Problem/Motivation

Current suites test controller calls and suppression helpers well but do not prove the full HTTP routing/proxy path, actual mail-manager transport prevention, form permissions/escaping or Drush command discovery. CI covers PostgreSQL and two Drupal/PHP combinations.

Evidence and scope

Reviewed 1.0.0-alpha1, source commit 02fd9d36af5237e712cecb7155d79725f7824880. Location: tests/src/Kernel/PostmarkWebhookAuthTest.php.

Coverage assessment; passing kernel tests do not establish these integration properties.

Proposed resolution

Add a focused end-to-end contract suite using official synthetic webhook fixtures and fake transports. Verify Basic Auth through routing, admin permission/CSRF, no-secret page source, real command registration and installation/upgrade behavior. Include supported database coverage based on project policy.

Acceptance criteria

Tests must fail when transport is reached for a suppressed recipient, route authentication disappears, or secrets render. Add browser checks for the small admin UI at narrow widths and keyboard use. Keep expensive provider/network tests optional and avoid duplicating helper assertions.

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

Assigned: Unassigned » jmcerda
Status: Active » Needs review

The integration coverage is implemented across the prerequisite slices and final contract suite. Tests now exercise real routed Basic Auth, retry handling for synthetic bounce/complaint/subscription fixtures, transport prevention through core mail and Mailer Plus, form access and CSRF, cached form resubmission, upgrades, and actual Drush discovery/JSON output. A separately installed HTTP fixture verifies /subdirectory endpoint generation and authenticated access.

The six-job PostgreSQL matrix covers Drupal 10.3/PHP 8.3 and Drupal 11/PHP 8.4, with Mailer Plus 1.6.2 and 2.0.2. The initial complete matrix passed; a fixture-hardening follow-up adds explicit file-read assertions and server cleanup. Its focused HTTP suite passes 3 tests and 39 assertions.

Browser checks at 375 x 812 covered settings, preview, inspector, recovery confirmation, export and erasure review. Keyboard navigation, labels and repeated submissions were checked; form-cache and narrow-input issues found during verification were fixed. This does not claim a full screen-reader or production-theme audit. All code remains pending final integration and release.

  • jmcerda committed be0a3e09 on 1.x
    Issue #3621137: Consolidate validation release notes
    

  • jmcerda committed df59bfe9 on 1.x
    Issue #3621137: Prepare 1.0.0-alpha2 release notes and upgrade guidance
    

  • jmcerda committed a6d79e88 on 1.x
    Issue #3621137: Harden integration fixture failures and server cleanup
    

  • jmcerda committed 233e0ec5 on 1.x
    Issue #3621137: Verify subdirectory HTTP and responsive operator...
jmcerda’s picture

Status: Needs review » Fixed

Integrated into the 1.x development branch and included in 1.0.0-alpha2. The release tag and branch are mirrored to Drupalcode. The six-job Drupal 10/11 and Mailer Plus integration matrix passes. See the release notes for database updates and retained-history limitations. This records module publication; site deployment is a separate operation.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.