Add tests workflow + tonight's fixes (AuthProvider, stale test assertions, bandit findings) - #28
Open
Tharumini03 wants to merge 11 commits into
Open
Tharumini03 wants to merge 11 commits into
Tharumini03 wants to merge 11 commits into
Conversation
Runs testing/unit, testing/integration, and integrated-backend/tests against GitHub-hosted runners with no live services and no GGUF model load, so pushes and PRs get real backend test signal without needing the local stack. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
check-sso resolving authenticated:false (e.g. an expired or server-invalidated token) now clears localStorage, so ProtectedRoute stops granting access to a dead session. A network error reaching Keycloak is left untouched instead -- that's genuinely unknown, not a confirmed "no session," so an existing session survives a transient outage rather than being logged out by it. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…lidate These were checking for text that no longer exists in the app: auth.js (removed now that auth is Keycloak-only) and the old PDF-only upload/validation error messages (upload now accepts PDF/DOCX/PPTX/TEX). test_auth_api_paths now skips when auth.js is absent instead of failing on a file that was deliberately deleted; the other two assertions match the current, real error text. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Generator and judge GGUF downloads now pin to a specific HF commit (GENERATOR_REVISION/JUDGE_REVISION) instead of tracking each repo's default branch, so a future push to either repo can't silently swap the model a fresh checkout downloads. Threaded through ensure_gguf() and both call sites in registry.py. qdrant_vectors.py's md5 use for sparse-vector indexing is non-cryptographic (bucketing words into an index space, not hashing anything sensitive); marked with usedforsecurity=False so bandit stops flagging it as B324. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
learnmate.storage.mongo_vectors does real np.asarray/np.linalg.norm work and is imported transitively by the learnmate package, so integrated-backend/tests fails at collection on a clean runner without it (confirmed: ModuleNotFoundError: No module named 'numpy'). Scoped to this job's own extras step, not testing/requirements.txt, since testing/unit and testing/integration don't need it. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ble-invoke StrictMode's dev-only double-invoke ran this effect twice back to back; without a cancelled guard on the create-or-reuse decision itself (not just the state updates after it), both invocations saw "no existing session" and each called createSession(), leaving one real session plus an orphaned duplicate for the same document (confirmed via API: two session_ids, same document_id, 3ms apart). Converted the effect to a single async function with a cancelled flag checked before every state update and before the create-or-reuse branch, matching the pattern already used in AuthProvider.jsx and chat.jsx. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The "evaluate" toggles in ResourcesPanel and MyAccountSettings had a <label> wrapping the checkbox visually but no htmlFor/id pairing, so a screen reader announcing the input alone gets no accessible name. Added matching id/htmlFor pairs on both. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
A passage-scope request asks for its whole item count in one unbatched call, so a flat max_tokens was silently capping larger requests before they could finish. _max_tokens_for() scales a per-item token budget (calibrated the same way whole_document.MAX_PER_CALL is) by the requested count, floored at 1024 and capped at 3072 to stay inside GENERATOR_N_CTX's headroom after the prompt. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds the dependencies and npm scripts this session's test work runs on: vitest + testing-library + jest-axe for unit/accessibility tests, cypress + mochawesome for E2E, newman for Postman collections. eslint.config.js gets Node/Cypress globals for the new cypress.config.js/tests/**/*.mjs and cypress/e2e/**/*.js files so lint doesn't flag their environment-specific globals. .gitignore excludes cypress's screenshot/video output. Note: package.json's new scripts (test, test:e2e, test:postman:*) reference integrated-frontend/tests/, cypress/, vitest.config.js, and cypress.config.js, which are not part of this push (untracked, not requested) -- so these scripts won't run correctly on this branch until those files are pushed separately. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Chat-session rename never made it into the UI; struck from the checklist rather than left as a perpetually-unchecked box. See testing/RESULTS.md's 19 Sep 2026 Scope Deviation entry for the full reasoning. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Covers, in order: bug fixes and their regression tests, the first live Cypress run and root-causing Journey B, the R-13/R-02/R-08/R-12 pass tables, the five targeted fixes, two scope deviations (chat rename, this doc itself being unreviewed test code at one point), remaining R-02/R-14 coverage with two accessibility defects (dark-theme button contrast, missing upload focus indicator), the Journey B de-flake (API-seeded message instead of typed + judged) with its addendum quoting the real recovered error text, and the CI workflow's numpy gap. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
.github/workflows/tests.yml: runstesting/unit,testing/integration, andintegrated-backend/testson push/PR, with no live services and no GGUF load.fix: clear a dead session on check-sso, not on a network blip— AuthProvider now clears localStorage when check-sso resolvesauthenticated: false(an expired/invalidated token), but leaves an existing session alone on a network error reaching Keycloak (unknown, not confirmed dead).test: fix stale assertions in test_frontend_contracts and test_pdf_validate— these were checking for text removed earlier (the localauth.jsclient, PDF-only upload messages); now skip/assert against current reality.fix: address bandit B615 (unpinned HF revision) and B324 (weak hash use)— pins generator/judge GGUF downloads to specific HF commits; marks the non-cryptographic md5 use inqdrant_vectors.pyasusedforsecurity=False.Expected CI result
4 known, pre-existing failures in
testing/unitare expected until this PR's own AuthProvider/test-assertion fixes are what's actually being tested — this PR is that fix landing, so CI should be green. If it isn't, that's new information, not the expected "stale test" state.Test plan
Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com