/home/techb158/trellopowerup.abdallabala.com/docs
Edit: /home/techb158/trellopowerup.abdallabala.com/docs/23-testing-evidence.md (2961B)
# Testing Evidence Summary
## 1. Test command
Run the full test suite with:
```bash
npm test
```
## 2. Test suites
| Test file | Purpose |
|---|---|
| `tests/risk-engine.test.js` | Verifies risk score, normalized score, and gate logic |
| `tests/storage-layer.test.js` | Verifies JSON storage and repository behavior |
| `tests/api-workflow.test.js` | Verifies main API workflows |
| `tests/mitigation-workflow.test.js` | Verifies mitigation creation, update, evidence, and residual risk behavior |
| `tests/gate-workflow.test.js` | Verifies gate history, reviewer decisions, notes, and audit behavior |
| `tests/integration-workflow.test.js` | Verifies Trello, Jira, Asana, and Microsoft Planner adapter workflows |
| `tests/oauth-live-connectors.test.js` | Verifies OAuth provider configuration and live connector boundaries |
| `tests/reporting-workflow.test.js` | Verifies JSON, HTML, and CSV report generation |
| `tests/access-control.test.js` | Verifies roles, permissions, and protected operations |
| `tests/production-hardening.test.js` | Verifies security headers, readiness, config checks, and backup support |
## 3. Expected output
```text
All COSMIC AI-Risk engine tests passed.
All COSMIC AI-Risk storage layer tests passed.
All COSMIC AI-Risk mitigation workflow tests passed.
All COSMIC AI-Risk gate workflow tests passed.
All COSMIC AI-Risk integration workflow tests passed.
All COSMIC AI-Risk OAuth and live connector tests passed.
All COSMIC AI-Risk reporting workflow tests passed.
All COSMIC AI-Risk access control tests passed.
All COSMIC AI-Risk production hardening tests passed.
All COSMIC AI-Risk API workflow tests passed.
```
## 4. Manual verification checklist
| Check | Expected result |
|---|---|
| Open dashboard | Main dashboard loads |
| Add risk | Risk appears in register and dashboard recalculates |
| Edit risk | Updated fields persist |
| Delete risk | Risk is removed from register |
| Add mitigation | Mitigation appears on Mitigations page |
| Add evidence | Evidence reference is saved |
| Evaluate gate | Gate status and criteria update |
| Add reviewer decision | Decision appears in gate history |
| Run simulated PM sync | Sync run appears in integration history |
| Open reports | Report links work |
| Export CSV | CSV downloads or opens |
| Switch user actor | Permissions change in UI |
| Open readiness endpoint | `/api/ready` returns `ok: true` |
| Run backup | Backup file and manifest are created |
## 5. Testing limitations
The current tests are local prototype tests. They do not perform live calls to Trello, Jira, Asana, or Microsoft Planner unless production credentials and live integration flags are configured. This is intentional because automated submission tests should not depend on external services.
## 6. Recommended instructor demonstration
During the demo, run:
```bash
npm test
npm start
```
Then demonstrate the dashboard, workflows, reports, and access control screen.