Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Add authorization-boundary, integration and component tests

Open
#60 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
csharp, sqlite

Research direction

Start in LearnStack.Core.Tests and read the existing service tests, then inspect LearnStack.Core.Tests/LearnStack.Core.Tests.csproj:9 and the named flows and components. The work is complete when wrong-user cases, end-to-end auth and sharing flows, component tests, and enforced CI coverage meet the listed acceptance criteria.

Written by the indexing model from the issue text.

Description

enhancement

Tier 3 — testing

Problem

There are 38 tests, all in LearnStack.Core.Tests, all covering service-level happy paths against SQLite. Nothing covers the parts most likely to cause a production incident:

  • Authorization boundaries — can user A read, update or delete user B's resources, ideas or groups? The services take userId as a parameter and every caller must pass the right one; that contract is untested.
  • The share-token flow and the anonymous /shared/{token} page
  • The friend invitation accept flow (expiry, self-accept, double-accept)
  • Any Blazor component (no bUnit)
  • No coverage threshold, and coverlet.collector is referenced but not enforced
Evidence
  • LearnStack.Core.Tests/ — UrlNormalizerTests (6), ContentIdeaServiceTests (19), LearningResourceServiceTests (12), OpenGraphServiceTests (7)
  • LearnStack.Core.Tests/LearnStack.Core.Tests.csproj:9 — coverlet present, unused
Proposed fix
  1. Add a cross-user authorization test per service method.
  2. Add a WebApplicationFactory integration test project covering register → login → create → share → anonymous view, and the friend-invitation edge cases.
  3. Add bUnit tests for ResourceForm, ResourceCard and the Pulse components.
  4. Enforce a coverage floor in CI.
Acceptance criteria
  • Every service method has a "wrong user" test
  • Auth and sharing flows covered end to end
  • Coverage reported in CI and enforced
Dominant language
HTML
Stars
10
Forks
0
Avg merge
3h 42m
Merged PRs (30d)
14

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from kasuken/LearnStack

All issues in kasuken/LearnStack

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.