12 Commits

Author SHA1 Message Date
553364b82c test: send-to-person workflow (assign + reassign) across complaint/inquiry/observation
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m21s
Covers the recipient_type=person branch of the unified send-to endpoint for all
3 modules: assign to px_employee, verify the assignee can open the item detail,
then reassign to a different user. 3/3 pass, 0 FAIL.

Harness: get_e2e_user_id + get_e2e_assignment_state CLI helpers.
2026-06-15 15:11:54 +03:00
45b75eb9ef fix: align workflow behavior (Phase 1) + lucide icon-race mitigation
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m27s
Behavioral consistency across complaint/inquiry/observation (re-run: 0 FAIL):
- activation gate on complaints: complaint_send_to + send_to_department_form now
  reject status=open ("Activate this complaint before sending it to a department")
- observation resolve dead-end fixed: observation_change_status now allows
  hospital_admin (was triage_perm/px_admin only) + added a Resolve action on the
  observation detail page -> accepted dept responses can be resolved from the flow
- status validation: Observation.clean() rejects invalid statuses + a DB
  CheckConstraint (migration 0016 normalizes legacy "new"->"open" first)
- inquiry sent_to_department consistency: inquiry_transfer_to_department now also
  sets sent_to_department=True/At (matches observation/complaint for cross-module queries)

Lucide icon-race mitigation: added a defensive `window.lucide || {createIcons:noop}`
shim to the three base layouts + standalone CDN pages (login, select_hospital,
password reset) so the "lucide is not defined" ReferenceError can't throw during
navigation races. Audit listener classifies any residual occurrence as WARN (cosmetic).

Docs: docs/workflows.md records the intentional complaint vs inquiry/observation
differences (multi-dept join + manager review vs single-dept flat) + the field-name map.

Specs: champion spec now activates before send (matches the new gate).
2026-06-14 23:27:03 +03:00
32e2a3f996 fix: require activation before sending observation/inquiry to a department
Some checks failed
Build and Push Docker Image / build (push) Failing after 6m52s
An item could be sent to a department while still in its initial (open) state,
bypassing activation. Added a status guard to the 4 send entry points:
- observation_send_to_department / observation_send_to (AJAX)
- inquiry_transfer_to_department / inquiry_send_to (AJAX)
Rejects with "Activate this {observation/inquiry} before sending it to a
department." if status is open. Re-sends after a rejection still work (item
stays in_progress).

Also:
- seed_e2e_dept_response: observation status "new" -> "open" (valid initial;
  "new" isn't a valid ObservationStatus, which is why activate never moved it)
- spec: Flow A/B/C now activate before send
2026-06-14 21:27:39 +03:00
8c75baf30a test: make inquiry/observation Flow A visible (UI-driven with API fallback)
All checks were successful
Build and Push Docker Image / build (push) Successful in 28s
Flow A now drives the real screens - detail page, Send-to modal, dept-response
page, Accept button - so the run is watchable in headed mode. Each visible step
falls back to a direct POST if the UI doesn't persist, so the flow still
completes reliably. Flows B/C unchanged.
2026-06-14 19:05:07 +03:00
23b6e239b5 test: inquiry + observation dept-response workflow E2E
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m2s
Adds headed Playwright coverage for the simpler dept-response flow
(PX send -> champion responds -> PX accept/reject), 3 flows per module
(happy path, token response, reject loop). 6/6 pass; 50 PASS / 5 WARN / 0 FAIL.

Findings (documented in report):
- token-response form pages (inquiry + observation) render the dashboard
  chrome instead of the response form -> anonymous champions can't submit
  via the emailed link (backend POST still works)
- NameError get_email_header_html in inquiry_transfer_to_department (notif
  email silently fails)
- observation can't jump new->resolved (status machine needs intermediate steps)

Harness:
- seed_e2e_dept_response, get_e2e_dept_response_state CLI helpers
- E2E_MAXIMIZED=1 fullscreen mode in playwright.config.ts
- report: appended "Inquiry & Observation dept-response workflow" section
2026-06-14 16:55:54 +03:00
17981fdf82 test: harden champion/manager spec against post-login session timing
All checks were successful
Build and Push Docker Image / build (push) Successful in 23s
ensureAuth() probes an auth-required endpoint after each login() and re-logs-in
if the session hasn't settled (occasionally needed under slowMo after rapid
role swaps). Also observes the HTTP status of every second-pass POST so any
auth bounce is visible. App logic unchanged (verified via the test client).
2026-06-14 15:37:54 +03:00
ef53f69833 test: champion/manager workflow E2E + fix investigation bugs
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m7s
Adds headed Playwright coverage for the full send-to-department lifecycle
(PX send -> champion investigates -> manager approves/rejects -> PX accepts ->
resolve), including the token investigation sub-flow and both reject loops.

Bugs fixed (found by the new test):
- champion_start_investigation: NameError - InvestigationAnswer not imported
  (complaints/views.py) -> the "create questions" POST was 500ing
- champion_start_investigation: staff_member.phone_number -> Staff.phone
  (would have AttributeError'd once the import was fixed)

Harness:
- create_e2e_isolated_env: bind dept-manager as department.manager + create
  e2e-staff Staff profile in the champion's department
- seed_e2e_complaint, get_e2e_workflow_state CLI helpers for setup/assertions
- champion-manager-workflow.spec.ts (flows A/B/C1/C2)

Report: appended "Champion/Manager Workflow Audit" section.
2026-06-14 15:23:14 +03:00
7369d08012 feat: unified reference numbers + feedback modules QA audit
All checks were successful
Build and Push Docker Image / build (push) Successful in 4m14s
Reference numbers (unified scheme PREFIX-YYYYMM-HOSP-NNNN, e.g. CMP-202606-HHN-0001):
- new ReferenceSequence model + generate_reference() helper (apps/core)
- Complaint/Inquiry/Observation/Appreciation/Suggestion emit unified refs via save()
- prefix-based auto-routing in public track API (CMP/INQ/OBS trackable; APR/SGT internal-only)
- removed legacy CMP-/INQ- generators in ui_views, integrations, px_sources
- migrations: core.0003_referencesequence, appreciation.0006, feedback.0008, observations.0012
- unit tests (format, sanitization, monthly reset, 40-thread concurrency)

QA audit:
- isolated E2E hospital sandbox mirroring HH-N + 10 role users (create_e2e_isolated_env)
- feedback-modules-audit.spec.ts + audit helper (headed, run-to-completion)
- reports/feedback-modules-qa-report.md

Also bundles accumulated in-progress work across complaints, observations,
organizations, templates, and other modules.
2026-06-14 14:29:23 +03:00
c5f76b3855 updates
Some checks are pending
Build and Push Docker Image / build (push) Waiting to run
2026-05-11 14:45:30 +03:00
e119312a9c clean up version 2026-04-19 10:53:12 +03:00
177a7e0f5f updates 2026-04-08 17:13:35 +03:00
23d439f5a5 fix: harden multi-tenant data isolation across 8 modules
Pre-production security fixes to prevent cross-hospital data leaks:

- Standards API: add get_queryset() filtering by department__hospital
- Reports service: add user param with hospital filtering to all querysets
- RCA views: replace is_superuser with tenant_hospital pattern, add access
  checks to all 11 mutation views
- Notifications views: replace is_superuser patterns with _get_notification_hospital
  helper across all 5 settings functions
- Appreciation API: add tenant_hospital fallback to AppreciationViewSet,
  AppreciationStatsViewSet, and LeaderboardView
- AI Analytics: add tenant_hospital fallback in ExecutiveSummaryGenerator and
  ActionRecommendationEngine
- SourceUserRestrictionMiddleware: remove None from ALLOWED_URL_NAMES
- Complaint export: fix nullable patient/due_at/description crashes in CSV
  and Excel export, fix invalid get_category_display/get_source_display calls

E2E test updates:
- Update isolation gap tests to actively assert hospital filtering
- Fix CSV export test to use API context for download handling
- Switch clinical-staff tests to serial mode to prevent race conditions
2026-04-07 01:23:10 +03:00