/home/techb158/cosmic.abdallabala.com/docs
NameSizeModeActions
00-design-study.md36780666editdlrm
01-uml-class-diagram.puml118690666editdlrm
02-use-case-diagram.puml37630666editdlrm
03-sequence-diagrams.puml97320666editdlrm
04-database-entity-model.mmd70510666editdlrm
05-database-schema.sql133720666editdlrm
06-diagram-preview.html50210666editdlrm
07-design-checklist.md32560666editdlrm
08-step-2-storage-layer.md53250666editdlrm
09-step-3-risk-crud-ui.md33800666editdlrm
10-step-4-mitigation-workflow.md39960666editdlrm
11-step-5-deployment-gate-workflow.md22920666editdlrm
12-step-6-multi-pm-integration.md37700666editdlrm
13-step-6-1-microsoft-planner-integration.md23350666editdlrm
14-step-7-reporting-export.md41580666editdlrm
15-step-7-1-oauth-live-connectors.md45450666editdlrm
16-step-8-user-roles-access-control.md32970666editdlrm
17-step-9-production-deployment-security.md42280666editdlrm
18-step-10-final-academic-submission.md31990666editdlrm
19-final-report-draft.md68140666editdlrm
20-instructor-submission-checklist.md36390666editdlrm
21-demo-script.md39480666editdlrm
22-traceability-matrix.md48470666editdlrm
23-testing-evidence.md29610666editdlrm
24-evaluation-rubric-mapping.md29100666editdlrm
25-final-deployment-runbook.md32140666editdlrm
26-known-limitations-and-future-work.md26320666editdlrm
27-final-qa-checklist.md28930666editdlrm
28-demo-rehearsal-script.md36180666editdlrm
29-submission-freeze-report.md27690666editdlrm
30-final-known-issues.md18760666editdlrm
dashboard-spec.md36910666editdlrm
Edit: /home/techb158/cosmic.abdallabala.com/docs/23-testing-evidence.md (2961B)
# Testing Evidence Summary ## 1. Test command Run the full test suite with: ```bash npm test ``` ## 2. Test suites | Test file | Purpose | |---|---| | `tests/risk-engine.test.js` | Verifies risk score, normalized score, and gate logic | | `tests/storage-layer.test.js` | Verifies JSON storage and repository behavior | | `tests/api-workflow.test.js` | Verifies main API workflows | | `tests/mitigation-workflow.test.js` | Verifies mitigation creation, update, evidence, and residual risk behavior | | `tests/gate-workflow.test.js` | Verifies gate history, reviewer decisions, notes, and audit behavior | | `tests/integration-workflow.test.js` | Verifies Trello, Jira, Asana, and Microsoft Planner adapter workflows | | `tests/oauth-live-connectors.test.js` | Verifies OAuth provider configuration and live connector boundaries | | `tests/reporting-workflow.test.js` | Verifies JSON, HTML, and CSV report generation | | `tests/access-control.test.js` | Verifies roles, permissions, and protected operations | | `tests/production-hardening.test.js` | Verifies security headers, readiness, config checks, and backup support | ## 3. Expected output ```text All COSMIC AI-Risk engine tests passed. All COSMIC AI-Risk storage layer tests passed. All COSMIC AI-Risk mitigation workflow tests passed. All COSMIC AI-Risk gate workflow tests passed. All COSMIC AI-Risk integration workflow tests passed. All COSMIC AI-Risk OAuth and live connector tests passed. All COSMIC AI-Risk reporting workflow tests passed. All COSMIC AI-Risk access control tests passed. All COSMIC AI-Risk production hardening tests passed. All COSMIC AI-Risk API workflow tests passed. ``` ## 4. Manual verification checklist | Check | Expected result | |---|---| | Open dashboard | Main dashboard loads | | Add risk | Risk appears in register and dashboard recalculates | | Edit risk | Updated fields persist | | Delete risk | Risk is removed from register | | Add mitigation | Mitigation appears on Mitigations page | | Add evidence | Evidence reference is saved | | Evaluate gate | Gate status and criteria update | | Add reviewer decision | Decision appears in gate history | | Run simulated PM sync | Sync run appears in integration history | | Open reports | Report links work | | Export CSV | CSV downloads or opens | | Switch user actor | Permissions change in UI | | Open readiness endpoint | `/api/ready` returns `ok: true` | | Run backup | Backup file and manifest are created | ## 5. Testing limitations The current tests are local prototype tests. They do not perform live calls to Trello, Jira, Asana, or Microsoft Planner unless production credentials and live integration flags are configured. This is intentional because automated submission tests should not depend on external services. ## 6. Recommended instructor demonstration During the demo, run: ```bash npm test npm start ``` Then demonstrate the dashboard, workflows, reports, and access control screen.