Skip to content

chore(backend): close lint debt and enforce strict route typing - #147

Merged
LucasSantana-Dev merged 1 commit into
mainfrom
chore/backend-lint-debt-136
Mar 10, 2026
Merged

LucasSantana-Dev merged 1 commit into
mainfrom
chore/backend-lint-debt-136

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Mar 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • remove backend lint guardrails and run strict backend lint by default
  • close strict lint debt by replacing unsafe request-body/query usage with schema-typed parsing
  • remove non-null auth assertions by introducing explicit authenticated user-id guards in backend routes
  • make session/file-store wiring type-safe in middleware and keep Redis adapter strict
  • align docs with strict backend lint state

Closes #136

Changes

  • packages/backend/package.json
    • removed lint:base ignore-pattern guardrail script
    • lint now runs strict backend lint directly
  • packages/backend/src/middleware/session.ts
    • typed session-file-store import usage
    • removed unsafe redis-store client casts
  • packages/backend/src/middleware/validate.ts
    • generic schema typing to avoid unsafe assignment from zod parse output
  • backend routes updated with typed parsing and no non-null assertions:
    • management.ts
    • managementAutoMessages.ts
    • managementEmbeds.ts
    • moderation.ts
    • music/playbackRoutes.ts
    • music/queueRoutes.ts
    • music/stateRoutes.ts
    • toggles.ts
    • twitch.ts
    • lastfm.ts
  • docs:
    • README.md strict backend lint wording
    • CHANGELOG.md unreleased notes for lint-debt closure

Verification

  • npm run lint:full --workspace=packages/backend
  • npm run lint
  • npm run type:check
  • npm test

All commands passed locally.

Summary by CodeRabbit

Release Notes

  • New Features

    • Added /api/health/auth-config endpoint to verify OAuth and session configuration status.
  • Improvements

    • Enhanced backend input validation and type safety across all API routes for more reliable operations.
    • Strengthened session middleware security with improved store configuration.

@netlify

netlify Bot commented Mar 10, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for regal-bunny-0c8efe ready!

Name Link
🔨 Latest commit 976823a
🔍 Latest deploy log https://app.netlify.com/projects/regal-bunny-0c8efe/deploys/69b0697b6267ce000796755e
😎 Deploy Preview https://deploy-preview-147--regal-bunny-0c8efe.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@vercel

vercel Bot commented Mar 10, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Mar 10, 2026 6:57pm

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file backend size/l labels Mar 10, 2026
@coderabbitai

coderabbitai Bot commented Mar 10, 2026 •

Copy link
Copy Markdown

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR removes backend lint ignore patterns and introduces schema-based request validation with userId authentication guards across multiple routes and middleware, making the entire backend subject to strict linting rules.

Changes

Cohort / File(s) Summary
Documentation & Lint Configuration
CHANGELOG.md, README.md, packages/backend/package.json
Removed lint ignore patterns from backend scripts; updated documentation to reflect strict linting across full backend; removed lint:base script.
Core Middleware
packages/backend/src/middleware/session.ts, packages/backend/src/middleware/validate.ts
Added session-file-store integration with explicit file-based store setup; updated Redis adapter wiring; introduced Schema<TOutput> type alias for zod validators with explicit type casting for safeParse inputs.
Management Routes
packages/backend/src/routes/management.ts, packages/backend/src/routes/managementAutoMessages.ts, packages/backend/src/routes/managementEmbeds.ts
Introduced requireUserId(req) helper; replaced direct req.userId and req.body/req.query access with schema-parsed values; added userId validation and typed body parsing for command and embed operations.
Moderation Routes
packages/backend/src/routes/moderation.ts
Added requireUserId(req) helper; replaced direct query/body access with schema-based parsing (s.casesQuery.parse, s.updateReasonBody.parse); enforced typed userId retrieval for logging and service calls.
Music Routes
packages/backend/src/routes/music/playbackRoutes.ts, packages/backend/src/routes/music/queueRoutes.ts, packages/backend/src/routes/music/stateRoutes.ts
Introduced zod schemas for request body validation (play, volume, repeat, seek, queue operations); added requireUserId(req) helper; replaced manual body field access with validated schema data; improved SSE client set handling with explicit guard initialization.
OAuth & Integration Routes
packages/backend/src/routes/lastfm.ts, packages/backend/src/routes/twitch.ts
Added zod schema parsing for OAuth callback query and Twitch body operations; replaced direct token/body extraction with schema-validated results.
Feature Toggles
packages/backend/src/routes/toggles.ts
Introduced requireUserId(req) helper; replaced direct req.userId access with validated userId in feature toggle endpoints.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

Suggested labels

size/l, ci

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'chore(backend): close lint debt and enforce strict route typing' clearly and specifically summarizes the main changes: removing lint debt guardrails and adding strict type validation to backend routes.
Linked Issues check ✅ Passed All acceptance criteria from issue #136 are met: ignore patterns removed from lint scripts, all 12 previously scoped debt files updated with schema-typed parsing and userId guards, and full backend lint passes without rule relaxation.
Out of Scope Changes check ✅ Passed All changes are directly related to addressing issue #136: removing lint guardrails, replacing unsafe request parsing with schema-typed validation, and adding explicit userId guards across all specified files.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch chore/backend-lint-debt-136

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
4.8% Duplication on New Code (required ≤ 3%)

See analysis details on SonarQube Cloud

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
69.9% Coverage on New Code (required ≥ 80%)
4.9% Duplication on New Code (required ≤ 3%)

See analysis details on SonarQube Cloud

@LucasSantana-Dev
LucasSantana-Dev merged commit af0cc18 into main Mar 10, 2026
13 of 15 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the chore/backend-lint-debt-136 branch March 10, 2026 19:03

This branch was successfully deployed

1 active deployment
Preview — 976823a5 Deployed Mar 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend ci dependencies Pull requests that update a dependency file size/l

Projects

None yet

Development

Successfully merging this pull request may close these issues.

tech debt: clear backend strict lint debt and remove guardrail ignores

1 participant