Conversation
…critical broken links 522 (connection timed out) and 523 (origin unreachable) are Cloudflare-edge errors returned when the checked site's own origin temporarily cannot be reached. While it is down, every same-origin link fails at once and recovers with it; Google backs off and retries 5xx rather than treating the URLs as dead. The public one-page check was reporting a scan-time origin hiccup as critical, confidence=verified 'Broken internal links' findings -- inventing a defect the page does not have (same family as the 429/503 throttle fix). Same-origin (internal) 522/523 checks now classify as transient infra failures instead of broken links, so they never become critical findings or inflate the critical count. External targets' 522/523 stay reportable: that is a real observation about the referenced site, not our own footprint. Two regression tests: the classifier (internal vs external vs image vs real failures) and an end-to-end audit where same-origin links return 522/523 but an external link returns 523, pinning the report to zero criticals while the external failure is still evidenced.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe audit engine now treats same-origin HTTP 522 and 523 responses as transient infrastructure failures. It excludes these responses from broken-resource findings while continuing to report equivalent failures for external resources. ChangesSame-origin infrastructure failure handling
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 81d3ddf89b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| check.kind === "internal" && | ||
| check.status && | ||
| CLOUDFLARE_ORIGIN_ERRORS.has(check.status) |
There was a problem hiding this comment.
Reclassify redirected checks by their final origin
When a same-origin link redirects to another origin and that external destination returns 522/523, kind remains "internal" because it is assigned before fetchResource follows redirects, while status comes from the final hop. This predicate consequently suppresses the broken-link finding for an external target that the change explicitly intends to keep reportable; only treat the response as a same-origin infrastructure failure when the final URL is still on the checked origin.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 41674d2a17
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| function isBrokenResource(check) { | ||
| if (isThrottledResource(check)) return false; | ||
| if (isSameOriginInfraFailure(check)) return false; |
There was a problem hiding this comment.
Apply the infra-failure rule to page proof counts
When a same-origin link returns 522/523, this predicate removes it from findings and backend page summaries, but the saved /check report's PageProof in src/App.jsx still counts every !check.ok or status ≥400 as a broken link. The resulting report can show zero critical findings while its raw page evidence still labels those same transient checks as broken; reuse the same classification when computing that displayed count.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Superseded by #91 (fresh branch from current main). This branch's merge history would also revert shipped work from #83/#85/#90 (URL-scheme validation, policy-page CTAs, methodology CTA), so it could not be merged as-is; #91 carries only the same-origin 522/523 classifier fix and its regression tests, cleanly based on origin/main. |
What
The public anonymous one-page check (
POST /api/public-check, page at/check) runs the shared audit engine. When the checked site's origin behind Cloudflare temporarily fails, every same-origin internal link returns 522 (connection timed out) or 523 (origin unreachable) at once — Cloudflare-edge errors for the site's own origin. The engine classified those as broken, so/checkreported "Broken internal links" as critical, confidence=verified findings and inflated the critical count: inventing a defect the page does not have (the links work as soon as the origin recovers, and Google backs off and retries 5xx rather than dropping URLs).Change
shared/audit-engine.js(the engine/checkruns through — no route changes needed):isSameOriginInfraFailure(check)predicate: an internal (same-origin) link check returning 522/523 is transient infrastructure, not a broken link.isBrokenResourcenow excludes those, so they never become critical findings, never inflatesummary.critical, and stay out of per-page broken-link counts and the repair brief.Tests
shared/audit-engine.test.mjs:Validation
npm run test:audit-engine— 23/23 passnpm run test:public-check— 5/5 passnpm run test:worker-dispatch— 10/10 passnpm run check(18 suites + build) — exit 0, zero failuresSummary by CodeRabbit