Add authorization-boundary, integration and component tests
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- csharp, sqlite
- Domain
- authentication, authorization, ci-cd, frontend, testing
Research direction
Start in LearnStack.Core.Tests and read the existing service tests, then inspect LearnStack.Core.Tests/LearnStack.Core.Tests.csproj:9 and the named flows and components. The work is complete when wrong-user cases, end-to-end auth and sharing flows, component tests, and enforced CI coverage meet the listed acceptance criteria.
Written by the indexing model from the issue text.
Description
Tier 3 — testing
Problem
There are 38 tests, all in LearnStack.Core.Tests, all covering service-level happy paths against SQLite. Nothing covers the parts most likely to cause a production incident:
- Authorization boundaries — can user A read, update or delete user B's resources, ideas or groups? The services take
userIdas a parameter and every caller must pass the right one; that contract is untested. - The share-token flow and the anonymous
/shared/{token}page - The friend invitation accept flow (expiry, self-accept, double-accept)
- Any Blazor component (no bUnit)
- No coverage threshold, and
coverlet.collectoris referenced but not enforced
Evidence
LearnStack.Core.Tests/—UrlNormalizerTests(6),ContentIdeaServiceTests(19),LearningResourceServiceTests(12),OpenGraphServiceTests(7)LearnStack.Core.Tests/LearnStack.Core.Tests.csproj:9— coverlet present, unused
Proposed fix
- Add a cross-user authorization test per service method.
- Add a
WebApplicationFactoryintegration test project covering register → login → create → share → anonymous view, and the friend-invitation edge cases. - Add bUnit tests for
ResourceForm,ResourceCardand the Pulse components. - Enforce a coverage floor in CI.
Acceptance criteria
- Every service method has a "wrong user" test
- Auth and sharing flows covered end to end
- Coverage reported in CI and enforced
- Dominant language
- HTML
- Stars
- 10
- Forks
- 0
- Avg merge
- 3h 42m
- Merged PRs (30d)
- 14
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from kasuken/LearnStack
-
enhancement
Difficulty 1/5 Under an hour Newbie friendliness 91/100
kasuken/LearnStack#59 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 35/100
kasuken/LearnStack#72 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 30/100
kasuken/LearnStack#71 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 35/100
kasuken/LearnStack#70 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 45/100
kasuken/LearnStack#69 ·
Maintainers usually reply within 1 day
All issues in kasuken/LearnStack
Similar issues
-
documentation security
Difficulty 2/5 Half a day Newbie friendliness 72/100
-
enhancement needs-verification phase-2-optimize
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
FootprintAI/Containarium#2277 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 1-3 hours Newbie friendliness 92/100
Maintainers usually reply within 1 day
-
bug(services): classifySBOMStatus misclassifies UnsupportedSchema as generic ReasonSBOMGenerationFailedPossibly taken @bhuvan-somisetty claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Mend: dependency security vulnerability untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
opensearch-project/OpenSearch-Dashboards#12878 ·
Maintainers usually reply within 1 day