Adopt be-framework/psalm-plugin across all demos - #21
Conversation
Wires up the Be Framework Psalm plugin in each demo's composer.json and adds a per-demo psalm.xml so contributors can statically detect: - Being constructors missing #[Input] or #[Inject] - #[Validate] methods throwing non-DomainException (silently bypassed) Dogfood results highlight the plugin's value: 6 real bugs surfaced — blog-publishing (4) and user-registration (2) had #[Validate] methods throwing InvalidArgumentException, which the framework does not catch. Those throws would silently bypass validation at runtime. Stock unused-class / unused-method / unused-property false positives (Be Framework loads classes via #[Be] reflection) are suppressed in each psalm.xml. Run with: composer psalm
Six validators were throwing InvalidArgumentException from inside #[Validate] methods. The framework's SemanticValidator only catches DomainException, so those throws would silently bypass validation at runtime — the offending value would reach business logic unchecked. Detected by be-framework/psalm-plugin (InvalidValidateException rule). - blog-publishing: AuthorName, Excerpt, HtmlBody, Slug now throw new InvalidAuthorNameException / InvalidExcerptException / InvalidHtmlBodyException / InvalidSlugException - user-registration: AvatarUrl, HashedPassword now throw new InvalidAvatarUrlException / InvalidHashedPasswordException Each new exception extends \DomainException and carries a #[Message] attribute matching the existing convention in src/Exception/.
|
Warning Rate limit exceeded
You’ve run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (29)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The plugin repo's default branch was renamed main -> 1.x to match the Be Framework versioning convention (0.x, 1.x). Update each demo's require-dev constraint accordingly.
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai full review |
✅ Actions performedFull review triggered. |
Allows @coderabbitai approve / resolve commands to issue formal GitHub review states (Approve / Request changes) instead of plain comments, once this lands on the default branch.
Summary
composer psalmand a per-demopsalm.xmlso the plugin can detect Be Framework-specific runtime errors at static-analysis time.#[Validate]methods were throwingInvalidArgumentException, which the framework'sSemanticValidatordoes not catch (catch (DomainException $e)only). Those throws would silently bypass validation in production. This PR also fixes them by introducing dedicatedDomainExceptionsubclasses that follow the existingsrc/Exception/Invalid*Exception.phpconvention (with#[Message]en/ja translations).Bugs fixed by the plugin
blog-publishing:AuthorName,Excerpt,HtmlBody,Sluguser-registration:AvatarUrl,HashedPasswordCommits
Add be-framework/psalm-plugin to all demos— composer.json + psalm.xml in 8 demos.Fix #[Validate] throws that bypass framework validation— 6 new exception classes, 6 throw-site updates.Test plan
cd demos/<demo> && composer installcomposer psalmreports zeroInvalidValidateException/MissingBeingParameterAttributeacross all demoscomposer devwhere applicable)