Skip to content

fix(backend): resolve source corruption (#2870) - #2872

Open
HRamiroAlbornoz wants to merge 4 commits into
QuickLendX:mainfrom
HRamiroAlbornoz:fix/source-corruption-2870
Open

HRamiroAlbornoz wants to merge 4 commits into
QuickLendX:mainfrom
HRamiroAlbornoz:fix/source-corruption-2870

Conversation

@HRamiroAlbornoz

Copy link
Copy Markdown

What

Fixes 136 tsc --noEmit errors caused by source code corruption across 10 backend files (merge conflict artifacts from commits after #2832).

Changes

Reverts to clean baselines (6 files)

  • runner.ts → commit 5ecfb039
  • policy.ts → commit b8fba721
  • shutdown-ordering.test.ts → commit 04b047b8
  • api-key-rotation-integration.test.ts → commit 9989a3c0
  • migration-runner-mocked.test.ts → commit 79d893d2
  • conditional-write.test.ts → commit b2fc36ba

Reverts to last clean commits (3 files)

  • api-keys-audit-logs.test.ts → commit c6988e38
  • migration-failure-boundary.test.ts → surgical fixes only (5 typos)
  • v006_kyc_records.ts → 1 surgical fix (duplicate .map/.filter)

Surgical fixes (1 file)

  • auditLogService.ts: ?= → ??

Pre-existing bugs fixed in runner.ts (9 fixes)

  • instance of → instanceof
  • Removed duplicate let durationMs/let state! declarations
  • Removed applyTx() and rollbackTx() (undefined functions)
  • Removed if (concurrentlyApplied) blocks (undefined variable)
  • Defined versions from migrations.map(m => m.version)
  • Fixed error message using row.version/row.name
  • Replaced toCount() with direct cast
  • Destructured to/all from options params

Security patches (2 additions)

  • SEC-1: Reject non-.ts files in require() — prevents arbitrary code execution
  • SEC-2: Validate MIGRATIONS_DIR env var against path traversal

Validation

  • tsc --noEmit: 0 parser errors in the 10 fixed files
  • runner.ts and policy.ts: 0 errors
  • Code review: 0 standards violations, no spec regressions

- Revert 6 files to clean git baselines (runner.ts, policy.ts,
  shutdown-ordering.test.ts, api-key-rotation.test.ts,
  migration-runner-mocked.test.ts, conditional-write.test.ts)
- Revert 3 test files to last clean commits
- Fix 5 typos in migration-failure-boundary.test.ts (ALLOWEB->ALLOWED, load`->load)
- Fix auditLogService.ts: ?= -> ?? (nullish coalescing)
- Fix v006_kyc_records.ts: remove duplicate .map/.filter chains
- Fix 9 pre-existing bugs in runner.ts:
  instanceof, duplicate let, applyTx/rollbackTx removal,
  concurrentlyApplied removal, versions definition, error message,
  toCount->cast, to/all destructuring
- SEC-1: reject non-.ts files in require() (prevents arbitrary code execution)
- SEC-2: validate MIGRATIONS_DIR against path traversal
- Adds "typecheck": "tsc --noEmit" to package.json scripts
- Fixes CI job #111141501220 (npm error: Missing script: "typecheck")
- scopes.ts: remove duplicate validateScopes, define ScopeValidationResult
  and describeValueType, fix hasRequiredScopes (granted set, required var)
- pg.ts: replace jest.fn() with plain functions (jest not a dependency)
- cors.ts: add @types/cors, type origin callback params
- logging/policy.ts: fix getPolicyFieldsForTier (arg vs tier mismatch)
- package.json: add typecheck script for CI
- Sync lockfile with new devDependencies (@types/cors, jest, supertest,
  fast-check, js-yaml)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant