Skip to content

fix: repair failing tests and type errors across api + shared packages - #187

Open
stooit wants to merge 1 commit into
mainfrom
quantcode/e2e-tier2-2178-1789489135
Open

stooit wants to merge 1 commit into
mainfrom
quantcode/e2e-tier2-2178-1789489135

Conversation

@stooit

@stooit stooit commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Summary

Fixes all failing tests (22/22 now pass) and eliminates all tsc --noEmit type errors across the api and shared packages. No test files were modified and no dependencies were added.

Root causes & fixes

  • Pagination stub (packages/shared/src/utils/pagination.ts): paginate<T>() threw "not implemented". Implemented against the test contract — 1-indexed pages, slice((page-1)*size, ...), totalPages = ceil(total/size). Out-of-range page yields empty data; empty array yields total: 0, totalPages: 0. Added defensive clamping on page/size.
  • Field-name inconsistency (packages/shared/src/types.ts): User declared userName, but the API route handlers and the (unmodifiable) tests use username. Renamed the shared type field to username to match the contract.
  • Missing import (packages/api/src/routes/users.ts): badRequest was called but never imported, causing a runtime ReferenceError on the missing-fields path (crash instead of 400). Added it to the existing ../lib/errors import.
  • Auth method case bug (packages/api/src/middleware/auth.ts): the public-method allow-list contained lowercase "post", but c.req.method is always uppercase, so POST fell through to token validation and returned 401 instead of being public. Replaced with a case-normalised Set comparison.
  • Type resolution (tsconfig.json): process and bun:test failed to resolve (TS2580/TS2307). bun-types was already a declared devDependency but never wired into the compiler — added "types": ["bun-types"]. No new dependency added.

Verification

  • bun test → 22 pass, 0 fail
  • bunx tsc --noEmit → clean (exit 0)

Assumptions

  • The unmodifiable tests define the contract, so field names and the public-POST policy were reconciled toward what the tests expect rather than changing tests.

Security note (flagged for follow-up)

The tests mandate unauthenticated writes (POST is public) and rely on a static bearer token with a hardcoded "test-token" fallback. Implemented faithfully to satisfy the tests, but this pattern conflicts with ISM-1536/ISM-0580 and should not reach a real service without an auth review.

…check

Implement paginate() against test contract; rename User.userName to
username to match the API and test surface; import missing badRequest
helper; fix case-sensitive HTTP method allow-list that forced tokens on
POST. Wire existing bun-types into tsconfig to resolve process/bun:test
type errors without new dependencies.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant