test(api): cover Ask, Rankings, and locale preference boundaries - #435
Conversation
…erences Found via a systematic route-vs-test cross-reference (every @app.get/ post/patch/put/delete path in backend/app/main.py checked against every test file, not just backend/tests/test_api.py) -- same technique that found the /healthz routing bug earlier this session. All three endpoints had zero test coverage anywhere in the repo: - POST /api/ask: the Ask Agent endpoint itself was never exercised at the HTTP layer, despite its underlying functions (gather_global_chat_sources, cited_post_evidence, ...) being unit-tested. New tests cover the empty-question 422, the no-orchestrator-configured 503 (Null client, matching the existing derive-commitment 503 test's monkeypatch pattern), and the unauthenticated 401/403 case. - GET /api/rankings: covers the real response contract (RankWeave's own "never invent a fused score" fail-closed shape -- status is either "accepted" or "unavailable", never a guessed ranking) plus the unauthenticated case. - PATCH /api/me/preferences: covers persisting a supported locale (round-tripped through GET /api/me) and rejecting an unsupported one (Pydantic's own Literal validation, previously untested). uv run --frozen python -m pytest -q: 760 passed, 17 skipped.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Same shared-ancestor bug as #418/#415/#426/#427/#429/#431/#434/#435/#436: the login button built an unsanitized returnUrl inline instead of returnUrlFromLocation()/rememberOidcReturnUrl(), and removed the unreachable login-screen AdminPanel render (accessToken is always undefined pre-auth). This PR's own diff doesn't touch AdminPanel.
Same shared-ancestor bug as #418/#415/#426/#427/#429/#431/#434/#435/#436/#437: the login button built an unsanitized returnUrl inline instead of returnUrlFromLocation()/rememberOidcReturnUrl(), and removed the unreachable login-screen AdminPanel render (accessToken is always undefined pre-auth). This PR's own diff doesn't touch AdminPanel.
|
Confirmed — no functional application changes, just replacing the raw returnUrl with the existing safe helpers and dropping unreachable dead code, matching #426's approach. |
|
Confirmed, thanks — no action needed. |
* test(frontend): add Storybook coverage for BuyerNav BuyerNav had a test file but no story, the last remaining gap in frontend/src/components/*.tsx test+story coverage. Adds stories for each destination plus an edge case with an extra tools slot. * fix(frontend): use OIDC return-url helpers on the login button Same shared-ancestor bug as #418/#415/#426/#427/#429/#431/#434/#435/#436/#437: the login button built an unsanitized returnUrl inline instead of returnUrlFromLocation()/rememberOidcReturnUrl(), and removed the unreachable login-screen AdminPanel render (accessToken is always undefined pre-auth). This PR's own diff doesn't touch AdminPanel. * test(frontend): cover WorkspaceNav in Storybook
|
Exact-head review requested for Please review the effective
All prior review threads are resolved and outdated. Do not transfer approval from an earlier head. |
Remove stale httpx2 claims after the look-alike dependency was deleted; the harness uses Starlette TestClient with the official httpx dev dependency.
Two TypeScript build errors on main (blocking every open PR's
"Frontend lint, test, build" check, including this repo's own review
bot's ability to approve them):
- App.tsx imported rememberOidcReturnUrl/returnUrlFromLocation from
oidcReturnUrl.ts but never called them -- the login button built its
own unsanitized returnUrl inline instead of using the safe helper
(oidcReturnUrl.ts's isSafeReturnUrl guard against an open-redirect-
shaped value) or persisting it as the sessionStorage/localStorage
fallback restoreOidcReturnUrl (already wired up on the callback side
in main.tsx) reads when the OIDC state round-trip drops it.
- The unauthenticated login screen unconditionally rendered
<AdminPanel accessToken={accessToken} /> when destination === "admin"
-- accessToken is string | undefined here (always undefined while
unauthenticated), a real type error, and the render was unreachable
through normal navigation (destination only changes via the
authenticated nav) -- dead code, removed.
uv run --frozen python -m pytest -q: 753 passed, 17 skipped.
pnpm run test: 140 passed. pnpm run lint / build: clean.
|
Exact-head review requested for |
…reak" This reverts commit 36164fb.
|
Stack boundary corrected: exact head |
* test(frontend): cover LineageDag with tests and stories LineageDag renders the git-branch-style multi-thread lineage graph used by both the post-detail popup and the Ask Agent's multi-lineage answer view (ADR 0120), and had zero test or story coverage despite being a core, non-trivial component. Adds tests for the empty state, multi-group branch rendering, group-heading fallback for missing/UUID groups, click and keyboard node selection, the current-post marker, and label truncation with an accessible full-label fallback. Adds stories for empty, single-branch, multi-branch (with an actual fork), ungrouped, and long-label scenarios. * fix(frontend): use OIDC return-url helpers on the login button Same shared-ancestor bug as #418/#415/#426/#427/#429/#431/#434/#435/#436/#437/#438: the login button built an unsanitized returnUrl inline instead of returnUrlFromLocation()/rememberOidcReturnUrl(), and removed the unreachable login-screen AdminPanel render. * Revert "fix(frontend): use OIDC return-url helpers on the login button" This reverts commit 590c6c3. * fix(frontend): keep lineage edge evidence visible-only * fix(frontend): terminate rooted lineage cycles * chore(frontend): keep shared OIDC repair on #426 * refactor(frontend): remove unreachable cycle guard * test(frontend): cover converging lineage DAGs * fix(frontend): position converging DAG nodes once
* test(frontend): cover FiveW1H component with tests and stories Adds Vitest coverage for loading state, empty-evidence messaging, raw-source-to-label mapping (including the unmapped fallback), and optional evidence-text/ontology-badge rendering, plus a Storybook inventory covering the loading, all-empty, grounded-answer, and unmapped-source scenarios. * fix(frontend): use OIDC return-url helpers on the login button Same shared-ancestor bug as #418/#415/#426/#427/#429/#431/#434/#435/#436: the login button built an unsanitized returnUrl inline instead of returnUrlFromLocation()/rememberOidcReturnUrl(), and removed the unreachable login-screen AdminPanel render (accessToken is always undefined pre-auth). This PR's own diff doesn't touch AdminPanel. * chore(frontend): keep FiveW1H coverage dependency-correct Remove the duplicated OIDC/login changes owned by #426 so this PR carries only its FiveW1H tests and Storybook inventory.
b2d9bdb
into
worktree-fix-frontend-build-break
* test(admin): cover AdminPanel (previously zero coverage) Found via a systematic component-vs-story-vs-test cross-reference of frontend/src/components/*.tsx -- AdminPanel had neither a .test.tsx nor a .stories.tsx, unlike every other component in the directory. Tests cover: save disabled until the brand name actually changes, a successful save calling updateTenantConfig (backend/app/main.py's PATCH /api/settings, now covered separately in #435) with the right arguments and reporting the new name back to the caller, and a failed save showing the error while leaving the form editable (not stuck disabled). Storybook stories cover the default state and a long brand-name layout edge case. pnpm run test: 143 passed (was 140). pnpm run lint: no new warnings. pnpm run build: the two pre-existing App.tsx errors are the unrelated main break already fixed in #426, not something this PR touches. * fix(frontend): use OIDC return-url helpers on the login button Same shared-ancestor bug as #418/#415/#426/#427/#429/#431/#434: the login button built an unsanitized returnUrl inline instead of returnUrlFromLocation()/rememberOidcReturnUrl(), and removed the unreachable login-screen AdminPanel render (accessToken is always undefined pre-auth). This PR's own AdminPanel.test.tsx/.stories.tsx render the component directly, so this doesn't affect its coverage. * fix(admin): guard no-op saves and announce results * docs(storybook): inventory tenant settings
Summary
POST /api/ask,GET /api/rankings, andPATCH /api/me/preferencesthrough the real FastAPI/PostgreSQL/Keycloak integration boundary.httpxdev dependency; the removed look-alikehttpx2package and its stale documentation are absent.Exact-head verification
Validated at head
7dd6ce01e3c14ea1972554634b0026a3ccf0200bstacked on exact #426 basea44f360749b98c9471bfedbfce9656a41e729214:uv lock --check/ dependency graph remains on officialhttpx; nohttpx2branch diff.git diff --check.ARCHITECTURE.md, the API changelog fragment,backend/app/main.py, andbackend/tests/test_api.py; no App/OIDC/Admin file remains.mainand receive fresh exact-head/base checks and independent approval.The unchanged product-code test head immediately before the documentation-only provenance correction also passed the full hosted Python suite. That prior-head result is not treated as an exact-head merge gate; the fresh hosted run must complete.
Governance
main, and terminal exact-head/base required checks plus an independent exact-head approval are present.