Skip to content

fix(auth): harden oauth redirect contract checks - #150

Merged
LucasSantana-Dev merged 1 commit into
mainfrom
fix/oauth-discord-redirect-contract
Mar 10, 2026
Merged

LucasSantana-Dev merged 1 commit into
mainfrom
fix/oauth-discord-redirect-contract

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Mar 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • add auth-config diagnostics (clientId, authorizeUrlPreview) without exposing secrets
  • mark auth-config degraded when redirect origin is outside configured frontend origins
  • harden deploy workflow with OAuth redirect contract smoke validation on /api/auth/discord
  • add/adjust backend unit+integration tests for health/auth redirect behavior

Verification

  • npm run lint
  • npm run type:check
  • npm run build
  • npm run test
  • npm run test --workspace=packages/backend -- tests/unit/utils/authHealth.test.ts tests/integration/routes/health.test.ts tests/integration/routes/auth.test.ts

Notes

  • Discord Developer Portal redirect list still needs to include exactly: https://lucky.lucassantana.tech/api/auth/callback for client 962198089161134131.

Summary by CodeRabbit

Release Notes

  • Bug Fixes

    • OAuth configuration diagnostics improved: health endpoint now includes client configuration information and detects mismatched redirect origins, returning degraded status when misconfiguration is detected.
    • Deploy process now validates OAuth redirect contracts to ensure proper configuration before deployment.
  • Documentation

    • Updated health endpoint and deploy workflow documentation with new validation details.

@vercel

vercel Bot commented Mar 10, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Mar 10, 2026 7:59pm

@netlify

netlify Bot commented Mar 10, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for regal-bunny-0c8efe ready!

Name Link
🔨 Latest commit f2d9920
🔍 Latest deploy log https://app.netlify.com/projects/regal-bunny-0c8efe/deploys/69b077e2bb28be0008608622
😎 Deploy Preview https://deploy-preview-150--regal-bunny-0c8efe.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Mar 10, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

This PR introduces OAuth redirect contract validation and health diagnostics for Discord OAuth integration by adding utility functions to build authorization URL previews and comprehensive health checks, refactoring the health endpoint to use these utilities, and enhancing the deploy workflow with validation steps that verify the OAuth redirect contract with expected parameters.

Changes

Cohort / File(s) Summary
OAuth Health Utilities
packages/backend/src/utils/authHealth.ts
New utility module exporting buildAuthorizeUrlPreview() and buildAuthConfigHealth() functions to construct Discord OAuth authorize URLs, validate redirect URIs against configured origins, and aggregate OAuth and session health warnings.
Health Endpoint Refactoring
packages/backend/src/routes/health.ts
Simplified /api/health/auth-config handler by delegating health composition to the new buildAuthConfigHealth() utility, reducing inline validation logic.
Deploy Workflow Validation
.github/workflows/deploy.yml
Added OAuth redirect contract smoke check hitting /api/auth/discord, verifying 302 response with correct Location header pointing to Discord authorize endpoint, and validating query parameters client_id and redirect_uri.
Integration & Unit Tests
packages/backend/tests/integration/routes/health.test.ts, packages/backend/tests/integration/routes/auth.test.ts, packages/backend/tests/unit/utils/authHealth.test.ts
Added assertions for new auth.clientId and auth.authorizeUrlPreview fields in health responses, verified absence of secrets in preview URLs, introduced test cases for redirect origin mismatch scenarios, and added unit tests for OAuth URL preview and health status computation.
Documentation
README.md, CHANGELOG.md
Updated to document new health-config response fields (clientId, authorizeUrlPreview), deploy workflow OAuth redirect validation, and expected behavior for degraded auth states when redirect origins mismatch.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

size/m

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title 'fix(auth): harden oauth redirect contract checks' clearly and specifically summarizes the main change—hardening OAuth redirect contract validation—which aligns with the primary objectives of adding diagnostics, marking degraded states, and enforcing validation.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/oauth-discord-redirect-contract

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@sonarqubecloud

Copy link
Copy Markdown

@sonarqubecloud

Copy link
Copy Markdown

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (3)
.github/workflows/deploy.yml (1)

194-195: Consider extracting hardcoded contract values to workflow-level environment variables.

The hardcoded expected_client_id and expected_redirect_uri are deployment contract expectations (not secrets), but extracting them to workflow-level env: would improve maintainability if these values need to change across environments.

env:
  EXPECTED_CLIENT_ID: '962198089161134131'
  EXPECTED_REDIRECT_URI: 'https://lucky.lucassantana.tech/api/auth/callback'
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/deploy.yml around lines 194 - 195, Extract the hardcoded
deployment-contract values used as expected_client_id and expected_redirect_uri
into workflow-level environment variables (e.g., EXPECTED_CLIENT_ID and
EXPECTED_REDIRECT_URI) so the workflow step references those env vars instead of
literals; update the workflow top-level env: to define EXPECTED_CLIENT_ID and
EXPECTED_REDIRECT_URI and replace occurrences of expected_client_id and
expected_redirect_uri in the relevant job/step with references to those env
variables.
packages/backend/src/utils/authHealth.ts (1)

57-57: Prefer replaceAll() for literal string replacement.

SonarCloud flagged this line. Since you're replacing a literal + character (not a regex pattern), replaceAll is cleaner and more explicit.

♻️ Suggested fix
-    return `${DISCORD_AUTHORIZE_BASE}?${query.toString().replace(/\+/g, '%20')}`
+    return `${DISCORD_AUTHORIZE_BASE}?${query.toString().replaceAll('+', '%20')}`
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@packages/backend/src/utils/authHealth.ts` at line 57, Replace the regex-based
replacement with a literal string replacement: change the call on
query.toString() that currently uses .replace(/\+/g, '%20') to use
.replaceAll('+', '%20') so the return value constructed with
DISCORD_AUTHORIZE_BASE uses replaceAll for the '+' -> '%20' substitution; update
the expression where the URL is returned in the function that builds the Discord
authorize URL (the line referencing DISCORD_AUTHORIZE_BASE and
query.toString()).
packages/backend/tests/unit/utils/authHealth.test.ts (1)

67-80: Consider adding a test for invalid redirect URI parsing.

The buildAuthConfigHealth function has a try-catch block (source lines 103-105) that handles malformed redirect URIs. Adding a test for this edge case would improve coverage.

🧪 Suggested test
test('returns degraded when redirect URI is invalid', () => {
    const response = buildAuthConfigHealth({
        clientId: '962198089161134131',
        redirectUri: 'not-a-valid-url',
        frontendOrigins: ['https://lucky.lucassantana.tech'],
        sessionSecretConfigured: true,
        redisHealthy: true,
    })

    expect(response.status).toBe('degraded')
    expect(response.warnings).toContain('OAuth redirect URI is invalid')
})
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@packages/backend/tests/unit/utils/authHealth.test.ts` around lines 67 - 80,
Add a unit test for buildAuthConfigHealth to cover the malformed redirect URI
branch: create a test that calls buildAuthConfigHealth with redirectUri set to
an invalid string like "not-a-valid-url" (keep other params valid), then assert
the returned status is 'degraded' and that warnings contains 'OAuth redirect URI
is invalid'; place this alongside the existing tests in authHealth.test.ts to
ensure the try-catch path for redirect URI parsing is exercised.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Nitpick comments:
In @.github/workflows/deploy.yml:
- Around line 194-195: Extract the hardcoded deployment-contract values used as
expected_client_id and expected_redirect_uri into workflow-level environment
variables (e.g., EXPECTED_CLIENT_ID and EXPECTED_REDIRECT_URI) so the workflow
step references those env vars instead of literals; update the workflow
top-level env: to define EXPECTED_CLIENT_ID and EXPECTED_REDIRECT_URI and
replace occurrences of expected_client_id and expected_redirect_uri in the
relevant job/step with references to those env variables.

In `@packages/backend/src/utils/authHealth.ts`:
- Line 57: Replace the regex-based replacement with a literal string
replacement: change the call on query.toString() that currently uses
.replace(/\+/g, '%20') to use .replaceAll('+', '%20') so the return value
constructed with DISCORD_AUTHORIZE_BASE uses replaceAll for the '+' -> '%20'
substitution; update the expression where the URL is returned in the function
that builds the Discord authorize URL (the line referencing
DISCORD_AUTHORIZE_BASE and query.toString()).

In `@packages/backend/tests/unit/utils/authHealth.test.ts`:
- Around line 67-80: Add a unit test for buildAuthConfigHealth to cover the
malformed redirect URI branch: create a test that calls buildAuthConfigHealth
with redirectUri set to an invalid string like "not-a-valid-url" (keep other
params valid), then assert the returned status is 'degraded' and that warnings
contains 'OAuth redirect URI is invalid'; place this alongside the existing
tests in authHealth.test.ts to ensure the try-catch path for redirect URI
parsing is exercised.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ab213aa0-e2d1-4f1e-bd69-e45e77350f6f

📥 Commits

Reviewing files that changed from the base of the PR and between d5fc353 and f2d9920.

📒 Files selected for processing (8)
  • .github/workflows/deploy.yml
  • CHANGELOG.md
  • README.md
  • packages/backend/src/routes/health.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
  • packages/backend/tests/unit/utils/authHealth.test.ts
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
  • GitHub Check: SonarCloud Scan
  • GitHub Check: Quality Gates
🧰 Additional context used
📓 Path-based instructions (31)
**/*.{js,jsx,ts,tsx,vue,html}

📄 CodeRabbit inference engine (.cursor/rules/accessibility-openness.mdc)

Provide accessible UI components using semantic HTML and ARIA attributes where necessary

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/tests/integration/routes/health.test.ts
  • packages/backend/src/routes/health.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/dependency-injection.mdc)

**/*.{ts,tsx,js,jsx}: Prefer constructor injection for classes that require dependencies
Avoid global mutable singletons unless necessary
Use explicit interfaces for external dependencies to make testing easier

**/*.{ts,tsx,js,jsx}: Include required references in PRs/code for non-trivial logic: TypeScript (official docs), MDN (JavaScript reference), and official docs for any runtime/framework/libraries used (e.g., Node.js, React) as applicable.
Before assuming behavior of an API, include the doc link and a ≤25-word quote when the change relies on it.

**/*.{ts,tsx,js,jsx}: Prefer named exports for clear usage and easier refactors in TypeScript/JavaScript
Keep import order consistent: external first, then internal modules
Remove dead code and unused imports

**/*.{ts,tsx,js,jsx}: Use PascalCase naming convention for React/UI components
Use camelCase naming convention for variables and functions
Use UPPER_SNAKE_CASE naming convention for constants
Maintain consistent import grouping and ordering within the project, keeping third-party imports separate from local imports
For external data sources (HTTP, database), always validate and sanitize input using type guards or schema validators

**/*.{ts,tsx,js,jsx}: Use Prettier with no semicolons, single quotes, 4-space indent, 80 character width
Files must not exceed 250 lines and this is enforced

Implement TypeScript typecheck and linter in CI quality checks

**/*.{ts,tsx,js,jsx}: Use TypeScript for enhanced type safety
Implement error handling and error logging
Avoid commenting code unless extremely necessary - code should explain itself with descriptive names
Leave NO todos, placeholders or missing pieces in the code
Variables and functions must use camelCase
Constants must use UPPER_SNAKE_CASE
Use arrow functions for methods and computed properties
Avoid unnecessary curly braces in conditionals; use concise syntax for simple statements
Maintain consistent import grouping/order: external imports first, then...

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/tests/integration/routes/health.test.ts
  • packages/backend/src/routes/health.ts
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/error-handling.mdc)

**/*.{js,jsx,ts,tsx}: Never throw strings. Throw Error (or typed subclasses) with descriptive messages
Include causal error as cause when available for better debugging
Define clear, stable error codes (e.g., ERR_AUTH_EXPIRED, ERR_NETWORK_TIMEOUT)
Provide optional metadata (e.g., details, retryable, status, correlationId) in error objects
Use domain error classes per area (e.g., AuthenticationError, ValidationError, NetworkError)
Log errors with structure (message, code, stack, cause, correlationId, user context where appropriate)
Mark retryable vs nonRetryable errors where helpful for operations
Set timeouts and handle aborts/cancellations; avoid dangling requests in API/network code
Implement backoff for transient failures; avoid infinite retries
Map HTTP status → domain errors; 4xx vs 5xx behave differently (e.g., retry for 5xx/network)

**/*.{js,jsx,ts,tsx}: Use functional components with hooks in React/React Native. Avoid class components.
Keep components focused on a single responsibility; extract complex logic into custom hooks.
Keep state local when possible. Use Context/Zustand/Redux only when necessary for state management.
If props or state traverse more than 3 levels, consider using context or a feature-scoped store instead of prop drilling.
Use performance optimization techniques: React.memo, useMemo, useCallback, Suspense (web), and virtualization for long lists; avoid unnecessary re-renders.
Web accessibility: use semantic HTML, labels, focus management, keyboard navigation, and aria-* attributes as needed.
React Native accessibility: use accessibility props (accessible, accessibilityLabel), proper roles and labels.
Identify and extract repetitive UI components proactively to components/ with clear props and minimal coupling.
Web styles: prefer co-located styles or design system tokens; avoid global style leakage.
React Native styles: prefer StyleSheet.create, design tokens, and theme providers; avoid in...

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/tests/integration/routes/health.test.ts
  • packages/backend/src/routes/health.ts
**/*.{test,spec}.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/frontend.mdc)

**/*.{test,spec}.{js,jsx,ts,tsx}: Test behavior, not implementation. Prefer Testing Library utilities for testing React/React Native components.
For React Native tests: mock native modules and test component interactions and accessibility labels.

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/pattern.mdc)

Introduce interfaces at module boundaries to enable testing and substitutions

**/*.{ts,tsx}: Avoid using any type in TypeScript. If unavoidable, use unknown with type guards and justify with a code comment
Prefer interface for defining public object shapes in TypeScript, use type for unions and utility types
Use TypeScript utility types such as Partial, Pick, Omit, Readonly, and Record when appropriate
Use I{Name} naming convention for interfaces in TypeScript
Use T{Name} naming convention for type aliases and utility types in TypeScript

**/*.{ts,tsx}: Functions must be less than 50 lines with cyclomatic complexity less than 10
Do not use any types - ESLint enforces this at error level

**/*.{ts,tsx}: Prefer types over interfaces for most cases
Don't ever use any - type safety always
Avoid enums; use const objects instead
For complex types, create a separate file to declare them and import them
Avoid using any type; if unavoidable, use unknown with type guards and justify with code comment
Prefer interface for public API shapes; use type for unions and utility types
Use TypeScript utility types (Partial, Pick, Omit, Readonly, Record)

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/tests/integration/routes/health.test.ts
  • packages/backend/src/routes/health.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/pattern.mdc)

**/*.{test,spec}.{ts,tsx,js,jsx}: Test behavior, not implementation details
Prefer unit tests for core logic; add integration tests at meaningful boundaries

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
**/*.{test,spec}.{js,ts,jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/testing-quality.mdc)

**/*.{test,spec}.{js,ts,jsx,tsx}: Use Jest + a React testing library for unit and component tests as applicable
Test behavior, not implementation details

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/documentation.mdc)

**/*.{js,ts,tsx,jsx}: Minimize comments in code; explain the 'why' when non-obvious, let code express the 'what' through clear naming
Document trade-offs briefly when deviating from ideal patterns

**/*.{js,ts,tsx,jsx}: Store secrets, ports, and hosts in environment variables (.env, .env.example) and never hardcode them
Avoid redundant or decorative AI comments; code should be self-explanatory and only commented when logic is non-obvious; prefer refactoring over lengthy comments

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/tests/integration/routes/health.test.ts
  • packages/backend/src/routes/health.ts
packages/backend/tests/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/lucky-backend-api.mdc)

Organize tests in packages/backend/tests/ with unit tests under unit/ and integration tests under integration/, following existing patterns with fixtures and setup

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
packages/backend/**

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

The backend package depends on shared and contains Express API with auth and guild routes

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/tests/integration/routes/health.test.ts
  • packages/backend/src/routes/health.ts
**/*.{js,mjs,ts,mts}

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

Use Node.js version ≥22 with ESM (ECMAScript modules) only; no CommonJS

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/tests/integration/routes/health.test.ts
  • packages/backend/src/routes/health.ts
{packages/*/tests/**/*.test.{js,ts},tests/**/*.test.{js,ts}}

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

Add or adjust unit and integration tests when changing behavior; follow existing patterns in packages/*/tests and root tests/ directories

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
**/*.{spec,test}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/quality.mdc)

**/*.{spec,test}.{ts,tsx,js,jsx}: Use Jest for unit and integration tests
Test behavior, not implementation details
Run unit, integration tests, and coverage report in CI quality checks

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
packages/backend/**/*.ts

📄 CodeRabbit inference engine (.cursor/rules/subagent-backend.mdc)

packages/backend/**/*.ts: Apply .cursor/rules/lucky-backend-api.mdc for structure and conventions when acting as backend specialist
Use .cursor/skills/backend-express/SKILL.md for Express routes, middleware, and services when acting as backend specialist
Use @lucky/shared for config and DB/Redis when needed in backend code

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/tests/integration/routes/health.test.ts
  • packages/backend/src/routes/health.ts
packages/backend/tests/**/*.ts

📄 CodeRabbit inference engine (.cursor/rules/subagent-backend.mdc)

Follow existing patterns for unit and integration tests in packages/backend/tests/

Files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
{CHANGELOG.md,README.md}

📄 CodeRabbit inference engine (.cursor/rules/agent-rules.mdc)

ALWAYS update CHANGELOG.md and README.md as changes are made.

Files:

  • CHANGELOG.md
  • README.md
CHANGELOG.md

📄 CodeRabbit inference engine (.cursor/rules/templates-examples.mdc)

CHANGELOG.md must be updated with all changes in pull requests

Always update CHANGELOG.md with all code changes

Update CHANGELOG.md with all changes, include breaking changes documentation, and reference issues and PRs

Files:

  • CHANGELOG.md
{CHANGELOG.md,docs/**}

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

Update CHANGELOG.md and relevant docs/ files when behavior or setup changes

Files:

  • CHANGELOG.md
README.md

📄 CodeRabbit inference engine (.cursor/rules/templates-examples.mdc)

README.md must be updated if behavior changed

Update README.md if behavior changed

Files:

  • README.md
packages/backend/src/**/*.ts

📄 CodeRabbit inference engine (CLAUDE.md)

packages/backend/src/**/*.ts: Validation must use Zod schemas in backend/src/schemas/ and be applied via validateBody, validateParams, or validateQuery
Do not reassign req.query in Express middleware - it is read-only in Express 5

Files:

  • packages/backend/src/utils/authHealth.ts
  • packages/backend/src/routes/health.ts
packages/backend/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/lucky-backend-api.mdc)

packages/backend/src/**/*.{ts,tsx}: Use shared config and env from @lucky/shared when needed; avoid duplicating env parsing in backend code
Keep tokens and secrets in environment variables only; never hardcode or expose in code

Files:

  • packages/backend/src/utils/authHealth.ts
  • packages/backend/src/routes/health.ts
**/{.github/workflows,}/*.{yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)

**/{.github/workflows,}/*.{yml,yaml}: CI pipeline must include setup step (node install, environment)
CI pipeline must include lint step (TypeScript typecheck + linter)
CI pipeline must include build step (production build)
CI pipeline must include test step (unit + integration) with coverage report
CI pipeline must include quality step (static analysis, vulnerability scan)

Files:

  • .github/workflows/deploy.yml
**/{.github/workflows,dependabot.yml}/*.{yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)

Configure dependency update bot with PR templates and tests (recommended)

Files:

  • .github/workflows/deploy.yml
**/.github/workflows/*.{yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)

**/.github/workflows/*.{yml,yaml}: Configure SAST / secrets scan on PRs (recommended)
Publish artifacts only from protected pipeline steps

Files:

  • .github/workflows/deploy.yml
{jest.config.*,*.coverage.*,.nycrc*,nyc.config.*,coveragerc,.github/workflows/*.yml,.github/workflows/*.yaml}

📄 CodeRabbit inference engine (.cursor/rules/testing-quality.mdc)

Minimum recommended coverage threshold: 85% (raise per project risk)

Files:

  • .github/workflows/deploy.yml
{.github/workflows/*.{yml,yaml},*.github/workflows/*.{yml,yaml},.gitlab-ci.yml,.circleci/config.yml,bitbucket-pipelines.yml}

📄 CodeRabbit inference engine (.cursor/rules/testing-quality.mdc)

CI must run in order: lint → build → test → quality checks

Files:

  • .github/workflows/deploy.yml
{.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}

📄 CodeRabbit inference engine (.cursor/rules/workflow.mdc)

{.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}: CI/CD pipeline must include in order: Setup (Node install, env config) → Lint (TypeScript typecheck, linter) → Build (production build, artifacts) → Test (unit, integration, coverage) → Quality (static analysis, vulnerability scan)
Publish artifacts only from protected pipeline steps in CI/CD

Files:

  • .github/workflows/deploy.yml
{**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}

📄 CodeRabbit inference engine (.cursor/rules/workflow.mdc)

{**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}: Use cross-platform environment handling in scripts, cross-platform deletion utilities instead of OS-specific commands, pass non-interactive flags (--yes, --ci) by default in automation, and avoid OS-specific commands
Ensure logs are stream-friendly (no pagers) in scripts; when a pager might be used, pipe to cat

Files:

  • .github/workflows/deploy.yml
packages/backend/src/routes/**/*.ts

📄 CodeRabbit inference engine (CLAUDE.md)

packages/backend/src/routes/**/*.ts: Backend route handlers must use asyncHandler wrapper and throw AppError.xxx() instead of manual try/catch blocks
Rate limiting: use apiLimiter (100/min), authLimiter (20/15min), or writeLimiter (30/min) as appropriate

Place routes under packages/backend/src/routes/ directory

Files:

  • packages/backend/src/routes/health.ts
packages/backend/src/{routes,middleware}/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/lucky-backend-api.mdc)

Return consistent JSON error responses with appropriate HTTP status codes; do not expose stack traces or secrets in responses

Files:

  • packages/backend/src/routes/health.ts
packages/backend/src/routes/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/lucky-backend-api.mdc)

Structure routes in packages/backend/src/routes/ directory with separate files for auth, guilds, toggles, and index routes

Files:

  • packages/backend/src/routes/health.ts
🧠 Learnings (23)
📓 Common learnings
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.683Z
Learning: Applies to packages/backend/src/{services,middleware}/**/*.{ts,tsx} : Implement Discord OAuth for authentication in backend services
📚 Learning: 2026-03-09T20:21:31.448Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/quality.mdc:0-0
Timestamp: 2026-03-09T20:21:31.448Z
Learning: Applies to src/**/*.{ts,tsx,js,jsx} : Implement health/readiness endpoints in backend services

Applied to files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • README.md
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/tests/integration/routes/health.test.ts
  • packages/backend/src/routes/health.ts
📚 Learning: 2026-03-09T20:21:08.600Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.600Z
Learning: Applies to {packages/*/tests/**/*.test.{js,ts},tests/**/*.test.{js,ts}} : Add or adjust unit and integration tests when changing behavior; follow existing patterns in `packages/*/tests` and root `tests/` directories

Applied to files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
📚 Learning: 2026-03-09T20:20:38.683Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.683Z
Learning: Applies to packages/backend/src/{services,middleware}/**/*.{ts,tsx} : Implement Discord OAuth for authentication in backend services

Applied to files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • CHANGELOG.md
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/src/routes/health.ts
📚 Learning: 2026-03-09T20:20:38.683Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.683Z
Learning: Applies to packages/backend/tests/**/*.{ts,tsx} : Organize tests in `packages/backend/tests/` with unit tests under `unit/` and integration tests under `integration/`, following existing patterns with fixtures and setup

Applied to files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
📚 Learning: 2026-03-09T20:21:38.087Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-backend.mdc:0-0
Timestamp: 2026-03-09T20:21:38.087Z
Learning: Applies to packages/backend/tests/**/*.ts : Follow existing patterns for unit and integration tests in `packages/backend/tests/`

Applied to files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
📚 Learning: 2026-03-09T20:21:31.448Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/quality.mdc:0-0
Timestamp: 2026-03-09T20:21:31.448Z
Learning: Applies to tests/**/*.test.{ts,tsx,js,jsx} : Add integration tests where appropriate

Applied to files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/tests/integration/routes/health.test.ts
📚 Learning: 2026-03-09T20:20:56.345Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-frontend.mdc:0-0
Timestamp: 2026-03-09T20:20:56.345Z
Learning: Applies to packages/frontend/tests/**/*.{ts,tsx,js} : Write tests in `packages/frontend/tests/` using existing test patterns (e.g., Playwright for e2e if configured)

Applied to files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
📚 Learning: 2026-03-09T20:21:58.981Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-frontend.mdc:0-0
Timestamp: 2026-03-09T20:21:58.981Z
Learning: Write unit and integration tests in `packages/frontend/tests`; use Playwright for E2E tests when changing user flows

Applied to files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
  • packages/backend/tests/integration/routes/auth.test.ts
📚 Learning: 2026-03-09T20:22:47.441Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-09T20:22:47.441Z
Learning: For unit tests and Jest ESM mocks, use the `testing-lucky` skill

Applied to files:

  • packages/backend/tests/unit/utils/authHealth.test.ts
📚 Learning: 2026-03-09T20:21:31.448Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/quality.mdc:0-0
Timestamp: 2026-03-09T20:21:31.448Z
Learning: Applies to tests/**/*.test.ts : Integration tests must use naming convention `*.test.ts` and be located inside a `/tests` folder at the project's root

Applied to files:

  • packages/backend/tests/integration/routes/auth.test.ts
📚 Learning: 2026-03-09T20:21:31.448Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/quality.mdc:0-0
Timestamp: 2026-03-09T20:21:31.448Z
Learning: Applies to **/*.{spec,test}.{ts,tsx,js,jsx} : Test behavior, not implementation details

Applied to files:

  • packages/backend/tests/integration/routes/auth.test.ts
📚 Learning: 2026-03-09T20:20:38.683Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.683Z
Learning: Applies to packages/backend/src/routes/**/*.{ts,tsx} : Structure routes in `packages/backend/src/routes/` directory with separate files for auth, guilds, toggles, and index routes

Applied to files:

  • packages/backend/tests/integration/routes/auth.test.ts
  • packages/backend/src/utils/authHealth.ts
  • packages/backend/src/routes/health.ts
📚 Learning: 2026-03-09T20:20:32.235Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/documentation.mdc:0-0
Timestamp: 2026-03-09T20:20:32.235Z
Learning: Applies to README.md : Update README.md if behavior changed

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:20:38.683Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.683Z
Learning: Applies to packages/backend/src/{routes,middleware}/**/*.{ts,tsx} : Return consistent JSON error responses with appropriate HTTP status codes; do not expose stack traces or secrets in responses

Applied to files:

  • README.md
  • packages/backend/tests/integration/routes/health.test.ts
📚 Learning: 2026-03-09T20:20:23.872Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: CLAUDE.md:0-0
Timestamp: 2026-03-09T20:20:23.872Z
Learning: Applies to packages/backend/src/routes/**/*.ts : Backend route handlers must use `asyncHandler` wrapper and throw `AppError.xxx()` instead of manual try/catch blocks

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:22:47.441Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-09T20:22:47.441Z
Learning: Use database commands: `npm run db:generate` for Prisma generation, `npm run db:migrate` for migrations, `npm run db:deploy` for deployment, `npm run db:studio` for database studio

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:21:08.600Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.600Z
Learning: Applies to package.json : Use npm workspaces monorepo structure with packages in `packages/*` directory containing: `shared` (config, services, types, utils), `bot` (Discord.js/Discord Player), `backend` (Express API), and `frontend` (React/Vite)

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:21:58.981Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-frontend.mdc:0-0
Timestamp: 2026-03-09T20:21:58.981Z
Learning: Keep frontend code scoped to `packages/frontend`; communicate with backend via `services/api.ts` using the configured env base URL; do not access shared database or Redis directly

Applied to files:

  • packages/backend/src/utils/authHealth.ts
  • packages/backend/src/routes/health.ts
📚 Learning: 2026-03-09T20:20:38.683Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.683Z
Learning: Applies to packages/backend/src/{services,middleware}/**/*.{ts,tsx} : Use SessionService in middleware for session handling; keep session and auth logic centralized

Applied to files:

  • packages/backend/src/utils/authHealth.ts
📚 Learning: 2026-03-09T20:20:56.345Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-frontend.mdc:0-0
Timestamp: 2026-03-09T20:20:56.345Z
Learning: Applies to packages/frontend/src/**/*.{ts,tsx} : Do not depend on `lucky/shared` package in frontend code; make API calls to backend via configured base URL (env)

Applied to files:

  • packages/backend/src/utils/authHealth.ts
  • packages/backend/src/routes/health.ts
📚 Learning: 2026-03-09T20:21:15.586Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-shared.mdc:0-0
Timestamp: 2026-03-09T20:21:15.586Z
Learning: Applies to packages/shared/**/*.ts : Organize the Lucky Shared Package with the following directory structure: Config in `packages/shared/src/config/` (environment, constants, feature toggles, YouTube config); Services in `packages/shared/src/services/` (DatabaseService, Redis client/operations, FeatureToggleService, ReactionRoles, RoleManagement); Types in `packages/shared/src/types/` (errors, commands, common, discord, music); Utils in `packages/shared/src/utils/` (error handling, retry, embeds, log, monitoring, composables, prismaClient)

Applied to files:

  • packages/backend/src/utils/authHealth.ts
📚 Learning: 2026-03-09T20:21:38.087Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-backend.mdc:0-0
Timestamp: 2026-03-09T20:21:38.087Z
Learning: Applies to packages/backend/**/*.ts : Use `lucky/shared` for config and DB/Redis when needed in backend code

Applied to files:

  • packages/backend/src/utils/authHealth.ts
  • packages/backend/src/routes/health.ts
🪛 GitHub Check: SonarCloud Code Analysis
packages/backend/src/utils/authHealth.ts

[warning] 57-57: Prefer String#replaceAll() over String#replace().

See more on https://sonarcloud.io/project/issues?id=LucasSantana-Dev_Nexus&issues=AZzZVLtbki7imgSd2U02&open=AZzZVLtbki7imgSd2U02&pullRequest=150

🔇 Additional comments (9)
CHANGELOG.md (1)

10-17: LGTM!

The changelog entry accurately documents the OAuth diagnostics additions and deploy workflow validation changes, following the existing Keep a Changelog format.

packages/backend/tests/integration/routes/auth.test.ts (1)

65-74: LGTM!

The refactored test using URL parsing and searchParams assertions is more robust and provides clearer failure messages than string-based matching. This approach correctly validates the OAuth redirect contract.

.github/workflows/deploy.yml (1)

220-256: LGTM!

The OAuth redirect contract validation logic is well-structured:

  • Validates Discord host and authorize path
  • Verifies client_id and redirect_uri match expected values
  • Provides descriptive error messages for CI debugging
packages/backend/src/utils/authHealth.ts (1)

60-123: LGTM!

The health builder correctly:

  • Exposes only non-secret diagnostics (clientId is the public Discord application ID)
  • Validates redirect URI origin against configured frontend origins
  • Returns degraded status with descriptive warnings when validation fails
README.md (1)

81-81: LGTM!

Documentation accurately reflects the new health-config contract fields and deploy workflow validation behavior.

Also applies to: 145-147

packages/backend/src/routes/health.ts (1)

27-45: LGTM!

Clean refactor that improves separation of concerns by delegating health composition to the buildAuthConfigHealth utility. The route handler is now focused on gathering inputs and returning the response.

packages/backend/tests/integration/routes/health.test.ts (2)

134-137: Good security verification.

These assertions ensure the health endpoint doesn't accidentally expose secrets in the response. This is an important safeguard.


169-182: LGTM!

Comprehensive test coverage for the new degraded status scenario when the redirect origin doesn't match configured frontend origins.

packages/backend/tests/unit/utils/authHealth.test.ts (1)

30-81: LGTM!

Good unit test coverage for the health config builder, covering the main scenarios: successful validation, origin mismatch, and incorrect callback path.

This branch was successfully deployed

1 active deployment
Preview — f2d99201 Deployed Mar 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant