Skip to content

release: v1.8.1 - #172

Merged
datvt243 merged 16 commits into
mainfrom
release/v1.8.1
Sep 27, 2026
Merged

datvt243 merged 16 commits into
mainfrom
release/v1.8.1

Conversation

@datvt243

Copy link
Copy Markdown
Owner

0f87eb4 chore(release): bump version to v1.8.1
4b84729 Merge pull request #171 from datvt243/156-post-apiv2-authregister
66a9299 Merge remote-tracking branch 'origin/staging' into 156-post-apiv2-authregister
5437632 test(auth): add regression coverage proving v2 register reaches the fixed handler
6faec85 Merge pull request #170 from datvt243/155-token-exp-in
a318e76 Merge remote-tracking branch 'origin/staging' into 155-token-exp-in
6cfba0a test(auth): add regression coverage proving access/refresh token expiry is config-driven
2faa537 Merge pull request #169 from datvt243/154-puppeteer-chrome-executable
247983c test(services): add coverage for Puppeteer executablePath resolution
04ccc28 Merge pull request #168 from datvt243/153-critical-candidate-me
0dc9b77 test(candidate_me): add regression coverage for ObjectId candidateId filter
a2ec824 Merge pull request #167 from datvt243/152-password-hash-leaked
fd5a958 test(candidate): add regression coverage proving password hash is never returned
c28d31c Merge pull request #166 from datvt243/157-post-create-responses
e599a16 test(services): add regression coverage for POST .../create returning real _id
d5fe00f Merge pull request #151 from datvt243/release/v1.8.0

Closes #152.
Closes #153.
Closes #154.
Closes #155.
Closes #156.
Closes #157.

datvt243 and others added 16 commits September 27, 2026 05:30
chore(release): sync v1.8.0 version bump back to staging
… real _id

Closes #157. The production fix was already live on `staging` since
commit f355e2f (2026-08-21) — `baseCreateDocument`'s hookAfterSave
result was already propagated correctly — but no regression test ever
covered it and the diagram node was never backfilled.

- src/__tests__/services/baseCreateDocument.test.ts: direct unit
  coverage of the hookAfterSave replacement propagation.
- src/__tests__/candidate_profile/BaseService.test.ts: spot-checks a
  real CV section create flow through the unmocked
  createCrudService/BaseService.ts/services/index.ts code path (only
  the Mongoose model is faked) — confirms the response's _id is the
  real persisted id, not null.
- agent-hub: backfill evidence (implementer + verifier) and seal node
  fix-create-response-null-id.

npm test: 140 passed, 140 total. npm run build: clean.

Node: fix-create-response-null-id (SEALED)
Evidence: agent-hub/evidence/implementer/2026-09-28/fix-create-response-null-id-plan.md,
agent-hub/evidence/verifier/2026-09-28/fix-create-response-null-id-seal.md

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
test(services): add regression coverage for POST .../create returning real _id
…er returned

Closes #152. The production fix was already live on `staging` since
commit f355e2f (2026-08-21) — handlerGetInformationByEmail/
handlerGetInformationById already exclude the password field correctly
— but no regression test ever covered it and the diagram node was
never backfilled.

- src/__tests__/candidate/candidate.service.test.ts: 3 tests proving
  both handlers exclude password by default, and that a given
  whitelisted select string is no longer silently dropped (the old
  double-wrap no-op bug).
- agent-hub: backfill evidence (implementer + verifier) and seal node
  fix-candidate-password-leak.

npm test: 143 passed, 143 total. npm run build: clean.

Node: fix-candidate-password-leak (SEALED)
Evidence: agent-hub/evidence/implementer/2026-09-28/fix-candidate-password-leak-plan.md,
agent-hub/evidence/verifier/2026-09-28/fix-candidate-password-leak-seal.md

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
test(candidate): add regression coverage proving password hash is never returned
…filter

Closes #153. The production fix was already live on staging as part of
the fix-candidate-me-nosql-filter-collapse pass (issue #135, SEALED
2026-09-19) — handlerGetAboutMe already stringifies the ObjectId _id
before filtering CV-section queries by candidateId — but no test ever
exercised an ObjectId-typed _id specifically (every existing test used
a plain string, which would pass even with the old bug), and the
diagram node was never backfilled.

- src/__tests__/candidate_me/index.test.ts: new describe block using a
  fake ObjectId-like _id (only a .toString() method, not a string) and
  asserting every CV-section query receives the stringified
  candidateId, never the raw object, never silently dropped.
- agent-hub: backfill evidence (implementer + verifier) and seal node
  fix-candidate-me-candidateid-not-string.

npm test: 141 passed, 141 total (independently re-run by the verifier
subagent, matching exactly). npm run build: clean.

Node: fix-candidate-me-candidateid-not-string (SEALED)
Evidence: agent-hub/evidence/implementer/2026-09-28/fix-candidate-me-candidateid-not-string-plan.md,
agent-hub/evidence/verifier/2026-09-28/fix-candidate-me-candidateid-not-string-seal.md

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
test(candidate_me): add regression coverage for ObjectId candidateId filter
Closes #154. The production fix was already live on staging since
add-docker-support (issue #24, SEALED 2026-09-06) — createCV already
uses PUPPETEER_EXECUTABLE_PATH as an optional override, falling back
to Puppeteer's own bundled Chromium resolution when unset, with no
hardcoded path anywhere. Live-Docker-verified previously, but never
unit-tested, and the diagram node was never backfilled.

- src/__tests__/services/createPDF.test.ts: mocks puppeteer.launch
  entirely (no real browser spawned) and asserts createCV calls it
  with no executablePath key when PUPPETEER_EXECUTABLE_PATH is unset,
  and with that exact value when set.
- agent-hub: backfill evidence (implementer + verifier) and seal node
  fix-chrome-executable-path.

npm test: 142 passed, 142 total. npm run build: clean.

Node: fix-chrome-executable-path (SEALED)
Evidence: agent-hub/evidence/implementer/2026-09-28/fix-chrome-executable-path-plan.md,
agent-hub/evidence/verifier/2026-09-28/fix-chrome-executable-path-seal.md

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
test(services): add coverage for Puppeteer executablePath resolution
…ry is config-driven

Closes #155. The production fix was already live on staging since
commit f355e2f (2026-08-21) — both jwtSign() call sites (login,
refresh) already pass TOKEN_EXP_IN/TOKEN_REFRESH_EXP_IN — but no test
ever decoded a real issued JWT to prove exp/iat actually reflects the
configured duration, and the diagram node was never backfilled.

- src/__tests__/auth/tokenExpiry.test.ts: uses the real jwtSign/
  jwtVerify (unmocked) and real config, decodes issued tokens, and
  proves access vs refresh tokens get 2 distinct, config-driven
  lifetimes (not a shared hardcoded default), plus regression checks
  for both fallback defaults ('1h' access, '7d' refresh).
- agent-hub: backfill evidence (implementer + verifier) and seal node
  fix-refresh-token-expiry-unused.

npm test: 143 passed, 143 total (independently re-run by the verifier
subagent). npm run build: clean.

Node: fix-refresh-token-expiry-unused (SEALED)
Evidence: agent-hub/evidence/implementer/2026-09-28/fix-refresh-token-expiry-unused-plan.md,
agent-hub/evidence/verifier/2026-09-28/fix-refresh-token-expiry-unused-seal.md

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
test(auth): add regression coverage proving access/refresh token expiry is config-driven
…ixed handler

Closes #156. The originally buggy file (src/api/v1/auth/services/
register.ts, missing await on bcryptGenerateSalt) no longer exists —
it was removed by consolidate-v1-v2-auth (issue #77, SEALED
2026-08-29), which merged v1/v2 auth into one shared implementation.
v2/auth.route.ts now wires /register to the same authRegister
controller v1 uses, whose handlerRegister already awaits
bcryptGenerateSalt correctly (already indirectly proven by the
existing auth.service.test.ts assertion). The diagram node was never
backfilled after the consolidation.

- src/__tests__/auth/v2AuthRoute.test.ts: asserts v2's /register route
  handler is the literal same authRegister function reference as v1 —
  proves v2 reaches the already-correct, already-tested handler, not a
  separate still-broken code path.
- agent-hub: backfill evidence (implementer + verifier) and seal node
  fix-v2-register-missing-await.

npm test: 141 passed, 141 total (independently re-run by the verifier
subagent). npm run build: clean.

Node: fix-v2-register-missing-await (SEALED)
Evidence: agent-hub/evidence/implementer/2026-09-28/fix-v2-register-missing-await-plan.md,
agent-hub/evidence/verifier/2026-09-28/fix-v2-register-missing-await-seal.md

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
test(auth): add regression coverage proving v2 register reaches the fixed handler
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@datvt243
datvt243 merged commit f557772 into main Sep 27, 2026
3 checks passed
@datvt243
datvt243 deleted the release/v1.8.1 branch September 27, 2026 19:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment