Skip to content

release: promote GitHub access onboarding and Next security fixes - #54

Merged
CountableNewt merged 16 commits into
mainfrom
dev
Sep 30, 2026
Merged

CountableNewt merged 16 commits into
mainfrom
dev

Conversation

@CountableNewt

@CountableNewt CountableNewt commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Promotes the reviewed Development changes for GitHub repository onboarding and the Next security update. Accounts with no accessible repositories can configure GitHub access, refresh the picker, and resume on the Repo tab after installation. Selected-repository callbacks preserve the chosen branch, and the real backend 409 installer URL is validated against its origin, endpoint, and project.

Includes #49 (CI cleanup and naming-suite retention guard), #50 (remaining test scheduler guards), #51 (Next/eslint 16.3.6 and transitive dependencies), and #53 (MCP-13). Backend changes are test-only; no database migrations.

Validation completed:

  • Local final frontend: 182 tests, types, lint, Next 16.3.6 build. Two unrelated navigation warnings are tracked as MCP-15.
  • Local Swift: 217 tests and release build with warnings treated as errors.
  • Exact fix: restore GitHub access onboarding for empty repository lists #53 head f9c4d98 passed full hosted CI; merged into dev as da7859f.
  • Dependency deployment 505bb09c-fd5a-4869-927e-08a6cb19c31b at 247d96f reached SUCCESS. Fresh Linux Sharp optimization returned WebP 256×134 with cache MISS; generated OG image returned PNG 1200×630.
  • Authenticated Development Runtime: retained counts, zero/unknown distinction, category/version details, assignment save/reload, telemetry-only save preserving assignments, unsaved draft preservation across analytics window changes. Original settings restored.

Final Development acceptance at da7859f:

  • Merged-dev CI 36654693285 and release CI 36654787448 passed.
  • Web deployment eab26857-a796-4075-9522-f25e6d8846fd and Gateway deployment 6663ad2f-3878-4bf8-98b3-57993783f90b reached SUCCESS at the reviewed commit. Gateway health passed after its deployment.
  • Authenticated browser verified empty-picker controls, empty-to-populated refresh, and simulated installation callback without prior selection: Repo mounts, picker reopens, refreshed results appear, callback URL clears to ?tab=repo. These cases used temporary tab-local fetch mocks; real repository connection remained intact and all test interception/tabs were removed.
  • Real Runtime dashboard reloaded with expected counts, original settings, and no captured browser errors/warnings.
  • Gateway health returned ok; negotiated WebP optimization returned HTTP 200, cache MISS, decoded 256×134.

Browser limitation: the installer API navigation was blocked by the browser client. The access button generated the correct canonical project-scoped URL and absolute Repo return URL. A new live GitHub installation/access grant was not performed; authenticated installer behavior is covered by backend route tests.

Remaining release gate: explicit Production approval, followed by main CI, Railway deployment success, and Production smoke checks. No backend runtime source changes, database migrations, or Railway deployment configuration changes.

After approved promotion, verify exact Production deployment health and default-branch dependency alerts, then close superseded #21 once its replacement is confirmed on main. Production currently retains 11 open Next alerts (2 critical, 4 high, 5 medium).

CountableNewt and others added 16 commits September 27, 2026 22:34
`withMcpToolNamingApp` boots the full app, so `SkillUsageRetentionLifecycle`
spawns a detached prune at boot. Its per-project DELETEs take a write lock on
the same shared in-memory SQLite database the suite is inserting into, which
intermittently failed the suite with "database is locked".

Disable the scheduler the way SkillUsageRouteTests and SkillUsageAnalyticsTests
already do.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The `ci` job never declared `needs: changes` and read none of the four outputs,
so the job and `scripts/ci-detect-changes.sh` fed nothing. Path filtering now
lives in each Railway service's `watchPatterns`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Railway omits `sleepApplication` from a service's deploy config once app sleep
is off, so `railway config plan` reports `null -> false` for Gateway and Web in
both environments on every run.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…-job

Fix the flaky MCP naming suite and drop the unused CI job
…ites

Every suite that calls `configure(app)` gets a detached `SkillUsageService.prune`
at boot, whose per-project DELETEs can lock the shared in-memory SQLite database
the suite is writing to. McpToolNamingTests hit this intermittently; these five
suites carry the same race.

Gating the lifecycle on `.testing` would have fixed all of them at once, but
AdminAnalyticsRollupLifecycle documents that schedulers are expected to run under
`--env testing` for staging, so this follows the existing per-suite convention
instead.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
All 11 open alerts were against `next` 16.2.9 in apps/web. Nine are patched in
16.2.11, but the two critical ones require >= 16.3.3, so this goes to the current
16.3 patch release and moves `eslint-config-next` in lockstep.

Supersedes Dependabot PR #21, which only reached 16.2.11.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…aining-suites

Disable the retention scheduler in the remaining app-booting test suites
chore(deps): bump next to 16.3.6 to clear all 11 Dependabot alerts
Resume and refresh the repository catalog after installation even when no repository was selected, so first-time users can grant access and continue onboarding.
Protect the empty repository picker path with session and tenant checks before an installation intent can be created, including installation without a selected repository.
Provide the authenticated installer an absolute project return target, mount the Repo tab for legacy callbacks, and preserve the chosen branch when resuming. Cover the real project page and refreshed catalog flow.
The connect-repo conflict response points to the frontend installer rather than GitHub directly. Allow that exact same-origin endpoint for the current project while rejecting foreign origins, paths, duplicate project parameters, and userinfo; exercise the actual backend response shape.
fix: restore GitHub access onboarding for empty repository lists
@CountableNewt
CountableNewt marked this pull request as ready for review September 30, 2026 01:44
@CountableNewt
CountableNewt merged commit ede7788 into main Sep 30, 2026
4 checks passed
@CountableNewt

Copy link
Copy Markdown
Collaborator Author

Production accepted at merge commit ede7788: main CI 36656713497 passed; Web deployment 8f3adc35-637d-449e-b189-dfad0f54b725 and Gateway deployment ea554c34-6a14-4bbc-8f42-a8ac643eea9c both succeeded. Post-deploy health returned ok; unauthenticated installer returned 401; fresh WebP optimization decoded 256×134 with cache MISS; generated OG decoded 1200×630. Main has Next/eslint-config-next 16.3.6 and zero open Dependabot alerts. Superseded #21 is closed, and no open PRs remain. Authenticated Development UI was verified; signed-in Production UI is not claimed because the test account requires a new OAuth access grant that has not been approved.

@CountableNewt

Copy link
Copy Markdown
Collaborator Author

Additional browser smoke: a signed-in Production session became available for stygian-tech-test-user without an agent OAuth authorization action. The real Dashboard and Projects pages rendered correctly with no captured warnings/errors. This Production account has no projects; populated Runtime and repository flow acceptance remains the authenticated Development evidence. No Production fixture project or new credentials were created.

This branch was previously deployed

1 inactive deployment
MyContextProtocol / dev — da7859f3 Deployed Sep 30, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant