playwright-core
Battle-tested Playwright patterns for E2E, API, component, visual, accessibility, and security testing. Covers locators, assertions, fixtures, netwo…
它会碰到什么
逐条看命中(30 条严重或高危)
- 严重
auth-flows.md:1027cred-paths2. **Never hard-code credentials in test files**. Use environment variables or a `.env` file loaded via `dotenv`. In `playwright.config.ts`, set `process.env` v
- 严重
authentication.md:1296cred-paths| Hardcode credentials in test files | Security risk. Credentials leak into version control and CI logs.
- 严重
configuration.md:26cred-paths// Load environment variables from .env file
- 严重
configuration.md:27cred-pathsdotenv.config({ path: path.resolve(__dirname, ".env") }) - 严重
configuration.md:114cred-pathsdotenv.config({ path: path.resolve(__dirname, ".env") }) - 严重
configuration.md:199cred-paths// Load environment-specific .env file: .env.staging, .env.production, etc.
- 严重
configuration.md:199cred-paths// Load environment-specific .env file: .env.staging, .env.production, etc.
- 严重
configuration.md:199cred-paths// Load environment-specific .env file: .env.staging, .env.production, etc.
- 严重
configuration.md:201cred-pathsdotenv.config({ path: path.resolve(__dirname, `.env.${ENV}`) }) - 严重
configuration.md:238cred-pathsdotenv.config({ path: path.resolve(__dirname, `.env.${ENV}`) }) - 严重
configuration.md:513cred-paths### Pattern 5: `.env` File Setup
- 严重
configuration.md:516cred-paths**Avoid when**: Never commit `.env` files with real secrets. Provide `.env.example` instead.
- 严重
configuration.md:519cred-paths# .env.example (commit this)
- 严重
configuration.md:524cred-paths# .env.local (gitignored)
- 严重
configuration.md:529cred-paths# .env.staging (gitignored)
- 严重
configuration.md:536cred-paths# .gitignore
- 严重
configuration.md:537cred-paths.env
- 严重
configuration.md:538cred-paths.env.local
- 严重
configuration.md:539cred-paths.env.staging
- 严重
configuration.md:648cred-paths| Committing `.env` files with real credentials | Security risk
- 严重
configuration.md:648cred-paths| Committing `.env` files with real credentials | Security risk
- 严重
configuration.md:648cred-paths| Committing `.env` files with real credentials | Security risk
- 严重
nextjs.md:23cred-paths# .env.test — loaded by Next.js automatically when NODE_ENV=test
- 严重
nextjs.md:125cred-paths### Environment Variables with `.env.test`
- 严重
nextjs.md:127cred-pathsNext.js loads `.env.test` automatically when `NODE_ENV=test`. Use this for test-specific overrides.
- 严重
nextjs.md:130cred-paths# .env.test (commit this -- no real secrets)
- 严重
nextjs.md:135cred-paths# .env.test.local (gitignored -- real test secrets)
- 严重
nextjs.md:141cred-paths# .gitignore
- 严重
nextjs.md:1011cred-paths| Skip `.env.test` and hardcode test values in config | Values scatter across config and test files; hard to maintain
- 严重
nextjs.md:1011cred-paths| Skip `.env.test` and hardcode test values in config | Values scatter across config and test files; hard to maintain
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Playwright Core Testing
> Opinionated, production-tested Playwright guidance — every pattern includes when (and when _not_) to use it.
46 reference guides covering the full Playwright testing surface: selectors, assertions, fixtures, network mocking, auth, visual regression, accessibility, API testing, debugging, and more — with TypeScript and JavaScript examples throughout.
Golden Rules
getByRole()over CSS/XPath — resilient to markup changes, mirrors how users see the page- Never
page.waitForTimeout()— useexpect(locator).toBeVisible()orpage.waitForURL() - Web-first assertions —
expect(locator)auto-retries;expect(await locator.textContent())does not - Isolate every test — no shared state, no execution-order dependencies
baseURLin config — zero hardcoded URLs in tests- Retries:
2in CI,0locally — surface flakiness where it matters - Traces:
'on-first-retry'— rich debugging artifacts without CI slowdown - Fixtures over globals — share state via
test.extend(), not module-level variables - One behavior per test — multiple related
expect()calls are fine - Mock external services only — never mock your own app; mock third-party APIs, payment gateways, email
Guide Index
Writing Tests
| What you're doing | Guide | Deep dive |
| -------------------------- | ------------------------------------------------------ | -------------------------------------------------- |
| Choosing selectors | [locators.md](locators.md) | [locator-strategy.md](locator-strategy.md) |
| Assertions & waiting | [assertions-and-waiting.md](assertions-and-waiting.md) | |
| Organizing test suites | [test-organization.md](test-organization.md) | [test-architecture.md](test-architecture.md) |
| Playwright config | [configuration.md](configuration.md) | |
| Fixtures & hooks | [fixtures-and-hooks.md](fixtures-and-hooks.md) | |
| Test data | [test-data-management.md](test-data-management.md) | |
| Auth & login | [authentication.md](authentication.md) | [auth-flows.md](auth-flows.md) |
| API testing (REST/GraphQL) | [api-testing.md](api-testing.md) | |
| Visual regression | [visual-regression.md](visual-regression.md) | |
| Accessibility | [accessibility.md](accessibility.md) | |
| Mobile & responsive | [mobile-and-responsive.md](mobile-and-responsive.md) | |
| Component testing | [component-testing.md](component-testing.md) | |
| Network mocking | [network-mocking.md](network-mocking.md) | [when-to-mock.md](when-to-mock.md) |
| Forms & validation | [forms-and-validation.md](forms-and-validation.md) | |
| File uploads/downloads | [file-operations.md](file-operations.md) | [file-upload-download.md](file-upload-download.md) |
| Error & edge cases | [error-and-edge-cases.md](error-and-edge-cases.md) | |
| CRUD flows | [crud-testing.md](crud-testing.md) | |
| Drag and drop | [drag-and-drop.md](drag-and-drop.md) | |
| Search & filter UI | [search-and-filter.md](search-and-filter.md) | |
Debugging & Fixing
| Problem | Guide |
| -------------------------- | ---------------------------------------- |
| General debugging workflow | [debugging.md](debugging.md) |
| Specific error message | [error-index.md](error-index.md) |
| Flaky / intermittent tests | [flaky-tests.md](flaky-tests.md) |
| Common beginner mistakes | [common-pitfalls.md](common-pitfalls.md) |
Framework Recipes
| Framework | Guide |
| ----------------------------------- | ------------------------ |
| Next.js (App Router + Pages Router) | [nextjs.md](nextjs.md) |
| React (CRA, Vite) | [react.md](react.md) |
| Vue 3 / Nuxt | [vue.md](vue.md) |
| Angular | [angular.md](angular.md) |
Specialized Topics
| Topic | Guide |
| ------------------------------------------ | ------------------------------------------------------------------ |
| Multi-user & collaboration | [multi-user-and-collaboration.md](multi-user-and-collaboration.md) |
| WebSockets & real-time | [websockets-and-realtime.md](websockets-and-realtime.md) |
| Browser APIs (geo, clipboard, permissions) | [browser-apis.md](browser-apis.md) |
| iframes & Shadow DOM | [iframes-and-shadow-dom.md](iframes-and-shadow-dom.md) |
| Canvas & WebGL | [canvas-and-webgl.md](canvas-and-webgl.md) |
| Service workers & PWA | [service-workers-and-pwa.md](service-workers-and-pwa.md) |
| Electron apps | [electron-testing.md](electron-testing.md) |
| Browser extensions | [browser-extensions.md](browser-extensions.md) |
| Security testing | [security-testing.md](security-testing.md) |
| Performance & benchmarks | [performance-testing.md](performance-testing.md) |
| i18n & localization | [i18n-and-localization.md](i18n-and-localization.md) |
| Multi-tab & popups | [multi-context-and-popups.md](multi-context-and-popups.md) |
| Clock & time mocking | [clock-and-time-mocking.md](clock-and-time-mocking.md) |
| Third-party integrations | [third-party-integrations.md](third-party-integrations.md) |
Architecture Decisions
| Question | Guide |
| ------------------------ | -------------------------------------------- |
| Which locator strategy? | [locator-strategy.md](locator-strategy.md) |
| E2E vs component vs API? | [test-architecture.md](test-architecture.md) |
| Mock vs real services? | [when-to-mock.md](when-to-mock.md) |
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。