
// ...
if (canEdit) {
select.addEventListener('change', () => { void onLookbackChange(select.value); });
}
With mockUser('admin') providing only role: 'admin' and no groups, isAdmin() returns false, canEdit is false, the change listener is never attached, and the persist/revert/tampered-value tests (which dispatch a change event and assert the selector reverts to '30') fail with select.value === ''.
Fix
Migrate the test fixture to the group-membership model:
import { ADMINISTRATORS_GROUP_ID } from '../permissions';
const mockUser = (role: string | null) => {
if (role === null) { (state.getCurrentUser as jest.Mock).mockReturnValue(null); return; }
const groups = role === 'admin' ? [ADMINISTRATORS_GROUP_ID] : [];
(state.getCurrentUser as jest.Mock).mockReturnValue({ id: 'u', email: 'u@example.com', groups });
};
(For the non-admin user/readonly cases the empty-groups fallback already yields canEdit === false, which is what those tests assert.) Validate with npx jest recommendations-lookback from frontend/.
Scope note
Filed as a separate issue rather than folded into PR #924 because that PR's scope is the Purchaser group / admin carve-out and it does not modify this file; fixing an unrelated base-branch test fixture there would expand the PR's blast radius. Reference: CodeRabbit / pr-iterate triage on PR #924.
Summary
frontend/src/__tests__/recommendations-lookback.test.tsfails on the base branchfeat/multicloud-web-frontenditself (thefrontend-build-sentinelworkflow that runsRun frontend testsis red on the latest base tipeb85a507band the prior commitf3920e426). Because the failure lives on base, every feature branch rebased on top inherits a redBuild frontend (push)/frontend-build-sentinelcheck and cannot reach a CLEAN merge state through CI on its own.Surfaced while running the pr-iterate loop on PR #924 (which does not touch this file; the file is byte-identical between base and the PR branch).
Root cause
The test's
mockUserhelper still uses the pre-#917 legacyrolefield:After the group-membership authorization migration (#912 / #917),
permissions.tsisAdmin()derives admin status fromuser.groups.includes(ADMINISTRATORS_GROUP_ID)and ignoresroleentirely.canAccess('update', 'config')falls back toisAdmin()wheneffectivePermissionsis absent. Inrecommendations.ts::renderLookbackToolbar()the lookback<select>change listener is only attached whencanEdit === canAccess('update', 'config')is true:With
mockUser('admin')providing onlyrole: 'admin'and nogroups,isAdmin()returns false,canEditis false, the change listener is never attached, and the persist/revert/tampered-value tests (which dispatch achangeevent and assert the selector reverts to'30') fail withselect.value === ''.Fix
Migrate the test fixture to the group-membership model:
(For the non-admin
user/readonlycases the empty-groups fallback already yieldscanEdit === false, which is what those tests assert.) Validate withnpx jest recommendations-lookbackfromfrontend/.Scope note
Filed as a separate issue rather than folded into PR #924 because that PR's scope is the Purchaser group / admin carve-out and it does not modify this file; fixing an unrelated base-branch test fixture there would expand the PR's blast radius. Reference: CodeRabbit / pr-iterate triage on PR #924.