Skip to content

test(web): replace hardcoded server-fn hex with synthetic fixture - #201

Merged
duyetbot merged 1 commit into
masterfrom
fix/200-no-hardcoded-serverfn-hex
Sep 25, 2026
Merged

duyetbot merged 1 commit into
masterfrom
fix/200-no-hardcoded-serverfn-hex

Conversation

@duyetbot

@duyetbot duyetbot commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Fixes #200

What

The server-function regression tests embedded a live 64-char hex id
(HEX_FN_ID in apps/web/src/server-server-fn.test.ts, and inline in the
legacyStoryRedirectPath test in apps/web/src/lib/slug.test.ts) along with
its 8-char prefix. Those literals read as real production identifiers and put
one into git history. Replaced with "deadbeef".repeat(8) — obviously fake
hex that keeps the exact shape the transport depends on (64-char hex for a
server-fn id, 8-char hex for a story permalink), so every assertion still
exercises the same code path. Comments now say "synthetic" rather than
"production".

grep -rn "98a5ddcb" . is now clean; so is 98a5ddcb12725b5c.

Also updated the 8-char prefix literals that came from the same id
(server-server-fn.test.ts regression comment + page-route request, and the
isServerFnPath page-route case in server-fn-request.test.ts) so no
fragment of the real hash is left behind. 98a5ddcb → deadbeef is
length- and alphabet-identical, so the routing logic is exercised identically.

What is deliberately NOT changed

We keep createServerFn for first-party UI — this is not a rewrite to
/api routes.
The research decision is locked: submitStory remains a
createServerFn({ method: "POST" }) in apps/web/src/lib/submit-fn.ts, and
SubmitForm still calls the typed server function directly. /api is for
external and webhook consumers only. The real fix for the
"/_serverFn/* gets 307'd to a story page" failure is the reserved-prefix
guard, not changing the transport.

Verification

  • vitest run src/server-server-fn.test.ts src/lib/slug.test.ts src/lib/server-fn-request.test.ts → 3 files, 23 tests passed.
  • biome check on the three touched files → clean.
  • Full vitest run in apps/web: 150 files / 1572 tests pass. The 4 failing
    files are a pre-existing environment issue (Error: No such built-in module: node:sqlite on Node 20.19.2) — verified failing on a clean stash of
    master too, unrelated to this change.

Summary by Sourcery

Use synthetic hexadecimal identifiers in server-function routing tests to avoid committing live-looking production identifiers while preserving regression coverage.

Enhancements:

  • Replace production-looking server-function identifiers in routing regression tests with synthetic hexadecimal fixtures while preserving the tested identifier shapes and transport behavior.

Tests:

  • Update server-function and slug routing regression tests to use synthetic identifiers and verify the same redirect-protection paths.

The server-fn regression tests embedded a live 64-char hex id and its
8-char prefix as literals, which reads as a real production identifier
and puts one in git history. Swap them for `"deadbeef".repeat(8)`,
which keeps the exact shape the transport needs (64-char hex for a
server-fn id, 8-char hex for a story permalink) while being obviously
synthetic, and reword the comments to say "synthetic" instead of
"production".

Behaviour under test is unchanged: `_serverFn` is still in
RESERVED_TOP, so `legacyStoryRedirectPath("/_serverFn/<hex>")` still
returns null and a server-function POST is still never redirected to a
story page. submitStory stays a createServerFn.

Refs #200
@sourcery-ai

sourcery-ai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Test fixtures now use obviously synthetic deadbeef hex values instead of a live-looking server-function identifier, preserving the exact lengths and routing scenarios under test without changing production server-function behavior.

File-Level Changes

Change Details Files
Replace the committed production-looking server-function identifier with a deterministic synthetic hex fixture while preserving transport and routing shapes.
  • Define the 64-character server-function fixture as "deadbeef".repeat(8).
  • Use the matching 8-character deadbeef prefix in page-route and path-matching regression cases.
  • Update comments to identify the values as synthetic without changing the tested behavior.
apps/web/src/server-server-fn.test.ts
apps/web/src/lib/slug.test.ts
apps/web/src/lib/server-fn-request.test.ts

Assessment against linked issues

Issue Objective Addressed Explanation
#200 Replace the hardcoded production-looking server-function identifier and its fragments in both tests with an obviously synthetic 64-character hexadecimal fixture, and update comments accordingly. ✅
#200 Ensure the /_serverFn prefix remains reserved so server-function requests are not redirected to legacy story pages. ✅
#200 Keep submitStory implemented as a typed createServerFn rather than rewriting it or other first-party server functions to API routes, while documenting the fn-versus-API decision. ✅

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c579c564-d369-40c2-940c-32fbdd3b3f05


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Approved.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@duyetbot
duyetbot merged commit 45a5be8 into master Sep 25, 2026
5 checks passed
@duyetbot
duyetbot deleted the fix/200-no-hardcoded-serverfn-hex branch September 25, 2026 18:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remove hardcoded production server-fn hex; keep createServerFn (not API rewrite)

1 participant