Skip to content

Add tests workflow + tonight's fixes (AuthProvider, stale test assertions, bandit findings) - #28

Open
Tharumini03 wants to merge 11 commits into
deploymentfrom
test/add-ci-workflow
Open

Tharumini03 wants to merge 11 commits into
deploymentfrom
test/add-ci-workflow

Conversation

@Tharumini03

Copy link
Copy Markdown
Collaborator

Summary

  • Adds .github/workflows/tests.yml: runs testing/unit, testing/integration, and integrated-backend/tests on push/PR, with no live services and no GGUF load.
  • fix: clear a dead session on check-sso, not on a network blip — AuthProvider now clears localStorage when check-sso resolves authenticated: false (an expired/invalidated token), but leaves an existing session alone on a network error reaching Keycloak (unknown, not confirmed dead).
  • test: fix stale assertions in test_frontend_contracts and test_pdf_validate — these were checking for text removed earlier (the local auth.js client, PDF-only upload messages); now skip/assert against current reality.
  • fix: address bandit B615 (unpinned HF revision) and B324 (weak hash use) — pins generator/judge GGUF downloads to specific HF commits; marks the non-cryptographic md5 use in qdrant_vectors.py as usedforsecurity=False.

Expected CI result

4 known, pre-existing failures in testing/unit are expected until this PR's own AuthProvider/test-assertion fixes are what's actually being tested — this PR is that fix landing, so CI should be green. If it isn't, that's new information, not the expected "stale test" state.

Test plan

  • Workflow YAML matches the exact spec given, verified byte-for-byte with a diff.
  • Each fix commit reviewed in isolation against its own diff before committing.
  • Confirm the Actions run on this PR is green (reporting back separately with the run URL).

Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com

Tharumini03 and others added 11 commits September 19, 2026 23:12
Runs testing/unit, testing/integration, and integrated-backend/tests against
GitHub-hosted runners with no live services and no GGUF model load, so pushes
and PRs get real backend test signal without needing the local stack.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
check-sso resolving authenticated:false (e.g. an expired or server-invalidated
token) now clears localStorage, so ProtectedRoute stops granting access to a
dead session. A network error reaching Keycloak is left untouched instead --
that's genuinely unknown, not a confirmed "no session," so an existing session
survives a transient outage rather than being logged out by it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…lidate

These were checking for text that no longer exists in the app: auth.js (removed
now that auth is Keycloak-only) and the old PDF-only upload/validation error
messages (upload now accepts PDF/DOCX/PPTX/TEX). test_auth_api_paths now skips
when auth.js is absent instead of failing on a file that was deliberately
deleted; the other two assertions match the current, real error text.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Generator and judge GGUF downloads now pin to a specific HF commit
(GENERATOR_REVISION/JUDGE_REVISION) instead of tracking each repo's default
branch, so a future push to either repo can't silently swap the model a fresh
checkout downloads. Threaded through ensure_gguf() and both call sites in
registry.py.

qdrant_vectors.py's md5 use for sparse-vector indexing is non-cryptographic
(bucketing words into an index space, not hashing anything sensitive); marked
with usedforsecurity=False so bandit stops flagging it as B324.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
learnmate.storage.mongo_vectors does real np.asarray/np.linalg.norm work and is
imported transitively by the learnmate package, so integrated-backend/tests
fails at collection on a clean runner without it (confirmed: ModuleNotFoundError:
No module named 'numpy'). Scoped to this job's own extras step, not
testing/requirements.txt, since testing/unit and testing/integration don't need it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ble-invoke

StrictMode's dev-only double-invoke ran this effect twice back to back; without
a cancelled guard on the create-or-reuse decision itself (not just the state
updates after it), both invocations saw "no existing session" and each called
createSession(), leaving one real session plus an orphaned duplicate for the
same document (confirmed via API: two session_ids, same document_id, 3ms apart).

Converted the effect to a single async function with a cancelled flag checked
before every state update and before the create-or-reuse branch, matching the
pattern already used in AuthProvider.jsx and chat.jsx.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The "evaluate" toggles in ResourcesPanel and MyAccountSettings had a <label>
wrapping the checkbox visually but no htmlFor/id pairing, so a screen reader
announcing the input alone gets no accessible name. Added matching
id/htmlFor pairs on both.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
A passage-scope request asks for its whole item count in one unbatched call, so
a flat max_tokens was silently capping larger requests before they could finish.
_max_tokens_for() scales a per-item token budget (calibrated the same way
whole_document.MAX_PER_CALL is) by the requested count, floored at 1024 and
capped at 3072 to stay inside GENERATOR_N_CTX's headroom after the prompt.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds the dependencies and npm scripts this session's test work runs on:
vitest + testing-library + jest-axe for unit/accessibility tests, cypress +
mochawesome for E2E, newman for Postman collections. eslint.config.js gets
Node/Cypress globals for the new cypress.config.js/tests/**/*.mjs and
cypress/e2e/**/*.js files so lint doesn't flag their environment-specific
globals. .gitignore excludes cypress's screenshot/video output.

Note: package.json's new scripts (test, test:e2e, test:postman:*) reference
integrated-frontend/tests/, cypress/, vitest.config.js, and cypress.config.js,
which are not part of this push (untracked, not requested) -- so these scripts
won't run correctly on this branch until those files are pushed separately.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Chat-session rename never made it into the UI; struck from the checklist
rather than left as a perpetually-unchecked box. See testing/RESULTS.md's
19 Sep 2026 Scope Deviation entry for the full reasoning.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Covers, in order: bug fixes and their regression tests, the first live Cypress
run and root-causing Journey B, the R-13/R-02/R-08/R-12 pass tables, the five
targeted fixes, two scope deviations (chat rename, this doc itself being
unreviewed test code at one point), remaining R-02/R-14 coverage with two
accessibility defects (dark-theme button contrast, missing upload focus
indicator), the Journey B de-flake (API-seeded message instead of typed +
judged) with its addendum quoting the real recovered error text, and the CI
workflow's numpy gap.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant