The pattern
Save the session once
Write a test whose only job is to hold a browser open while you log in manually, then save the state:tests/setup/capture-sso.test.yaml
sso-state.json.
The file holds the cookies, localStorage, and IndexedDB state the session
needs.
Load it in every test
tests/reports.test.yaml
authLoad restores the browser state and refreshes the active page. The app
then sees the restored session; the initial page load may have occurred before
the state was applied.
Keeping the session fresh
State files expire with the IdP session. Two options keep the session valid.Continuous refresh
AddauthSave to a test’s after: section so each run rolls the state forward:
Re-capture on failure
When the saved session expires, run the capture test locally, complete the manual sign-in, and replace the state supplied to CI. A headless scheduled job cannot complete this manual login. If the provider permits an automated test-account login, a cached auth module (autoAuth: true) can store and reuse the session within a configured TTL. It
does not bypass provider restrictions. See
cache authenticated sessions.
Automating the IdP
Sometimes there is no state shortcut: for example, testing the login flow itself. If you must drive the provider’s UI:- Use a dedicated test account with 2FA that accepts TOTP, not SMS or push.
Generate codes in a
javascriptstep withOTPAuth; see authenticator-app codes. - Check the provider’s automation and account policies. Use a dedicated test tenant where available.
- Keep the login in one module so when it breaks, one file breaks.