PR 0 of the router domain split (docs/website/API_V2_PLAN.md § Phase 2). The
split promises that admin.routes.js can be carved into one router file per
business capability without moving a single URL. That promise has to be proved
by a diff, not asserted in review — this lands the tool that proves it, with no
router file moved.
scripts/routeManifest.js walks the live Express stack (runtime introspection,
not source parsing: route paths in admin.routes.js sit on the line *after*
`adminRouter.get(`, which defeats greps) and writes a sorted { method, path }
list to routes.manifest.json. It reproduces the frozen baseline in
docs/website/api-route-inventory.json byte-for-byte — 199 public routes plus 2
on the internal listener — so the freeze is confirmed accurate, not just
claimed.
Scope is /api/** and /.well-known/** plus the internal app. The SPA catch-all,
/uploads and /brand are filesystem-conditional static mounts, so including them
would make the output depend on whether CI had built the client. Static mounts
are not API contract.
Also emits routes.guards.json — a review aid, not a contract: per route, the
handler count and the *named* middleware on its mount chain. Router-level
`use(noindex, isLoggedIn, staffOnly)` gates never appear in an individual
route's own stack, so an extracted capability router that forgot to re-apply
one would otherwise publish authenticated endpoints silently. Names are a hint
only (requireRole(...) returns an anonymous arrow), but a vanished requireAuth
is unambiguous — and the test suite asserts every /admin/** and /player/**
route still carries it.
The plan's optional unauthenticated-status snapshot was tried and dropped, as
it allowed: against the dead-port mariadb pool the tests use, the sweep sits on
the pool's acquire timeout and had not finished after two minutes. A flaky
two-minute gate is worse than none; the requireAuth assertion covers the same
regression deterministically.
CI runs `npm run routes:manifest -- --check` on every PR, so a URL change can
only merge by deliberately committing the new manifest.
Co-Authored-By: Claude <noreply@anthropic.com>
81 lines
2.9 KiB
YAML
81 lines
2.9 KiB
YAML
# Gate every pull request into `main` on a fast, DB-free check suite so a broken
|
|
# build or failing test can't reach the deployable branch. Complements
|
|
# build-images.yml, which runs only AFTER merge (on push to main) to publish
|
|
# images — this one runs BEFORE merge.
|
|
#
|
|
# Enforcement (one-time, in the Gitea UI):
|
|
# Repository Settings → Branches → Branch Protection (rule for `main`)
|
|
# • Enable Status Check
|
|
# • Status check patterns: PR Checks / *
|
|
# Note: Gitea only lists a context in its dropdown after it has reported once,
|
|
# so let this workflow run on one PR first. The `PR Checks / *` glob matches
|
|
# without needing the dropdown.
|
|
#
|
|
# Runner: reuses the existing self-hosted `ubuntu-latest` runner. These jobs need
|
|
# only Node (no Docker socket), and the server tests stub their models + point the
|
|
# DB pool at a dead port, so no MariaDB service is required.
|
|
|
|
name: PR Checks
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
|
|
# A newer push to the same PR cancels the in-flight run.
|
|
concurrency:
|
|
group: pr-checks-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
server-tests:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 20
|
|
cache: npm
|
|
cache-dependency-path: server/package-lock.json
|
|
- name: Install server deps
|
|
run: npm ci --prefix server
|
|
- name: Run server tests
|
|
run: npm test --prefix server
|
|
- name: Check the route manifest is current
|
|
# The URL surface is frozen while admin.routes.js is carved up by capability
|
|
# (docs/website/API_V2_PLAN.md § Phase 2). Regenerating from the live Express
|
|
# stack and diffing proves a "mechanical" refactor moved no URL. A PR that
|
|
# really does change one has to commit the new manifest, putting it in front
|
|
# of a reviewer instead of letting it pass silently.
|
|
run: npm run routes:manifest --prefix server -- --check
|
|
|
|
client-build:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 20
|
|
cache: npm
|
|
cache-dependency-path: client/package-lock.json
|
|
- name: Install client deps
|
|
run: npm ci --prefix client
|
|
- name: Run client tests
|
|
# Pure-logic unit tests on Node's built-in runner (no browser/DOM).
|
|
run: npm test --prefix client
|
|
- name: Build client
|
|
run: npm run build --prefix client
|
|
|
|
bot-install:
|
|
# No tests/build to run; a clean install still catches a broken or
|
|
# out-of-sync lockfile before it ships in the bot image.
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 20
|
|
cache: npm
|
|
cache-dependency-path: bot/package-lock.json
|
|
- name: Install bot deps
|
|
run: npm ci --prefix bot
|