fix(deno): recognize Deno's npm-referrer missing-package error - #3560
Conversation
A scaffolded `--runtime deno` project runs its tasks as `deno run -A npm:veryfront@<version>`, so optional first-party extensions are probed from inside the npm cache. Deno reports an unresolvable package from such a referrer as Could not find package 'X' from referrer 'file:///...'. `reportedMissingSpecifier` did not know that shape, so `isMissingFirstPartyExtensionModule` returned false and the probe for the not-installed-by-default `@veryfront/ext-auth-jwt` was rethrown instead of being tolerated, killing boot before the server ever bound. Add the referrer shape to the recognized resolver messages. The transitive-dependency guard is unchanged: a missing `jose` reported from an installed extension still fails the anchor check and surfaces.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe extension resolver now parses Deno npm-referrer missing-package errors. Tests cover classification of missing first-party packages and exclusion of missing transitive dependencies. ChangesDeno package resolution
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
`deno add npm:veryfront` and `deno install -g npm:veryfront` resolve the CLI out of the global Deno npm cache. From that referrer Deno appends the owning package identifier to its resolution failure: Could not find package 'X' from referrer 'Y' (veryfront@0.1.1228). #3560 taught `reportedMissingSpecifier` the bare referrer shape, but the trailing parenthetical left the message unparsed, so every optional first-party extension the root npm package deliberately does not depend on still threw a fatal unclassified error on the documented `deno add` install path and the published CLI could not start a project. Extend that one pattern with the optional ` (pkg@version)` suffix. The transitive-dependency guard is unchanged: a missing `jose` reported from an installed extension still fails the anchor check and surfaces. Found during a DX dogfood walk of the published installation docs, which advertise Deno as a first-class runtime. Confidence: high Scope-risk: narrow Reversibility: clean
Found by a DX dogfood walk of https://veryfront.com/docs/code/getting-started/create-project against published CLI 0.1.1228.
Symptom
The documented Deno path is dead on arrival. Scaffold succeeds and prints
cd test-app/deno task dev, but the very next documented command never binds a port:curl→ 000, the server never starts. Reproduced twice. The equivalent--runtime bunscaffold works, so this is Deno-specific.Root cause
@veryfront/ext-auth-jwtisbuiltin-deferredwithrootNpm: false(src/extensions/first-party-defaults.ts) — it is deliberately not a dependency of the root npm package. Failing to import it is the expected path, andcreateOptionalBuiltinExtensionis supposed to swallow that failure viaisMissingFirstPartyExtensionModule.The classifier never got the chance. A
--runtime denoscaffold runs its tasks asdeno run -A npm:veryfront@<version>, so the extension probe is issued from a referrer inside the npm cache. In that configuration Deno words the resolution failure as:reportedMissingSpecifierrecognizedCannot find package …,Cannot find module … from …,Import "…" not a dependency, andUnable to resolve …, but notCould not find package … from referrer ….error.codeisERR_MODULE_NOT_FOUND, soisMissingModuleErrorsaid yes, but the anchored specifier could not be extracted — and the function fails closed, returningfalse. The optional-builtin handler then rethrew, and boot died.Fix: add the referrer shape to the recognized resolver messages. One anchored pattern, no behaviour change anywhere else.
Regression test
src/extensions/first-party-import.test.ts— Deno BDD, alongside the existing per-runtime message-shape cases (parses exact Deno and Node package-subpath error shapes,parses Bun relative, package, and object-shaped missing-module errors). It lives there rather than inveryfront-e2ebecause the defect is a pure string-classification bug: it needs no browser, no deployment, and no credentials, and it runs in the pre-push gate.The new case asserts both directions, which is the point of this classifier:
Could not find package '@veryfront/ext-auth-jwt' from referrer '…/node_modules/.deno/veryfront@…/…/first-party-import.js'.anchored on@veryfront/ext-auth-jwt→true(tolerate: extension genuinely not installed).Could not find package 'jose' from referrer '…/node_modules/@veryfront/ext-auth-jwt/esm/src/index.js'.anchored on@veryfront/ext-auth-jwt→false(surface: a broken transitive dependency of an installed extension must not be misread as "not installed").The test was written first and confirmed failing on the first assertion (
Values are not equal: false / true) before the one-line fix landed.Verification of the original symptom
Reproduced end to end in a sandbox outside the repo with the published CLI pinned at 0.1.1228, then re-ran the exact documented command with the same pattern applied to the scaffold's resolved copy of
first-party-import.js:Before: no bind,
000. After:200.Full pre-push suite passes.
Summary by CodeRabbit
Bug Fixes
Tests