Repository navigation
Development - #44
Merged
Merged
Development#44
Conversation
…ning with Gitleaks
There was a problem hiding this comment.
Pull request overview
This PR broadens the repository’s “guardrails” and developer workflow: it adds new verification scripts (env example/schema drift, Prisma drift, docs/project-map drift, local CI mirror), strengthens CI (coverage artifacts, extra Prisma checks, secret scanning), and updates standards/docs/templates accordingly. It also refactors a large set of tests (and a few runtime components) to reduce/avoid TypeScript type assertions by introducing shared test stubs/helpers and more explicit runtime narrowing.
Changes:
- Add new governance/verification tooling (env.example verification, Prisma drift verification, project-map drift verification, local CI mirror runner, duplication harness + allowlists).
- Update CI/workflows and Jest coverage configuration (coverage reporting + artifact upload; additional Prisma migration/status step; secret scanning workflow).
- Refactor tests and selected runtime code to remove unsafe type assertions and improve runtime validation/narrowing patterns.
Reviewed changes
Copilot reviewed 131 out of 133 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
| tools/small-helper-duplication-allowlist.json | Add allowlist scaffold for small-helper duplication harness |
| tools/duplication-allowlist.json | Add allowlist scaffold for core duplication harness |
| test/support/stubs.ts | Add shared test stubs/helpers (ConfigService + prototype stubs + method binder) |
| test/support/http.ts | Add shared HTTP ArgumentsHost/ExecutionContext factory helpers for tests |
| test/rate-limiters.int-spec.ts | Switch to shared config stub helper |
| test/idempotency.int-spec.ts | Replace FastifyRequest casts with request-like shape + reflective invocation helper |
| test/auth/auth-e2e.harness.ts | Add safer response-body field helpers; remove unnecessary type assertion on JSON.parse |
| test/auth/auth-account-deletion.e2e-spec.ts | Use new e2e harness helpers for structured field access |
| test/auth-emails-worker.int-spec.ts | Replace ad-hoc stubs/casts with shared stub helpers |
| test/admin-last-admin.int-spec.ts | Switch to shared config stub helper |
| scripts/verify-project-map-drift.ts | New verifier for AGENTS + docs index link/enumeration drift |
| scripts/verify-prisma-drift.ts | New verifier for Prisma schema validation + generated artifact drift |
| scripts/verify-env-example.ts | New verifier to ensure env.example matches schema + invariants |
| scripts/verify-e2e.ts | Add prisma:migrate:status before deploy in e2e lane |
| scripts/verify-ci-local.ts | New “non-Docker CI mirror” runner script |
| scripts/install-git-hooks.cjs | Add script to configure .githooks via core.hooksPath |
| scripts/architecture-smells.ts | Extend smell scanner rules (HttpCode literals, native Nest exceptions, missing ApiErrorCodes, worker wall-clock) |
| libs/shared/list-query/sort.ts | Tighten allowed-field checks via own-property guard; reduce casts |
| libs/shared/list-query/sort.spec.ts | Reduce unnecessary as unknown in test input |
| libs/shared/list-query/list-query.ts | Reduce unnecessary casting for filter object key extraction |
| libs/shared/list-query/list-query.spec.ts | Deduplicate repeated assertions via helper |
| libs/shared/list-query/filter.ts | Tighten allowlist checks via own-property guard; reduce casts |
| libs/shared/list-query/cursor.ts | Reduce JSON.parse assertion; tighten allowlist access via own-property guard |
| libs/shared/list-query/cursor-after.spec.ts | Add helper to enforce string cursor values (less casting) |
| libs/platform/storage/object-storage.service.spec.ts | Switch to shared config stub; reduce unsafe casts for config inspection |
| libs/platform/redis/redis.service.spec.ts | Switch to shared config stub; tighten mock typing/narrowing |
| libs/platform/rbac/rbac.guard.spec.ts | Replace manual ExecutionContext mocks with shared helper; use prototype stubs |
| libs/platform/rbac/rbac.decorator.ts | Remove redundant as unknown on Reflect metadata read |
| libs/platform/rbac/db-role-hydrator.service.spec.ts | Use prototype stubs rather than as unknown as |
| libs/platform/queue/trace-propagation.spec.ts | Tighten runtime narrowing; use shared config stub; safer Worker mock access |
| libs/platform/queue/queue.producer.ts | Tighten BullMQ generics; reduce unsafe payload casts |
| libs/platform/queue/queue-name.ts | Remove nominal branding in favor of runtime validation (avoid assertions) |
| libs/platform/queue/job-name.ts | Remove nominal branding in favor of runtime validation (avoid assertions) |
| libs/platform/queue/job-meta.ts | Refactor OTEL meta merge with runtime validation and safer reads |
| libs/platform/push/push.jobs.spec.ts | Replace ad-hoc stubs with prototype stubs; reduce unsafe casts |
| libs/platform/push/fcm-push.service.ts | Remove redundant JSON.parse(... ) as unknown |
| libs/platform/push/fcm-push.service.spec.ts | Switch to shared config stub |
| libs/platform/otel/telemetry.ts | Extract request-path parsing helper; safer access to req.url |
| libs/platform/logging/logging.module.ts | Use Reflect-based property access/syncing for request IDs + status code reads |
| libs/platform/http/request-context.decorator.spec.ts | Replace FastifyRequest casts with request-like shape + reflective calls |
| libs/platform/http/list-query/list-query.pipe.ts | Avoid casting arbitrary value into record; safely coerce |
| libs/platform/http/list-query/list-query.pipe.spec.ts | Tighten error narrowing without unsafe casting |
| libs/platform/http/list-query/list-query.decorator.ts | Remove unnecessary cast on Query(new ListQueryPipe(...)) |
| libs/platform/http/list-query/api-list-query.decorator.ts | Avoid index-cast by checking own properties before lookup |
| libs/platform/http/interceptors/response-envelope.interceptor.ts | Refactor list-envelope detection + normalized meta derivation |
| libs/platform/http/interceptors/response-envelope.interceptor.spec.ts | Update tests to use shared HTTP context + safer meta reads |
| libs/platform/http/idempotency/idempotency.service.spec.ts | Use prototype stubs instead of as unknown as |
| libs/platform/http/idempotency/idempotency.core.ts | Remove redundant JSON.parse(... ) as unknown; reduce body cast |
| libs/platform/http/idempotency/idempotency.core.spec.ts | Replace FastifyRequest casts with request-like shape + reflective call |
| libs/platform/http/filters/problem-details.filter.ts | Safer parsing of HttpException response shape + header narrowing |
| libs/platform/http/filters/problem-details.filter.spec.ts | Use shared ArgumentsHost helper; simplify reply mocks |
| libs/platform/http/filters/feature-error.mapper.spec.ts | Use shared ArgumentsHost helper |
| libs/platform/http/fastify-hooks.ts | Extract raw-request requestId/id syncing helper |
| libs/platform/http/fastify-adapter.ts | Extract querystring parser helper; avoid unsafe cast on qs.parse output |
| libs/platform/email/email.service.spec.ts | Switch to shared config stub; improve jest mock typing |
| libs/platform/di/app-service.provider.spec.ts | Avoid unsafe useFactory casts; treat factory as maybe-async |
| libs/platform/db/tx-retry.spec.ts | Replace ad-hoc PrismaClient casts with prototype stubs and safer error creation |
| libs/platform/config/env.validation.ts | Refactor validation error formatting with Reflect-based safe accessors |
| libs/platform/config/env.transforms.ts | Make TransformEnvBoolean resilient to non-object obj values |
| libs/platform/auth/auth-keyring.service.ts | Tighten JWK typing/validation; safer export/import handling |
| libs/platform/auth/auth-keyring.service.spec.ts | Remove stubConfig; use ConfigService directly; tighten JWK typing |
| libs/platform/auth/access-token.guard.spec.ts | Replace casts with prototype stubs; create real logger instance with mocked methods |
| libs/platform/auth/access-token-verifier.service.ts | Remove redundant JSON.parse(... ) as unknown |
| libs/features/users/infra/storage/users-profile-image-storage.adapter.spec.ts | Replace partial-cast helper with prototype stubs |
| libs/features/users/infra/persistence/prisma-users.repository.ts | Add explicit Prisma-enum-to-domain mapping helpers for role/status |
| libs/features/users/infra/persistence/prisma-users.repository.spec.ts | Use prototype stubs; tighten transaction client typing |
| libs/features/users/infra/jobs/user-account-deletion-email.jobs.spec.ts | Use prototype stubs for queue/email |
| libs/features/users/infra/http/user-account-deletion.controller.ts | Replace raw @HttpCode(204) with HttpStatus.NO_CONTENT |
| libs/features/users/infra/http/profile-image.controller.ts | Replace raw @HttpCode(...) with HttpStatus.* |
| libs/features/users/infra/http/dtos/me.dto.ts | Harden custom validator helper against malformed constraints/value shapes |
| libs/features/users/app/user-profile-image.service.ts | Avoid includes cast by using some equality check |
| libs/features/auth/infra/security/google-oidc-id-token-verifier.ts | Replace Function-based dynamic import; add module shape guard |
| libs/features/auth/infra/persistence/prisma-auth.repository.users.spec.ts | Use prototype stubs; tighten transaction client typing |
| libs/features/auth/infra/persistence/prisma-auth.repository.prisma-errors.ts | Safer meta parsing for unique constraint detection |
| libs/features/auth/infra/persistence/prisma-auth.repository.mappers.ts | Add explicit Prisma-enum-to-domain mapping; remove email cast |
| libs/features/auth/infra/http/me-push-token.controller.spec.ts | Replace partial-cast helpers with prototype stubs; tighten response narrowing |
| libs/features/auth/infra/http/auth.controller.ts | Replace raw @HttpCode(...) with HttpStatus.* |
| libs/features/auth/app/auth.service.oidc.spec.ts | Replace Email casts with normalizeEmail helper |
| libs/features/auth/app/auth.service.helpers.spec.ts | Remove unsafe cast by typing verifier as the interface |
| libs/features/auth/app/auth.service.deleted-user.spec.ts | Replace Email cast with normalizeEmail helper |
| libs/features/admin/infra/persistence/prisma-admin.mappers.ts | New explicit mappers for admin-facing enums/actions |
| libs/features/admin/infra/persistence/prisma-admin-users.query-builders.ts | Use new admin mappers instead of string casts |
| libs/features/admin/infra/persistence/prisma-admin-audit.repository.spec.ts | Use prototype stubs; tighten nextCursor handling |
| libs/features/admin/infra/persistence/prisma-admin-audit.query-builders.ts | Use new admin mappers instead of string casts |
| jest.config.cjs | Improve coverage collection patterns; add reporters |
| eslint.config.mjs | Enforce “no type assertions” and discourage unnecessary assertions |
| env.example | Convert optional integration examples to commented guidance; adjust sample values |
| docs/standards/testing-strategy.md | Document coverage command + exclusions + posture |
| docs/standards/README.md | Expand/reorder standards index |
| docs/standards/database.md | Document Prisma drift + migrate status expectations |
| docs/standards/configuration.md | Document env.example verification gate |
| docs/standards/code-quality.md | Document duplication harness; clarify worker wall-clock expectation |
| docs/standards/ci-cd.md | Document new CI gates and local CI mirror |
| docs/standards/api-response-standard.md | Codify controller rules (HttpStatus constants, ApiErrorCodes, avoid native exceptions) |
| docs/README.md | Add/expand docs index links |
| docs/openapi/openapi.yaml | Update snapshot for AccountDeletionDto schema typing |
| docs/guide/development-workflow.md | Add verify:env / verify:ci-local / duplication:report to workflow |
| docs/exec-plans/tech-debt-tracker.md | Add technical debt tracker template |
| docs/exec-plans/README.md | Add execution plan process documentation |
| docs/exec-plans/completed/.gitkeep | Add placeholder for completed plans |
| docs/exec-plans/active/.gitkeep | Add placeholder for active plans |
| docs/exec-plans/_template.md | Add execution plan template |
| docs/engineering/README.md | Add links for new agent/guardrail docs |
| docs/engineering/parallel-agent-workflow.md | Add guidance for parallel agent/worktree workflows |
| docs/engineering/guardrails.md | New guardrails overview + command catalog |
| docs/engineering/duplication-harness.md | New duplication harness documentation |
| docs/engineering/backend-runtime-evidence.md | New guidance on runtime evidence expectations |
| docs/engineering/agent-pr-loop.md | New agent delivery loop contract documentation |
| docs/contributing/commit-conventions.md | Add commit message conventions documentation |
| docs/adr/README.md | Add ADR index |
| commitlint.config.cjs | Add commitlint rules + allowed scopes/types |
| apps/worker/src/jobs/users-account-deletion.worker.ts | Replace job-name switch/casts with type-guard routing |
| apps/worker/src/jobs/users-account-deletion.handlers.spec.ts | Use prototype stubs for Prisma/storage/job |
| AGENTS.md | Expand agent workflow + guardrails + commands; codify “no type assertions” rule |
| .jscpd.small-helpers.json | Add small-helper duplication scan profile |
| .jscpd.json | Add core duplication scan profile |
| .gitignore | Ignore .tmp/ output |
| .github/workflows/governance.yml | Add gitleaks secret scan workflow |
| .github/workflows/ci.yml | Add verify:prisma + verify:env; switch to coverage run + upload; add migrate status |
| .github/pull_request_template.md | Expand PR template for risk class, acceptance criteria, evidence, verification honesty |
| .githooks/commit-msg | Add commit-msg hook to enforce commitlint locally |
| _WIP/architecture-smells.md | Remove generated report from repo |
| _WIP/2026-02-26_architecture-smell-scan-engineering-proposal.md | Remove old proposal doc from repo |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
80
to
+85
| if (issues.length > 0) { | ||
| throw new ListQueryValidationError(issues); | ||
| } | ||
| if (!afterObj) { | ||
| throw new ListQueryValidationError([{ field: 'cursor', message: 'Cursor "after" is missing' }]); | ||
| } |
Comment on lines
+9
to
+14
| export function createPrototypeStub< | ||
| TClass extends abstract new (...args: never[]) => object, | ||
| TProps extends object, | ||
| >(ctor: TClass, props: TProps): InstanceType<TClass> & TProps { | ||
| return Object.assign(Object.create(ctor.prototype), props); | ||
| } |
| exit 1 | ||
| fi | ||
|
|
||
| npx --no -- commitlint --edit "$1" |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Phase Task IDs Covered
P1-2,P2-1,P3-4Architecture Smell Impact
OpenAPI / Error Code Impact
yes/no)Verification
npm run verifynpm run smells:arch:cinpm run verify:e2e(when DB/Redis/queue/storage behavior changed)Risk / Rollback