Skip to content

Repair main: dependency conflict, dropped tracing wiring, PendingTx model, strict-mode and lint errors, docs and audit gates - #369

Merged
EmmanuelOchaje merged 8 commits into
StellarTickets:mainfrom
Majormaxx:fix/main-ci-repair
Sep 27, 2026
Merged

EmmanuelOchaje merged 8 commits into
StellarTickets:mainfrom
Majormaxx:fix/main-ci-repair

Conversation

@Majormaxx

Copy link
Copy Markdown
Contributor

Closes #368

main has been red on every job since #367 merged (19e56d2). This PR gets the test, docs-check and migration-lint inputs back to green and restores the code that merge dropped. Each commit is one concern so it can be reviewed, or reverted, on its own.

Commits

  1. restored dependencies and bootstrap lost in the swagger merge. @nestjs/swagger pinned to ^11.4.7 (the newest release whose peers are Nest 11), the five @opentelemetry/* dependencies from Add opt-in OpenTelemetry tracing hooks #365 put back, @nestjs/platform-express bumped to ^11.2.6 (pulls multer 2.4.0, closing four high advisories), lockfile regenerated. src/main.ts is the pre-merge bootstrap (dotenv, startTracing() before any Nest import, CSP directives, JSON body limit) with feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367's additions layered on through the same dynamic-import block: CORS_ORIGINS, GlobalExceptionFilter, Swagger outside production. src/app.module.ts gets its TracingShutdownService import back.
  2. restored the PendingTx model dropped from the Prisma schema. Copied verbatim from 09e199e, matching the existing migration 20260925090000_add_pending_tx column for column, plus the pendingTxs relation on User.
  3. fixed strict-mode type errors in specs, factories and the scanner guard. Seven one-line fixes; no behaviour change except scanner-device.guard.ts, which now ignores a non-string ticketId param instead of failing to compile.
  4. declared the body limit, CSP and cache TTL env vars and regenerated docs. JSON_BODY_LIMIT, CSP_DIRECTIVES and CACHE_TTL_SECONDS were read by code but missing from env.validation.ts, which is what docs:check flags. docs/CONFIGURATION.md and the four missing Bruno requests are generator output.
  5. passed HttpExceptions through the global exception filter unchanged. @Catch() with no HttpException branch turned every 404, 403 and validation 400 into 500 INTERNAL_ERROR in production. HttpExceptions now keep their status and Nest's body shape; three tests added. This is the one change here that is not a restoration; call it out if you would rather have it in its own PR.
  6. fixed the events controller and capacity lock specs. The controller spec passes ResponseCacheInterceptor through the existing passthrough option; the capacity-lock spec joins the tagged-template chunks before looking for FOR UPDATE.
  7. made the audit gate follow transitive findings and allowlisted the Prisma CLI advisory. npm audit lists a package that is only vulnerable through a dependency with the dependency's name in via, not an advisory id, so check-audit.js could never allowlist prisma or @prisma/config. It now walks those names down to the root advisory. deepmerge-ts (GHSA-ggr8-5vv4-36mx) is allowlisted with the reason in the file: only the Prisma CLI's config loader reaches it, and no Prisma 6.x ships the fixed 8.x line.
  8. cleared eslint errors across DTOs, interceptors and specs. Typed the @Transform callbacks ({ value: unknown }), typed jest mocks and captured call arguments, rewrote BigIntSerializerInterceptor.serializeBigInts over unknown, and typed the filters' Request / Response. Same test cases, same runtime behaviour.

Evidence (Node 22.23.3, clean npm ci from the new lockfile)

gate before (19e56d2) after
npm ci ERESOLVE added 901 packages
npx tsc --noEmit 19 errors 0
npx eslint "src/**/*.ts" 127 errors 0
npx jest --coverage 2 suites / 33 tests failing 70 suites, 575 tests, coverage 72.5 / 64.6 / 71.6 / 72.6 (thresholds 65 / 60 / 60 / 65)
npm run build fails on tsc ok
npm run docs:check 3 env vars + 4 Bruno files out of date ok
npm run audit:check 5 findings at or above high ok

Not run locally: e2e-test and migration-lint need Postgres, which this machine does not have. The schema change is a verbatim restore of the model the existing migration was generated from, so migrate diff should report no drift; please let the workflow confirm.

Out of scope

  • test/*.e2e-spec.ts carry 29 eslint errors of the same no-unsafe-* kind. CI lints src/** only, so they are not a gate; happy to follow up.
  • src/common/filters/domain-exception.filter.ts is no longer registered anywhere after feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367 (the global filter handles DomainError). Left in place; deleting it is a separate decision.
  • The Bruno generator does not expand fields inherited through extends, so every confirm-* request in docs/bruno/ lacks signedXdr. Tracked in the follow-up PR that documents the API.

@netlify

netlify Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for stellarticketsbackend ready!

Name Link
🔨 Latest commit fb3611c
🔍 Latest deploy log https://app.netlify.com/projects/stellarticketsbackend/deploys/6ab96f5b3466ee000877a38b
😎 Deploy Preview https://deploy-preview-369--stellarticketsbackend.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@EmmanuelOchaje
EmmanuelOchaje merged commit fb3611c into StellarTickets:main Sep 27, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

main is red since the swagger merge: npm ci, tsc, eslint, jest, docs-check and audit all fail

2 participants