test: cover user-token deletes for plain and encoded keys - #7
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The change is isolated to test coverage and the new assertions precisely validate the intended request behavior without introducing production-code risk.
Review effort: Lite
Findings: None
What changed in this PR
Adds regression coverage ensuring config delete uses the correct OpenAPI delete endpoint (items/* vs encodedItems/*) and request shape when authenticating with a user token, specifically for keys that are plain, contain /, or contain \, and ensuring no operator query parameter is included.
Changes:
- Add a new test that iterates over plain/slash/backslash keys and validates DELETE method, exact request path (plain vs Base64URL-encoded), and Bearer auth header.
- Assert the reported operation target in JSON output matches
config.deleteand preserves the original key string.
| File | Description |
|---|---|
tests/openapi.rs |
Adds a user-token-focused regression test validating config delete behavior for plain and path-sensitive keys without an operator parameter. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
config deleteuses the encoded-items endpoint for keys containing/or\, but the existing deletion coverage only exercised consumer tokens with an operator. Add user-token regression coverage for ordinary, slash, and backslash keys.The test checks the DELETE method, the exact plain or Base64URL-encoded path without an operator query parameter, Bearer authentication, and the reported operation target.
Validation:
cargo fmt --checkbash -n scripts/mutation-smoke.shcargo clippy --locked --offline --all-targets --all-features -- -D warningscargo test --locked --offline— 180 tests passedgit diff --check