Files
DodoSSH/tests/DodoSSH.Client.App.Layout.Tests/ScreenLayoutTests.cs
T
jaap-jan 2caedd93ff Merge branch 'main' into the Android head
Main grew the screens the host-management plan called for — hosts, pins, snippets, logs,
import, teams — plus the ObjectStore and Import projects behind two of them, and moved
WindowsDeviceKeyStore into the desktop head's Platform folder.

Five of those view models landed in a directory this branch had already moved, so they
join the rest in DodoSSH.Client.Shell: git spotted the rename and put them there, and the
namespaces followed. Shell picks up ObjectStore and Import as a result, which the Android
head then gets transitively and will use neither of at first — scoped storage means there
is no ~/.ssh/config to import, and file transfer is out of its first scope.

Desktop suites green at 155 and 64.
2026-07-31 21:03:22 +02:00

1484 lines
59 KiB
C#

using Avalonia;
using Avalonia.Controls;
using Avalonia.Headless;
using Avalonia.Input;
using Avalonia.Threading;
using Avalonia.VisualTree;
using DodoSSH.Client.App.Views;
using DodoSSH.Client.Domain;
using DodoSSH.Client.Import;
using DodoSSH.Client.Session;
using DodoSSH.Client.Session.Tests;
using DodoSSH.Client.Shell.ViewModels;
using DodoSSH.Client.Ssh;
using DodoSSH.Client.Storage;
using DodoSSH.Client.Terminal;
using DodoSSH.Client.Transfer;
using DodoSSH.Crypto;
using NSubstitute;
namespace DodoSSH.Client.App.Layout.Tests;
/// <summary>
/// Whether each screen fits in the space the window gives it.
/// </summary>
/// <remarks>
/// <para>
/// This suite used to measure one control, <c>VaultColumn</c>, because there was one. The design import
/// split it in two — the host list lives beside the terminal, and everything else in the vault has a screen
/// of its own — and added a titlebar, a nav rail and a status bar. That is five things to measure, and the
/// split is what keeps every one of them measurable: none contains the terminal's WebView, and
/// <c>MainWindow</c> still cannot be laid out here at all, because WebView2's adapter refuses the headless
/// dispatcher's MTA thread. <see cref="LayoutHarnessTests"/> pins that.
/// </para>
/// <para>
/// One test per shape a user can put a screen into, because a shape that is never laid out is a shape never
/// checked. The host sidebar has three — list, list with the editor open, and list folded away — and the
/// vault screen has one per category plus one per editor.
/// </para>
/// <para>
/// A real <c>VaultViewModel</c> over a real unlocked vault, rather than a stand-in. Compiled bindings
/// resolve against the declared data type, so a stand-in would have to be the same type anyway — and the
/// editors' height depends on real content: a key with a real armour block in the box is taller than an
/// empty one.
/// </para>
/// </remarks>
public sealed class ScreenLayoutTests : IAsyncLifetime
{
private const string Passphrase = "a sufficiently long passphrase";
private const string ServerUrl = "https://dodossh.example";
/// <remarks>Far below the shipped profile: nothing here attacks a wrap.</remarks>
private static readonly Argon2Profile CheapProfile =
Argon2Profile.FromStoredParameters(memoryKibibytes: 8 * 1024, passes: 1, parallelism: 1);
private readonly FakeAccountServer server = new();
private readonly StubKeyBinding keyBinding = new();
private readonly VaultKnownHostStore knownHosts = new();
private ClientCacheFactory caches = null!;
private TerminalWorkspace workspace = null!;
private VaultSession session = null!;
private VaultViewModel vault = null!;
/// <remarks>
/// Constructed and never started: the sign-out card binds to the shell rather than to a vault, and what
/// it shows comes from properties a fresh one already answers. Starting it would migrate a cache and
/// read a profile, neither of which any rectangle here depends on.
/// </remarks>
private MainWindowViewModel shell = null!;
/// <remarks>
/// Over a substitute factory that is never asked for a session. Every shape measured here is one the
/// screen is in before a connection exists or after one has failed, which is deliberate: the two panes
/// are at their widest with the local one full and the remote one carrying its explanation, and a
/// connected pane is the same template with shorter names in it.
/// </remarks>
private TransfersViewModel transfers = null!;
private static CancellationToken Token => TestContext.Current.CancellationToken;
/// <inheritdoc />
public async ValueTask InitializeAsync()
{
caches = ClientCacheFactory.ForMemory($"layout-{Guid.CreateVersion7():N}");
await caches.MigrateAsync(Token);
await new AccountProvisioner(server, keyBinding, caches, TimeProvider.System, CheapProfile)
.EnrollAsync(ServerUrl, Passphrase, "laptop", "Personal", Token);
var outcome = await new SessionOpener(caches, TimeProvider.System).UnlockAsync(Passphrase, Token);
outcome.IsUnlocked.ShouldBeTrue(outcome.Message);
session = outcome.Session!;
// Never started and never connected through: no screen's layout depends on the terminal, and the
// substitute is here only because the view model's constructor asks for one.
workspace = new TerminalWorkspace(
new InMemoryTerminalAssetProvider(new Dictionary<string, TerminalAsset>(StringComparer.Ordinal)),
Substitute.For<ISshConnectionFactory>(),
TimeProvider.System);
await knownHosts.OpenAsync(session, Token);
// Offline. A null connection is what these screens show on a laptop with no network, and it keeps
// every sync pass out of a suite that is only measuring rectangles.
vault = new VaultViewModel(session, workspace, knownHosts, static () => null);
shell = new MainWindowViewModel(
new ClientPaths(Path.Combine(Path.GetTempPath(), $"dodossh-layout-{Guid.CreateVersion7():N}")),
caches,
workspace,
knownHosts,
new UnavailableDeviceKeyStore(),
static (_, _) => throw new InvalidOperationException("A layout test has no network."),
TimeProvider.System,
Substitute.For<ISftpSessionFactory>(),
CheapProfile);
transfers = new TransfersViewModel(
Substitute.For<ISftpSessionFactory>(), TimeProvider.System);
await SeedAsync();
// Attached after seeding, so the host picker has something in it and the local pane has listed this
// machine's home directory — which is what puts real names of real length into the row template.
transfers.Attach(vault, knownHosts);
}
/// <inheritdoc />
public async ValueTask DisposeAsync()
{
await shell.DisposeAsync();
await transfers.DisposeAsync();
await vault.DisposeAsync();
knownHosts.Close();
await workspace.DisposeAsync();
await session.DisposeAsync();
caches.Dispose();
}
// ---- The host sidebar ----
[Fact]
public async Task TheHostSidebarFitsWithNoEditorOpen()
{
await MeasureSidebarAsync(faults => faults.ShouldBeEmpty());
}
/// <remarks>
/// The tight one, and the reason this suite still exists. The sidebar is 268 pixels wide against the old
/// column's 340, and the host editor is the tallest thing in it: six fields, an authentication picker
/// with a two-line item template, a checkbox, a paragraph of hint text and three buttons, all sharing a
/// column with the list above them.
/// </remarks>
[Fact]
public async Task TheHostSidebarFitsWithItsEditorOpen()
{
vault.SelectedHost = vault.Hosts[0];
vault.EditSelectedHostCommand.Execute(null);
vault.EditorAuthenticationChoices.Count
.ShouldBeGreaterThan(1, "the picker has to be populated for this to measure anything");
// Measured with a credential selected, because an empty picker is shorter than one showing a
// qualifier beside a label.
vault.EditorSelectedAuthentication = vault.EditorAuthenticationChoices
.First(choice => choice.Kind is AuthenticationKind.Credential);
await MeasureSidebarAsync(faults => faults.ShouldBeEmpty());
}
/// <remarks>
/// Folding the list away is the one thing a user can do to this control that changes which of its parts
/// is on screen, so it is a shape worth laying out on its own.
/// </remarks>
[Fact]
public async Task TheHostSidebarFitsWithItsListFoldedAway()
{
vault.ToggleHostsCommand.Execute(null);
vault.AreHostsExpanded.ShouldBeFalse();
await MeasureSidebarAsync(faults => faults.ShouldBeEmpty());
}
/// <remarks>
/// Headings are rows in the same list as the hosts, drawn from a different template, and they are the
/// widest thing in a 268-pixel column: a name, a chevron and a count on one line. Measured with one group
/// folded, because a folded heading is the shape whose row is on screen without any of its hosts.
/// </remarks>
[Fact]
public async Task TheHostSidebarFitsWithGroupHeadingsInTheList()
{
await SeedGroupsAsync(3);
vault.SidebarRows.OfType<SidebarGroupHeader>().Count()
.ShouldBe(3, "one heading per group, and no ungrouped heading while nothing is ungrouped");
vault.ToggleGroupCommand.Execute(vault.SidebarRows.OfType<SidebarGroupHeader>().First());
await MeasureSidebarAsync(faults => faults.ShouldBeEmpty("with three headings and one folded"));
}
/// <remarks>
/// <para>
/// The one thing a wrong answer here breaks is unrecoverable from the keyboard: <c>MainWindow</c> takes
/// the keyboard off the terminal's native child window first and then focuses this target, so a target
/// that cannot take focus leaves the user with no focused element and no way back except the mouse.
/// </para>
/// <para>
/// Which is why this asserts that focus was <i>taken</i> rather than that the right control was named.
/// A <c>ListBox</c> is not focusable by default, so the call returns false against a list that has not
/// asked to be — and <c>Focus()</c> on a collapsed control is a no-op that is not replayed when it is
/// revealed, which is exactly what the folded-away case would hit.
/// </para>
/// </remarks>
[Fact]
public async Task TheSidebarsKeyboardTargetTakesFocusInBothOfItsShapes()
{
await OnTheSidebarAsync((sidebar, _) =>
{
sidebar.KeyboardTarget.ShouldBeSameAs(sidebar.HostList);
sidebar.KeyboardTarget.Focus().ShouldBeTrue("the list is showing");
});
vault.ToggleHostsCommand.Execute(null);
await OnTheSidebarAsync((sidebar, _) =>
{
sidebar.KeyboardTarget.ShouldBeSameAs(sidebar.HostFilter);
sidebar.KeyboardTarget.Focus().ShouldBeTrue("the list is folded away, so the filter takes it");
});
}
/// <remarks>
/// The editor open with the list still on screen behind it, which is the state a user is most likely to
/// leave the sidebar in — so it is the state the keyboard answer most has to hold in.
/// </remarks>
[Fact]
public async Task TheSidebarsKeyboardTargetStillTakesFocusWithTheEditorOpen()
{
vault.NewHostCommand.Execute(null);
await OnTheSidebarAsync((sidebar, _) =>
{
sidebar.HostList.IsEffectivelyVisible.ShouldBeTrue();
sidebar.KeyboardTarget.Focus().ShouldBeTrue();
});
}
/// <remarks>
/// <para>
/// The strip along the sidebar's bottom edge with the question in it instead of the three buttons. Its
/// tallest shape is a host with a terminal open on it, which adds a disclosure the ordinary case has
/// not got — in a 268-pixel column whose middle is a list that has already taken every spare pixel.
/// </para>
/// <para>
/// Worth measuring rather than assuming, because this is the one card in the application a user cannot
/// scroll: the sidebar's only <c>ScrollViewer</c> is inside the host list, so a button pushed past the
/// bottom edge here would leave the question unanswerable in either direction.
/// </para>
/// </remarks>
[Fact]
public async Task TheHostSidebarFitsWithADeletionInQuestion()
{
vault.SelectedHost = vault.Hosts[0];
vault.SelectedHost.IsConnected = true;
vault.DeleteHostCommand.Execute(null);
vault.IsConfirmingDeletion.ShouldBeTrue();
vault.PendingDeletion.ShouldNotBeNull().HasUsage.ShouldBeTrue("the open terminal is the long shape");
await MeasureSidebarAsync(faults => faults.ShouldBeEmpty());
}
/// <remarks>
/// <para>
/// What a double-click on a machine does everywhere else, and did not do here: it opens a shell on it.
/// The gesture is wired in the control rather than bound in the markup, which is exactly the sort of
/// wiring that compiles whether or not it is connected to anything — so it is worth a test that
/// performs the gesture.
/// </para>
/// <para>
/// Proved through a connection that is refused before any network is involved. The host is left bound
/// to a key that has been deleted, which <c>TryBuildAuthentication</c> turns into a sentence on the
/// status line rather than a socket — so what this asserts is that the command ran, with nothing
/// timing out to make it flaky.
/// </para>
/// </remarks>
[Fact]
public async Task DoubleClickingAHostConnectsToIt()
{
var keyId = vault.Keys[0].EntityId;
vault.SelectedHost = vault.Hosts[0];
vault.EditSelectedHostCommand.Execute(null);
vault.EditorSelectedAuthentication = vault.EditorAuthenticationChoices
.Single(choice => choice.Kind is AuthenticationKind.SshKey && choice.EntityId == keyId);
await vault.SaveHostCommand.ExecuteAsync(null);
vault.SelectedKey = vault.Keys.Single(row => row.EntityId == keyId);
vault.DeleteKeyCommand.Execute(null);
await vault.ConfirmDeleteCommand.ExecuteAsync(null);
vault.SelectedHost = null;
vault.Status = string.Empty;
await OnTheSidebarAsync((sidebar, window) =>
{
var row = sidebar.HostList.GetVisualDescendants()
.OfType<ListBoxItem>()
.First();
var centre = row.TranslatePoint(
new Point(row.Bounds.Width / 2, row.Bounds.Height / 2), window)
?? throw new InvalidOperationException("the row is not in this window's tree");
window.MouseDown(centre, MouseButton.Left);
window.MouseUp(centre, MouseButton.Left);
window.MouseDown(centre, MouseButton.Left);
window.MouseUp(centre, MouseButton.Left);
Dispatcher.UIThread.RunJobs();
vault.SelectedHost.ShouldNotBeNull("a press on a row selects it");
vault.Status.ShouldContain(
"not in this keychain any more",
Case.Insensitive,
"the double-click has to reach the connect command");
});
}
// ---- The hosts screen ----
//
// Measurable for the first time. Every rectangle below lived in MainWindow.axaml until the terminal
// moved out from under it, and nothing in that window can be laid out here — so the connect banner, the
// two host key prompts and the conflict log had never been through this harness at all. They are also
// the four worst candidates for that: each appears only in a state somebody has to reproduce by hand.
[Fact]
public async Task TheHostsScreenFitsWithNothingToAnnounce()
{
await MeasureHostsAsync(faults => faults.ShouldBeEmpty("the ordinary shape"));
}
[Fact]
public async Task TheHostsScreenFitsWithAHostSelected()
{
vault.SelectedHost = vault.Hosts[0];
await MeasureHostsAsync(faults => faults.ShouldBeEmpty("with the overview showing a host"));
}
[Fact]
public async Task TheHostsScreenFitsWhileAHostKeyIsBeingApproved()
{
vault.PendingHostKey = new HostKeyPresentation(
"db.internal", 22, "ssh-ed25519", "SHA256:6dPPMHRQGYRSHXBEmqBBIQVMlBfsAcHRDbmfMPWtpvI");
await MeasureHostsAsync(faults => faults.ShouldBeEmpty("with the unknown-key prompt up"));
}
[Fact]
public async Task TheHostsScreenFitsWhileAHostKeyIsRefused()
{
vault.HostKeyMismatch =
"db.internal:22 presented ssh-ed25519 SHA256:8jkLPQ2mVvTnBqXfWzYc4RdEuHgNsA1oIpKlZbCxMv0, "
+ "and this keychain has SHA256:6dPPMHRQGYRSHXBEmqBBIQVMlBfsAcHRDbmfMPWtpvI pinned for it.";
await MeasureHostsAsync(faults => faults.ShouldBeEmpty("with the mismatch refusal up"));
}
/// <remarks>
/// Twenty, because one is not the case that broke. The log sits on an <c>Auto</c> row above the overview,
/// and an <c>ItemsControl</c> with no ceiling grows for as long as it has rows — so a pass that merged a
/// vault's worth of items pushed everything below it off the bottom of a screen with nothing to scroll.
/// It survived as long as it did because this markup was inside the window, where no test could reach it;
/// finding it is what the extraction was for. The fix is the <c>ScrollViewer</c> and <c>MaxHeight</c> in
/// <c>HostsScreen.axaml</c>, and this is what holds them there.
/// </remarks>
[Fact]
public async Task TheHostsScreenFitsWithAConflictLogTooLongToShow()
{
for (var i = 0; i < 20; i++)
{
vault.Conflicts.Add(new ConflictRowViewModel(new ConflictNotice(
Guid.CreateVersion7(),
Guid.CreateVersion7(),
ConflictKind.FieldOverridden,
$"'host-{i}' was changed on two machines, and the other machine's value was kept.",
[],
TimeProvider.System.GetUtcNow())));
}
await MeasureHostsAsync(faults => faults.ShouldBeEmpty("with twenty merged conflicts to report"));
}
/// <remarks>
/// The group panel is a row of its own at the foot of this screen, so it competes with the overview above
/// it for the same column — and it grows sideways as groups are added, which is the direction a
/// fixed-width column has least of. Six, because that is more than anybody's first three and enough to
/// need the horizontal scroller rather than to overflow silently.
/// </remarks>
[Fact]
public async Task TheHostsScreenFitsWithMoreGroupsThanTheRowHasRoomFor()
{
await SeedGroupsAsync(6);
await MeasureHostsAsync(faults => faults.ShouldBeEmpty("with six groups along the bottom"));
}
/// <remarks>
/// The question replaces the buttons rather than stacking under them — the same rule the sidebar's own
/// deletion follows — and it is the taller of the two, because it says how many hosts are about to move.
/// </remarks>
[Fact]
public async Task TheHostsScreenFitsWhileAGroupDeletionIsBeingConfirmed()
{
await SeedGroupsAsync(3);
vault.SelectedGroup = vault.Groups[0];
vault.DeleteGroupCommand.Execute(null);
vault.IsConfirmingGroupDeletion.ShouldBeTrue("the question has to be up for this to measure it");
await MeasureHostsAsync(faults => faults.ShouldBeEmpty("with the group question up"));
}
// ---- The vault screen ----
[Fact]
public async Task TheVaultScreenFitsInEveryCategory()
{
foreach (var section in new[]
{
VaultSection.All, VaultSection.Keys, VaultSection.Credentials,
})
{
vault.Section = section;
await MeasureVaultAsync(faults => faults.ShouldBeEmpty($"the {section} category"));
}
}
/// <remarks>
/// The tall one: a private key needs a real text area, and the vault screen's detail pane is 244 pixels
/// wide — the narrowest column any form in this application has to fit into.
/// </remarks>
[Fact]
public async Task TheVaultScreenFitsWithTheKeyEditorOpen()
{
vault.NewKeyCommand.Execute(null);
vault.IsEditingKey.ShouldBeTrue();
vault.ShowsKeys.ShouldBeTrue("opening an editor has to bring its own category into view");
vault.KeyEditorPrivateKey = string.Join(
'\n',
Enumerable.Repeat("b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gt", 6));
await MeasureVaultAsync(faults => faults.ShouldBeEmpty());
}
[Fact]
public async Task TheVaultScreenFitsWithThePasswordEditorOpen()
{
vault.NewCredentialCommand.Execute(null);
vault.IsEditingCredential.ShouldBeTrue();
vault.ShowsCredentials.ShouldBeTrue("opening an editor has to bring its own category into view");
await MeasureVaultAsync(faults => faults.ShouldBeEmpty());
}
/// <remarks>
/// The generate form, in the 244-pixel detail pane — two algorithm buttons side by side plus two
/// paragraphs of explanation, in the narrowest column in the application. The paragraphs are the risk:
/// they are what says the file has no passphrase, and a sentence pushed off the bottom is a limitation
/// nobody was told about.
/// </remarks>
[Fact]
public async Task TheVaultScreenFitsWithTheGenerateFormOpen()
{
vault.NewGeneratedKeyCommand.Execute(null);
vault.IsGeneratingKey.ShouldBeTrue();
await MeasureVaultAsync(faults => faults.ShouldBeEmpty());
}
/// <remarks>
/// Both drop highlights forced on at once, which is a state the screen never actually reaches — the
/// point is that an overlay covering a whole pane does not change the layout of anything beneath it.
/// It cannot check the thing most likely to be wrong, which is <c>IsHitTestVisible="False"</c>: an
/// overlay that hit-tests lays out identically and swallows the events that would clear it. That one is
/// in docs/manual-checks.md.
/// </remarks>
[Fact]
public async Task TheTransfersScreenFitsWithTheDropHighlightsShowing()
{
transfers.IsLocalDropTarget = true;
transfers.IsRemoteDropRefused = true;
await MeasureTransfersAsync(faults => faults.ShouldBeEmpty("with a drop in progress"));
}
// ---- The import screen ----
[Fact]
public async Task TheImportScreenFitsBeforeAnythingHasBeenScanned()
{
await MeasureImportAsync(faults => faults.ShouldBeEmpty("the state it opens in"));
}
/// <remarks>
/// The shape with something to decide about: a table of candidate hosts with tickboxes, a warning
/// block above it, and a footer carrying the sentence that says key files are not read. That sentence
/// is the one that must not be pushed off the bottom — it is the difference between an import somebody
/// understands and one they think is broken.
/// </remarks>
[Fact]
public async Task TheImportScreenFitsWithHostsToChooseFromAndWarnings()
{
await MeasureImportAsync(
faults => faults.ShouldBeEmpty("with a scanned list"),
await ScannedImportAsync());
}
// ---- The host keys screen ----
[Fact]
public async Task TheHostKeysScreenFitsWithNothingApprovedYet()
{
foreach (var pin in vault.KnownHostPins.ToList())
{
await knownHosts.ForgetAsync(pin.Host, pin.Port, Token);
}
await vault.LoadAsync(Token);
vault.KnownHostPins.ShouldBeEmpty();
await MeasurePinsAsync(faults => faults.ShouldBeEmpty("the empty state"));
}
/// <remarks>
/// The shape the column widths were chosen for. A fingerprint is never trimmed — comparing a shortened
/// one against a published one is not something anybody can do — so this table has one column that
/// refuses to give ground, and this is what says the rest still fits beside it.
/// </remarks>
[Fact]
public async Task TheHostKeysScreenFitsWithPinsAndOneSelected()
{
var pins = new KnownHostsViewModel(vault);
pins.VisiblePins.ShouldNotBeEmpty("an empty list is the easy case and proves nothing here");
pins.Selected = pins.VisiblePins[0];
await MeasurePinsAsync(faults => faults.ShouldBeEmpty("with a pin selected"), pins);
}
[Fact]
public async Task TheHostKeysScreenFitsWhenTheFilterMatchesNothing()
{
var pins = new KnownHostsViewModel(vault) { Filter = "no such fingerprint" };
pins.VisiblePins.ShouldBeEmpty();
await MeasurePinsAsync(faults => faults.ShouldBeEmpty("with the filter matching nothing"), pins);
}
// ---- The logs screen ----
[Fact]
public async Task TheLogsScreenFitsWithNeitherLogWrittenTo()
{
await MeasureLogsAsync(faults => faults.ShouldBeEmpty("the empty state"), LogSection.Connections);
}
/// <remarks>
/// Six columns in one row, and the two widest — an address and a device name — are both variable. A
/// connection still open is measured alongside the finished ones because its row carries the longest
/// value the LASTED column ever holds: the words "still open" rather than a duration.
/// </remarks>
[Fact]
public async Task TheConnectionLogFitsWithALiveRowAndAFinishedOne()
{
var logs = await SeedLogsAsync();
logs.Connections.ShouldNotBeEmpty();
logs.Connections.Any(row => row.IsLive).ShouldBeTrue("the live row is the wide one");
await MeasureLogsAsync(
faults => faults.ShouldBeEmpty("with a live connection above a finished one"),
LogSection.Connections,
logs);
}
/// <remarks>
/// The FIELDS column is the one that grows: it is a list of names, and a host has eleven of them.
/// Measured with an edit that touched several, because one field name fits anywhere.
/// </remarks>
[Fact]
public async Task TheActivityLogFitsWithAnEditThatTouchedSeveralFields()
{
var logs = await SeedLogsAsync();
logs.Section = LogSection.Activity;
logs.Activity.ShouldNotBeEmpty();
await MeasureLogsAsync(
faults => faults.ShouldBeEmpty("with the keychain log showing"), LogSection.Activity, logs);
}
// ---- The snippets screen ----
[Fact]
public async Task TheSnippetsScreenFitsWithNothingSavedYet()
{
vault.Snippets.ShouldBeEmpty("the seed makes none, which is what a new keychain looks like");
await MeasureSnippetsAsync(faults => faults.ShouldBeEmpty("the empty state"));
}
/// <remarks>
/// The detail pane's longest shape: a multi-line command in a box, its notes, two buttons and the
/// paragraph saying what a terminal will do with it — in a 300-pixel column. Measured with a snippet
/// that runs, because that is the one with the extra button.
/// </remarks>
[Fact]
public async Task TheSnippetsScreenFitsWithAMultiLineSnippetSelected()
{
await SeedSnippetsAsync();
var snippets = NewSnippetsScreen(new InsertTarget(1, "prod-db"));
snippets.Selected = snippets.Visible.Single(row => row.RunsOnInsert);
await MeasureSnippetsAsync(faults => faults.ShouldBeEmpty("with a running snippet selected"), snippets);
}
/// <remarks>
/// The editor, which is the tallest thing on this screen: a name, a 140-pixel command box, notes, the
/// checkbox and the paragraph explaining what leaving it off buys.
/// </remarks>
[Fact]
public async Task TheSnippetsScreenFitsWithItsEditorOpen()
{
await SeedSnippetsAsync();
var snippets = NewSnippetsScreen();
snippets.Selected = snippets.Visible[0];
snippets.EditCommand.Execute(null);
snippets.IsEditing.ShouldBeTrue();
await MeasureSnippetsAsync(faults => faults.ShouldBeEmpty("with the editor open"), snippets);
}
[Fact]
public async Task TheSnippetsScreenFitsWhenTheFilterMatchesNothing()
{
await SeedSnippetsAsync();
var snippets = NewSnippetsScreen();
snippets.Filter = "no such command";
snippets.Visible.ShouldBeEmpty();
await MeasureSnippetsAsync(faults => faults.ShouldBeEmpty("with the filter matching nothing"), snippets);
}
/// <remarks>
/// The detail pane with the question in place of EDIT and DELETE, in its longest shape: a key several
/// hosts authenticate with, which is three sentences and a box in the narrowest column in the
/// application.
/// </remarks>
[Fact]
public async Task TheVaultScreenFitsWithADeletionInQuestion()
{
var keyId = vault.Keys[0].EntityId;
foreach (var host in vault.Hosts.Take(4).ToList())
{
vault.SelectedHost = host;
vault.EditSelectedHostCommand.Execute(null);
vault.EditorSelectedAuthentication = vault.EditorAuthenticationChoices
.Single(choice => choice.Kind is AuthenticationKind.SshKey && choice.EntityId == keyId);
await vault.SaveHostCommand.ExecuteAsync(null);
}
vault.Section = VaultSection.Keys;
vault.SelectedVaultItem = vault.VaultItems.Single(row => row.EntityId == keyId);
vault.DeleteSelectedItemCommand.Execute(null);
vault.PendingDeletion.ShouldNotBeNull().HasUsage
.ShouldBeTrue("four bound hosts are what makes this the long shape");
await OnTheVaultAsync((screen, window) =>
{
LayoutHarness.Unreachable(window).ShouldBeEmpty();
// And it says something. A card whose bindings did not resolve would lay out perfectly as three
// empty rows, which is the one failure a fit test cannot see: compiled bindings against the
// wrong data type are a logged message rather than an exception.
var card = screen.GetVisualDescendants().OfType<ConfirmDeleteCard>().ShouldHaveSingleItem();
var said = string.Join(
" ",
card.GetVisualDescendants().OfType<TextBlock>().Select(text => text.Text));
said.ShouldContain("key-0", Case.Insensitive, "the question has to name what is going");
said.ShouldContain("4 hosts authenticate with it");
said.ShouldContain("no undo");
});
}
/// <remarks>
/// The rail is the only way to reach a category, so a button that lands on nothing walls off three
/// quarters of the screen. The fit tests above prove the buttons are inside the window; this proves they
/// are the size a pointer can find, which a zero-height row in a collapsed border would not be.
/// </remarks>
[Fact]
public async Task TheCategoryRailIsBigEnoughToClick()
{
await OnTheVaultAsync((screen, _) =>
{
var buttons = screen.GetVisualDescendants()
.OfType<Button>()
.Where(button => button.Classes.Contains("cat"))
.ToList();
buttons.Count.ShouldBe(4, "one per category that exists");
foreach (var button in buttons)
{
button.Bounds.Height.ShouldBeGreaterThan(20);
button.Bounds.Width.ShouldBeGreaterThan(120);
}
});
}
// ---- The transfers screen ----
/// <remarks>
/// <para>
/// The widest thing in this window and the one with the least room to give: two file listings side by
/// side, each with four columns, and a queue underneath — all inside 826 pixels once the nav rail has
/// taken its column. The header row is the tight part, because it holds a host picker, a password box,
/// a button and a chip on one line.
/// </para>
/// <para>
/// Measured disconnected, which is the state the screen opens in and the one where the local pane is at
/// its fullest: it lists this machine's home directory, so the row template is exercised with real names
/// of real length rather than with fixtures chosen to fit.
/// </para>
/// </remarks>
[Fact]
public async Task TheTransfersScreenFitsBeforeAnythingIsConnected()
{
await MeasureTransfersAsync(faults => faults.ShouldBeEmpty());
}
/// <remarks>
/// <para>
/// The queue is the half of this screen that only exists once something has been asked for, so a shape
/// nothing puts a row into is a shape never laid out. Three rows, because the row template changes with
/// the state: a running one shows a bar and a STOP, a stopped one shows RESUME and DISCARD, and a failed
/// one carries the server's own sentence in the column the other two put a byte count in.
/// </para>
/// <para>
/// The rows are placed directly rather than driven through the queue. What is being measured is the
/// template at each state, and running a real transfer to reach those states would put a thread-pool
/// hand-off and a filesystem in the middle of a test about rectangles. What the queue does is measured in
/// <c>DodoSSH.Client.Transfer.Tests</c>.
/// </para>
/// </remarks>
[Fact]
public async Task TheTransfersScreenFitsWithTransfersInTheQueue()
{
Enqueue(TransferDirection.Download, "artefact.tar.gz", 402_653_184, 149_000_000,
TransferState.Running, bytesPerSecond: 6_500_000);
Enqueue(TransferDirection.Upload, "site-backup-2026-07-30.sql.gz", 8_100_000_000, 3_200_000_000,
TransferState.Cancelled);
Enqueue(TransferDirection.Upload, "deploy.sh", 4_096, 0, TransferState.Failed,
failure: "deploy.sh is already in that directory on the host. Rename or remove it first — "
+ "nothing here overwrites a file that is already there.");
transfers.Transfers.Count.ShouldBe(3);
await MeasureTransfersAsync(faults => faults.ShouldBeEmpty());
}
/// <remarks>
/// The trust card covers the whole screen, and it is the one thing here a user cannot get past without
/// pressing something — so a button of its own that fell outside the window would leave the screen
/// permanently blocked.
/// </remarks>
[Fact]
public async Task TheTransfersScreenFitsWithTheHostKeyCardShowing()
{
transfers.PendingHostKey = new HostKeyPresentation(
"db.internal", 22, "ssh-ed25519", "SHA256:0123456789abcdefghijklmnopqrstuvwxyzABCDEFG");
await MeasureTransfersAsync(faults => faults.ShouldBeEmpty());
}
/// <remarks>
/// The question in front of deleting something on the host, which takes a row out of the remote pane's
/// column while the listing under it is still showing. A directory, because that is the longer of the
/// two warnings, and a path deep enough to wrap in a pane a third of the window wide.
/// </remarks>
[Fact]
public async Task TheTransfersScreenFitsWithADeletionInQuestion()
{
transfers.PendingRemoteDeletion = new RemoteDeletionRequest(
"2026-07-30",
"/srv/releases/site/backups/nightly/2026-07-30",
IsDirectory: true);
await MeasureTransfersAsync(faults => faults.ShouldBeEmpty());
}
// ---- The chrome ----
/// <remarks>
/// <para>
/// The two constants the whole height budget is subtracted from, held against the markup that declares
/// them. If either bar grows, every screen gets less room than this suite thinks it does and every
/// measurement above quietly becomes optimistic.
/// </para>
/// <para>
/// Laid out with no data context, which is the point: these are fixed-height strips and their geometry
/// must not depend on what is bound into them. A binding that made one of them grow with its contents
/// would fail here.
/// </para>
/// </remarks>
[Fact]
public async Task TheChromeIsTheHeightTheBudgetAssumes()
{
await LayoutHarness.OnTheUiThreadAsync(
() =>
{
var titleBar = new TitleBar();
var titleWindow = LayoutHarness.HostAtMinimumSize(
titleBar, LayoutHarness.MinimumWidth, LayoutHarness.TitleBarHeight);
try
{
titleBar.Bounds.Height.ShouldBe(LayoutHarness.TitleBarHeight);
LayoutHarness.Unreachable(titleWindow).ShouldBeEmpty();
}
finally
{
titleWindow.Close();
}
var statusBar = new StatusBar();
var statusWindow = LayoutHarness.HostAtMinimumSize(
statusBar, LayoutHarness.MinimumWidth, LayoutHarness.StatusBarHeight);
try
{
statusBar.Bounds.Height.ShouldBe(LayoutHarness.StatusBarHeight);
}
finally
{
statusWindow.Close();
}
},
Token);
}
/// <remarks>
/// Eight destinations in a 54-pixel column. The rail runs vertically, so what runs out here is height
/// rather than width — at the window's minimum the entries have to leave room for each other, which is
/// the same failure the old four-button selector was one label away from. It got tighter when the host
/// keys left the keychain screen and became a destination of their own, and tighter again with snippets
/// and then the logs — which is why the count is asserted rather than left to the fit check: an entry
/// silently dropping off the bottom would still pass every other assertion here.
/// </remarks>
[Fact]
public async Task TheNavRailHoldsEightDestinationsAtTheWindowsMinimum()
{
await LayoutHarness.OnTheUiThreadAsync(
() =>
{
var rail = new NavRail();
var window = LayoutHarness.HostAtMinimumSize(
rail, LayoutHarness.NavRailWidth, LayoutHarness.ScreenHeight);
try
{
var buttons = rail.GetVisualDescendants().OfType<Button>().ToList();
buttons.Count.ShouldBe(8, "one per screen the rail reaches");
foreach (var button in buttons)
{
button.Bounds.Height.ShouldBeGreaterThan(20);
// One pixel narrower than the rail, because the rail draws its own divider down its
// right edge and that comes out of the content. Stated exactly rather than as a
// lower bound: a button that stopped filling the rail would leave a dead strip
// beside every destination, which is precisely the kind of near-miss a bound hides.
button.Bounds.Width.ShouldBe(LayoutHarness.NavRailWidth - 1);
}
LayoutHarness.Unreachable(window).ShouldBeEmpty();
}
finally
{
window.Close();
}
},
Token);
}
// ---- The unlock screen ----
/// <remarks>
/// <para>
/// The card a locked application is entirely made of, in its two shapes: an ordinary launch, and one
/// where shells were left running and the disclosure about them appears. It was extracted from
/// <c>MainWindow.axaml</c> to be measurable at all — that window cannot be shown here, so anything
/// inside it is unmeasured by construction — and it is the card with the least room to spare.
/// </para>
/// <para>
/// The status line is set to something long on purpose. It is bound to whatever the last thing that
/// happened said, and the longest of those is a sentence about an expired sign-in, which is exactly the
/// message this screen is most likely to be carrying on the launch where the extra rows also appear.
/// </para>
/// </remarks>
[Theory]
[InlineData(0)]
[InlineData(2)]
public async Task TheUnlockCardFitsTheCardItIsShownIn(int liveSessions)
{
shell.LiveSessionCount = liveSessions;
shell.CanUnlockWithDevice = true;
shell.StatusMessage = "Your sign-in has expired, so this machine is offline: the token endpoint "
+ "returned 400: Invalid refresh token. Sign in again from Preferences to start syncing.";
await MeasureCardAsync(static () => new UnlockCard());
}
[Fact]
public async Task TheUnlockBoxTakesEnterAsUnlock()
{
// Enter is how everybody finishes typing a password, and this screen had no answer to it until the
// gesture below existed: the passphrase box is where locking puts the keyboard, so the one thing a
// user does without thinking did nothing at all until they found the button.
//
// The gesture is what can be asserted; that pressing it unlocks is ShellFlowTests' business,
// against the command this binds to.
await LayoutHarness.OnTheUiThreadAsync(
() =>
{
var card = new UnlockCard { DataContext = shell };
var window = LayoutHarness.HostAtMinimumSize(
card, LayoutHarness.CardContentWidth, LayoutHarness.CardContentHeight);
try
{
var binding = card.PassphraseBox.KeyBindings.ShouldHaveSingleItem();
binding.Gesture.ShouldBe(new KeyGesture(Key.Enter));
binding.Command.ShouldBeSameAs(shell.UnlockCommand);
}
finally
{
window.Close();
}
},
Token);
}
// ---- The sign-out confirmation ----
/// <remarks>
/// <para>
/// The one new card that has to share a screen with an unlock prompt, and the only one whose height
/// depends on what it is saying: the warning is a sentence about the outbox, and the disclosure about
/// shells left running appears only when there are some. Both are wrapped paragraphs, which is the
/// shape that grows.
/// </para>
/// <para>
/// Measured in the space a card gives its contents rather than inside <c>MainWindow</c>, which cannot
/// be laid out here — see <c>LayoutHarnessTests.WhyTheWindowItselfIsNeverShown</c>. What that leaves
/// unchecked is the card's own frame, which is a fixed border and a constant padding.
/// </para>
/// </remarks>
[Fact]
public async Task TheSignOutCardFitsTheCardItIsShownIn()
{
// Its tallest shape: a shell left running adds a disclosure box that an ordinary sign-out does not
// have, an open transfer session adds a line beneath it, and a locked vault carries the longer of
// the two warnings.
shell.LiveSessionCount = 1;
shell.Transfers.IsConnected = true;
await MeasureCardAsync(static () => new SignOutCard());
}
/// <summary>Lays a setup-screen card out in the space <c>Border.card</c> gives its contents.</summary>
/// <remarks>
/// The card is <em>built</em> inside the dispatched call rather than passed in already constructed, and
/// that is not style. Avalonia binds <c>Dispatcher.UIThread</c> to whichever thread first asks for it, so
/// a control constructed on the test thread before any other test has dispatched makes that thread the
/// UI thread — and every later property set from the harness's own thread then throws. It depends on the
/// order the tests happen to run in, which is why it survived until a phase that added new ones.
/// </remarks>
private Task MeasureCardAsync(Func<Control> build) =>
LayoutHarness.OnTheUiThreadAsync(
() =>
{
var card = build();
card.DataContext = shell;
var window = LayoutHarness.HostAtMinimumSize(
card, LayoutHarness.CardContentWidth, LayoutHarness.CardContentHeight);
try
{
LayoutHarness.Unreachable(window).ShouldBeEmpty();
}
finally
{
window.Close();
}
},
Token);
// ---- Helpers ----
/// <summary>Lays the sidebar out at the width the hosts screen gives it.</summary>
private Task MeasureSidebarAsync(Action<IReadOnlyList<string>> assert) =>
OnTheSidebarAsync((_, window) => assert(LayoutHarness.Unreachable(window)));
private Task OnTheSidebarAsync(Action<HostSidebar, Window> body) =>
LayoutHarness.OnTheUiThreadAsync(
() =>
{
var sidebar = new HostSidebar { DataContext = vault };
var window = LayoutHarness.HostAtMinimumSize(
sidebar, LayoutHarness.HostSidebarWidth, LayoutHarness.ScreenHeight);
try
{
body(sidebar, window);
}
finally
{
window.Close();
}
},
Token);
/// <summary>Lays the hosts screen out at the size it gets beside the nav rail and under the strip.</summary>
/// <remarks>
/// The shell is the data context, not the vault — the sidebar is handed the vault from inside the
/// screen's own markup. <see cref="MainWindowViewModel.Vault"/> is assigned rather than reached through
/// an unlock, which would be a second enrollment for no extra rectangle.
/// </remarks>
private Task MeasureHostsAsync(Action<IReadOnlyList<string>> assert) =>
LayoutHarness.OnTheUiThreadAsync(
() =>
{
shell.Vault = vault;
shell.State = ShellState.Unlocked;
var screen = new HostsScreen { DataContext = shell };
var window = LayoutHarness.HostAtMinimumSize(
screen, LayoutHarness.ScreenWidth, LayoutHarness.ScreenHeight);
try
{
assert(LayoutHarness.Unreachable(window));
}
finally
{
window.Close();
}
},
Token);
/// <summary>Lays the import screen out at the size it gets beside the nav rail.</summary>
private Task MeasureImportAsync(
Action<IReadOnlyList<string>> assert,
ImportViewModel? import = null) =>
LayoutHarness.OnTheUiThreadAsync(
() =>
{
var screen = new ImportScreen
{
DataContext = import ?? new ImportViewModel(vault, new SshConfigLocator()),
};
var window = LayoutHarness.HostAtMinimumSize(
screen, LayoutHarness.ScreenWidth, LayoutHarness.ScreenHeight);
try
{
assert(LayoutHarness.Unreachable(window));
}
finally
{
window.Close();
}
},
Token);
/// <summary>
/// An import view model that has scanned a real file, so the table has rows in it.
/// </summary>
/// <remarks>
/// Through a temporary directory rather than by populating the rows directly, because the shape being
/// measured is what the parser produces — an entry with two warnings under it is taller than one
/// without, and inventing the rows would measure a layout nothing generates.
/// </remarks>
private async Task<ImportViewModel> ScannedImportAsync()
{
var directory = Path.Combine(Path.GetTempPath(), $"dodossh-import-{Guid.CreateVersion7():N}");
Directory.CreateDirectory(directory);
try
{
await File.WriteAllTextAsync(
Path.Combine(directory, "config"),
"""
Host *
ServerAliveInterval 30
Host prod-db
HostName database.production.internal
User deploy
Port 2222
IdentityFile ~/.ssh/id_ed25519
Host bastion-eu-west-1
HostName bastion.eu-west-1.example.com
User ops
ProxyCommand nc %h %p
Compression yes
compression no
Match host anything
User root
""");
var import = new ImportViewModel(vault, new SshConfigLocator(directory));
// Awaited, not fired. ScanCommand reads a file, so executing without awaiting measures an empty
// table — which is the other test.
await import.ScanCommand.ExecuteAsync(null);
import.HasRows.ShouldBeTrue("the fixture has hosts in it");
import.HasWarnings.ShouldBeTrue("the fixture has a Match block and a wildcard block");
return import;
}
finally
{
Directory.Delete(directory, recursive: true);
}
}
/// <summary>Lays the host keys screen out at the size it gets beside the nav rail.</summary>
private Task MeasurePinsAsync(
Action<IReadOnlyList<string>> assert,
KnownHostsViewModel? pins = null) =>
LayoutHarness.OnTheUiThreadAsync(
() =>
{
var screen = new KnownHostsScreen { DataContext = pins ?? new KnownHostsViewModel(vault) };
var window = LayoutHarness.HostAtMinimumSize(
screen, LayoutHarness.ScreenWidth, LayoutHarness.ScreenHeight);
try
{
assert(LayoutHarness.Unreachable(window));
}
finally
{
window.Close();
}
},
Token);
/// <summary>Lays the logs screen out at the size it gets beside the nav rail.</summary>
private Task MeasureLogsAsync(
Action<IReadOnlyList<string>> assert,
LogSection section,
LogsViewModel? logs = null) =>
LayoutHarness.OnTheUiThreadAsync(
() =>
{
var model = logs ?? NewLogsScreen();
model.Section = section;
var screen = new LogsScreen { DataContext = model };
var window = LayoutHarness.HostAtMinimumSize(
screen, LayoutHarness.ScreenWidth, LayoutHarness.ScreenHeight);
try
{
assert(LayoutHarness.Unreachable(window));
}
finally
{
window.Close();
}
},
Token);
private LogsViewModel NewLogsScreen(params LiveConnection[] live) =>
new(session, () => live);
/// <summary>
/// Writes one of each kind of entry and reads them back.
/// </summary>
/// <remarks>
/// Through the repositories the recorders write to, rather than through the recorders themselves: those
/// write on a background task on purpose, and a layout suite that waited on one would be measuring
/// rectangles behind a race.
/// </remarks>
private async Task<LogsViewModel> SeedLogsAsync()
{
await session.ConnectionLog.CreateAsync(
session.ActiveVaultId,
new ConnectionLogSecret
{
HostLabel = "customer-a-production-database",
Address = "deployment-account@db-01.customer-a.internal:22022",
StartedAt = new DateTimeOffset(2026, 7, 30, 9, 15, 0, TimeSpan.Zero),
Duration = TimeSpan.FromMinutes(74),
Outcome = ConnectionOutcome.Refused,
DeviceName = "jaap-jan-workstation",
},
Token);
await session.ActivityLog.CreateAsync(
session.ActiveVaultId,
new ActivityLogSecret
{
ItemKind = "Host",
ItemId = Guid.CreateVersion7(),
ItemLabel = "customer-a-production-database",
Operation = ActivityOperation.Updated,
ChangedFields = "Hostname, Port, Username, Options, Group",
At = new DateTimeOffset(2026, 7, 30, 9, 15, 0, TimeSpan.Zero),
DeviceName = "jaap-jan-workstation",
},
Token);
var logs = NewLogsScreen(new LiveConnection(
"customer-a-production-database",
"deployment-account@db-01.customer-a.internal:22022",
new DateTimeOffset(2026, 7, 31, 8, 0, 0, TimeSpan.Zero),
"jaap-jan-workstation"));
await logs.ReloadAsync(Token);
return logs;
}
/// <summary>Lays the snippets screen out at the size it gets beside the nav rail.</summary>
/// <remarks>
/// The insert function throws. Nothing measured here presses a button, and a substitute that returned a
/// plausible answer would make it possible to write a layout test that quietly exercised the transport.
/// </remarks>
private Task MeasureSnippetsAsync(
Action<IReadOnlyList<string>> assert,
SnippetsViewModel? snippets = null) =>
LayoutHarness.OnTheUiThreadAsync(
() =>
{
var screen = new SnippetsScreen { DataContext = snippets ?? NewSnippetsScreen() };
var window = LayoutHarness.HostAtMinimumSize(
screen, LayoutHarness.ScreenWidth, LayoutHarness.ScreenHeight);
try
{
assert(LayoutHarness.Unreachable(window));
}
finally
{
window.Close();
}
},
Token);
private SnippetsViewModel NewSnippetsScreen(InsertTarget? target = null) =>
new(
vault,
() => target ?? InsertTarget.None,
static (_, _, _, _) => throw new InvalidOperationException("A layout test inserts nothing."));
/// <summary>Lays the transfers screen out at the width it gets beside the nav rail.</summary>
private Task MeasureTransfersAsync(Action<IReadOnlyList<string>> assert) =>
LayoutHarness.OnTheUiThreadAsync(
() =>
{
var screen = new TransfersScreen { DataContext = transfers };
var window = LayoutHarness.HostAtMinimumSize(
screen, LayoutHarness.ScreenWidth, LayoutHarness.ScreenHeight);
try
{
assert(LayoutHarness.Unreachable(window));
}
finally
{
window.Close();
}
},
Token);
/// <summary>Puts one transfer on the queue in a given state, without moving a byte.</summary>
private void Enqueue(
TransferDirection direction,
string name,
long length,
long transferred,
TransferState state,
double bytesPerSecond = 0,
string? failure = null) =>
transfers.Transfers.Add(new TransferRowViewModel(new TransferSnapshot(
Guid.CreateVersion7(),
direction,
name,
Path.Combine(Path.GetTempPath(), name),
SftpPath.Combine("/srv/releases", name),
length,
transferred,
state,
bytesPerSecond,
failure)));
/// <summary>Lays the vault screen out at the width it gets once the nav rail has taken its column.</summary>
private Task MeasureVaultAsync(Action<IReadOnlyList<string>> assert) =>
OnTheVaultAsync((_, window) => assert(LayoutHarness.Unreachable(window)));
private Task OnTheVaultAsync(Action<VaultScreen, Window> body) =>
LayoutHarness.OnTheUiThreadAsync(
() =>
{
var screen = new VaultScreen { DataContext = vault };
var window = LayoutHarness.HostAtMinimumSize(
screen, LayoutHarness.ScreenWidth, LayoutHarness.ScreenHeight);
try
{
body(screen, window);
}
finally
{
window.Close();
}
},
Token);
/// <remarks>
/// Enough rows in every list that none is empty, because an empty list is the easiest case and the one
/// least worth certifying.
/// </remarks>
private async Task SeedAsync()
{
for (var i = 0; i < 6; i++)
{
vault.NewHostCommand.Execute(null);
vault.EditorLabel = $"host-{i}";
vault.EditorHostname = $"host-{i}.internal";
vault.EditorUsername = "deploy";
await vault.SaveHostCommand.ExecuteAsync(null);
}
for (var i = 0; i < 4; i++)
{
vault.NewKeyCommand.Execute(null);
vault.KeyEditorLabel = $"key-{i}";
vault.KeyEditorPrivateKey =
$"-----BEGIN OPENSSH PRIVATE KEY-----\nMATERIAL-{i}\n-----END OPENSSH PRIVATE KEY-----\n";
await vault.SaveKeyCommand.ExecuteAsync(null);
}
for (var i = 0; i < 3; i++)
{
vault.NewCredentialCommand.Execute(null);
vault.CredentialEditorLabel = $"credential-{i}";
vault.CredentialEditorPassword = $"password-{i}";
vault.CredentialEditorUsername = $"account-{i}";
await vault.SaveCredentialCommand.ExecuteAsync(null);
}
// Pins come from approving a fingerprint at connect time, not from an editor, so they are seeded
// through the store the connect path writes to. Two for one endpoint, because a host offering keys
// of two algorithms is ordinary and the duplicate is one of the things this list has to show.
foreach (var (host, algorithm) in new[]
{
("host-0.internal", "ssh-ed25519"),
("host-0.internal", "ecdsa-sha2-nistp256"),
("gone.internal", "ssh-ed25519"),
})
{
await knownHosts.TrustAsync(
new HostKeyPresentation(
host, 22, algorithm, $"SHA256:{algorithm}-fingerprint-0123456789abcdefghijklmnop"),
Token);
}
// Back to where the vault screen opens, so every test starts from the state a user would see.
vault.Section = VaultSection.All;
await vault.LoadAsync(Token);
}
/// <summary>
/// Adds snippets, including the two shapes that decide this screen's height.
/// </summary>
/// <remarks>
/// Not part of <see cref="SeedAsync"/>, so the empty state stays measurable — and because most keychains
/// have none, which is the shape somebody sees the first time they open the screen.
/// </remarks>
private async Task SeedSnippetsAsync()
{
await vault.SaveSnippetAsync(
null,
new SnippetSecret
{
Label = "tail the application log",
Command = "sudo journalctl -u dodossh-api -f --since '10 minutes ago'",
Notes = "Ctrl+C to stop.",
},
Token);
await vault.SaveSnippetAsync(
null,
new SnippetSecret
{
Label = "restart the api",
Command = "sudo systemctl daemon-reload\nsudo systemctl restart dodossh-api\nsystemctl status dodossh-api --no-pager",
Notes = "Check the on-call rota before running this in production.",
RunsOnInsert = true,
},
Token);
vault.Snippets.Count.ShouldBe(2);
}
/// <summary>
/// Adds groups and files the seeded hosts across them.
/// </summary>
/// <remarks>
/// Not part of <see cref="SeedAsync"/>, on purpose. A vault with no groups is what a new one is and what
/// most of them stay, and it is the shape in which the sidebar draws no headings at all — so it has to
/// remain the one every other test here measures.
/// </remarks>
private async Task SeedGroupsAsync(int count)
{
for (var i = 0; i < count; i++)
{
vault.GroupEditorLabel = $"customer-{i}-production";
await vault.SaveGroupCommand.ExecuteAsync(null);
}
vault.Groups.Count.ShouldBe(count);
// Filed through the host editor, which is the only way a user can do it, so this also exercises the
// picker the sidebar's headings are built out of.
for (var i = 0; i < vault.Hosts.Count; i++)
{
vault.SelectedHost = vault.Hosts[i];
vault.EditSelectedHostCommand.Execute(null);
vault.EditorSelectedGroup = vault.EditorGroupChoices
.First(choice => choice.EntityId == vault.Groups[i % count].EntityId);
await vault.SaveHostCommand.ExecuteAsync(null);
}
}
}