Skip to content

Commit 37eaf16

Browse files
hotlongclaude
andcommitted
docs(plugin-dev): re-anchor the dead tracker citations in packages/plugins/plugin-dev/src to the commits that decided them
Six comment lines in three files cited two tracker numbers that no longer resolve. Each now cites the commit in this repository's history that decided what the line describes (ruling C+D, form C): - the security-enforcement warning asks the published `security` service, and asks it in start(): commit 7552e03 (dev-plugin.ts x2, and three test-file comments); - plugin-hono-server's current-user endpoints key on the same published service instead of the init()-registered internals: commit c1731d0 (dev-plugin.ts x1). Comments only; every touched file keeps its line count. Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289 Co-authored-by: Claude <noreply@anthropic.com>
1 parent 33e4a56 commit 37eaf16

3 files changed

Lines changed: 6 additions & 6 deletions

File tree

‎packages/plugins/plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ import { DevPlugin } from './dev-plugin';
5050
// the next transform that lands in this file.
5151
import '@objectstack/plugin-security';
5252

53-
// [#10036] The state under test is "SecurityPlugin LOADED but its start()
53+
// [commit 7552e0337] The state under test is "SecurityPlugin LOADED but its start()
5454
// bailed", so `@objectstack/plugin-security` is deliberately NOT mocked here —
5555
// the real plugin's real `init()`/`start()` phase split is what constructs the
5656
// state. Every OTHER optional dependency is mocked away for the same reason as

‎packages/plugins/plugin-dev/src/dev-plugin.test.ts‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ describe('DevPlugin', () => {
8787

8888
const plugin = new DevPlugin({ seedAdminUser: false });
8989
await plugin.init(ctx);
90-
// [#10036] `start()` too: the "nothing is enforcing security" warning
90+
// [commit 7552e0337] `start()` too: the "nothing is enforcing security" warning
9191
// asserted at the bottom of this test moved to the start phase, because
9292
// `security` — the published service that means enforcement, as opposed
9393
// to the `init()`-registered internals that only mean "plugin loaded" —
@@ -124,7 +124,7 @@ describe('DevPlugin', () => {
124124
);
125125
expect(securityWarn).toBeDefined();
126126
// …and with the plugin genuinely absent it says so, rather than reporting
127-
// the loaded-but-failed-to-start state (#10036).
127+
// the loaded-but-failed-to-start state (the two told apart since commit 7552e0337).
128128
expect(securityWarn![0]).toContain('SecurityPlugin is not loaded');
129129
});
130130

‎packages/plugins/plugin-dev/src/dev-plugin.ts‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1060,7 +1060,7 @@ export class DevPlugin implements Plugin {
10601060
);
10611061
}
10621062
// Same reasoning, same surface: "nothing is enforcing security" belongs
1063-
// next to the banner, not buried in the init log (#10036, #3900).
1063+
// next to the banner, not buried in the init log (#3900; commit 7552e0337 moved this check here from init()).
10641064
this.warnIfNothingIsEnforcingSecurity(ctx);
10651065
ctx.logger.info('');
10661066
ctx.logger.info(' API: /api/v1/data/:object');
@@ -1075,7 +1075,7 @@ export class DevPlugin implements Plugin {
10751075
* so the slots stay empty — but silence about unenforced RBAC/RLS/masking
10761076
* would be its own kind of fake).
10771077
*
1078-
* ## Why this asks for `security`, and why it asks in `start()` (#10036)
1078+
* ## Why this asks for `security`, and why it asks in `start()` (commit 7552e0337)
10791079
*
10801080
* This used to probe `security.permissions` / `security.rls` /
10811081
* `security.fieldMasker` from `init()`. Both halves of that were wrong, and
@@ -1094,7 +1094,7 @@ export class DevPlugin implements Plugin {
10941094
* internal handles and enforces nothing, so the warning stayed silent in
10951095
* the one state where its text is literally true. (The same presence
10961096
* signal misled `plugin-hono-server`'s `/auth/me/permissions`, fixed in
1097-
* #10035 by this same move — two consumers, two packages, one misread:
1097+
* commit c1731d023 by this same move — two consumers, two packages, one misread:
10981098
* that is a property of the signal, not of either reader.)
10991099
*
11001100
* - **Wrong phase.** `security` is registered in `SecurityPlugin.start()`,

0 commit comments

Comments
 (0)