Skip to content

fix: 시드 username 검증을 생성 정책과 맞춤 - #528

Merged
chanwoo7 merged 1 commit into
developfrom
fix/release-review-seed-username
Oct 8, 2026
Merged

chanwoo7 merged 1 commit into
developfrom
fix/release-review-seed-username

Conversation

@chanwoo7

@chanwoo7 chanwoo7 commented Oct 8, 2026

Copy link
Copy Markdown
Member

요약

  • 릴리즈 #527의 Codex 리뷰를 반영합니다.
  • #526에서 계정 생성 username 정책에 영문 대문자를 허용했지만, prisma/seed/credential-policy.ts는 소문자 전용 정규식 사본을 따로 들고 있었습니다.
    • 그래서 ADMIN_SEED_USERNAME=Ops.Admin처럼 생성 경로에서는 통과하는 값이 시드에서는 거절됩니다.
  • 시드 검증이 USERNAME_PATTERN과 MIN/MAX_USERNAME_LENGTH를 직접 쓰도록 바꿔 사본을 없앴습니다.
    • 위반 메시지는 "영문 대소문자"로 고쳤고, 값은 이전처럼 메시지에 싣지 않습니다.

테스트

  • src/test/seed-credential-policy.spec.ts를 추가했습니다.
    • username 10건(소문자·대문자 혼용·전부 대문자·4자·80자·3자·81자·공백·@·한글)에 대해 시드 검증과 AdminCreateAdminInput이 같은 판정을 내리는지 표로 확인합니다.
    • 위반 메시지에 값이 실리지 않는지, password 위반은 별도 메시지로 거절하는지 각 1건 확인합니다.
  • 반증: 수정 전 시드 정책으로 되돌리면 대문자 케이스 2건이 실패합니다.

플랜 대조

대상 상태
릴리즈 리뷰 지적(시드 username 검증 동기화) 한 것
플랜 01의 "대문자 허용" 범위 안의 누락분 보완 한 것: 플랜에 없던 파일이지만 같은 정책의 사본이라 함께 맞췄습니다.

릴리즈 #527 Codex 리뷰 반영. #526에서 생성 정책에 대문자를 허용했는데 prisma/seed/credential-policy.ts는 소문자 전용 정규식을 따로 들고 있어 ADMIN_SEED_USERNAME=Ops.Admin 같은 값이 시드에서 거절됨.

- 시드 검증이 USERNAME_PATTERN·MIN/MAX_USERNAME_LENGTH를 직접 쓰도록 변경(정책 사본 제거)
- 위반 메시지: 소문자 → 영문 대소문자, 값은 계속 싣지 않음

테스트
- src/test/seed-credential-policy.spec.ts: username 10건을 시드 검증과 AdminCreateAdminInput이 같은 판정을 내리는지 표로 확인, 메시지에 값 미포함·password 위반 메시지 각 1건
- 반증: 수정 전 시드 정책으로 되돌리면 대문자 케이스 2건 실패
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: CaQuick/caquick-be/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 99faa969-42ed-4447-a00f-094afb6aeadb

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T01:34:32.090130Z fbac569 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

🩺 NestJS Doctor — 90/100 (Excellent)

진단 484건 (error 12).

Category error warning info
architecture 1 1 44
correctness 0 266 0
performance 0 36 28
schema 0 0 76
security 11 21 0
architecture / security 상위 항목
  • error architecture/architecture/no-manual-instantiation: Manual instantiation of 'OutboxRepository' detected. Use dependency injection instead.
  • info architecture/architecture/no-barrel-export-internals: Barrel file re-exports internal type 'IAuditLogRepository'.
  • warning security/security/no-exposed-env-vars: Direct 'process.env.NODE_ENV' access in 'AuthController'. Use ConfigService instead.
  • warning security/security/require-guards-on-endpoints: Endpoint 'start' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'callback' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'refresh' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'logout' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'sellerLogin' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'sellerRefresh' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'sellerLogout' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'devIssueToken' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'adminLogin' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'adminRefresh' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'adminLogout' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'getJwks' has no @UseGuards() at class or method level.

오탐 포함 가능 · 기준 docs/guide/architecture-conventions.md

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

🧹 knip — dead-code 리포트

Unused exported types (1)
전체 리포트
Unused exported types (1)
RateLimitPolicy  type  src/global/rate-limit/index.ts:4:8

청소 후보(오탐 가능) · 기준 docs/guide/architecture-conventions.md

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Coverage report

St.❔
Category Percentage Covered / Total
🟢 Statements 98% 10692/10910
🟢 Branches 92.92% 4070/4380
🟢 Functions 97.53% 2133/2187
🟢 Lines 98.57% 9728/9869

Test suite run success

4262 tests passing in 384 suites.

Report generated by 🧪jest coverage report action from fbac569

@chanwoo7
chanwoo7 merged commit 8e20ef8 into develop Oct 8, 2026
17 checks passed
@chanwoo7
chanwoo7 deleted the fix/release-review-seed-username branch October 8, 2026 01:37
@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant