Skip to content

fix: framework diagnostics + dev CSP + login quick-login + test warnings - #28

Merged
antosubash merged 2 commits into
mainfrom
feat/diagnostics-csp-and-warnings
Apr 16, 2026
Merged

antosubash merged 2 commits into
mainfrom
feat/diagnostics-csp-and-warnings

Conversation

@antosubash

@antosubash antosubash commented Apr 16, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Framework diagnostics bugs (SM004 / SM007 / SM012) — all three were false-positives rather than real module-side issues. Fixed the diagnostic code itself.
  • Dev-mode CSP — Vite's HMR scripts and WebSocket were blocked because the default CSP only allowed 'self'. Added SecurityHeadersMiddleware.dev_csp(vite_dev_url) and wired it when settings.is_development.
  • Login quick-login buttons — .env.example documented a feature ("dev-only clickable login for seeded bootstrap accounts") that was never implemented. login_page now emits dev_accounts props in dev, and Login.tsx renders a "Dev quick-login" strip under the form.
  • Vite 8 housekeeping — dropped vite-tsconfig-paths in favor of Vite 8's native resolve.tsconfigPaths: true; swapped @vitejs/plugin-react-swc for @vitejs/plugin-react (SWC plugin warning); moved [tool.uv] dev-dependencies to the standard [dependency-groups] dev.
  • Cleaned up all pytest/Vite deprecation warnings — TestClient/httpx per-request cookies moved to the client, JWT test secrets bumped to ≥32 bytes, vitest 3 → 4 (oxc alignment), pydantic-settings stopped leaking the repo's real .env into users-module tests.

Root causes, briefly

  • SM004: _check_phantom_renders used pages_dir.glob("*.tsx") (non-recursive), so nested pages like pages/Users/Index.tsx were reported as missing. Now uses rglob + relative-path keys, and skips lowercase helper dirs (components/, hooks/, …) so shared components aren't flagged as orphan pages.
  • SM012: set(vars(app.state)) always returned {'_state'} — Starlette's State stores every attribute in __dict__['_state']. The diff was always empty, so every module that overrode register_settings() got warned. Now snapshots app.state._state.
  • SM007: only counted register_* hooks. Auth is a shared-contract module that legitimately overrides only locale_dirs(). Added locale_dirs, static_mounts, template_dirs, on_startup, and on_shutdown to the "not empty" list.
  • Users-test bootstrap failures: the dev .env exports SM_USERS_BOOTSTRAP_EMAIL (needed for the new quick-login buttons), and UsersSettings was auto-loading that file during tests. An autouse fixture in modules/users/tests/conftest.py disables env_file and scrubs leaked SM_USERS_* vars for every test.

Test plan

  • make test — 558 Python + 8 JS tests pass, zero warnings (was 9 warnings before).
  • uv run ty check framework/core/simple_module_core/diagnostics framework/hosting/simple_module_hosting — clean.
  • uv run ruff format --check + uv run ruff check — clean.
  • npx tsc --noEmit -p host/client_app/tsconfig.json — clean.
  • npm run build — production bundle succeeds; every module page chunk emitted via native resolve.tsconfigPaths.
  • Dev boot (make dev) — no SM004/SM007/SM012/orphan warnings, and no Vite vite-tsconfig-paths / plugin-react-swc suggestions.
  • Browser smoke at /users/login — CSP header now allows http://localhost:5050 + ws://localhost:5050; dev_accounts renders two quick-login buttons (Admin / User) in dev.

…users/login

Clears every spurious boot warning, unblocks the Vite dev server under CSP,
wires the dev-account quick-login buttons the .env.example promises, and
deletes the last pytest/Vite deprecation warnings.

- SM004: _check_phantom_renders now recurses into page subdirs (was missing
  nested pages like Users/Users/Index.tsx) and skips lowercase helper dirs.
- SM012: snapshot app.state._state instead of vars(app.state), which only
  ever contained '{'_state'}' and always reported an empty diff.
- SM007: treat locale_dirs/static_mounts/template_dirs/on_startup/on_shutdown
  as legitimate overrides so shared-contract modules (Auth) don't warn.
- CSP: SecurityHeadersMiddleware.dev_csp() whitelists the Vite origin +
  ws:// for HMR; install_middleware wires it when settings.is_development.
- Login: pass bootstrap admin/user creds as dev_accounts prop in dev, and
  render "Dev quick-login" buttons under the sign-in form.
- Vite: swap vite-tsconfig-paths → resolve.tsconfigPaths: true, and
  @vitejs/plugin-react-swc → @vitejs/plugin-react (SWC plugin warning).
- uv: [tool.uv] dev-dependencies → [dependency-groups] dev.
- Tests: stop pydantic-settings from leaking the repo's .env into users
  fixtures; move TestClient/httpx per-request cookies onto the client;
  bump JWT test secrets to ≥32 bytes; vitest 3 → 4 (esbuild→oxc warning).
@antosubash antosubash changed the title fix: silence framework diagnostics/CSP + surface dev quick-login on /… fix: framework diagnostics + dev CSP + login quick-login + test warnings Apr 16, 2026
- conftest: reorder the autouse fixture after the module imports, and
  delete unused hash_password/create_verified_user/create_unverified_user
  helpers that were dead code (nothing in the test suite imports them).
  Keeps the file under the 300-line cap after the env-isolation fixture.
- Login.tsx: biome formatting tweak on the dev-quick-login <p>.
@antosubash
antosubash merged commit 83941d2 into main Apr 16, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant