Repository navigation
[PROJ-1821] Make anonymous session probe console-clean - #360
Conversation
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 42 minutes Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Repository YAML (base), Organization UI (inherited) Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
WalkthroughThe governance session endpoint now permits anonymous requests and returns a discriminated anonymous or authenticated response. OpenAPI documents, TypeScript session types, auth context derivation, and tests were updated to reflect the new contract. ChangesGovernance session authentication
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related issues
Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Warning Review ran into problems🔥 ProblemsThese MCP integrations need to be re-authenticated in the Integrations settings: Notion Comment |
4131661 to
c4d923a
Compare
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@tests/governance-auth-cookie.test.ts`:
- Around line 112-127: Add a test alongside the existing anonymous-session test
that sends a stale or invalid governance session cookie, configures
getSessionByTokenMock to resolve null, and verifies the session endpoint returns
status 200 with { authenticated: false }. Also assert getSessionByTokenMock is
called once, and close the Fastify app as in the existing test.
In `@web-next/lib/api/client.ts`:
- Around line 31-43: Add Zod runtime parsing to the getSession response boundary
in client.ts, using schemas that require did, handle, and expiresAt for
authenticated sessions and accept authenticated: false for anonymous sessions.
Parse the fetched payload before returning it to auth-provider.tsx, and add
tests covering a malformed authenticated payload and a valid anonymous response.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Organization UI (inherited)
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 270f92f6-4a0d-456d-8726-4d48d51e0342
📒 Files selected for processing (8)
docs/docs-site/openapi.jsondocs/openapi-public.jsondocs/openapi.jsonsrc/governance/routes/auth.tstests/governance-auth-cookie.test.tsweb-next/components/auth-provider.tsxweb-next/e2e/production-hard-refresh.spec.tsweb-next/lib/api/client.ts
💤 Files with no reviewable changes (1)
- web-next/e2e/production-hard-refresh.spec.ts
|
CI follow-up cc1b5df: extracted the pure Zod session response contract from the Axios browser client so root backend tests do not require web-next-only dependencies. Local reproduction: contract test 3/3; exact npm run verify 155/155 files and 1,698/1,698 tests; TypeScript, CLI, SDK, docs, legacy web, and web-next 25-page production build all pass. |
|
@coderabbitai full review |
✅ Action performedFull review finished. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@tests/web-next-auth-client.test.ts`:
- Around line 1-30: Expand the “web-next auth session response contract” suite
with negative cases for strict-mode extra properties, empty authenticated
identity fields, malformed or non-offset expiresAt values, and a non-boolean
authenticated discriminator. Add each case through parseSessionResponse and
assert it throws, while preserving the existing anonymous, valid authenticated,
and missing-field coverage.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Organization UI (inherited)
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 089f838e-5964-40ea-93b5-d8cfceade357
📒 Files selected for processing (10)
docs/docs-site/openapi.jsondocs/openapi-public.jsondocs/openapi.jsonsrc/governance/routes/auth.tstests/governance-auth-cookie.test.tstests/web-next-auth-client.test.tsweb-next/components/auth-provider.tsxweb-next/e2e/production-hard-refresh.spec.tsweb-next/lib/api/client.tsweb-next/lib/api/session-contract.ts
💤 Files with no reviewable changes (1)
- web-next/e2e/production-hard-refresh.spec.ts
Summary
Production blocker
The Corgi Commons public story from #357 is live, and #359's signed-out pilot/waitlist copy is deployed. Production currently reports exact SHA
2dc550ea6767ee08fcaeaa26b07518e44e3cefe1. The affected routes are functionally healthy, but every anonymous rendered route still logs a 401 from/api/governance/auth/session. This hotfix closes that PI-review smoke-test blocker without weakening authenticated governance or waitlist gates.Exact review scope
2dc550ea6767ee08fcaeaa26b07518e44e3cefe1c4d923a8ab57f70e01374abb64d45bb674c0e3abValidation
npm run verify: 154 test files, 1,694 tests, backend/CLI/SDK fixtures, legacy web lint/build, and the 25-page web-next static export — pass.rate_limited_will_retry; no exemption is being applied.Linear: https://linear.app/andrewnord/issue/PROJ-1821/web-align-corgi-commons-cold-start-story-across-public-and-reviewer