Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[quality] the bundle e2e suite never drives root-OWNERS authorization on an issue or the OWNERS-based /lgtm refusal on a pull request through dist/index.js

Đã đóng
#282 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 2 ngày

Một pull request liên quan đã được merge.

  • #283 của @hivecommons-hive — đã merge

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
35/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
github, typescript
Lĩnh vực
security, testing-qa

Hướng nghiên cứu

Start with src/utils/auth.ts and the existing bundle tests, especially bundle.test.ts and triggerTestAndLgtmCancel.test.ts. Add tests/bundle/ownersAuth.test.ts using the listed helpers, then run npm run test:coverage:e2e. Done means the three specified issue and pull-request OWNERS authorization cases execute through dist/index.js with the expected comments, label behavior, and API reads.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

hive/covered-by-pr kind/cleanup quality testing

Finding

src/utils/auth.ts holds the OWNERS-based authorization behind /lgtm, /approve and the /test//retest triggers (assertAuthorizedByOwnersOrMembership, L244). Three of its arms are unit-covered but never run through the committed dist/index.js:

  • assertRootOwner + retrieveOwnersFile (L271–290, L338–364) — on an issue (not a pull request) the root OWNERS file of the default branch is read through GET …/contents/OWNERS, base64-decoded, parsed, and the commenter is matched against the role. The only bundle route for that path answers 404 (bundle.test.ts:443, the author-refusal case), so the membership fallback is all dist/ ever exercises on issues; no bundle test sends /lgtm to a plain issue at all.
  • assertPullRequestOwner's refusal (L321–322) — on a pull request whose OWNERS files cover the changed files but list neither the commenter as reviewer nor approver, Cannot apply the lgtm label because Error: <login> is not a reviewer or approver for any changed file. Every bundle /lgtm on an OWNERS repository is by a listed reviewer; the OWNERS-less refusal (triggerTestAndLgtmCancel.test.ts:293) goes through the membership arm instead.

Evidence

  • Unit: npx vitest run --coverage on main @ ec76a3b (vitest 5.0.3, @vitest/coverage-v8) → src/utils/auth.ts 100 % lines / 98.43 % branches. __tests__/utils/auth.test.ts:361-387 and __tests__/label/lgtm.test.ts:348 exercise all three arms with mocked octokit.
  • End-to-end: npm run test:coverage:e2e (the vitest.e2e-coverage.config.mjs recipe from #274: source-mapped bundle built from __tests__/bundle/coverageEntry/, same revision, __tests__/bundle only) → src/utils/auth.ts 63.1 % lines / 53.12 % branches; unreached statement lines include 271-290, 321-322, 338-364 (from coverage/coverage-final.json). The two runs are reported separately by design (vitest.e2e-coverage.config.mjs header): their statement maps come from different transforms and do not line-merge.

Unit-covered, not e2e-covered → medium.

Recommendation

  • Add __tests__/bundle/ownersAuth.test.ts (new file, importing comment, helpersFor, ownersProbe, ownersReads, queueRead, repo, token from ./helpers) with three cases driving /lgtm through dist/index.js:
    1. issue, root OWNERS lists the commenter as reviewer → GET …/contents/OWNERS (200, base64), GET …/labels, POST …/issues/1/labels {labels:['lgtm']}, no /orgs/…/members or /collaborators read, then the post-command config reads;
    2. issue, root OWNERS does not list the commenter → exit 1, one refusal comment naming the login and role, no label write, no membership fallback;
    3. pull request, OWNERS + sdk/OWNERS covering sdk/file.go, commenter in neither → exit 1, refusal comment … is not a reviewer or approver for any changed file, no contents/OWNERS read, no membership read, then the config reads and tide's gate.

Measured with those three cases on the same recipe: auth.ts e2e rises to 79.61 % lines / 70.31 % branches; what remains unreached in the file are throw/catch arms (L22, 42-43, 61, 64, 98, 101, 135-139, 179, 208-222, 279, 311, 348-359) that the unit suite already pins.

Disjoint from the open hold-gated PRs: #230 (vitest.config.mjs), #242 (cronJobsInput.test.ts), #244 (meow.test.ts), #246 (labelCommands.test.ts, helpers.ts repoLabels).

Priority

  • Impact: medium — authorization is the gate in front of every label and merge command; the OWNERS branch of it has never been exercised by the shipped bundle
  • Effort: low

Filed by quality agent (hold-gated mode)

hive: close-on-merge

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

Ngôn ngữ chính
TypeScript
Star
132
Fork
23
Merge trung bình
1 ngày 20 giờ
Pull request đã merge (30 ngày)
134

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của cncf/prow-github-actions

Tất cả issue của cncf/prow-github-actions

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.