Skip to content

Adopt be-framework/psalm-plugin across all demos - #21

Merged
koriym merged 4 commits into
1.xfrom
psalm-plugin
May 16, 2026
Merged

koriym merged 4 commits into
1.xfrom
psalm-plugin

Conversation

@koriym

@koriym koriym commented May 16, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopts be-framework/psalm-plugin in all eight demos, wiring composer psalm and a per-demo psalm.xml so the plugin can detect Be Framework-specific runtime errors at static-analysis time.
  • The plugin caught six real bugs on first run — six #[Validate] methods were throwing InvalidArgumentException, which the framework's SemanticValidator does not catch (catch (DomainException $e) only). Those throws would silently bypass validation in production. This PR also fixes them by introducing dedicated DomainException subclasses that follow the existing src/Exception/Invalid*Exception.php convention (with #[Message] en/ja translations).

Bugs fixed by the plugin

  • blog-publishing: AuthorName, Excerpt, HtmlBody, Slug
  • user-registration: AvatarUrl, HashedPassword

Commits

  1. Add be-framework/psalm-plugin to all demos — composer.json + psalm.xml in 8 demos.
  2. Fix #[Validate] throws that bypass framework validation — 6 new exception classes, 6 throw-site updates.

Test plan

  • cd demos/<demo> && composer install
  • composer psalm reports zero InvalidValidateException / MissingBeingParameterAttribute across all demos
  • Existing demos still run (e.g. composer dev where applicable)

koriym added 2 commits May 16, 2026 10:40
Wires up the Be Framework Psalm plugin in each demo's composer.json and
adds a per-demo psalm.xml so contributors can statically detect:
- Being constructors missing #[Input] or #[Inject]
- #[Validate] methods throwing non-DomainException (silently bypassed)

Dogfood results highlight the plugin's value: 6 real bugs surfaced —
blog-publishing (4) and user-registration (2) had #[Validate] methods
throwing InvalidArgumentException, which the framework does not catch.
Those throws would silently bypass validation at runtime.

Stock unused-class / unused-method / unused-property false positives
(Be Framework loads classes via #[Be] reflection) are suppressed in
each psalm.xml.

Run with: composer psalm
Six validators were throwing InvalidArgumentException from inside
#[Validate] methods. The framework's SemanticValidator only catches
DomainException, so those throws would silently bypass validation at
runtime — the offending value would reach business logic unchecked.

Detected by be-framework/psalm-plugin (InvalidValidateException rule).

- blog-publishing: AuthorName, Excerpt, HtmlBody, Slug now throw new
  InvalidAuthorNameException / InvalidExcerptException /
  InvalidHtmlBodyException / InvalidSlugException
- user-registration: AvatarUrl, HashedPassword now throw new
  InvalidAvatarUrlException / InvalidHashedPasswordException

Each new exception extends \DomainException and carries a #[Message]
attribute matching the existing convention in src/Exception/.
@coderabbitai

coderabbitai Bot commented May 16, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@koriym has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 4 minutes and 55 seconds before requesting another review.

You’ve run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: fd14340d-ed6e-491c-bc48-f985742eade3

📥 Commits

Reviewing files that changed from the base of the PR and between 598e315 and c4a6f09.

📒 Files selected for processing (29)
  • .coderabbit.yaml
  • demos/blog-publishing/composer.json
  • demos/blog-publishing/psalm.xml
  • demos/blog-publishing/src/Exception/InvalidAuthorNameException.php
  • demos/blog-publishing/src/Exception/InvalidExcerptException.php
  • demos/blog-publishing/src/Exception/InvalidHtmlBodyException.php
  • demos/blog-publishing/src/Exception/InvalidSlugException.php
  • demos/blog-publishing/src/Semantic/AuthorName.php
  • demos/blog-publishing/src/Semantic/Excerpt.php
  • demos/blog-publishing/src/Semantic/HtmlBody.php
  • demos/blog-publishing/src/Semantic/Slug.php
  • demos/contact-form/composer.json
  • demos/contact-form/psalm.xml
  • demos/hello-world/composer.json
  • demos/hello-world/psalm.xml
  • demos/insurance-claim/composer.json
  • demos/insurance-claim/psalm.xml
  • demos/loan-application/composer.json
  • demos/loan-application/psalm.xml
  • demos/medical-triage/composer.json
  • demos/medical-triage/psalm.xml
  • demos/order-processing/composer.json
  • demos/order-processing/psalm.xml
  • demos/user-registration/composer.json
  • demos/user-registration/psalm.xml
  • demos/user-registration/src/Exception/InvalidAvatarUrlException.php
  • demos/user-registration/src/Exception/InvalidHashedPasswordException.php
  • demos/user-registration/src/Semantic/AvatarUrl.php
  • demos/user-registration/src/Semantic/HashedPassword.php
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch psalm-plugin

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

The plugin repo's default branch was renamed main -> 1.x to match the
Be Framework versioning convention (0.x, 1.x). Update each demo's
require-dev constraint accordingly.
@koriym

koriym commented May 16, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 16, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@koriym

koriym commented May 16, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented May 16, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

Allows @coderabbitai approve / resolve commands to issue formal GitHub
review states (Approve / Request changes) instead of plain comments,
once this lands on the default branch.
@koriym
koriym merged commit 6812517 into 1.x May 16, 2026
25 checks passed
@koriym
koriym deleted the psalm-plugin branch May 16, 2026 17:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant