Repository navigation
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughEl PR migra el envío de correos de recuperación a Resend, exige ChangesEndurecimiento de autenticación y recuperación
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
src/modules/session/routes/session.routes.js (1)
20-40:⚠️ Potential issue | 🟡 Minor | ⚡ Quick winDocumentá la respuesta
429del login.Desde la Line 40 este endpoint puede devolver
429por elloginRateLimiter, pero el Swagger de arriba no lo declara. Queda desalineado el contrato público justo en una ruta sensible.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/modules/session/routes/session.routes.js` around lines 20 - 40, El bloque de Swagger para el endpoint definido por router.post("/", loginRateLimiter, login) no documenta la respuesta 429 que puede devolver el loginRateLimiter; actualizá el comentario OpenAPI/SWagger sobre este POST para agregar una 429 response (p. ej. description: "Demasiadas solicitudes / rate limit excedido") y apuntá al esquema de error existente (por ejemplo ErrorResponse) para mantener el contrato público alineado con el comportamiento real del middleware loginRateLimiter.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/lib/email.service.js`:
- Around line 1-3: The module currently instantiates const resend = new
Resend(process.env.RESEND_API_KEY) at import time which will throw if
RESEND_API_KEY is missing; change to lazy initialization so importing the module
never reads the env. For example, remove the top-level new Resend(...) and
instead create a getResendClient() or initResendIfNeeded() used by
sendPasswordResetEmail that reads process.env.RESEND_API_KEY at call-time (or
after validateEnv() runs) and throws a clear error if the key is absent; update
any usages of the top-level resend variable to call that getter.
In `@tests/unit/session/rate-limit.test.js`:
- Around line 13-20: Los tests están creando un limiter de prueba con
makeTestLimiter en vez de usar los middlewares reales; reemplaza las instancias
de makeTestLimiter por los middlewares exportados loginRateLimiter y
passwordResetRateLimiter, elimina o deja de usar la función makeTestLimiter, e
importa los middlewares reales en la suite para que los tests ejerzan la
configuración shipped (headers, windowMs, limits, mensajes). Asegúrate además de
adaptar las aserciones para comprobar las propiedades relevantes (por ejemplo
windowMs, limit, standardHeaders/legacyHeaders y message) sobre los objetos
reales loginRateLimiter/passwordResetRateLimiter en lugar del stub.
---
Outside diff comments:
In `@src/modules/session/routes/session.routes.js`:
- Around line 20-40: El bloque de Swagger para el endpoint definido por
router.post("/", loginRateLimiter, login) no documenta la respuesta 429 que
puede devolver el loginRateLimiter; actualizá el comentario OpenAPI/SWagger
sobre este POST para agregar una 429 response (p. ej. description: "Demasiadas
solicitudes / rate limit excedido") y apuntá al esquema de error existente (por
ejemplo ErrorResponse) para mantener el contrato público alineado con el
comportamiento real del middleware loginRateLimiter.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 4b2c2ae6-780a-4280-a9f9-4a871d2941fa
⛔ Files ignored due to path filters (1)
package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (7)
package.jsonsrc/config/env.config.jssrc/lib/email.service.jssrc/middlewares/rateLimiter.jssrc/modules/session/routes/session.routes.jssrc/modules/users/users/routes/users.routes.jstests/unit/session/rate-limit.test.js
|



Summary by CodeRabbit
New Features
Changes
Chores
Tests