Close-out proof for Option B: load each public shell (shell, shell-docs,
shell-dashboard) on staging and prod and assert that
(a) the inlined `window.__SHOWCASE_CONFIG__` matches the env's
expected URL set (per-env value, not a leaked default), and
(b) every backend fetch host matches a tight per-env allowlist —
anchored regexes pinned to the EXACT hosts captured from real
page-load inventories (Railway public domains for the staging
services, bare-domain copilotkit.ai hosts for prod, plus the
shared third-party allowlist for analytics/fonts/HubSpot/Reo/
REB2B/scarf/CDN).
An env-leak (someone re-bakes a URL into the artifact) shows up as
either the wrong `__SHOWCASE_CONFIG__` value OR a request to the
other-env's host — either branch fails the test.
This is the test referenced in plan-B B14 / spec §10 items 2,3,10.
Runs against LIVE deployments — no webServer block, fetches public
URLs. Gated to run in CI after the B15 Railway env-var wiring deploy
has settled.
Scoping notes:
- Spec file at `showcase/tests/env-routing.spec.ts`. The existing
`showcase/tests/playwright.config.ts` is the integrations smoke
harness (`testDir: ./e2e`); creating a separate, narrowly-scoped
config at `showcase/playwright.env-routing.config.ts` keeps the
two suites independent so neither can pull the other in by
accident under `playwright test`.
- `testMatch: /env-routing\.spec\.ts$/` belt-and-suspenders the
`testDir: ./tests` selection.
- Verified well-formed locally via `tsc --noEmit` against
`showcase/shell-dashboard/`'s @playwright/test + @types/node
install (the only place those deps are installed in the worktree;
`showcase/tests/` has no node_modules in this worktree because
npm install is symlinked-only by the blitz harness). Full
browser execution requires deployed shells and is gated to
post-deploy in CI.