Skip to content

test(a11y): gate the foreign-traffic, wardriving and areas analytics tabs - #59

Merged
dborup merged 1 commit into
masterfrom
codex/fix-1706-axe-analytics-tab-routes
Sep 17, 2026
Merged

dborup merged 1 commit into
masterfrom
codex/fix-1706-axe-analytics-tab-routes

Conversation

@dborup

@dborup dborup commented Sep 17, 2026

Copy link
Copy Markdown
Owner

Problem

The last command of the "Run JS unit tests (packet-filter)" CI step, test-a11y-axe-routes-coverage.js (Kpa-clawbot#1706), fails on master:

axe ROUTES missing analytics tabs (issue #1706): areas, foreign-traffic, wardriving

The gate requires every data-tab button in public/analytics.js to be exercised by the axe-core browser gate (test-a11y-axe-1668.js). The Foreign Traffic, Wardriving and Areas tabs were added after the gate (July 2026) without matching ROUTES entries. The tabs are real — each has a case arm in the renderTab dispatch (public/analytics.js:316-318) — so the expectation is not stale: the axe gate simply never scanned these tabs.

This failure has been hidden until now because the same CI step stopped earlier, on the Kpa-clawbot#1648 M4 icon scan (fixed separately in #56).

Change

test-a11y-axe-1668.js only (+4/−1):

  • Adds /analytics?tab=foreign-traffic, /analytics?tab=wardriving and /analytics?tab=areas to ROUTES, so the browser gate visits each tab, runs the existing mount assertion (tab active, content non-empty) and then axe.
  • Adds the three tabs to REGISTERED_ANALYTICS_TABS, so the selftest's dispatch-arm reciprocity check covers them too.

Not changed: the coverage assertion, the selftest, the wait/mount logic, axe rules, the allowlist, workflows, production code.

Verification

All local, macOS arm64, Node v25.6.1 — not GitHub CI.

On this branch's HEAD (e3f57426, base e17377d8):

  • test-a11y-axe-routes-coverage.js: fails on base with exactly the three tabs; passes on HEAD (declared=20 covered=20).
  • test-a11y-axe-1668-selftest.js: passes (routes=29).
  • node --check test-a11y-axe-1668.js and git diff --check: clean.

Local integration of master e17377d8 + #56 (52ae9d1c) + this change:

axe browser gate (isolated local Go server on :13581 with a copy of test-fixtures/e2e-fixture.db, prepared like CI: freshen, seed, migrate; pinned playwright 1.58.2 / @axe-core/playwright 4.11.3 / axe-core 4.12.1; installed Google Chrome 151 via CHROMIUM_PATH with DNS restricted to localhost — CI uses Playwright's bundled Chromium with network access, so results may differ):

  • The three new tabs: 12/12 cells clean (2 viewports × 2 themes × 3 routes).
  • A separate diagnostic probe using the gate's navigation and wait confirmed each tab was active and loaded (no loading/error state, API calls 200) when axe ran:
    • Wardriving: populated content (329 elements, 4 tables).
    • Foreign Traffic: real section headings, but the fixture has no foreign traffic, so its lists are empty — no populated-data coverage.
    • Areas: the fixture has no configured Areas, so axe only sees the empty-state message — the data view is not covered. Populated coverage would need a fixture/config change, not made here.

Known limitations

🤖 Generated with Claude Code

…tabs

test-a11y-axe-routes-coverage.js (Kpa-clawbot#1706) requires every data-tab button
in public/analytics.js to be exercised by the axe gate. The Foreign
Traffic, Wardriving and Areas tabs were added afterwards without ROUTES
entries, so the coverage check failed and the axe gate never scanned
them. Add the three routes and register the tabs so the selftest's
dispatch-arm reciprocity also covers them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant