Skip to content

feat: add missing CLI flags + fix all documentation - #43

Merged
ajianaz merged 2 commits into
developfrom
feat/docs-fix-and-missing-flags
May 30, 2026
Merged

ajianaz merged 2 commits into
developfrom
feat/docs-fix-and-missing-flags

Conversation

@ajianaz

@ajianaz ajianaz commented May 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

New CLI Flags (8 additions)

Review command:

  • --commit <ref> — review git commit/range (e.g. HEAD, HEAD~3..HEAD, abc123)
  • --diff-file <path> — review from a diff file instead of git
  • --quiet / -q — suppress non-essential output
  • --severity <level> — filter results by minimum severity (info|minor|major|critical)

Scan command:

  • --focus <areas> — override focus areas (e.g. security,performance)

Config command (new):

  • cora config show — display resolved configuration
  • cora config set <key> <value> — set config values (model, provider, format, severity)

Documentation Fixes (25 inconsistencies)

README: cargo install cora-cli, config path ~/.cora/config.toml, removed non-existent flags, removed Homebrew, rewrote commands section, fixed env vars table

Website docs (7 pages): Installation, Usage, CLI Reference, Providers, Examples, Configuration, Getting Started — all fixed to match actual code

Test Fix

  • Version assertion uses env!(CARGO_PKG_VERSION) instead of hardcoded 0.1.0

Test Results

  • 151/151 tests pass (129 unit + 16 integration + 6 config)
  • cargo check zero errors, zero warnings

Summary by CodeRabbit

  • New Features

    • Added cora config subcommand to display and configure settings.
    • Extended cora review with --commit, --diff-file, --quiet, and --severity filtering options.
    • Added --focus parameter to cora scan for overriding focus areas.
  • Documentation

    • Updated installation guides, CLI reference, and usage examples to reflect current command patterns, flags, and configuration structure.

Review Change Stack

Flags added:
- review --commit <ref>: review git commit/range
- review --diff-file <path>: review from diff file
- review --quiet: suppress non-essential output
- review --severity <level>: filter by min severity
- scan --focus <areas>: override focus areas
- config show: display resolved config
- config set <key> <value>: update config values

Documentation fixes:
- README: cargo install cora-cli, fix config path, remove
  non-existent flags (--branch, --full, --commit HEAD),
  remove Homebrew (tap doesn't exist), fix env vars table
- Website docs: fix all 10 inconsistencies across 7 pages
- Fix test version assertion (use env var, not hardcoded)

Fixes version test to use CARGO_PKG_VERSION env var
@coderabbitai

coderabbitai Bot commented May 30, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@ajianaz, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 49 minutes and 14 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: c5f643c4-10de-42d2-a0a3-d2f24b3bdbdd

📥 Commits

Reviewing files that changed from the base of the PR and between cd26703 and 90ff275.

📒 Files selected for processing (3)
  • src/commands/config_cmd.rs
  • src/commands/review.rs
  • src/main.rs
📝 Walkthrough

Walkthrough

This PR expands the cora CLI with configuration management, extended review workflows, and scan filtering. It adds a new cora config show/set subcommand, extends review with commit/diff-file/quiet/severity options, adds scan focus filtering, and comprehensively updates documentation to reflect the changes.

Changes

Configuration Management System

Layer / File(s) Summary
Config command implementation and CLI dispatch
src/commands/config_cmd.rs, src/commands/mod.rs, src/main.rs
New module exports execute_config_show (displays resolved config) and execute_config_set (updates ~/.cora/config.toml for model/provider/format/severity). Main.rs adds Command::Config variant with ConfigAction::{Show, Set} enum and dispatch to config subcommands.

Review & Scan Workflow Enhancements

Layer / File(s) Summary
Git commit diff API
src/git/diff.rs
New get_commit_diff(ref_str) helper generates diffs for commits and ranges, choosing between git diff and git show --format= based on ref syntax.
Review command extended capabilities
src/commands/review.rs
ReviewOptions gains commit, diff_file, quiet, and severity fields. execute_review treats empty diffs as no-op when quiet is set, filters response issues by severity threshold, and get_diff now supports reading local diff files and delegating to the git API for commits.
Scan command focus filtering
src/commands/scan.rs
ScanOptions adds focus field. execute_scan computes effective_focus by preferring CLI --focus over config focus, then passes it to scan_files.
CLI surface expansion and command wiring
src/main.rs
Adds Review flags (--commit, --diff-file, --quiet, --severity), Scan flag (--focus). ReviewOpts and ScanOpts structs are extended with corresponding fields. Command matching threads these through to handlers. Streaming status is suppressed in quiet mode.
Tests and comprehensive documentation updates
tests/cli_basic.rs, README.md, website/src/routes/docs/*
Version test uses dynamic crate version. README expanded with fuller command examples, updated config format, new environment variables. Website docs (CLI reference, configuration, examples, installation, providers, usage, getting-started) are comprehensively refreshed to reflect new flags, command modes, and configuration structure.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐰 The config commands hop in with show and set,
Review modes dance with commit and file yet,
Scan focuses in, quiet moments appear,
CLI expands far, the docs crystal clear!
A feature so full, from git to the web,
Your workflow now richly configured ahead!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changes: adding missing CLI flags and fixing documentation inconsistencies across the codebase.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/docs-fix-and-missing-flags

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 11

🧹 Nitpick comments (2)
src/commands/config_cmd.rs (1)

183-187: 💤 Low value

Duplicates loader::cora_dir().

cora_config_dir is identical to cora_dir in src/config/loader.rs. Consider promoting the loader's helper to pub(crate) and reusing it to avoid drift in the ~/.cora path.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/commands/config_cmd.rs` around lines 183 - 187, The function
cora_config_dir duplicates loader::cora_dir; change the helper in loader
(cora_dir) to pub(crate) and replace cora_config_dir to call loader::cora_dir()
instead of reimplementing the home path logic, removing the duplicated function
and importing loader::cora_dir where config_cmd uses it so the single source of
truth (loader::cora_dir) defines the ~/.cora path.
src/git/diff.rs (1)

53-59: 💤 Low value

Consider guarding against ref strings parsed as git options.

ref_str flows straight into git diff/git show as an argument. A value beginning with - (e.g. --output=<file>) would be interpreted as a git option rather than a revision, which can have surprising side effects. Since this is a local dev tool the blast radius is small, but rejecting refs that start with - (or validating the ref) is cheap hardening.

Also note git show <merge-commit> --format= produces no diff by default for merge commits — acceptable, just be aware.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/git/diff.rs` around lines 53 - 59, The get_commit_diff function currently
passes ref_str directly into git_cmd (used with "diff" or "show"), which allows
values starting with '-' to be interpreted as git options; update
get_commit_diff to validate/sanitize ref_str before calling git_cmd (e.g.,
reject or error for refs that start with '-' or otherwise fail validation),
returning an Err when the ref is invalid, or prefixing the ref with "--" only
when appropriate; reference the get_commit_diff function and the git_cmd call to
implement the guard and ensure all callers handle the resulting error.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@README.md`:
- Around line 151-153: The README examples use a positional path (e.g., "cora
scan . --focus security,performance") which doesn't match the CLI contract;
update those examples to either omit the path (rely on default current
directory) or use the long flag ("--path .") so they match the CLI; search for
occurrences of "cora scan . --focus" (and the other example similar at lines
nearby) and replace with either "cora scan --path . --focus
security,performance" or "cora scan --focus security,performance".
- Around line 239-241: The README example uses an invalid severity value
("severity: warning"); update the example to use one of the valid CLI severity
enums (info | minor | major | critical) by replacing the severity line (the
"severity" key in the config snippet) with a permitted value such as "severity:
minor" (or "info"/"major"/"critical") so the sample config is accurate and won't
mislead users.

In `@src/commands/config_cmd.rs`:
- Around line 100-109: The execute_config_set function currently only validates
the key; update it to also validate the provided value for keys "format" and
"severity": when key == "format" ensure value is one of
"pretty","json","compact","sarif" and when key == "severity" ensure value is one
of "info","minor","major","critical"; if the value is out of range, return an
anyhow::bail! with a clear message listing the allowed values (follow the
existing error style used for unsupported keys) so invalid values like "banana"
or "xml" are rejected before persisting.
- Around line 118-126: The current code silently swallows TOML parse errors by
using parse::<toml::Table>().unwrap_or_default(), which can wipe existing config
when you later write; replace the unwrap_or_default() with propagation of the
parse error (e.g. use .parse::<toml::Table>().with_context(|| format!("failed to
parse {} as TOML", path.display()))? or equivalent) so the error bubbles up
instead of returning an empty toml::Table; update the initialization of the
variable table (the let mut table = ... block) to return a contextualized error
on parse failure rather than defaulting.
- Around line 100-181: execute_config_set currently writes settings into
~/.cora/config.toml (using TOML tables) but loader::load_config only reads
CONFIG_FILENAME (.cora.yaml) and load_api_key_from_auth_file only reads
AUTH_FILENAME, so values set by execute_config_set never appear in runtime
Config; update execute_config_set to persist changes into the same YAML-backed
config used by loader::load_config (serialize into the CoraFile/serde_yaml
schema and write to CONFIG_FILENAME) or alternatively extend loader::load_config
to also read and merge the TOML file format written by execute_config_set;
locate execute_config_set, loader::load_config, CoraFile,
load_api_key_from_auth_file, CONFIG_FILENAME and AUTH_FILENAME to implement
consistent read/write behavior so config set updates are reflected at runtime.

In `@src/commands/review.rs`:
- Around line 95-103: The blocking logic is inverted: change the severity
comparison so block decisions match the output filter semantics. In the
should_block function in src/engine/review.rs and the blocking check in
src/commands/scan.rs replace comparisons using issue.severity >= min_severity
with issue.severity <= min_severity so that issues at or above the requested
minimum severity (e.g., critical/major when min_severity is major) will trigger
blocking consistently with the retain/filter logic in review.rs.

In `@website/src/routes/docs/cli-reference/`+page.svelte:
- Around line 134-139: Update the CLI examples that show positional path usage
to use the explicit flag form; replace instances of "cora scan <path>" and "cora
scan ." with "cora scan --path <dir>" and "cora scan --path ." (or leave as
"cora scan" for current directory) so the displayed command syntax matches the
CLI's defined option --path; adjust the two table rows that render <code
class="syntax-highlight">cora scan</code> and <code
class="syntax-highlight">cora scan .</code> accordingly.

In `@website/src/routes/docs/configuration/`+page.svelte:
- Line 73: The example YAML sets "severity: warning" which contradicts the
allowed values in the comment; update the "severity" key in the example to one
of the permitted values (e.g., "severity: minor" or "severity: major") so it
matches the comment's list (info, minor, major, critical) and ensure the
"severity" token in the snippet is changed accordingly.

In `@website/src/routes/docs/getting-started/`+page.svelte:
- Around line 124-125: Update the sample value for the severity field so it
matches the documented enum (info | minor | major | critical): replace the
current "warning" value used in the <div> showing <span
class="syntax-flag">severity:</span> with a valid enum value (e.g., "minor") and
make the same change for the other occurrence noted in the file (the second
severity example around the later block), ensuring both examples use a supported
enum value.

In `@website/src/routes/docs/usage/`+page.svelte:
- Around line 97-99: The displayed default-mode caption ("# Review staged
changes (default)") is inconsistent with the table (which says the default tries
staged first, then unpushed); update the text inside the span with class
"syntax-comment" (the element that currently contains "# Review staged changes
(default)") to reflect the actual behavior, e.g. "Review staged changes
(default: staged, then unpushed)" or similar wording so the page consistently
states "staged first, then unpushed" as the default.
- Line 177: The config example uses an invalid severity value ("warning");
update the example's severity field (the "severity:" entry) to one of the
allowed CLI enum values (info, minor, major, or critical) — e.g., replace
"warning" with "minor" so the snippet is copy-pasteable and valid.

---

Nitpick comments:
In `@src/commands/config_cmd.rs`:
- Around line 183-187: The function cora_config_dir duplicates loader::cora_dir;
change the helper in loader (cora_dir) to pub(crate) and replace cora_config_dir
to call loader::cora_dir() instead of reimplementing the home path logic,
removing the duplicated function and importing loader::cora_dir where config_cmd
uses it so the single source of truth (loader::cora_dir) defines the ~/.cora
path.

In `@src/git/diff.rs`:
- Around line 53-59: The get_commit_diff function currently passes ref_str
directly into git_cmd (used with "diff" or "show"), which allows values starting
with '-' to be interpreted as git options; update get_commit_diff to
validate/sanitize ref_str before calling git_cmd (e.g., reject or error for refs
that start with '-' or otherwise fail validation), returning an Err when the ref
is invalid, or prefixing the ref with "--" only when appropriate; reference the
get_commit_diff function and the git_cmd call to implement the guard and ensure
all callers handle the resulting error.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 48e75ad1-f17c-46b8-a78e-3e822caf1f3d

📥 Commits

Reviewing files that changed from the base of the PR and between 1caeab1 and cd26703.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (15)
  • README.md
  • src/commands/config_cmd.rs
  • src/commands/mod.rs
  • src/commands/review.rs
  • src/commands/scan.rs
  • src/git/diff.rs
  • src/main.rs
  • tests/cli_basic.rs
  • website/src/routes/docs/cli-reference/+page.svelte
  • website/src/routes/docs/configuration/+page.svelte
  • website/src/routes/docs/examples/+page.svelte
  • website/src/routes/docs/getting-started/+page.svelte
  • website/src/routes/docs/installation/+page.svelte
  • website/src/routes/docs/providers/+page.svelte
  • website/src/routes/docs/usage/+page.svelte

Comment thread README.md
Comment on lines +151 to 153
# Scan with focus areas
cora scan . --focus security,performance

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Scan examples use a positional path that doesn’t match the CLI contract.

These examples use cora scan . ..., but path is exposed as a long flag (--path). Docs should use cora scan --path . ... (or omit path and rely on default current directory).

Also applies to: 157-158

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@README.md` around lines 151 - 153, The README examples use a positional path
(e.g., "cora scan . --focus security,performance") which doesn't match the CLI
contract; update those examples to either omit the path (rely on default current
directory) or use the long flag ("--path .") so they match the CLI; search for
occurrences of "cora scan . --focus" (and the other example similar at lines
nearby) and replace with either "cora scan --path . --focus
security,performance" or "cora scan --focus security,performance".

Comment thread README.md
Comment on lines +239 to +241
severity: warning # minimum severity level
max_issues: 20 # max issues to report
focus: security,performance # focus areas

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Use a valid severity enum in the config example.

Line 239 shows severity: warning, but CLI severity values are info | minor | major | critical. This example can mislead users into invalid config values.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@README.md` around lines 239 - 241, The README example uses an invalid
severity value ("severity: warning"); update the example to use one of the valid
CLI severity enums (info | minor | major | critical) by replacing the severity
line (the "severity" key in the config snippet) with a permitted value such as
"severity: minor" (or "info"/"major"/"critical") so the sample config is
accurate and won't mislead users.

Comment on lines +100 to +109
pub fn execute_config_set(key: &str, value: &str) -> Result<()> {
// Validate the key
match key {
"model" | "provider" | "format" | "severity" => {}
_ => {
anyhow::bail!(
"unsupported key: {key}\nSupported keys: model, provider, format, severity"
);
}
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Validate the value, not just the key.

The key is validated but the value is accepted unconditionally, so cora config set severity banana or set format xml persists invalid data, diverging from the CLI flags which constrain severity to info|minor|major|critical and format to pretty|json|compact|sarif (see src/main.rs Lines 50, 115). Consider rejecting out-of-range values for format and severity here.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/commands/config_cmd.rs` around lines 100 - 109, The execute_config_set
function currently only validates the key; update it to also validate the
provided value for keys "format" and "severity": when key == "format" ensure
value is one of "pretty","json","compact","sarif" and when key == "severity"
ensure value is one of "info","minor","major","critical"; if the value is out of
range, return an anyhow::bail! with a clear message listing the allowed values
(follow the existing error style used for unsupported keys) so invalid values
like "banana" or "xml" are rejected before persisting.

Comment on lines +100 to +181
pub fn execute_config_set(key: &str, value: &str) -> Result<()> {
// Validate the key
match key {
"model" | "provider" | "format" | "severity" => {}
_ => {
anyhow::bail!(
"unsupported key: {key}\nSupported keys: model, provider, format, severity"
);
}
}

let dir = cora_config_dir()?;
std::fs::create_dir_all(&dir)
.with_context(|| format!("failed to create {}", dir.display()))?;

let path = dir.join("config.toml");

// Load existing config.toml content if it exists
let mut table = if path.is_file() {
let content = std::fs::read_to_string(&path)
.with_context(|| format!("failed to read {}", path.display()))?;
content
.parse::<toml::Table>()
.unwrap_or_default()
} else {
toml::Table::new()
};

// Map the key to the appropriate TOML structure
match key {
"model" => {
let provider = table
.entry("provider")
.or_insert_with(|| toml::Value::Table(toml::Table::new()));
if let toml::Value::Table(p) = provider {
p.insert("model".to_string(), toml::Value::String(value.to_string()));
}
}
"provider" => {
let provider = table
.entry("provider")
.or_insert_with(|| toml::Value::Table(toml::Table::new()));
if let toml::Value::Table(p) = provider {
p.insert("provider".to_string(), toml::Value::String(value.to_string()));
}
}
"format" => {
let output = table
.entry("output")
.or_insert_with(|| toml::Value::Table(toml::Table::new()));
if let toml::Value::Table(o) = output {
o.insert("format".to_string(), toml::Value::String(value.to_string()));
}
}
"severity" => {
let hook = table
.entry("hook")
.or_insert_with(|| toml::Value::Table(toml::Table::new()));
if let toml::Value::Table(h) = hook {
h.insert(
"min_severity".to_string(),
toml::Value::String(value.to_string()),
);
}
}
_ => unreachable!(),
}

let content = table.to_string();
std::fs::write(&path, content)
.with_context(|| format!("failed to write {}", path.display()))?;

println!(
"{} Set {} = {} in {}",
"✓".green().bold(),
key.bold(),
value.green(),
path.display()
);

Ok(())
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Confirm no general-config reader consumes ~/.cora/config.toml (only api_key should).
echo "=== references to config.toml / AUTH_FILENAME ==="
rg -nP --type=rust "config\.toml|AUTH_FILENAME" -C3
echo "=== what load_config actually reads ==="
ast-grep --pattern 'pub fn load_config($$$) -> $_ { $$$ }'
echo "=== CONFIG_FILENAME usage ==="
rg -nP --type=rust "CONFIG_FILENAME|\.cora\.yaml" -C2

Repository: ajianaz/cora-cli

Length of output: 14562


Fix cora config set to persist into the same config source loader::load_config reads

  • execute_config_set writes model/provider/format/severity into ~/.cora/config.toml (as TOML tables like [provider], [output], [hook]).
  • loader::load_config builds runtime Config exclusively from .cora.yaml (CONFIG_FILENAME) plus CLI overrides; ~/.cora/config.toml (AUTH_FILENAME) is only read for the API key (load_api_key_from_auth_file).
  • Therefore, values written by cora config set won’t be reflected in the runtime configuration returned by load_config.
  • Persist these settings into .cora.yaml using the existing CoraFile/serde_yaml schema (or update the loader to read a non-auth config file that matches what config set writes).
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/commands/config_cmd.rs` around lines 100 - 181, execute_config_set
currently writes settings into ~/.cora/config.toml (using TOML tables) but
loader::load_config only reads CONFIG_FILENAME (.cora.yaml) and
load_api_key_from_auth_file only reads AUTH_FILENAME, so values set by
execute_config_set never appear in runtime Config; update execute_config_set to
persist changes into the same YAML-backed config used by loader::load_config
(serialize into the CoraFile/serde_yaml schema and write to CONFIG_FILENAME) or
alternatively extend loader::load_config to also read and merge the TOML file
format written by execute_config_set; locate execute_config_set,
loader::load_config, CoraFile, load_api_key_from_auth_file, CONFIG_FILENAME and
AUTH_FILENAME to implement consistent read/write behavior so config set updates
are reflected at runtime.

Comment on lines +118 to +126
let mut table = if path.is_file() {
let content = std::fs::read_to_string(&path)
.with_context(|| format!("failed to read {}", path.display()))?;
content
.parse::<toml::Table>()
.unwrap_or_default()
} else {
toml::Table::new()
};

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Silent unwrap_or_default() can wipe the existing file (including the stored API key).

If ~/.cora/config.toml fails to parse as TOML, unwrap_or_default() discards its contents and starts from an empty table; the subsequent write then overwrites the file, destroying any prior data such as a saved api_key. Propagate the parse error with context instead of swallowing it.

🛡️ Proposed fix
-        content
-            .parse::<toml::Table>()
-            .unwrap_or_default()
+        content
+            .parse::<toml::Table>()
+            .with_context(|| format!("failed to parse existing {}", path.display()))?
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
let mut table = if path.is_file() {
let content = std::fs::read_to_string(&path)
.with_context(|| format!("failed to read {}", path.display()))?;
content
.parse::<toml::Table>()
.unwrap_or_default()
} else {
toml::Table::new()
};
let mut table = if path.is_file() {
let content = std::fs::read_to_string(&path)
.with_context(|| format!("failed to read {}", path.display()))?;
content
.parse::<toml::Table>()
.with_context(|| format!("failed to parse existing {}", path.display()))?
} else {
toml::Table::new()
};
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/commands/config_cmd.rs` around lines 118 - 126, The current code silently
swallows TOML parse errors by using parse::<toml::Table>().unwrap_or_default(),
which can wipe existing config when you later write; replace the
unwrap_or_default() with propagation of the parse error (e.g. use
.parse::<toml::Table>().with_context(|| format!("failed to parse {} as TOML",
path.display()))? or equivalent) so the error bubbles up instead of returning an
empty toml::Table; update the initialization of the variable table (the let mut
table = ... block) to return a contextualized error on parse failure rather than
defaulting.

Comment on lines +134 to +139
<td><code class="syntax-highlight">cora scan</code> <code class="text-[var(--muted-foreground)]">&lt;path&gt;</code></td>
<td>Scan files for issues</td>
</tr>
<tr>
<td><code class="syntax-highlight">cora review --file</code> <code class="text-[var(--muted-foreground)]">&lt;path&gt;</code></td>
<td>Review single file</td>
<td><code class="syntax-highlight">cora scan .</code> <code class="syntax-flag">[--incremental]</code></td>
<td>Scan only changed files</td>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

cora scan command syntax is documented incorrectly.

These rows show positional path usage, but the CLI defines path as --path <dir>. Please update examples to cora scan --path . (or just cora scan for current directory).

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@website/src/routes/docs/cli-reference/`+page.svelte around lines 134 - 139,
Update the CLI examples that show positional path usage to use the explicit flag
form; replace instances of "cora scan <path>" and "cora scan ." with "cora scan
--path <dir>" and "cora scan --path ." (or leave as "cora scan" for current
directory) so the displayed command syntax matches the CLI's defined option
--path; adjust the two table rows that render <code
class="syntax-highlight">cora scan</code> and <code
class="syntax-highlight">cora scan .</code> accordingly.

<pre class="whitespace-pre"><span class="syntax-comment"># cora project config</span>
<span class="syntax-highlight">review:</span>
<span class="syntax-flag">severity:</span> <span class="syntax-string">warning</span> <span class="syntax-comment"># minimum severity: info, warning, error</span>
<span class="syntax-flag">severity:</span> <span class="syntax-string">warning</span> <span class="syntax-comment"># minimum severity: info, minor, major, critical</span>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Example severity value contradicts allowed values.

Line 73 sets severity: warning but the same comment says valid levels are info, minor, major, critical. Use one of those values in the example.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@website/src/routes/docs/configuration/`+page.svelte at line 73, The example
YAML sets "severity: warning" which contradicts the allowed values in the
comment; update the "severity" key in the example to one of the permitted values
(e.g., "severity: minor" or "severity: major") so it matches the comment's list
(info, minor, major, critical) and ensure the "severity" token in the snippet is
changed accordingly.

Comment on lines +124 to +125
<div> <span class="syntax-flag">severity:</span> <span class="syntax-string">warning</span></div>
<div> <span class="syntax-flag">focus:</span> <span class="syntax-string">security,performance</span></div>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Severity example value is inconsistent with the documented enum.

The sample uses warning, but the documented valid values are info | minor | major | critical. Please align the example with the supported set.

Also applies to: 135-135

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@website/src/routes/docs/getting-started/`+page.svelte around lines 124 - 125,
Update the sample value for the severity field so it matches the documented enum
(info | minor | major | critical): replace the current "warning" value used in
the <div> showing <span class="syntax-flag">severity:</span> with a valid enum
value (e.g., "minor") and make the same change for the other occurrence noted in
the file (the second severity example around the later block), ensuring both
examples use a supported enum value.

Comment on lines +97 to +99
<div><span class="syntax-comment"># Review staged changes (default)</span></div>
<div><span class="syntax-cmd">$</span> <span class="syntax-highlight">cora review</span></div>
<div></div>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Align default-mode wording with the behavior described above.

Line 97 says default is “staged changes”, but the table states default tries staged first, then unpushed. Use one consistent description.

Suggested fix
-			<div><span class="syntax-comment"># Review staged changes (default)</span></div>
+			<div><span class="syntax-comment"># Review default mode (staged first, then unpushed)</span></div>
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
<div><span class="syntax-comment"># Review staged changes (default)</span></div>
<div><span class="syntax-cmd">$</span> <span class="syntax-highlight">cora review</span></div>
<div></div>
<div><span class="syntax-comment"># Review default mode (staged first, then unpushed)</span></div>
<div><span class="syntax-cmd">$</span> <span class="syntax-highlight">cora review</span></div>
<div></div>
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@website/src/routes/docs/usage/`+page.svelte around lines 97 - 99, The
displayed default-mode caption ("# Review staged changes (default)") is
inconsistent with the table (which says the default tries staged first, then
unpushed); update the text inside the span with class "syntax-comment" (the
element that currently contains "# Review staged changes (default)") to reflect
the actual behavior, e.g. "Review staged changes (default: staged, then
unpushed)" or similar wording so the page consistently states "staged first,
then unpushed" as the default.

<div><span class="syntax-comment"># .cora.yaml — example</span></div>
<div></div>
<div><span class="syntax-highlight">review:</span></div>
<div> <span class="syntax-flag">severity:</span> <span class="syntax-string">warning</span></div>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Use a valid severity enum value in the config example.

Line 177 uses warning, but the CLI severity levels are info | minor | major | critical. This example is copy-pasteable and currently invalid.

Suggested fix
-		<div>  <span class="syntax-flag">severity:</span> <span class="syntax-string">warning</span></div>
+		<div>  <span class="syntax-flag">severity:</span> <span class="syntax-string">minor</span></div>
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
<div> <span class="syntax-flag">severity:</span> <span class="syntax-string">warning</span></div>
<div> <span class="syntax-flag">severity:</span> <span class="syntax-string">minor</span></div>
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@website/src/routes/docs/usage/`+page.svelte at line 177, The config example
uses an invalid severity value ("warning"); update the example's severity field
(the "severity:" entry) to one of the allowed CLI enum values (info, minor,
major, or critical) — e.g., replace "warning" with "minor" so the snippet is
copy-pasteable and valid.

@ajianaz
ajianaz merged commit 0bfe809 into develop May 30, 2026
7 checks passed
@ajianaz
ajianaz deleted the feat/docs-fix-and-missing-flags branch June 1, 2026 02:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant