Repository navigation
fix(management): validate complete provider POST candidates before adoption - #5013
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe provider POST route now validates every new-provider draft before adoption. The route no longer skips draft validation when pin fields are absent. Tests verify that an invalid ChangesProvider validation
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to Invalid provider registrations are rejected before being saved, with no confirmed regression in successful registrations. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
✅ READY
Review readiness checklist
✅ 4/4 boxes ticked. This pull request is already Ready for Review. |
management-provider-validation.test.ts and codex-v2-gate.test.ts both sat at their file-size caps, so the cases added after the cap was set failed the ratchet. Move the lidge-jun#5013 pins-less POST candidate case and the three lidge-jun#4941 pristine-baseline pin cases into sibling files, register both in the layout maps, and leave the baselines unchanged. Cases are unchanged.
Summary
A management
POST /api/providersthat carries no pin fields never runsvalidateConfigCandidate: thepinsOwnedgate skips candidate validation entirely, so a provider field the management boundary does not check (for example an editor-owned enum such asapiKeyPoolStrategy) can persist a schema-invalid candidate before live adoption.validateConfigCandidateruns unconditionally on the completed POST draft; a failure returns 400 before any provider/default state is adopted.Regression coverage:
provider POST validates a pins-less candidate before live adoptionposts a schema-invalidapiKeyPoolStrategywith no pin fields and asserts a 400 with nothing persisted.Verification
Exact head:
ec5f84aae714799971eeac3c2022e0ddeedb384a(tree72a6ad8aea3dafdaf36edcdd36c94502221f2f4f), based on dev444cf77012a6563d10768088546a43a07399a0d7.bun x tsc --noEmitbun run structure:checkbun run privacy:scanbun test ./tests/server/management-provider-validation.test.tsReview readiness checklist
Review readiness checklist
This PR stays in draft until every box below is ticked. Tick all four boxes once the requirements are met:
All CI tests are green on my local testing. Local gates passed on this head (tsc, structure:check, privacy:scan, focused suite); fork CI dispatched.
I pushed my PR to the latest dev commit. The branch carries dev
444cf7701, 10 behind tip - inside the 10-commit window.I resolved all correct Codex and CodeRabbit findings. No review rounds yet on this head; the branch is new.
My PR is ready for review.
Summary by CodeRabbit