Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (5)
Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe PR updates the OpenAPI specification reference and adds low-level and Playwright regression coverage for user-token deletion of plain, slash-containing, and backslash-containing keys. ChangesItem deletion regression
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 2 files. (3 skipped: 3 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The E2E assertion conflicts with current behavior, and required release-note and documentation updates remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
Updates Portal to OpenAPI v0.3.12, enabling user-token deletion of encoded keys without an operator.
Changes:
- Adds parameter-binding and identity tests.
- Adds end-to-end deletion coverage.
- Documents and pins the updated contract.
| File | Summary | Review notes |
|---|---|---|
e2e/README.md |
Documents regression coverage. | Add the required CHANGES.md entry. Nit, 1 vote. |
e2e/portal-e2e/tests/portal-item-delete.spec.js |
Adds deletion scenarios for encoded keys. | Read-after-delete expects 404, but the current implementation returns 200 with an empty body. Critical, 1 vote. |
apollo-portal/src/test/java/com/ctrip/framework/apollo/openapi/v1/controller/ItemControllerParamBindLowLevelTest.java |
Expands operator and permission tests. | No final comments. |
apollo-portal/pom.xml |
Pins the OpenAPI contract to v0.3.12. |
Add the CHANGES.md entry and update API documentation and contract references. Nits, 2 and 1 votes. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| expect(deleteItem.status(), `delete ${target.kind} key without operator`).toBe(200); | ||
|
|
||
| const deletedItem = await request.get(`${namespaceUrl}/${target.resource}`, { headers }); | ||
| expect(deletedItem.status(), 'deleted key must no longer be readable').toBe(404); |
| <name>Apollo Portal</name> | ||
| <properties> | ||
| <apollo.openapi.spec.url>https://raw.githubusercontent.com/apolloconfig/apollo-openapi/v0.3.11/apollo-openapi.yaml</apollo.openapi.spec.url> | ||
| <apollo.openapi.spec.url>https://raw.githubusercontent.com/apolloconfig/apollo-openapi/v0.3.12/apollo-openapi.yaml</apollo.openapi.spec.url> |


What's the purpose of this PR
User-token deletion of keys containing
/or\fails before reaching the controller because the generated encoded-items DELETE interface requires anoperator. Upgrade the Portal contract reference to the released apollo-openapiv0.3.12, which makes that parameter optional so the existing controller can use the token owner. Consumer-token operator validation remains in place.Which issue(s) this PR fixes
Contract fix: apolloconfig/apollo-openapi#39
Brief changelog
v0.3.12contract.@regressionworkflow includes them.Validation
./mvnw -B -ntp clean test: 1281 passed, 1 skipped, no failures or errors. Used the released contract URL from the POM without a local spec override.spotless:applyand fullspotless:checkpassed.v0.3.11tov0.3.12comparison passed for 153 operations and 49 schemas.apollo-cli: user-token deletion without an operator passed for plain, slash, and backslash keys; subsequent reads returnednot_found, and other keys and values were preserved. Test apps and tokens were cleaned up.Follow this checklist to help us incorporate your contribution quickly and easily:
mvn clean testto make sure this pull request doesn't break anything.mvn spotless:applyto format your code.CHANGESlog.