Skip to content

Development - #44

Merged
fikrilal merged 22 commits into
mainfrom
development
Jun 5, 2026
Merged

fikrilal merged 22 commits into
mainfrom
development

Conversation

@fikrilal

@fikrilal fikrilal commented Jun 5, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • What changed:
  • Why:

Phase Task IDs Covered

  • Example: P1-2, P2-1, P3-4

Architecture Smell Impact

  • New findings:
  • Reduced findings:
  • Unchanged findings:
  • Smell trend by phase:

OpenAPI / Error Code Impact

  • OpenAPI snapshot changed? (yes/no)
  • Spectral impact:
  • Error code additions/changes:

Verification

  • npm run verify
  • npm run smells:arch:ci
  • npm run verify:e2e (when DB/Redis/queue/storage behavior changed)

Risk / Rollback

  • Risk areas:
  • Rollback plan:

@fikrilal fikrilal self-assigned this Jun 5, 2026
Copilot AI review requested due to automatic review settings June 5, 2026 00:08

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR broadens the repository’s “guardrails” and developer workflow: it adds new verification scripts (env example/schema drift, Prisma drift, docs/project-map drift, local CI mirror), strengthens CI (coverage artifacts, extra Prisma checks, secret scanning), and updates standards/docs/templates accordingly. It also refactors a large set of tests (and a few runtime components) to reduce/avoid TypeScript type assertions by introducing shared test stubs/helpers and more explicit runtime narrowing.

Changes:

  • Add new governance/verification tooling (env.example verification, Prisma drift verification, project-map drift verification, local CI mirror runner, duplication harness + allowlists).
  • Update CI/workflows and Jest coverage configuration (coverage reporting + artifact upload; additional Prisma migration/status step; secret scanning workflow).
  • Refactor tests and selected runtime code to remove unsafe type assertions and improve runtime validation/narrowing patterns.

Reviewed changes

Copilot reviewed 131 out of 133 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
tools/small-helper-duplication-allowlist.json Add allowlist scaffold for small-helper duplication harness
tools/duplication-allowlist.json Add allowlist scaffold for core duplication harness
test/support/stubs.ts Add shared test stubs/helpers (ConfigService + prototype stubs + method binder)
test/support/http.ts Add shared HTTP ArgumentsHost/ExecutionContext factory helpers for tests
test/rate-limiters.int-spec.ts Switch to shared config stub helper
test/idempotency.int-spec.ts Replace FastifyRequest casts with request-like shape + reflective invocation helper
test/auth/auth-e2e.harness.ts Add safer response-body field helpers; remove unnecessary type assertion on JSON.parse
test/auth/auth-account-deletion.e2e-spec.ts Use new e2e harness helpers for structured field access
test/auth-emails-worker.int-spec.ts Replace ad-hoc stubs/casts with shared stub helpers
test/admin-last-admin.int-spec.ts Switch to shared config stub helper
scripts/verify-project-map-drift.ts New verifier for AGENTS + docs index link/enumeration drift
scripts/verify-prisma-drift.ts New verifier for Prisma schema validation + generated artifact drift
scripts/verify-env-example.ts New verifier to ensure env.example matches schema + invariants
scripts/verify-e2e.ts Add prisma:migrate:status before deploy in e2e lane
scripts/verify-ci-local.ts New “non-Docker CI mirror” runner script
scripts/install-git-hooks.cjs Add script to configure .githooks via core.hooksPath
scripts/architecture-smells.ts Extend smell scanner rules (HttpCode literals, native Nest exceptions, missing ApiErrorCodes, worker wall-clock)
libs/shared/list-query/sort.ts Tighten allowed-field checks via own-property guard; reduce casts
libs/shared/list-query/sort.spec.ts Reduce unnecessary as unknown in test input
libs/shared/list-query/list-query.ts Reduce unnecessary casting for filter object key extraction
libs/shared/list-query/list-query.spec.ts Deduplicate repeated assertions via helper
libs/shared/list-query/filter.ts Tighten allowlist checks via own-property guard; reduce casts
libs/shared/list-query/cursor.ts Reduce JSON.parse assertion; tighten allowlist access via own-property guard
libs/shared/list-query/cursor-after.spec.ts Add helper to enforce string cursor values (less casting)
libs/platform/storage/object-storage.service.spec.ts Switch to shared config stub; reduce unsafe casts for config inspection
libs/platform/redis/redis.service.spec.ts Switch to shared config stub; tighten mock typing/narrowing
libs/platform/rbac/rbac.guard.spec.ts Replace manual ExecutionContext mocks with shared helper; use prototype stubs
libs/platform/rbac/rbac.decorator.ts Remove redundant as unknown on Reflect metadata read
libs/platform/rbac/db-role-hydrator.service.spec.ts Use prototype stubs rather than as unknown as
libs/platform/queue/trace-propagation.spec.ts Tighten runtime narrowing; use shared config stub; safer Worker mock access
libs/platform/queue/queue.producer.ts Tighten BullMQ generics; reduce unsafe payload casts
libs/platform/queue/queue-name.ts Remove nominal branding in favor of runtime validation (avoid assertions)
libs/platform/queue/job-name.ts Remove nominal branding in favor of runtime validation (avoid assertions)
libs/platform/queue/job-meta.ts Refactor OTEL meta merge with runtime validation and safer reads
libs/platform/push/push.jobs.spec.ts Replace ad-hoc stubs with prototype stubs; reduce unsafe casts
libs/platform/push/fcm-push.service.ts Remove redundant JSON.parse(... ) as unknown
libs/platform/push/fcm-push.service.spec.ts Switch to shared config stub
libs/platform/otel/telemetry.ts Extract request-path parsing helper; safer access to req.url
libs/platform/logging/logging.module.ts Use Reflect-based property access/syncing for request IDs + status code reads
libs/platform/http/request-context.decorator.spec.ts Replace FastifyRequest casts with request-like shape + reflective calls
libs/platform/http/list-query/list-query.pipe.ts Avoid casting arbitrary value into record; safely coerce
libs/platform/http/list-query/list-query.pipe.spec.ts Tighten error narrowing without unsafe casting
libs/platform/http/list-query/list-query.decorator.ts Remove unnecessary cast on Query(new ListQueryPipe(...))
libs/platform/http/list-query/api-list-query.decorator.ts Avoid index-cast by checking own properties before lookup
libs/platform/http/interceptors/response-envelope.interceptor.ts Refactor list-envelope detection + normalized meta derivation
libs/platform/http/interceptors/response-envelope.interceptor.spec.ts Update tests to use shared HTTP context + safer meta reads
libs/platform/http/idempotency/idempotency.service.spec.ts Use prototype stubs instead of as unknown as
libs/platform/http/idempotency/idempotency.core.ts Remove redundant JSON.parse(... ) as unknown; reduce body cast
libs/platform/http/idempotency/idempotency.core.spec.ts Replace FastifyRequest casts with request-like shape + reflective call
libs/platform/http/filters/problem-details.filter.ts Safer parsing of HttpException response shape + header narrowing
libs/platform/http/filters/problem-details.filter.spec.ts Use shared ArgumentsHost helper; simplify reply mocks
libs/platform/http/filters/feature-error.mapper.spec.ts Use shared ArgumentsHost helper
libs/platform/http/fastify-hooks.ts Extract raw-request requestId/id syncing helper
libs/platform/http/fastify-adapter.ts Extract querystring parser helper; avoid unsafe cast on qs.parse output
libs/platform/email/email.service.spec.ts Switch to shared config stub; improve jest mock typing
libs/platform/di/app-service.provider.spec.ts Avoid unsafe useFactory casts; treat factory as maybe-async
libs/platform/db/tx-retry.spec.ts Replace ad-hoc PrismaClient casts with prototype stubs and safer error creation
libs/platform/config/env.validation.ts Refactor validation error formatting with Reflect-based safe accessors
libs/platform/config/env.transforms.ts Make TransformEnvBoolean resilient to non-object obj values
libs/platform/auth/auth-keyring.service.ts Tighten JWK typing/validation; safer export/import handling
libs/platform/auth/auth-keyring.service.spec.ts Remove stubConfig; use ConfigService directly; tighten JWK typing
libs/platform/auth/access-token.guard.spec.ts Replace casts with prototype stubs; create real logger instance with mocked methods
libs/platform/auth/access-token-verifier.service.ts Remove redundant JSON.parse(... ) as unknown
libs/features/users/infra/storage/users-profile-image-storage.adapter.spec.ts Replace partial-cast helper with prototype stubs
libs/features/users/infra/persistence/prisma-users.repository.ts Add explicit Prisma-enum-to-domain mapping helpers for role/status
libs/features/users/infra/persistence/prisma-users.repository.spec.ts Use prototype stubs; tighten transaction client typing
libs/features/users/infra/jobs/user-account-deletion-email.jobs.spec.ts Use prototype stubs for queue/email
libs/features/users/infra/http/user-account-deletion.controller.ts Replace raw @HttpCode(204) with HttpStatus.NO_CONTENT
libs/features/users/infra/http/profile-image.controller.ts Replace raw @HttpCode(...) with HttpStatus.*
libs/features/users/infra/http/dtos/me.dto.ts Harden custom validator helper against malformed constraints/value shapes
libs/features/users/app/user-profile-image.service.ts Avoid includes cast by using some equality check
libs/features/auth/infra/security/google-oidc-id-token-verifier.ts Replace Function-based dynamic import; add module shape guard
libs/features/auth/infra/persistence/prisma-auth.repository.users.spec.ts Use prototype stubs; tighten transaction client typing
libs/features/auth/infra/persistence/prisma-auth.repository.prisma-errors.ts Safer meta parsing for unique constraint detection
libs/features/auth/infra/persistence/prisma-auth.repository.mappers.ts Add explicit Prisma-enum-to-domain mapping; remove email cast
libs/features/auth/infra/http/me-push-token.controller.spec.ts Replace partial-cast helpers with prototype stubs; tighten response narrowing
libs/features/auth/infra/http/auth.controller.ts Replace raw @HttpCode(...) with HttpStatus.*
libs/features/auth/app/auth.service.oidc.spec.ts Replace Email casts with normalizeEmail helper
libs/features/auth/app/auth.service.helpers.spec.ts Remove unsafe cast by typing verifier as the interface
libs/features/auth/app/auth.service.deleted-user.spec.ts Replace Email cast with normalizeEmail helper
libs/features/admin/infra/persistence/prisma-admin.mappers.ts New explicit mappers for admin-facing enums/actions
libs/features/admin/infra/persistence/prisma-admin-users.query-builders.ts Use new admin mappers instead of string casts
libs/features/admin/infra/persistence/prisma-admin-audit.repository.spec.ts Use prototype stubs; tighten nextCursor handling
libs/features/admin/infra/persistence/prisma-admin-audit.query-builders.ts Use new admin mappers instead of string casts
jest.config.cjs Improve coverage collection patterns; add reporters
eslint.config.mjs Enforce “no type assertions” and discourage unnecessary assertions
env.example Convert optional integration examples to commented guidance; adjust sample values
docs/standards/testing-strategy.md Document coverage command + exclusions + posture
docs/standards/README.md Expand/reorder standards index
docs/standards/database.md Document Prisma drift + migrate status expectations
docs/standards/configuration.md Document env.example verification gate
docs/standards/code-quality.md Document duplication harness; clarify worker wall-clock expectation
docs/standards/ci-cd.md Document new CI gates and local CI mirror
docs/standards/api-response-standard.md Codify controller rules (HttpStatus constants, ApiErrorCodes, avoid native exceptions)
docs/README.md Add/expand docs index links
docs/openapi/openapi.yaml Update snapshot for AccountDeletionDto schema typing
docs/guide/development-workflow.md Add verify:env / verify:ci-local / duplication:report to workflow
docs/exec-plans/tech-debt-tracker.md Add technical debt tracker template
docs/exec-plans/README.md Add execution plan process documentation
docs/exec-plans/completed/.gitkeep Add placeholder for completed plans
docs/exec-plans/active/.gitkeep Add placeholder for active plans
docs/exec-plans/_template.md Add execution plan template
docs/engineering/README.md Add links for new agent/guardrail docs
docs/engineering/parallel-agent-workflow.md Add guidance for parallel agent/worktree workflows
docs/engineering/guardrails.md New guardrails overview + command catalog
docs/engineering/duplication-harness.md New duplication harness documentation
docs/engineering/backend-runtime-evidence.md New guidance on runtime evidence expectations
docs/engineering/agent-pr-loop.md New agent delivery loop contract documentation
docs/contributing/commit-conventions.md Add commit message conventions documentation
docs/adr/README.md Add ADR index
commitlint.config.cjs Add commitlint rules + allowed scopes/types
apps/worker/src/jobs/users-account-deletion.worker.ts Replace job-name switch/casts with type-guard routing
apps/worker/src/jobs/users-account-deletion.handlers.spec.ts Use prototype stubs for Prisma/storage/job
AGENTS.md Expand agent workflow + guardrails + commands; codify “no type assertions” rule
.jscpd.small-helpers.json Add small-helper duplication scan profile
.jscpd.json Add core duplication scan profile
.gitignore Ignore .tmp/ output
.github/workflows/governance.yml Add gitleaks secret scan workflow
.github/workflows/ci.yml Add verify:prisma + verify:env; switch to coverage run + upload; add migrate status
.github/pull_request_template.md Expand PR template for risk class, acceptance criteria, evidence, verification honesty
.githooks/commit-msg Add commit-msg hook to enforce commitlint locally
_WIP/architecture-smells.md Remove generated report from repo
_WIP/2026-02-26_architecture-smell-scan-engineering-proposal.md Remove old proposal doc from repo

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines 80 to +85
if (issues.length > 0) {
throw new ListQueryValidationError(issues);
}
if (!afterObj) {
throw new ListQueryValidationError([{ field: 'cursor', message: 'Cursor "after" is missing' }]);
}
Comment thread test/support/stubs.ts
Comment on lines +9 to +14
export function createPrototypeStub<
TClass extends abstract new (...args: never[]) => object,
TProps extends object,
>(ctor: TClass, props: TProps): InstanceType<TClass> & TProps {
return Object.assign(Object.create(ctor.prototype), props);
}
Comment thread .githooks/commit-msg
exit 1
fi

npx --no -- commitlint --edit "$1"
@fikrilal
fikrilal merged commit 12e5a3f into main Jun 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants