Skip to content

[PROJ-1821] Make anonymous session probe console-clean - #360

Merged
AndrewNordstrom merged 4 commits into
mainfrom
dev/PROJ-1821-auth-session-console-clean
Jul 14, 2026
Merged

AndrewNordstrom merged 4 commits into
mainfrom
dev/PROJ-1821-auth-session-console-clean

Conversation

@AndrewNordstrom

@AndrewNordstrom AndrewNordstrom commented Jul 14, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Return a typed anonymous session state with HTTP 200 when the public site probes the governance session while logged out.
  • Preserve the frontend's null unauthenticated session state without generating a browser-console 401.
  • Remove the production hard-refresh test's suppression for the logged-out session error.
  • Regenerate all tracked OpenAPI artifacts for the anonymous and authenticated session response variants.

Production blocker

The Corgi Commons public story from #357 is live, and #359's signed-out pilot/waitlist copy is deployed. Production currently reports exact SHA 2dc550ea6767ee08fcaeaa26b07518e44e3cefe1. The affected routes are functionally healthy, but every anonymous rendered route still logs a 401 from /api/governance/auth/session. This hotfix closes that PI-review smoke-test blocker without weakening authenticated governance or waitlist gates.

Exact review scope

  • Base: 2dc550ea6767ee08fcaeaa26b07518e44e3cefe1
  • Head: c4d923a8ab57f70e01374abb64d45bb674c0e3ab
  • Changed files: 8

Validation

  • Full production-shaped npm run verify: 154 test files, 1,694 tests, backend/CLI/SDK fixtures, legacy web lint/build, and the 25-page web-next static export — pass.
  • GitHub implementation checks, security gates, docs verification, and CodeQL — pass on the exact head.
  • Focused governance auth regression suite: 4 files, 19 tests — pass.
  • Local CodeRabbit light review of the patch before the conflict-free rebase reported no HIGH or MEDIUM findings.
  • Governed current-head CodeRabbit review is still pending because the service returned rate_limited_will_retry; no exemption is being applied.

Linear: https://linear.app/andrewnord/issue/PROJ-1821/web-align-corgi-commons-cold-start-story-across-public-and-reviewer

@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 42 minutes

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: c90c4377-2449-4f0d-8cc2-68920846b4c5

📥 Commits

Reviewing files that changed from the base of the PR and between cc1b5df and 4045679.

📒 Files selected for processing (1)
  • tests/web-next-auth-client.test.ts

Walkthrough

The governance session endpoint now permits anonymous requests and returns a discriminated anonymous or authenticated response. OpenAPI documents, TypeScript session types, auth context derivation, and tests were updated to reflect the new contract.

Changes

Governance session authentication

Layer / File(s) Summary
Session endpoint contract and runtime
src/governance/routes/auth.ts, docs/openapi*.json, docs/docs-site/openapi.json
The session route allows unauthenticated access, returns 200 { authenticated: false } without a session, and documents separate anonymous and authenticated response schemas.
Web session response modeling
web-next/lib/api/session-contract.ts, web-next/lib/api/client.ts, web-next/components/auth-provider.tsx
Zod schemas define the discriminated session union, the client validates unknown responses, and the auth provider exposes a session only for authenticated responses.
Session validation and browser error coverage
tests/governance-auth-cookie.test.ts, tests/web-next-auth-client.test.ts, web-next/e2e/production-hard-refresh.spec.ts
Tests cover anonymous, stale-token, valid authenticated, and invalid session responses; browser console collection no longer filters the former logged-out 401 error.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related issues

  • PROJ-1523: Both changes derive frontend authentication state from the session endpoint; this PR additionally changes the endpoint to return an explicit anonymous response.

Possibly related PRs

Suggested labels: documentation, javascript

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title is concise and accurately summarizes the main change: making the anonymous session probe console-clean.
Description check ✅ Passed The description matches the patch scope, covering anonymous session 200 responses, frontend state handling, test changes, and OpenAPI regeneration.
Linked Issues check ✅ Passed The changes satisfy the linked issue's console-clean public-route objective while preserving authenticated access boundaries and updating the public session contract.
Out of Scope Changes check ✅ Passed All modified files are directly tied to the session probe behavior, response contract, or tests, with no unrelated scope visible.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev/PROJ-1821-auth-session-console-clean
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch dev/PROJ-1821-auth-session-console-clean

Warning

Review ran into problems

🔥 Problems

These MCP integrations need to be re-authenticated in the Integrations settings: Notion


Comment @coderabbitai help to get the list of available commands.

@AndrewNordstrom
AndrewNordstrom marked this pull request as ready for review July 14, 2026 01:04
@AndrewNordstrom

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@AndrewNordstrom

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@AndrewNordstrom

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot added documentation Improvements or additions to documentation javascript Pull requests that update javascript code labels Jul 14, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/governance-auth-cookie.test.ts`:
- Around line 112-127: Add a test alongside the existing anonymous-session test
that sends a stale or invalid governance session cookie, configures
getSessionByTokenMock to resolve null, and verifies the session endpoint returns
status 200 with { authenticated: false }. Also assert getSessionByTokenMock is
called once, and close the Fastify app as in the existing test.

In `@web-next/lib/api/client.ts`:
- Around line 31-43: Add Zod runtime parsing to the getSession response boundary
in client.ts, using schemas that require did, handle, and expiresAt for
authenticated sessions and accept authenticated: false for anonymous sessions.
Parse the fetched payload before returning it to auth-provider.tsx, and add
tests covering a malformed authenticated payload and a valid anonymous response.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 270f92f6-4a0d-456d-8726-4d48d51e0342

📥 Commits

Reviewing files that changed from the base of the PR and between 2dc550e and c4d923a.

📒 Files selected for processing (8)
  • docs/docs-site/openapi.json
  • docs/openapi-public.json
  • docs/openapi.json
  • src/governance/routes/auth.ts
  • tests/governance-auth-cookie.test.ts
  • web-next/components/auth-provider.tsx
  • web-next/e2e/production-hard-refresh.spec.ts
  • web-next/lib/api/client.ts
💤 Files with no reviewable changes (1)
  • web-next/e2e/production-hard-refresh.spec.ts

Comment thread tests/governance-auth-cookie.test.ts
Comment thread web-next/lib/api/client.ts Outdated
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 14, 2026
@AndrewNordstrom

Copy link
Copy Markdown
Collaborator Author

CI follow-up cc1b5df: extracted the pure Zod session response contract from the Axios browser client so root backend tests do not require web-next-only dependencies. Local reproduction: contract test 3/3; exact npm run verify 155/155 files and 1,698/1,698 tests; TypeScript, CLI, SDK, docs, legacy web, and web-next 25-page production build all pass.

@AndrewNordstrom

Copy link
Copy Markdown
Collaborator Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/web-next-auth-client.test.ts`:
- Around line 1-30: Expand the “web-next auth session response contract” suite
with negative cases for strict-mode extra properties, empty authenticated
identity fields, malformed or non-offset expiresAt values, and a non-boolean
authenticated discriminator. Add each case through parseSessionResponse and
assert it throws, while preserving the existing anonymous, valid authenticated,
and missing-field coverage.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 089f838e-5964-40ea-93b5-d8cfceade357

📥 Commits

Reviewing files that changed from the base of the PR and between 2dc550e and cc1b5df.

📒 Files selected for processing (10)
  • docs/docs-site/openapi.json
  • docs/openapi-public.json
  • docs/openapi.json
  • src/governance/routes/auth.ts
  • tests/governance-auth-cookie.test.ts
  • tests/web-next-auth-client.test.ts
  • web-next/components/auth-provider.tsx
  • web-next/e2e/production-hard-refresh.spec.ts
  • web-next/lib/api/client.ts
  • web-next/lib/api/session-contract.ts
💤 Files with no reviewable changes (1)
  • web-next/e2e/production-hard-refresh.spec.ts

Comment thread tests/web-next-auth-client.test.ts
@AndrewNordstrom
AndrewNordstrom merged commit 3a57110 into main Jul 14, 2026
22 of 33 checks passed
@AndrewNordstrom
AndrewNordstrom deleted the dev/PROJ-1821-auth-session-console-clean branch July 14, 2026 06:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant