Repository navigation
release: promote GitHub access onboarding and Next security fixes - #54
Conversation
`withMcpToolNamingApp` boots the full app, so `SkillUsageRetentionLifecycle` spawns a detached prune at boot. Its per-project DELETEs take a write lock on the same shared in-memory SQLite database the suite is inserting into, which intermittently failed the suite with "database is locked". Disable the scheduler the way SkillUsageRouteTests and SkillUsageAnalyticsTests already do. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The `ci` job never declared `needs: changes` and read none of the four outputs, so the job and `scripts/ci-detect-changes.sh` fed nothing. Path filtering now lives in each Railway service's `watchPatterns`. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Railway omits `sleepApplication` from a service's deploy config once app sleep is off, so `railway config plan` reports `null -> false` for Gateway and Web in both environments on every run. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…-job Fix the flaky MCP naming suite and drop the unused CI job
…ites Every suite that calls `configure(app)` gets a detached `SkillUsageService.prune` at boot, whose per-project DELETEs can lock the shared in-memory SQLite database the suite is writing to. McpToolNamingTests hit this intermittently; these five suites carry the same race. Gating the lifecycle on `.testing` would have fixed all of them at once, but AdminAnalyticsRollupLifecycle documents that schedulers are expected to run under `--env testing` for staging, so this follows the existing per-suite convention instead. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
All 11 open alerts were against `next` 16.2.9 in apps/web. Nine are patched in 16.2.11, but the two critical ones require >= 16.3.3, so this goes to the current 16.3 patch release and moves `eslint-config-next` in lockstep. Supersedes Dependabot PR #21, which only reached 16.2.11. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…aining-suites Disable the retention scheduler in the remaining app-booting test suites
chore(deps): bump next to 16.3.6 to clear all 11 Dependabot alerts
Resume and refresh the repository catalog after installation even when no repository was selected, so first-time users can grant access and continue onboarding.
Protect the empty repository picker path with session and tenant checks before an installation intent can be created, including installation without a selected repository.
Provide the authenticated installer an absolute project return target, mount the Repo tab for legacy callbacks, and preserve the chosen branch when resuming. Cover the real project page and refreshed catalog flow.
The connect-repo conflict response points to the frontend installer rather than GitHub directly. Allow that exact same-origin endpoint for the current project while rejecting foreign origins, paths, duplicate project parameters, and userinfo; exercise the actual backend response shape.
fix: restore GitHub access onboarding for empty repository lists
|
Production accepted at merge commit ede7788: main CI 36656713497 passed; Web deployment 8f3adc35-637d-449e-b189-dfad0f54b725 and Gateway deployment ea554c34-6a14-4bbc-8f42-a8ac643eea9c both succeeded. Post-deploy health returned ok; unauthenticated installer returned 401; fresh WebP optimization decoded 256×134 with cache MISS; generated OG decoded 1200×630. Main has Next/eslint-config-next 16.3.6 and zero open Dependabot alerts. Superseded #21 is closed, and no open PRs remain. Authenticated Development UI was verified; signed-in Production UI is not claimed because the test account requires a new OAuth access grant that has not been approved. |
|
Additional browser smoke: a signed-in Production session became available for stygian-tech-test-user without an agent OAuth authorization action. The real Dashboard and Projects pages rendered correctly with no captured warnings/errors. This Production account has no projects; populated Runtime and repository flow acceptance remains the authenticated Development evidence. No Production fixture project or new credentials were created. |
Promotes the reviewed Development changes for GitHub repository onboarding and the Next security update. Accounts with no accessible repositories can configure GitHub access, refresh the picker, and resume on the Repo tab after installation. Selected-repository callbacks preserve the chosen branch, and the real backend 409 installer URL is validated against its origin, endpoint, and project.
Includes #49 (CI cleanup and naming-suite retention guard), #50 (remaining test scheduler guards), #51 (Next/eslint 16.3.6 and transitive dependencies), and #53 (MCP-13). Backend changes are test-only; no database migrations.
Validation completed:
Final Development acceptance at da7859f:
Browser limitation: the installer API navigation was blocked by the browser client. The access button generated the correct canonical project-scoped URL and absolute Repo return URL. A new live GitHub installation/access grant was not performed; authenticated installer behavior is covered by backend route tests.
Remaining release gate: explicit Production approval, followed by main CI, Railway deployment success, and Production smoke checks. No backend runtime source changes, database migrations, or Railway deployment configuration changes.
After approved promotion, verify exact Production deployment health and default-branch dependency alerts, then close superseded #21 once its replacement is confirmed on main. Production currently retains 11 open Next alerts (2 critical, 4 high, 5 medium).