mirror of
https://github.com/CopilotKit/CopilotKit.git
synced 2026-09-14 16:26:20 +08:00
09b9f8910b
Non-functional cleanup pass on the showcase deploy-pipeline integration branch. All changes are scoped to comment rot, log severity for already- demoted runtime-config fields, length-aware env-name coalescing (a deliberately-empty primary no longer masks a populated alternate), and test-quality tightening. No production behavior change beyond the specific items below. Changes by area: - shell/shell-dashboard/shell-docs runtime-config.ts: factor the `process.env[primary] ?? process.env[alt]` chain into a shared length-aware `readEnvPair` helper. The prior `??` form treated `PRIMARY=""` as set, masking a populated alternate; the helper now treats empty-string as unset and falls through to the alternate. - shell-docs runtime-config.ts: demote the two recoverable URL fields (`intelligenceSignupUrl`, `posthogHost`) from console.info to console.warn. The `FATAL-CONFIG:` Sentry-alert prefix is preserved only on the true sentinels; the demoted fields now clear prod log- aggregation thresholds without raising ops alerts. - All three shells' runtime-config.ts: prefix log lines with the shell name (e.g. `[shell-docs runtime-config]`) so the shared log stream identifies which shell emitted the line. - shell-docs runtime-config-serialize.ts: rewrite the U+2028 / U+2029 RegExp arguments using six-character ASCII backslash-u escape sequences (was: literal codepoints in the string arg). The literal codepoints are line terminators that a formatter or editor could silently strip, breaking the security-critical XSS escape. The ASCII form is robust to any such pass. - shell-docs use-google-analytics.test.ts: de-tautologize the hook- order test. It now asserts `usePathname(` and `useEffect(` both exist in the source, so deleting all hooks would fail the test rather than trivially satisfying the early-return path. - shell-dashboard baseline-types.test.ts: update the partner-count expectation from 25 to 26 -- the 26th entry (Cloudflare) is a legitimate integration that landed independently; the test was stale and had nothing to do with this branch. - scripts/resolve-verify-matrix.ts: drop the `FIX 7 --` plan- internal prefix from a comment; keep the explanation. - shell-docs/.env.example: correct the `NEXT_PUBLIC_SHELL_URL` fallback claim (sentinel, not canonical prod host) and document the remaining 7 consumed env vars with their FATAL/warn/silent semantics so the example matches runtime-config.ts. Skipped: - C-SENTINEL-DEDUP (`http://ops.invalid` shared constant across shell-dashboard's next.config.ts and runtime-config.ts): both files are at different module levels (root vs src/lib) and the string appears once in each; extracting to a shared module would widen the diff into a refactor for marginal benefit. Skipped per the spec's "if it widens diff awkwardly, skip" guidance. - C-SSRTEST: already exhaustively covered. Each of the three shells has an SSR placeholder test that exercises every URL field via `new URL()` parseability and (for shell-docs) the analytics-key empty-string semantics. Treated as a no-op. Validation: shell + shell-dashboard + shell-docs runtime-config / serialize / GA tests green; bin/showcase Ruby suite green (87 runs); showcase/scripts resolve-verify-matrix + aggregate-build-results + lint-rule-no-public-env green (79 runs).