fix: harden commitment API route validation and tests - #1875
Closed
Cole-dev-cyber wants to merge 19 commits into
Closed
Cole-dev-cyber wants to merge 19 commits into
Cole-dev-cyber wants to merge 19 commits into
Conversation
|
@Cole-dev-cyber is attempting to deploy a commit to the 1nonly's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
@Cole-dev-cyber Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
Author
|
@Commitlabs-Org Hi! This PR is open and ready for review — happy to address any feedback. Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
This PR hardens the commitments API route validation path by establishing a durable regression contract for the implementation anchored at
src/app/api/commitments/search/route.ts. It introduces a strict validation boundary before service/database work: query parameters are schema-checked, authorization is enforced, errors are mapped to standardized API responses, and query results are bounded. Focused tests cover success, failure, empty, retry, permission, and boundary states, and the supported API contract is documented for existing consumers.Related Issue
Refs #
Changes
🛡️ Validation and error contract
[MODIFY]
src/lib/api/errors.tsBadRequestError,UnauthorizedError,ForbiddenError,NotFoundError,RateLimitError, andInternalError.[MODIFY]
src/lib/commitments/service.tslimitdefaults to 20, max 100;offsetmax 10,000.[MODIFY]
src/app/api/commitments/search/route.tsq,status,limit, andoffsetwith a reusable schema.401/403responses.Cache-Control: no-storeandRetry-Afteron retryable503responses.🧪 Test coverage
src/app/api/commitments/search/__tests__/search.test.tslimit=0,limit=101,offset=10001, negative values, and non-integer values.503withRetry-After, and a subsequent retry succeeds.📚 API contract and compatibility
docs/api/commitments.mdDesign tradeoffs
400instead of silently ignored; this protects the contract and forces malformed clients to correct their behavior.Verification Results
Limitations: no interactive UI is modified, so keyboard/focus/screen-reader/responsive/reduced-motion tests do not apply to this API-only change. Loading UI states remain the responsibility of consuming clients; this PR covers loading/retry behavior at the route/service async boundary.
search.test.tscover each statedocs/api/commitments.mdupdated; existing response shapes preservedRefs #<issue-number>Refs #<issue-number>in Related IssueCloses #1760