Repository navigation
fix(web): assert the deployed homepage og-home card in smoke - #199
Merged
Merged
Conversation
`pnpm run smoke` failed against production on a single check: the homepage assertion still looked for the literal `/og.jpg`, but the homepage has advertised the masthead variant `/og-home.jpg` since 177a633. The deployed page was correct; the assertion was stale, and `/og.jpg` is still the correct default card for every non-homepage page. - derive the expected URL from `SITE_OG_HOME_IMAGE_URL` instead of a hard-coded path, and compare the parsed `og:image` / `twitter:image` meta content so an attribute-order change cannot void the check - add a check that fetches the og:image the deployed homepage advertises and asserts a real JPEG, so a renamed or missing card fails in CI - add `src/lib/smoke-og-image.test.ts` pinning the constant, the shipped asset, the homepage/default split, and the smoke script's wiring No metadata, rendering, or asset change: the homepage keeps its current `https://aidr.today/og-home.jpg` card.
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideFixes the stale production smoke assertion by deriving the homepage OG image from the shared SEO constant, checking the exact rendered metadata and live JPEG, and adding tests that protect the homepage/default asset split and smoke-script behavior. Sequence diagram for post-deploy homepage OG image smoke checksequenceDiagram
participant Smoke as Smoke script
participant Homepage as Deployed homepage
participant Image as Advertised OG image
Smoke->>Homepage: fetch GET /
Homepage-->>Smoke: HTML with og:image and twitter:image
Smoke->>Smoke: metaContent(...)
Smoke->>Smoke: Compare with SITE_OG_HOME_IMAGE_URL
Smoke->>Image: fetch advertised og:image URL
Image-->>Smoke: 200 image/jpeg
Smoke->>Smoke: Validate size > 5 KB and JPEG FFD8
Smoke-->>Smoke: Pass homepage OG checks
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
duyet
marked this pull request as ready for review
September 25, 2026 18:06
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #191. Draft — do not merge yet.
48ca088d42a86b6550710b507567264b110ea73cfix/smoke-homepage-og-image-20260926master@caa4407(fix(web): keep story source metadata unit intact and skip empty rows #191)What is broken
pnpm --filter @aidr/web smoke— the post-deploy check thatpnpm run cf:deploy:prodruns on every production deploy — fails againsthttps://aidr.todayon exactly one assertion:The deployed homepage is correct. This is a stale assertion, not a product defect.
Root cause
Commit
177a633("feat(web): refresh OG images with homepage masthead variant") split the share image in two:SITE_OG_IMAGE_PATH/og.jpgSITE_OG_HOME_IMAGE_PATH/og-home.jpghomepageHead()passesimageUrl: SITE_OG_HOME_IMAGE_URL(apps/web/src/lib/seo.ts:172), so the homepage has emittedhttps://aidr.today/og-home.jpgsince that commit.apps/web/scripts/smoke.ts:75was never updated and kept a hard-codedbody.includes("/og.jpg")."/og-home.jpg"does not contain the substring"/og.jpg", so the check fails deterministically — it has failed on every production deploy since177a633, and the red smoke was never the reason it got noticed. The commit landed directly onmaster(no PR, no linked issue) and touched no test that runs the script, becauseapps/web/vitest.config.tsonly includesworker/**andsrc/**—scripts/has no unit coverage at all.Live evidence for the deployed value:
The fix
apps/web/scripts/smoke.tsSITE_OG_HOME_IMAGE_URLfrom../src/lib/site— the same moduleseo.tsimports it from — so the assertion and the renderer read one constant and a future rename cannot drift them apart.metaContent(body, "property", "og:image") === SITE_OG_HOME_IMAGE_URL, and adds the same check fortwitter:image.metaContentscans<meta>tags and matchesproperty=/content=independently of attribute order, so a renderer that reorders attributes cannot silently turn the assertion into a no-op. It also asserts the absolute URL, so a relative or wrong-originog:imagefails.GET homepage og:image -> 200 JPEG, which reads theog:imageout of the live homepage HTML and fetches that URL, asserting 200, animage/*content type, > 5 000 bytes, and aFFD8JPEG magic. The old check only string-matched the body, so a 404-ing or renamed card would have passed the smoke and shown up as a blank share preview in a crawler instead.apps/web/src/lib/smoke-og-image.test.ts(new, 6 tests)SITE_OG_HOME_IMAGE_PATHto/og-home.jpgandSITE_OG_HOME_IMAGE_URLtohttps://aidr.today/og-home.jpgapps/web/publicas real JPEGs over 5 KB (this is the "does the deployed URL actually resolve" guarantee at build time)homepageHead()→ the masthead card,pageHead()→/og.jpgscripts/smoke.ts(same pattern assrc/lib/aidr-guide.test.ts): the script must derive from the constant, must not re-introduce a hard-coded"/og.jpg"or"/og-home.jpg", and must keep the meta-tag and image-fetch checksThe three guard tests fail against
master'ssmoke.tsand pass after this change, verified by restoringgit show origin/master:apps/web/scripts/smoke.tsand re-running:Verification
All on
48ca088, in a clean worktree atorigin/mastercaa4407:pnpm --filter @aidr/web smoke(livehttps://aidr.today)pnpm --filter @aidr/web exec vitest run src/lib/smoke-og-image.test.tspnpm run testpnpm run lint(all workspaces)pnpm run check-typespnpm run build(client + SSR)git diff --check origin/master...HEADThe new
GET homepage og:image -> 200 JPEGcheck passes against production:and directly:
Smoke fixture limitations (unchanged, stated explicitly)
The smoke has no local fixture or mock server; it is a live-surface script and was run only against the deployed production base, which is the only supported target. Consequences worth recording:
/api/systemtotals,/__clerk/v1/environment, theaidr.ziprelease redirect). They cannot be exercised in CI or offline./api/subscribechecks send a livePOSTwith the deliberately invalid addressnot-an-email; it is rejected 4xx and never reaches a mail provider, but it is a real request against production.og:imagefrom the metadata, so a--base http://localhost:8787run still fetches the canonical production card. That is intentional — the metadata is hard-coded toSITE_URLfor every environment — and it is the asset a crawler would fetch. It is also why the equal-path guarantee is covered by the build-time test instead.Not changed on purpose
https://aidr.today/og-home.jpgis already what production serves; the bug was only in the assertion./og.jpgremains the default card for every non-homepage page, so the old literal was not simply "wrong everywhere" — only the homepage assertion was./og-home.jpgis not inapps/web/public/_headers, so it is served with the Workers defaultcache-control: public, max-age=0, must-revalidatewhile/og.jpggetsmax-age=86400from that file. Pre-existing, unrelated to this failure, and deliberately left alone here — it needs its own decision. The new smoke check does not assert cache headers, so it stays green either way./og-home.jpgis missing fromPUBLIC_ASSET_PATHS(apps/web/worker/public-assets.ts, used for mail-embedded assets) and from the/brandasset list. Also pre-existing and out of scope.Still failing, out of scope (reported for a follow-up)
verify-aidr drive homepagefails on production for a different, also-stale assertion, plus the same OG one:Two separate defects in
.cursor/skills/verify-aidr/bin/verify-aidr:"/og.jpg"in the homepage identity list — the same OG staleness fixed herePERMALINK_RE = /href="\/[0-9a-f]{8}"/, which no longer matches the deployedhref="/ed833179?lang=vi"form thatf5d525dintroducedNot touched: it is a separate live-verification tool with its own two-part failure, and bundling it would make this PR unfocused. It is tracked under #147 and should be a separate follow-up that also refreshes
features/homepage.md.Linked
Summary by Sourcery
Correct homepage social-image smoke coverage and add regression tests to ensure deployed metadata and assets remain aligned.
Bug Fixes:
Enhancements:
Tests: