@crossplatformai/skills
Version:
Reusable Agent Skills for CrossPlatform.ai projects.
86 lines (60 loc) • 4.51 kB
Markdown
# Fast Auth Playbook
For policy, sensitive material rules, and bootstrap conditions, see `automation-auth.md`. This document covers mechanics only.
## Standard Identity
- Automation user: `automation@local.test`
## Verification Code Retrieval
Query the latest code from the local database. Concrete connection values live in the target repo's `.env` or app `AGENTS.md`.
```sql
SELECT code FROM verification_codes
WHERE email_id IN (
SELECT id FROM user_emails WHERE email = 'automation@local.test'
)
ORDER BY created_at DESC LIMIT 1;
```
Retrieve the code without printing, logging, or exposing it.
## Per-Surface Flow
### Web
| Step | Pattern |
| -------------- | ---------------------------------------------------------------------------------------------- |
| Startup | Read `WEB_DEV_PORT` from the repo `.env`; start the dev server |
| Sign-in entry | Navigate to `http://localhost:${WEB_DEV_PORT}/sign-in` |
| Code retrieval | Query the local DB for the latest verification code |
| Verify success | Page URL is `/profile`; visible text includes `automation@local.test` and "Profile" |
| Token check | `localStorage.getItem('@${APP_SLUG}_auth_access_token')` and `_auth_refresh_token` are present |
Automation: Playwright browser. Fill `input[type="email"]` with `automation@local.test`, submit, then fill the 6 `input[autocomplete="one-time-code"]` inputs with the retrieved code.
### Mobile
| Step | Pattern |
| -------------- | -------------------------------------------------------------------------------- |
| Startup | Start the local dev client (Expo/iOS simulator/Android emulator) |
| Sign-in entry | Launch the app and navigate to the sign-in screen |
| Code retrieval | Query the local DB for the latest verification code |
| Verify success | Profile screen is visible with `automation@local.test` |
| Token check | AsyncStorage contains `@${APP_SLUG}_auth_access_token` and `_auth_refresh_token` |
Automation: Maestro on a supported target: iOS Simulator or Android emulator/device. Use
repository-owned flows and commands when present. When they are absent, report the gap and confirm
the minimal Maestro approach instead of improvising CLI or flow syntax. On iOS Simulator, enter the
OTP without exposing it; a repository-approved local helper may copy the code to the simulator
pasteboard with `xcrun simctl pbcopy booted` for pasting into the focused first OTP field.
### Desktop
| Step | Pattern |
| -------------- | ------------------------------------------------------------------------------------------- |
| Startup | Start the Electron app; read `DESKTOP_DEV_PORT` and `DESKTOP_CDP_PORT` from `.env` |
| Sign-in entry | Navigate to the sign-in screen through the visible renderer UI |
| Code retrieval | Query the local DB for the latest verification code |
| Verify success | `/profile` is visible with `automation@local.test` and "Profile" |
| Token check | Renderer `localStorage` contains `@${APP_SLUG}_auth_access_token` and `_auth_refresh_token` |
Automation: Playwright Electron attached to the app window through the repo-specific CDP target. Fill email and OTP inputs through the renderer context.
## Timing
Approximate per surface when the app and database are already running:
- Web: ~15 seconds
- Mobile: ~20 seconds
- Desktop: ~20 seconds
Actual time depends on simulator boot state, dev server readiness, and database response.
## Where Concrete Values Live
Read these from the nearest app `AGENTS.md` before executing:
- `WEB_DEV_PORT`, `API_DEV_PORT`, `DESKTOP_DEV_PORT`, `DESKTOP_CDP_PORT`
- `APP_SLUG` (determines token storage key prefix)
- Database host, port, name, user, and password
- Sign-in route path, profile route path, and mobile screen identifiers
- Platform-specific OTP input accessibility IDs or selectors
Do not hardcode ports, routes, or credentials in this shared playbook.