The dual-column account filter from PR LeanerCloud/cloud-commitments-cli#956 (cloud_account_id = ANY(uuids) OR (provider = $p AND account_id = ANY(externals))) has NO real-database test. All coverage is mock-store (handler) / pgxmock (SQL text+args) level - it asserts the generated SQL but never executes it against Postgres. This is exactly the class of green-but-blind tests that let four prior PRs (LeanerCloud/cloud-commitments-cli#716/#741/#747/#881) merge while the account-filter bug survived (QA rows 305/306/384/431/452).
Additionally, the config integration suite (//go:build integration) is pre-existingly BROKEN (regression from LeanerCloud/cloud-commitments-cli#848 nullable-MonthlyCost): internal/config/store_postgres_test.go (package config_test) references undefined PurchasePlanFilter and pf, so go test -tags integration ./internal/config/ does not compile - meaning CI cannot run any real-DB test for this code path.
Fix
- (a) Repair
store_postgres_test.go so the integration suite compiles again.
- (b) Add a real-DB (testcontainers) test for
GetPurchaseHistoryFiltered proving: a row with cloud_account_id IS NULL + populated account_id IS returned when filtering by that account's UUID; and a same external-number row under a different provider is NOT returned (no cross-provider leak).
Why
Per CLAUDE.md §4: the regression test must replicate the REAL failing scenario and actually execute it. A mock test that asserts SQL strings would have stayed green with the original bug present. Discovered during adversarial verification of LeanerCloud/cloud-commitments-cli#956 (which proved the fix works via a throwaway testcontainers test - this issue makes that proof permanent + CI-enforced).
The dual-column account filter from PR LeanerCloud/cloud-commitments-cli#956 (
cloud_account_id = ANY(uuids) OR (provider = $p AND account_id = ANY(externals))) has NO real-database test. All coverage is mock-store (handler) / pgxmock (SQL text+args) level - it asserts the generated SQL but never executes it against Postgres. This is exactly the class of green-but-blind tests that let four prior PRs (LeanerCloud/cloud-commitments-cli#716/#741/#747/#881) merge while the account-filter bug survived (QA rows 305/306/384/431/452).Additionally, the config integration suite (
//go:build integration) is pre-existingly BROKEN (regression from LeanerCloud/cloud-commitments-cli#848 nullable-MonthlyCost):internal/config/store_postgres_test.go(packageconfig_test) references undefinedPurchasePlanFilterandpf, sogo test -tags integration ./internal/config/does not compile - meaning CI cannot run any real-DB test for this code path.Fix
store_postgres_test.goso the integration suite compiles again.GetPurchaseHistoryFilteredproving: a row withcloud_account_id IS NULL+ populatedaccount_idIS returned when filtering by that account's UUID; and a same external-number row under a different provider is NOT returned (no cross-provider leak).Why
Per CLAUDE.md §4: the regression test must replicate the REAL failing scenario and actually execute it. A mock test that asserts SQL strings would have stayed green with the original bug present. Discovered during adversarial verification of LeanerCloud/cloud-commitments-cli#956 (which proved the fix works via a throwaway testcontainers test - this issue makes that proof permanent + CI-enforced).