Skip to content

Aurora add-on polish: own login page, Quanta theme, CI and acceptance tests (#132, phase 4) - #136

Draft
sneridagh wants to merge 3 commits into
issue-132-phase-3from
issue-132-phase-4
Draft

sneridagh wants to merge 3 commits into
issue-132-phase-3from
issue-132-phase-4

Conversation

@sneridagh

@sneridagh sneridagh commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Fourth phase of #132, stacked on #135. Draft: please don't merge. Each phase gets its own PR, built on the previous one, and none is merged until the whole series has been reviewed.

The polish pass on the Aurora add-on: Aurora 1.0.0-alpha.16, a login page offering the same choices as Volto's, Aurora's theme and icons, CI, and an end-to-end test of a real sign-in.

Aurora 1.0.0-alpha.16

Upgraded following Aurora's upgrade guides (docs/upgrade-guide/plone-aurora.md and plone-components.md in its checkout). The changelogs list breaking changes for @plone/components only, and the guides cover all of them.

Change Done here
Quanta components moved to @plone/quanta Link imported from there
Icons moved to @plone/icons @plone/icons/svg/*.svg?react; types.d.ts imports @plone/icons/svg
@plone/components needs @plone/icons built first The harness's build-deps and build:deps build icons and quanta first

alpha.16 also fixes the server not loading translations. The dev server used to render raw keys (cmsui.auth.signInTo), and React replaced the page on hydration. Phase 3 had noted this as Aurora's dev-only hydration mismatch. The login page now arrives translated.

Aurora's /login, rendered by the add-on

Aurora's login page draws a password form and offers the loginActions slot inside that <Form>. The add-on's ways in are forms of their own, and a form inside a form is not HTML. Aurora's registry can add a route but not replace one. So lib/routes.ts swaps the file @plone/cmsui registers for /login, keeping the route's path and its place under Aurora's layout.

Piece What it does
routes/login.tsx Aurora's frame (close link, loginLogo and loginHero slots, heading) around core's LoginForm, the one Volto shows
Loader Lists the providers server-side, decides both switches, honours ?choose
Action Password sign-in (@login) and sending a magic link (@magic-link), called from the server through the virtual-host URL, like the callback route
lib/settings.ts IDENTITY_SHOW_PLONE_LOGIN and IDENTITY_REDIRECT_TO_SOLE_PROVIDER, over config.settings.identity, with Volto's defaults. Read in the loader, so at run time

If a later Aurora moves its login file, the add-on leaves Aurora's page alone and warns while the site builds. AGENTS.md notes the check to make on each Aurora upgrade.

This replaces phase 3's loginActions slot and its rootLoaderData utility. The callback page's retry link now goes to /login?choose=1, as in Volto.

Theme and icons

Aurora's provider buttons were half-styled: core's components read --identity-* custom properties that only Volto's stylesheet defined.

  • Tokens moved to core. The tokens and base classes core uses (identity-button, identity-surface, identity-spinner, …) moved to identity-core/src/styles.css, imported by core's entry point. Volto's styles.css keeps only its own (stats boxes, search boxes, tabs). Both bundles were checked to carry them.
  • Quanta in Aurora. AuroraIdentityUI.css maps the tokens onto Quanta's palette, and the buttons fill the login column.
  • Icons and paths. AuroraIdentityUI provides Quanta's arrow-right and close icons. A new IdentityUI.paths sends the password-reset link to Aurora's /reset-password; Volto keeps /passwordreset.

Also moved to core: asBoolean, asksToChoose and CHOOSE_LOGIN_PATH, with their tests. Volto re-exports them, so its imports are unchanged.

CI

.github/workflows/aurora.yml, called from main.yml on frontend changes:

Job Runs
Aurora: Lint, i18n, unit tests and build make install, lint (ESLint, typecheck, Prettier, Stylelint), ci-i18n, ci-test, build
Aurora: Sign-in through Dex Backend acceptance server, Dex with backend/tests/_resources/dex/config.yaml, a production build of Aurora, then Playwright

They pass actionlint, but they have not run on GitHub yet. This push is their first run.

Acceptance tests

frontend/aurora/acceptance, with make acceptance-* targets to start each service locally. They are documented in contributing.md.

Test Checks
Sign in through Dex /login?choose=1 shows the Dex button. Dex's own form signs the user in, and the browser lands on / with Aurora's session cookie
Sole provider /login goes straight to Dex
Refused sign-in /login-identity?error=access_denied explains, and leads back to /login?choose=1
Forged callback Refused

All four pass locally against the real stack.

Verified by hand

Against a local site with Dex:

  • Password action. A wrong password answers 401 and the form says so. The right one sets auth_seven and redirects to came_from.
  • Magic-link action. Without an email provider the backend answers 404, and the form shows the error. An actual magic-link send was not tested: it needs an email provider and mail delivery.
  • Unknown form. An unknown form answers 400.

Docs

  • New page: docs/docs/concepts/frontends.md explains why there are three packages, what core may import, IdentityUI, the shared translations and tokens, how Aurora reaches the backend, why /login is replaced, and the settings side by side.
  • Updated: AGENTS.md and contributing.md gain the new gates and the acceptance run.
  • Testing both frontends: a new section in contributing.md. Run them one at a time on port 3000, or side by side with Aurora on 3002, since Volto's development server takes 3000 and 3001. Provider sign-in works only on 3000, where the providers' redirect URI points. Dex, Quanta and gettext were added to Vale's vocabulary.

Checks

Check Result
Tests Core 282 (+3 IdentityUI, +1 @login, and 18 moved from Volto). Volto 664, the 18 gone to core. Aurora add-on 26
A new test, seen red The reset link test fails with the old hard-coded href
make -C frontend lint, make aurora-lint, both typechecks Pass
ci-i18n, both harnesses Pass
Storybook; Volto pnpm build; make aurora-build Pass. Each bundle carries one React: 18.2.0 in Volto, 19.3.0 in Aurora
make docs-build; Vale Pass; 0 errors

Not in this PR

  • One react-aria-components version across both harnesses.
  • An acceptance test of the magic link.
  • Aurora pages for identities, profile, consent and applications. Control panels stay Volto-only.

…ceptance tests

- Upgrade the Aurora harness to 1.0.0-alpha.16: imports from @plone/quanta
  and @plone/icons, which build before @plone/components.
- Render Aurora's /login with identity-core's LoginForm, keeping Aurora's
  frame: providers, magic link and, when enabled, the password form. The
  loginActions slot sits inside Aurora's password <Form>, so the add-on
  swaps the file @plone/cmsui registers for /login instead.
- Move the --identity-* tokens and base classes from volto-identity into
  identity-core, and map them onto Quanta in Aurora, with Quanta's icons.
- Move asBoolean, asksToChoose and CHOOSE_LOGIN_PATH into identity-core,
  add endpoints.login and IdentityUI.paths.
- Add .github/workflows/aurora.yml: lint, typecheck, i18n, unit tests and
  build, plus Playwright acceptance tests signing in through Dex.
- Document the frontend split in docs/docs/concepts/frontends.md.

Refs #132
…e by side

Volto's development server takes ports 3000 and 3001, so Aurora runs
beside it on 3002. Provider sign-in works only on port 3000, where the
providers' registered redirect URI points.

Refs #132
Stylelint skips node_modules only under its working directory, and the
harness lints ../packages/aurora-identity, so CI linted the CSS of every
package the add-on links to: 3086 errors, among them jsdom's default
stylesheet. A negated glob limits it to the add-on's own stylesheets.

Refs #132

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant