Repository navigation
Conversation
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 13 minutes and 46 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughSe actualiza la invocación del límite de tamaño en el middleware de subida, se cambia la excepción lanzada por las funciones Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~22 minutes Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 1 | ❌ 2❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (1 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@src/docs/image.schema.js`:
- Around line 3-47: The new OpenAPI schemas defined in imageSchemas are not
being picked up because imageSchemas is not merged into the global
components.schemas and this file is not included in the Swagger `apis` glob;
update the Swagger setup to import/require imageSchemas and merge its entries
into the existing components.schemas (e.g., extend the object used to build
swaggerSpec/components.schemas) and add this file's path pattern to the Swagger
`apis` array/glob so the new components and any JSDoc comments are parsed and
published.
In `@tests/unit/images/image.test.js`:
- Around line 166-173: The test "devuelve 403 cuando no hay token" is sending a
role header via asRole and asserting 403; change it to actually omit the
authorization header by calling
request(app).put("/products/1/image").attach("image", fakeFile, "test.jpg")
directly (or modify the asRole helper to not add any headers), and update the
assertion to expect 401 instead of 403; locate the assertion
expect(res.status).toBe(403) and the request call to adjust accordingly.
- Line 67: The tests are leaking mock implementations because beforeEach
currently calls vi.clearAllMocks(), which only clears call history; replace
those calls with vi.resetAllMocks() (or add vi.resetAllMocks() alongside
clearAllMocks) to reset mock implementations like mockResolvedValue in the
beforeEach blocks (refer to the existing beforeEach(() => vi.clearAllMocks())
occurrences in this file and the other two occurrences around the same spots) so
each test starts with clean mock implementations.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 04b88814-26fd-4cf3-8a62-7a658344a81a
⛔ Files ignored due to path filters (1)
package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (6)
src/docs/image.schema.jssrc/middlewares/upload.middleware.jssrc/modules/images/services/product-image.service.jssrc/modules/images/services/store-image.service.jssrc/modules/images/services/user-image.service.jstests/unit/images/image.test.js
There was a problem hiding this comment.
Actionable comments posted: 1
♻️ Duplicate comments (1)
tests/unit/images/image.test.js (1)
166-173:⚠️ Potential issue | 🟠 MajorEl test “sin token” está armado con autenticación y valida el status incorrecto.
En Line 166 el nombre del caso dice “no hay token”, pero en Line 167-170 se envía
x-test-role: seller; eso no es anónimo. Por eso el flujo termina en otro estado (hoy 404 en pipeline), no en el esperado para falta de auth.✅ Ajuste sugerido
- it("devuelve 403 cuando no hay token", async () => { - const res = await asRole( - request(app).put("/products/1/image").attach("image", fakeFile, "test.jpg"), - "seller" - ) - - expect(res.status).toBe(403); - }); + it("devuelve 401 cuando no hay token", async () => { + const res = await request(app) + .put("/products/1/image") + .attach("image", fakeFile, "test.jpg"); + + expect(res.status).toBe(401); + });🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@tests/unit/images/image.test.js` around lines 166 - 173, El test "devuelve 403 cuando no hay token" está enviando autenticación usando asRole, por eso no simula un request anónimo; actualiza la llamada que usa asRole(request(app).put("/products/1/image").attach("image", fakeFile, "test.jpg"), "seller") para que sea un request sin cabeceras de auth (por ejemplo llamar directamente request(app).put("/products/1/image").attach(...)) y mantener expect(res.status).toBe(403); alternativamente cambia el nombre del caso si quieres mantener el helper asRole; revisa los símbolos request(app).put("/products/1/image"), attach("image", fakeFile, "test.jpg") y asRole para ubicar el cambio.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@src/config/swagger.config.js`:
- Around line 71-79: El bloque security está mal ubicado fuera del objeto
OpenAPI y el glob de apis no incluye subdirectorios; mueve la propiedad security
dentro de la clave definition (junto a openapi/info/components/paths) para que
forme parte del documento OpenAPI y actualiza el arreglo apis para usar un
recursive glob como "./src/docs/**/*.schema.js" (o similar) para capturar
schemas en subdirectorios; busca las referencias a security y definition en
swagger-jsdoc configuration y ajusta la entrada apis para incluir patrones
recursivos.
---
Duplicate comments:
In `@tests/unit/images/image.test.js`:
- Around line 166-173: El test "devuelve 403 cuando no hay token" está enviando
autenticación usando asRole, por eso no simula un request anónimo; actualiza la
llamada que usa asRole(request(app).put("/products/1/image").attach("image",
fakeFile, "test.jpg"), "seller") para que sea un request sin cabeceras de auth
(por ejemplo llamar directamente
request(app).put("/products/1/image").attach(...)) y mantener
expect(res.status).toBe(403); alternativamente cambia el nombre del caso si
quieres mantener el helper asRole; revisa los símbolos
request(app).put("/products/1/image"), attach("image", fakeFile, "test.jpg") y
asRole para ubicar el cambio.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: fcac841e-61d4-4881-b61a-f84731912860
📒 Files selected for processing (4)
src/config/swagger.config.jssrc/docs/schemas/image.schema.jssrc/docs/schemas/index.jstests/unit/images/image.test.js
✅ Files skipped from review due to trivial changes (1)
- src/docs/schemas/index.js
There was a problem hiding this comment.
🧹 Nitpick comments (2)
tests/unit/images/image.test.js (2)
208-221: Fortalecer los tests de DELETE exitoso con asserts de efectos laterales.Hoy validan status/body, pero no que se ejecuten
update,extractFilePathydeleteImagecon argumentos correctos.🔍 Propuesta (ejemplo en product delete)
it("devuelve 200 cuando la imagen se elimina correctamente", async () => { prisma.products.findUnique.mockResolvedValue({ ...mockProduct, image_url: IMAGE_URL, store: { fk_user: 10 } }); extractFilePath.mockReturnValue("1/image.jpg"); prisma.products.update.mockResolvedValue({ ...mockProduct, image_url: null }); deleteImage.mockResolvedValue(); const res = await asRole( request(app).delete("/products/1/image"), "seller" ) expect(res.status).toBe(200); expect(res.body.message).toMatch(/eliminada/i); + expect(extractFilePath).toHaveBeenCalledWith(IMAGE_URL, expect.any(String)); + expect(prisma.products.update).toHaveBeenCalledWith({ + where: { id_product: 1 }, + data: { image_url: null }, + }); + expect(deleteImage).toHaveBeenCalled(); });Also applies to: 318-331, 442-455
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@tests/unit/images/image.test.js` around lines 208 - 221, El test "devuelve 200 cuando la imagen se elimina correctamente" verifica solo status/body; añade assertions que confirmen los efectos laterales: verifica que prisma.products.findUnique fue llamado con el id correcto (e.g. 1), que extractFilePath se llamó con el valor IMAGE_URL, que deleteImage se llamó con la ruta devuelta por extractFilePath ("1/image.jpg") y que prisma.products.update fue llamado para dejar image_url en null para el mismo producto; aplica el mismo patrón de aserciones en los otros casos referenciados (los tests en las secciones alrededor de las líneas 318-331 y 442-455) para garantizar que las funciones mock (prisma.products.update, extractFilePath, deleteImage) reciban los argumentos esperados y que el orden lógico se respete.
306-332: Agregar caso 401 enDELETE /stores/:id/imagepara paridad de cobertura.En este bloque faltaría el escenario “sin token”, que sí está contemplado en product/user delete.
➕ Propuesta de test
describe("DELETE /stores/:id/image", () => { + it("devuelve 401 cuando no hay token", async () => { + const res = await request(app).delete("/stores/1/image"); + expect(res.status).toBe(401); + }); + it("devuelve 404 cuando el comercio no tiene logo", async () => { prisma.stores.findUnique.mockResolvedValue({ ...mockStore, fk_user: 10 }); const res = await asRole( request(app).delete("/stores/1/image"), "seller" )🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@tests/unit/images/image.test.js` around lines 306 - 332, Add a 401 test case for DELETE /stores/:id/image that covers the "sin token" scenario: in the same describe("DELETE /stores/:id/image") block add an it that sends request(app).delete("/stores/1/image") without wrapping in asRole, does not set auth headers, and expects res.status toBe(401) (and optionally message toMatch /token|autentic/i); also assert that downstream mocks like prisma.stores.findUnique, prisma.stores.update, extractFilePath, and deleteImage were not called to ensure the request was rejected early.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@tests/unit/images/image.test.js`:
- Around line 208-221: El test "devuelve 200 cuando la imagen se elimina
correctamente" verifica solo status/body; añade assertions que confirmen los
efectos laterales: verifica que prisma.products.findUnique fue llamado con el id
correcto (e.g. 1), que extractFilePath se llamó con el valor IMAGE_URL, que
deleteImage se llamó con la ruta devuelta por extractFilePath ("1/image.jpg") y
que prisma.products.update fue llamado para dejar image_url en null para el
mismo producto; aplica el mismo patrón de aserciones en los otros casos
referenciados (los tests en las secciones alrededor de las líneas 318-331 y
442-455) para garantizar que las funciones mock (prisma.products.update,
extractFilePath, deleteImage) reciban los argumentos esperados y que el orden
lógico se respete.
- Around line 306-332: Add a 401 test case for DELETE /stores/:id/image that
covers the "sin token" scenario: in the same describe("DELETE
/stores/:id/image") block add an it that sends
request(app).delete("/stores/1/image") without wrapping in asRole, does not set
auth headers, and expects res.status toBe(401) (and optionally message toMatch
/token|autentic/i); also assert that downstream mocks like
prisma.stores.findUnique, prisma.stores.update, extractFilePath, and deleteImage
were not called to ensure the request was rejected early.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: a9c1bc6b-3577-43bb-a0ff-aafdb1632397
📒 Files selected for processing (1)
tests/unit/images/image.test.js
|
@CodeRabbit review |
✅ Actions performedReview triggered.
|
Summary by CodeRabbit
Notas de Lanzamiento
Documentation
Bug Fixes
Tests