Skip to content

fix(profiler): דגלי $project נשמרים אמיתיים, אחרת השאילתה השמורה היא פעולה אחרת - #3350

Merged
amirbiron merged 2 commits into
mainfrom
claude/platform-sync-async-investigation-tdobyb
Sep 7, 2026
Merged

amirbiron merged 2 commits into
mainfrom
claude/platform-sync-async-investigation-tdobyb

Conversation

@amirbiron

@amirbiron amirbiron commented Sep 7, 2026 •

Copy link
Copy Markdown
Owner

✨ תיאור קצר

$project נשאר בשלד המנורמל, ולכן כל שאילתה שנשמרה ב-query_raw עם ערכים אמיתיים והכילה אותו יצאה עם {"file_name": "<value>"}. וזו אינה היטלה מוסתרת — מחרוזת שאינה מתחילה ב-$ בתוך היטלה נקראת כקבוע, כלומר "החזר את הקבוע <value>" במקום "החזר את השדה file_name". התיקון מסווג דגלי היטלה כמבנה, בדיוק כמו שכיווני $sort כבר מסווגים.

📦 שינויים עיקריים

  • קוד (Backend)
  • בוט טלגרם
  • מסד נתונים/מיגרציות
  • תיעוד (docs/)
  • DevOps/CI/CD

פירוט:

  • _projection_structure חדשה: גוף $project שכולו 0/1/בוליאני/נתיב שדה מסווג כמבנה ונשמר אמיתי, ברקורסיה גם על היטלה מקוננת
  • _structural_stage_value מקבל ענף $project — ובניגוד ל-$limit/$sort, הוא אינו זורק
  • שלוש הערות שהשינוי הפך לשקריות עודכנו (_structural_stage_value, _raw_pipeline, וההנמקה של סריקת הבעלות)
  • docs/observability/query-performance-profiler.rst + docs/whats-new.rst

🔬 מה בדיוק היה שבור

נמדד מול MongoDB 8.0.32. ה-explain מחזיר את השלב השמור בתור:

{"$project": {"file_name": {"$const": "<value>"}, "code": {"$const": "<value>"}}}

$const — ארבע השמות של קבועים. שלב שבמציאות מושך את code, השדה הכבד ביותר באוסף, נותח כשלב שאינו קורא שום שדה.

והכשל היה שקט לגמרי: בניגוד ל-$limit, מחרוזת בהיטלה אינה גורמת למונגו לזרוק, ולכן _fix_pipeline_for_explain — שמתקנת רק את השלבים שזורקים ($limit, $skip, $sample) — לא נגעה בה.

🔒 למה הוולידציה צרה, וזו אינה החמרה קוסמטית

התיעוד של $project אומר "Non-zero integers are also treated as true". כלומר {"$project": {"file_name": 6865105071}} הוא היטלת הכללה חוקית לגמרי, ומזהה משתמש יושב בה בגלוי. סריקת הבעלות עוברת על גופי $match בלבד ולעולם לא תראה אותו — ולכן הדבר היחיד שמונע אותו הוא צרוּת הוולידציה. 0 ו-1 בלבד סוגרים את הדלת; יש טסט ייעודי על כך.

מקור: https://www.mongodb.com/docs/manual/reference/operator/aggregation/project/

הכל-או-כלום מכוון: $project שיש בו ולו ביטוי אחד חוזר כשלד שלם, ולא כתערובת של ערכים אמיתיים ו-<value>. שלב שחציו אמיתי נראה שלם ומתפרש אחרת ממה שרץ — זה הכשל עצמו בקנה מידה קטן יותר.

ההיקף שנשאר בחוץ, במפורש: $addFields/$set ו-$unset של אגרגציה. בשניהם ערך שהוא נתיב שדה בלבד הוא מבנה זהה, אבל הסיכון לקבוע חופשי גבוה יותר ואין להם היום מופע אמיתי לאמת מולו — כמו העמדה שהקובץ כבר נוקט לגבי $search. יש טסטים שמקבעים שהם נשארו בשלד.

🧪 בדיקות

  • Unit
  • Integration
  • Manual

291 טסטי פרופיילר עוברים, אפס רגרסיות.

tests/test_profiler_projection_is_replayable.py (19 טסטים) — לוגיקה בפייתון טהור, רץ בכל מקום.
tests/test_profiler_projection_mongo.py (2 טסטים) — הצרכן האמיתי, מדלג בלי MONGODB_URL.

חמישה מהטסטים החדשים הורצו על הקוד שלפני התיקון ונפלו:

FAILED …::test_the_saved_projection_is_the_real_one
FAILED …::test_no_placeholder_survives_anywhere_in_the_pipeline
FAILED …::test_exclusion_flags_are_kept
FAILED …::test_booleans_are_kept_as_booleans
FAILED …::test_a_nested_inclusion_is_kept

השאר הם טסטי גדר — הם אמורים לעבור בשני הצדדים, כי הם מאמתים התנהגות שלא השתנתה.

אימות מקצה לקצה, מול explain האמיתי

הפלט של הקוד המתוקן הורץ דרך explain, והושווה ב-queryShapeHash — טביעת האצבע שמונגו עצמה נותנת לצורת שאילתה:

queryShapeHash
הקוד המתוקן מייצר 312C72B3…2556
השאילתה שרצה בפועל 312C72B3…2556 ✅
הקוד הישן (מורעל) E6E56114…9717
בקרה שלילית — היטלה אחרת B48196ED…B46B

הבקרה השלילית נחוצה: בלעדיה ההשוואה הראשונה הייתה עוברת גם אם ה-hash מתעלם מ-$project לגמרי, ואז היא מוודאת שהשוואת מחרוזות עובדת ותו לא.

📝 סוג שינוי

  • fix: תיקון באג

✅ צ'קליסט

  • בדיקות רצות ועוברות
  • תיעוד עודכן
  • אין סודות/מפתחות בקוד
  • אין מחיקות מסוכנות
  • הודעת הקומיט תואמת Conventional Commits
  • עיינתי במסמכי אתר התיעוד — נתיב: docs/observability/query-performance-profiler.rst | המשפט: "וגם ערכי המבנה: $limit, $skip וכיווני $sort. אלה אינם נתוני משתמש אלא צורת השאילתה... הם נשמרים אמיתיים כי בלעדיהם הניתוח מתאר שאילתה אחרת." — זה בדיוק הנימוק שהורחב כאן ל-$project, ולכן העמוד עודכן.
  • גם: docs/doc-authoring.rst (בלי ספירת מופעים בפרוזה), docs/versioning-stable-anchors.rst (What's New), docs/testing.rst (מוסכמת טסטי מונגו)

🧩 השפעות/סיכונים

  • פרודקשן: אין שינוי במסלול הכתיבה או בקריאה. משפיע רק על מה שנשמר ב-query_raw, שהוא העשרה לניתוח.
  • אבטחה: ההיתר החדש צר יותר ממה שמונגו מקבלת (גם 1.0 נדחה). $match והסינון לא נגעו כלל, ויש טסטים שמקבעים זאת.
  • פרטיות: דגלי היטלה אינם נתוני משתמש. הצורה היחידה שיכולה לשאת מזהה — מספר שלם שאינו 0/1 — נחסמת במפורש ונבדקת.

🔗 קישורים

  • ממשיך את #3349, שהלוגים שלו הם מה שאיפשר למצוא את זה.

⚠️ ממצא לדיווח, לא תוקן כאן

ה-docstring של tests/test_note_boards_mongo.py טוען "מתי הן רצות: כש-MONGODB_URL מוגדר והשרת נענה. ב-CI זה תמיד". זה אינו נכון: ג'וב Unit Tests רץ runs-on: ubuntu-latest בלי container:, והשירות mongodb מוגדר בלי ports:, ולכן שם השירות אינו נפתר וכל הטסטים האלה מדלגים בשקט. docs/testing.rst ו-.github/workflows/ci.yml עצמו (בהערה בשורה 236) מתעדים זאת נכון — רק ה-docstring סותר. לא תוקן כאן כי זה מחוץ להיקף.


🤖 Generated with Claude Code

https://claude.ai/code/session_01UBugD1DV8LhHBSGnvpAgzK


Generated by Claude Code

Review in cubic

Summary by Sourcery

Fix profiler query replay by preserving safely validated $project structure in raw aggregation pipelines.

Bug Fixes:

  • Preserve validated $project projection flags and field paths in profiler raw queries so replayed explains represent the original query instead of treating placeholders as constants.

Enhancements:

  • Add all-or-nothing structural validation for nested $project bodies while keeping expressions redacted and rejecting non-standard numeric flags that could expose identifiers.

Documentation:

  • Update query profiler documentation and release notes to describe validated structural values and $project replay behavior.

Tests:

  • Add pure-Python coverage for replayability, nested projections, validation boundaries, and unchanged redaction behavior.
  • Add optional MongoDB integration tests that compare queryShapeHash values for saved, actual, and deliberately different projections.

…פעולה אחרת

‏``$project`` נשאר בשלד המנורמל, ולכן כל שאילתה שנשמרה עם ערכים אמיתיים
והכילה אותו יצאה עם ``{"file_name": "<value>"}``. וזו אינה היטלה מוסתרת:
מחרוזת שאינה מתחילה ב-``$`` בתוך היטלה נקראת כ**קבוע**, כלומר "החזר את
הקבוע ``<value>``" במקום "החזר את השדה ``file_name``".

נמדד מול MongoDB 8.0.32: ה-``explain`` מחזיר את השלב בתור
``{"file_name": {"$const": "<value>"}}``, ו-``queryShapeHash`` שלו שונה
מזה של ההיטלה האמיתית — כלומר המנוע עצמו סופר אותן כשתי שאילתות. שלב
שמושך את ``code`` נותח כשלב שאינו קורא שום שדה.

הכשל היה שקט לגמרי: בניגוד ל-``$limit``, מחרוזת בהיטלה אינה גורמת למונגו
לזרוק, ולכן ``_fix_pipeline_for_explain`` — שמתקנת רק את השלבים שזורקים —
לא נגעה בה.

הוולידציה צרה בכוונה, וזו אינה החמרה קוסמטית. התיעוד של ``$project`` אומר
"Non-zero integers are also treated as true", כלומר
``{"file_name": 6865105071}`` הוא היטלת הכללה חוקית לגמרי שמזהה משתמש
יושב בה בגלוי; סריקת הבעלות עוברת על גופי ``$match`` בלבד ולעולם לא תראה
אותו. לכן מותרים ``0``/``1``/בוליאני/נתיב שדה בלבד, ברקורסיה גם על היטלה
מקוננת.

הכל-או-כלום מכוון: ``$project`` שיש בו ולו ביטוי אחד חוזר כשלד **שלם**
ולא כתערובת של ערכים אמיתיים ו-``<value>`` — שלב שחציו אמיתי נראה שלם
ומתפרש אחרת ממה שרץ, וזה הכשל עצמו בקנה מידה קטן יותר. ובניגוד
ל-``$limit``, הענף הזה **אינו זורק**: ``$project`` שאינו דגלים הוא
לגיטימי, ולזרוק שם היה מוחק מהדוח שאילתות תקינות.

‏``$addFields``/``$set`` ו-``$unset`` של אגרגציה נשארו בחוץ — אין להם היום
מופע אמיתי לאמת מולו, כמו העמדה שכבר ננקטת בקובץ לגבי ``$search``.

אימות: הפלט של הקוד המתוקן הורץ דרך ``explain`` האמיתי, ו-``queryShapeHash``
שלו זהה לזה של השאילתה שרצה בפועל (``312C72B3…``) ושונה מזה של הקוד הישן
(``E6E56114…``). בקרה שלילית: היטלה אחרת מקבלת hash שלישי (``B48196ED…``),
כלומר ה-hash אכן רגיש להיטלה וההשוואה אינה ריקה.

חמישה מהטסטים החדשים הורצו על הקוד שלפני התיקון ונפלו.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UBugD1DV8LhHBSGnvpAgzK
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @amirbiron, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 hour and 56 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

🧯 Dangerous deletes guard report

Policy: see .cursorrules — dangerous deletions are blocked unless wrapped safely.

Summary:

  • Flagged findings (blocking): 0
    0
  • Excluded matches (not blocking): 15
  • Total matches (all files): 129

Flagged findings (file:line:snippet):
(none)

Excluded matches (by path pattern)
./webapp/static/js/md_preview.bundle.js.map:4:  "sourcesContent": ["// Markdown-it plugin to render GitHub-style task lists; see\n//\n// https://github.com/blog/1375-task-lists-in-gfm-issues-pulls-comments\n// https://github.com/blog/1825-t … [truncated]
./docs/DOCUMENTATION_GUIDE.md:453:rm -rf _build
./docs/Makefile:24:	rm -rf $(BUILDDIR)
./Dockerfile:42:    rm -rf /var/lib/apt/lists/*
./Dockerfile:121:    rm -rf /var/lib/apt/lists/*
./node_modules/katex/package.json:153:    "build": "rimraf dist/ && mkdirp dist && cp README.md dist && rollup -c --failAfterWarnings && webpack && node update-sri.js package dist/README.md",
./node_modules/katex/src/fonts/Makefile:139:	rm -rf pfa ff otf ttf woff woff2
./node_modules/mermaid/dist/mermaid.js.map:4:  "sourcesContent": ["/**\n* Default values for dimensions\n*/\nconst defaultIconDimensions = Object.freeze({\n\tleft: 0,\n\ttop: 0,\n\twidth: 16,\n\theight: 16\n});\n/**\n* Default values for tr … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.esm/chunk-2M32CCKP.mjs.map:4:  "sourcesContent": ["{\n  \"name\": \"mermaid\",\n  \"version\": \"11.12.0\",\n  \"description\": \"Markdown-ish syntax for generating flowcharts, mindmaps, sequence d … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.esm.min/chunk-4HFYJGYH.mjs.map:4:  "sourcesContent": ["{\n  \"name\": \"mermaid\",\n  \"version\": \"11.12.0\",\n  \"description\": \"Markdown-ish syntax for generating flowcharts, mindmaps, sequen … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.esm.min/chunk-4HFYJGYH.mjs:1:var r={name:"mermaid",version:"11.12.0",description:"Markdown-ish syntax for generating flowcharts, mindmaps, sequence diagrams, class diagrams, gantt charts, git graph … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.core/chunk-KS23V3DP.mjs.map:4:  "sourcesContent": ["{\n  \"name\": \"mermaid\",\n  \"version\": \"11.12.0\",\n  \"description\": \"Markdown-ish syntax for generating flowcharts, mindmaps, sequence  … [truncated]
./node_modules/mermaid/dist/mermaid.min.js:1524:`,"getStyles"),c1e=RQe});var h1e={};dr(h1e,{diagram:()=>NQe});var NQe,f1e=N(()=>{"use strict";$ge();a1e();l1e();u1e();NQe={parser:Fge,db:n1e,renderer:o1e,styles:c1e}});var m1e,g1e=N(()=>{"use  … [truncated]
./node_modules/mermaid/dist/mermaid.min.js.map:4:  "sourcesContent": ["/**\n* Default values for dimensions\n*/\nconst defaultIconDimensions = Object.freeze({\n\tleft: 0,\n\ttop: 0,\n\twidth: 16,\n\theight: 16\n});\n/**\n* Default values fo … [truncated]
./README.md:842:find . -name "__pycache__" -exec rm -rf {} +

@sourcery-ai

sourcery-ai Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Reviewer's Guide

The PR fixes profiler query replay by narrowly recognizing recursive, flag-only $project bodies as structural and preserving them in query_raw, while leaving expression projections redacted. It adds focused unit tests plus an optional MongoDB explain integration test that verifies the saved and executed pipelines share the same query shape, and updates the related documentation.

Sequence diagram for profiler query replay with $project

sequenceDiagram
    participant Profiler
    participant StructuralStage as _structural_stage_value
    participant Projection as _projection_structure
    participant RawPipeline as _raw_pipeline
    participant MongoDB

    Profiler->>StructuralStage: _structural_stage_value("$project", body)
    StructuralStage->>Projection: _projection_structure(body)
    alt projection contains only structural flags
        Projection-->>StructuralStage: validated projection
        StructuralStage-->>RawPipeline: preserve projection
    else projection contains an expression
        Projection-->>StructuralStage: _NOT_STRUCTURAL
        StructuralStage-->>RawPipeline: normalized projection skeleton
    end
    RawPipeline->>MongoDB: explain(saved pipeline)
    MongoDB-->>Profiler: queryShapeHash
Loading

Flow diagram for replayable MongoDB projection handling

flowchart TD
    A["$project body"] --> B{_projection_structure}
    B -->|"Only 0, 1, booleans, $ paths, or nested flags"| C["Preserve real projection"]
    B -->|"Contains an expression or constant"| D["Keep projection as normalized skeleton"]
    C --> E["_raw_pipeline stores query_raw"]
    D --> E
    E --> F["Profiler explain uses matching query shape"]
Loading

File-Level Changes

Change Details Files
Classify replayable $project projection flags as structural values so saved queries preserve their actual projection semantics without exposing arbitrary user data.
  • Added recursive all-or-nothing validation for projection exclusions/inclusions, booleans, and field paths.
  • Integrated $project into structural-stage handling without rejecting valid expression-based projections; non-structural projections remain skeletonized.
  • Updated raw-pipeline and ownership-scan documentation to describe the narrower validation boundary and privacy rationale.
services/query_profiler_service.py
Add regression coverage proving projection preservation, privacy boundaries, and unchanged handling of out-of-scope stages.
  • Added pure-Python tests for production-shaped projections, nested structures, mixed expressions, booleans, exclusions, field paths, and disallowed numeric values.
  • Added assertions that $addFields, aggregation $unset, $match, and vector-query behavior remain unchanged.
tests/test_profiler_projection_is_replayable.py
Validate replayability against MongoDB's actual query-shape fingerprint.
  • Added an integration test that runs the production explain path and compares queryShapeHash for saved versus actual pipelines.
  • Added a negative control ensuring distinct projections produce distinct hashes, with isolated test-database cleanup.
tests/test_profiler_projection_mongo.py
Document the $project replayability fix and its testing/behavioral scope.
  • Explain why literal projection strings change query semantics and why all-or-nothing preservation is required.
  • Record the supported structural forms, excluded aggregation stages, and profiler behavior changes.
docs/observability/query-performance-profiler.rst
docs/whats-new.rst

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@coderabbitai

coderabbitai Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

Next included review available in 43 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 83da6d16-ce26-4d47-811c-eafe7e3290c1

📥 Commits

Reviewing files that changed from the base of the PR and between 55d2524 and 5b037b3.

📒 Files selected for processing (2)
  • services/query_profiler_service.py
  • tests/test_profiler_projection_mongo.py

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 096f25b9-e907-4904-82dd-bd18ebe10bfa

📥 Commits

Reviewing files that changed from the base of the PR and between b8b5d84 and 55d2524.

📒 Files selected for processing (5)
  • docs/observability/query-performance-profiler.rst
  • docs/whats-new.rst
  • services/query_profiler_service.py
  • tests/test_profiler_projection_is_replayable.py
  • tests/test_profiler_projection_mongo.py

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

הפרופיילר שומר כעת מבני $project תקינים עם ערכים אמיתיים. הוא מסווה שלבי $project מעורבים או ערכים שאינם מבניים. נוספו בדיקות יחידה, בדיקת queryShapeHash מול MongoDB ותיעוד.

Changes

שחזור שאילתות עם $project

Layer / File(s) Summary
אימות ושמירת מבנה ההיטלה
services/query_profiler_service.py
נוסף _projection_structure לאימות רקורסיבי של דגלים, נתיבי שדות ומבנים מקוננים. $project תקין נשמר כפי שהוא. שלב מעורב חוזר כשלד.
בדיקות גבולות ושימור נתונים
tests/test_profiler_projection_is_replayable.py
נבדקים מבנים תקינים, ביטויים, ערכים מספריים, רקורסיה, הסוואה ושלבים שאינם בתחום השינוי.
אימות מול MongoDB ותיעוד
tests/test_profiler_projection_mongo.py, docs/observability/query-performance-profiler.rst, docs/whats-new.rst
נבדק ש-queryShapeHash של הפייפליין השמור תואם לפייפליין המקורי. התיעוד מתאר את הוולידציה ואת גבולות הטיפול.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Merge Risk: ⚪ Minimal · up to 55d25

This change preserves valid $project structure in profiler query records while retaining normalization for unsupported or mixed projections. No actionable merge-blocking risk remains.

Sequence Diagram(s)

sequenceDiagram
  participant Test
  participant PersistentQueryProfilerService
  participant MongoDB
  Test->>PersistentQueryProfilerService: הפעלת _decide_raw_query
  PersistentQueryProfilerService->>PersistentQueryProfilerService: אימות _projection_structure
  PersistentQueryProfilerService-->>Test: הפייפליין השמור
  Test->>MongoDB: הרצת explain וחישוב queryShapeHash
  MongoDB-->>Test: חתימת צורת השאילתה
Loading

Poem

$project שומר דגלים באור,
ביטוי מעורב מקבל שלד ברור,
MongoDB בודק חתימה,
Claude Code כתב בדיקה חכמה,
והשאילתה חוזרת למסלול.
CodeKeeper forever 💫

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 28 functions across 3 files. (2 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed כותרת ה-PR קצרה, ברורה, ומתארת את התיקון המרכזי: שמירת דגלי $project כערכים אמיתיים בפרופיילר.
Description check ✅ Passed תיאור ה-PR מקיף את הבעיה, הסיבה, הפתרון, היקף השינוי, הבדיקות, הסיכונים, התיעוד והקישורים. חסרים פרטים מפורשים על תוכנית Rollback ועל תוצאות ה-Required Checks, אך התיאור ברובו שלם ורלוונטי.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 28 functions across 3 files. (2 skipped: 2 unsupported.)

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/platform-sync-async-investigation-tdobyb

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

⏱️ Performance report

(No performance test durations collected. Mark tests with @pytest.mark.performance.)

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

📖 Documentation Preview

The documentation has been built successfully!

To view locally:

  1. Download the artifacts
  2. Extract the zip file
  3. Open index.html in your browser

@codecov

codecov Bot commented Sep 7, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 91.30435% with 2 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
services/query_profiler_service.py 91.30% 1 Missing and 1 partial ⚠️

📢 Thoughts on this report? Let us know!

…תקלה

**בלוק הכותרת סתר את ההערה החדשה.** הוא הצהיר "מה נשמר עם ערכים אמיתיים:
תנאי סינון בלבד... כל שאר השלבים נשארים בשלד" — בעוד ההערה בסריקת הבעלות
אומרת שצרוּת ``_projection_structure`` היא הדבר היחיד שמונע מזהה משתמש
להישמר דרך ``$project``. הבלוק מתאר עכשיו שתי משפחות: תנאי סינון (ולידציה
מול רשימה) וערכי מבנה (ולידציה מול צורה צרה), ואומר מפורשות שסריקת הבעלות
אינה עוברת על השנייה.

ובאותו מעבר תועד גם מה שהתיקון **אינו** מכסה: המשפחה השנייה חלה על
``query_raw`` בלבד. ``query_shape`` ממשיך להחליף דגלי ``$project``
ב-``<value>``, וכפתור הניתוח נופל עליו כשאין ``query_raw`` — כלומר
בברירת המחדל, כש-``PROFILER_UNREDACTED_USER_IDS`` ריק.

**‏``except (ServerSelectionTimeoutError, Exception)`` בלע הכל.** האיבר
הראשון מת מול השני, ולכן כל תקלת קונפיגורציה — ``mongodb+srv://`` בלי
``dnspython``, אימות שגוי — הייתה הופכת לדילוג עם הסיבה השקרית "שרת לא
נגיש", ושתי הבדיקות שהן ההוכחה היחידה מקצה לקצה לתיקון היו נעלמות בשקט.
עכשיו נתפסת אי-נגישות בלבד, הודעת הדילוג נוקבת בשגיאה עצמה, וכל השאר עולה
בקול.

ובנוסף: בדיקת הנגישות ירדה מרמת המודול ל-fixture. קודם היא פתחה חיבור
בכל **איסוף** של pytest, גם בהרצה שאינה כוללת את הקובץ הזה.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UBugD1DV8LhHBSGnvpAgzK
@amirbiron
amirbiron merged commit 57734bc into main Sep 7, 2026
29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants