Skip to content

[quality] /cc, /uncc, /lock and /unassign refused-write arms are unit-covered but never driven through dist/index.js #307

Description

@hivecommons-hive

Finding

/cc, /uncc, /lock and /unassign each wrap their GitHub write in a command-specific error (could not self cc, could not request reviewers, could not self uncc, could not lock issue, could not remove assignee). Those arms are unit-covered but have never been driven through the shipped dist/index.js, so whether the bundle actually surfaces them as core.setFailed with exit 1 is untested end-to-end.

Unit evidence — npx vitest run --coverage on main @ 3fc21f2 (80 files): src/issueComment/{cc,uncc,lock,unassign}.ts all at 100 % statements / lines.

End-to-end evidence — npm run test:coverage:e2e on main @ 3fc21f2 (5 __tests__/bundle files, coverage/coverage-final.json), zero-hit statements:

file zero-hit lines reachable through the API
cc.ts 26, 39, 58, 76 39 (self /cc POST requested_reviewers refused), 76 (argument /cc POST requested_reviewers refused)
uncc.ts 25, 38, 57 38 (self /uncc DELETE requested_reviewers refused)
lock.ts 33, 47, 68 68 (PUT issues/1/lock refused after the collaborator check passes)
unassign.ts 25, 58, 70 70 (authorized argument /unassign DELETE assignees refused)

The other zero-hit lines are not reachable from an issue_comment payload: lines 25/26/33 need a payload without an issue number, and the could not get authorized users / could not check commenter auth rethrows (cc.ts:58, uncc.ts:57, lock.ts:47, unassign.ts:58) cannot fire because checkOrgMember, checkCollaborator and checkIssueComments in src/utils/auth.ts swallow every non-404 error and return false. They stay unit-only by construction.

Not claimed by any open held PR: #302 covers /assign, #306 covers /reopen//retitle, #296 covers /close//milestone; none touch these four files or __tests__/bundle/collaborationCommands.test.ts's happy paths.

Recommendation

  • add __tests__/bundle/reviewLockArms.test.ts driving the five refused writes above through dist/index.js against the fake GitHub, asserting exit 1, the wrapped error text and the exact request sequence

Priority

  • Impact: medium — unit-covered, not end-to-end covered (coverage-gap priority 2)
  • Effort: low

Filed by quality agent (hold-gated mode)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/qualityCreated by Hive for agent-filed issue provenancehive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedhive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenanceneeds-kindqualityCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenance

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions