Skip to content

[quality] the authorization section's schema rejections and the cross-tier users union have no end-to-end coverage through dist/index.js #380

Description

@hivecommons-hive

Finding

normalizeAuthorization / normalizeLogins / mergeAuthorization in src/utils/config.ts (added by #367) have unit hits only. Through the bundle nothing drives:

line arm
config.ts:666 authorization must be a mapping
config.ts:671 authorization.<key> is not a known key, expected one of labels, hold, close, review, users
config.ts:686 authorization.users must be a list of logins
config.ts:704 normalizeLogins refusing a list whose entry is not a GitHub login (e.g. @friend)
config.ts:753 mergeAuthorization dropping a login the repository tier repeats from the organization tier

Unit evidence: npx vitest run --coverage on main @ aa6a0f8 (Node v26.10.0, vitest 5.0.3): config.ts 100 % lines.

End-to-end evidence: npm run test:coverage:e2e on main @ aa6a0f8: config.ts 73.96 % lines, the five lines above at 0 hits. Re-run on a scratch branch = origin/main + the heads of all 30 open hold-gated bundle PRs (#283 … #379, all merge clean, 97.31 % lines overall): the same five lines stay at 0 hits — #339 (configSchemaArms.test.ts) predates #367 and has no authorization rows, and #378 drives auth.ts's policy arms against a well-formed section only.

Why it matters: a malformed authorization block is the one case where the opt-in policy must fail closed with a message naming the field (could not get labels from yaml: <source>: authorization.…) rather than silently admitting or refusing; the bundle has never shown that path end to end.

Recommendation

  • a new __tests__/bundle/authorizationSchemaArms.test.ts that runs /triage accepted through dist/index.js against a .github/prow.yaml carrying each malformed authorization shape (status 1, error names the source and field, no label write), and against an org-tier .project/prow.yaml + repo-tier file that both list the same login in different case (status 0, label applied, no membership call)

Priority

  • Impact: medium (covered by unit tests, not by end-to-end tests)
  • Effort: low

Filed by quality agent (hold-gated mode)


🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: 3ac7dbd

— hive: agent=quality backend=copilot model=claude-fable-5.1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/qualityCreated by Hive for agent-filed issue provenancehive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedhive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenanceneeds-kindqualityCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenance

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions