Repository navigation
feat: dashboard backend (v0.47 phase 3a) - #25
Conversation
…s, invites, org analytics Human-JWT routes for the future dashboard frontend. Non-members get 404, non-owners 403 on owner-only routes. Member removal is serialized by the tenant row lock so an org can never lose its last owner. Org analytics reuse the API-key analytics handlers. DEC-228..230.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (11)
Included review availability: Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughAdds human-authenticated dashboard routes for profile and organization management, member and invitation operations, and organization-scoped analytics. Adds database operations, API contracts, and tests for these routes. ChangesDashboard backend
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant DashboardClient
participant newMux
participant orgAnalytics
participant DB
participant analyticsHandler
DashboardClient->>newMux: Send human-authenticated analytics request
newMux->>orgAnalytics: Route organization analytics request
orgAnalytics->>DB: Check organization membership
orgAnalytics->>analyticsHandler: Delegate with tenant ID in request context
analyticsHandler-->>DashboardClient: Return analytics response
Merge Risk: ⚪ Minimal · up to The dashboard routes have no established merge-blocking issue and are mergeable after normal checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The new endpoints enforce human authentication and organization access, and member removal has a concurrency safeguard. However, two owner-only updates can complete after the caller loses ownership because authorization is checked before, rather than as part of, the update. The exposure is limited to an organization the caller previously owned. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 11.11% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 18 functions across 6 files. (5 skipped: 5 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
Summary
GET /v1/me/PATCH /v1/me— human profile (name, avatar_url)GET /v1/orgs/{id}(any member) /PATCH /v1/orgs/{id}(owner) — org detail/settingsGET /v1/orgs/{id}/members(any member) /DELETE /v1/orgs/{id}/members/{humanId}(owner) — member management, with a row-locked last-owner invariant (concurrent mutual-removal race-tested)GET /v1/orgs/{id}/invites/DELETE /v1/orgs/{id}/invites/{inviteId}(owner) — pending invite management, idempotent revokeGET /v1/orgs/{id}/analytics/overview//timeseries(any member) — human-JWT-scoped wrapper reusing the existing analytics handlers, no logic duplicatedAll human-JWT authenticated via
humanAuthMiddleware; non-member gets 404, non-owner gets 403 on owner-only routes (no enumeration).Deferred (documented, not built): org slug (needs a migration/uniqueness decision), leaving an org, ownership transfer, role changes, email change.
Test plan
gofmt/go vet/go buildcleango test ./...andgo test -race ./...clean against real Postgres+RedisTestRemoveTenantMemberConcurrentMutualRemovalKeepsAnOwnerstress-tested 15x with-race, stableTestOpenAPISpecParses/TestOpenAPIRoutesMatchRuntimepassSummary by CodeRabbit