Nobody can log in after the login page got a new look
A theme update on the identity provider changes the form. The API tests stay green while real people are locked out.
- Company Admin
- Employee
Why ordinary tests miss it
Most API tests ask the identity provider for a token directly, so they never see the login page people use. When its form changes, every test still passes.
Set it up
Add the environment with the sign-in “Login page (code + PKCE)”. Journey Lanes opens the login page like a browser, fills in the username and password, and the TOTP code when the page asks for one.
Save a test account per role, with its TOTP secret if it uses two-factor.
Make a short flow per role: log in, then open the first screen.
Monitor it every minute or every five minutes, and send alerts to Microsoft Teams, Slack, email or a webhook.
The moment it’s caught
- ✗ Failing: Log in per role
- “Log in per role” on Production is failing: 2 monitor runs in a row. First failure: “Log in”.
- ✗ Log in No sign-in form at login.example.com (answered 200)
The alert names the step and what the login page did. A second alert says when it passes again.
What you use
Next case: A role change quietly gives employees admin rights
Catch this one in your own product
Connect a repository, describe the journey, and run it against the mock in a few minutes.