fix(housekeeping): complete people read fidelity
CI / check (pull_request) Successful in 31s
CI / deploy (pull_request) Skipped
CI / release (pull_request) Skipped

This commit is contained in:
Simo committed 2026-08-29 10:34:44 +02:00
1 parent d1382c839e
commit 7920d4f46c
8 files changed
+564 -37

No files matched your search

@@ -1,6 +1,6 @@
# Task 11 — People workflow read models
Status: DONE — fix round 1
Status: DONE — fix round 2
## Delivered scope
@@ -15,12 +15,12 @@ Status: DONE — fix round 1
- User mail and current IP remain independently nullable fields. Each is projected only when the capability context contains the existing `PERMS.USERS_VIEW`; `PERMS.MOD_USERS_VIEW` alone receives the safe base projection with both values set to `null`, and a context with neither permission is forbidden.
- No new ACL slug or rank threshold was introduced. Staff filtering reuses the existing `getMinStaffRank()` source.
- The production user selection is explicit and excludes passwords, authentication tickets, secrets, and two-factor material. VPN settings intentionally exclude `vpn_api_key`.
- Adapters fail closed. Malformed driver envelopes, invalid or non-positive identifiers, corrupt links, non-serializable DTO values, and count failures map to `DEPENDENCY_UNAVAILABLE`. Missing valid detail entities map to `NOT_FOUND`; invalid request identifiers map to `VALIDATION`. No partial-result shape is returned because no People DTO explicitly names failed sources.
- Adapters fail closed. Malformed driver envelopes, invalid identifiers, corrupt links, non-serializable DTO values, and count failures map to `DEPENDENCY_UNAVAILABLE`. Primary/entity identifiers remain positive safe integers; zero is accepted only for the schema-declared guild `userId`/`roomId` and CFH `senderId`/`reportedId`/`roomId`/`moderatorId` sentinels. Missing valid detail entities map to `NOT_FOUND`; invalid request identifiers map to `VALIDATION`.
- Pagination clamps page size to 100 and offset to 10,000. Deterministic primary sorting, numeric-ID tie breaking, and `LIMIT`/`OFFSET` now execute in the database; no list query fetches a prefix for locale re-sorting or second slicing.
- Raw production adapters and `buildPeopleUserSelection` are module-private. Runtime exports expose only context-authorized query factories and singleton query surfaces.
- Multi-account clusters use one bounded CTE/window query, cap accounts per cluster at 100, and never issue one query per IP cluster.
- Multi-account clusters use one bounded CTE/window page query plus one independent matching-cluster count query, cap accounts per cluster at 100, and never issue one query per IP cluster.
- User detail/edit now includes the operator's watched state and canonical permission-rank data. Support ticket reads use the existing unified inbox through a strict, fail-closed, database-paged mode that includes CMS and help-center rows while leaving the legacy tolerant mode unchanged.
- Support desk/detail DTOs explicitly include queue counts, bounded staff, and the relevant active ban. Ticket messages/replies and staff rows are bounded.
- The unified `/support/tickets` inbox still merges CMS and help-center rows. The ticket desk now has its own strict CMS-only page loader preserving priority, category, assignee, and message count; help summaries include reply count. Support desk/detail DTOs explicitly include queue counts, bounded staff, and the relevant active ban.
- Active bans are filtered before sorting. Expiry `0` remains the permanent-active sentinel; expired rows cannot hide permanent or future-active bans in lists or details.
## Official fix round 1 findings
@@ -35,6 +35,12 @@ Status: DONE — fix round 1
The two official Minor findings remain parked and unchanged as instructed.
## Official fix round 2 findings
1. **Entity-aware sentinels:** canonical guild DTOs now use the real schema names `userId` and `roomId`. Serialization permits zero only on those two guild fields and the four named CFH fields when the containing DTO has the matching canonical entity href. Generic `*Id` zero values, negatives, unsafe integers, and primary ID zero remain unavailable failures.
2. **Support source fidelity:** `people.support.tickets` remains on strict `fetchUnifiedTicketInbox`. `people.support.ticket-desk` now dispatches to a distinct strict `website_tickets` loader with message aggregation and no help-center source. Real priority/category/assignee/message count and help reply count are present in canonical DTOs; malformed driver rows fail closed.
3. **Multi-account total:** the page CTE and matching-cluster count run as two bounded parallel queries. Empty pages retain the correct total without prefix loading or N+1 queries.
## Strict TDD evidence
### Cycle 1 — exact route catalog
@@ -253,27 +259,86 @@ Test Files 1 passed (1)
Tests 1 passed | 4 skipped (5)
```
## Fix round 2 strict behavioral TDD evidence
### Entity-aware schema sentinels
RED:
```text
pnpm exec vitest run --coverage.enabled=false src/features/housekeeping/domains/people/queries/people-queries.test.ts -t "zero sentinels"
Test Files 1 failed (1)
Tests 2 failed | 19 skipped (21)
Valid guild userId/roomId zero and CFH senderId/reportedId/moderatorId/roomId zero were rejected by generic identifier validation.
```
GREEN:
```text
same command
Test Files 1 passed (1)
Tests 2 passed | 19 skipped (21)
```
### CMS-only ticket desk and help reply counts
RED:
```text
pnpm exec vitest run --coverage.enabled=false src/features/housekeeping/domains/people/queries/people-queries.test.ts src/features/housekeeping/domains/people/queries/people-adapters-production.test.ts -t "CMS-only context loader|reply counts"
Test Files 2 failed (2)
Tests 2 failed | 28 skipped (30)
The desk received a help row with synthetic normal priority; help summary omitted replyCount.
```
GREEN:
```text
same command
Test Files 2 passed (2)
Tests 2 passed | 28 skipped (30)
```
### Independent multi-account total
RED:
```text
pnpm exec vitest run --coverage.enabled=false src/features/housekeeping/domains/people/queries/people-adapters-production.test.ts -t "beyond the last page"
Test Files 1 failed (1)
Tests 1 failed | 8 skipped (9)
Expected total 4 on the empty page; received 0.
```
GREEN:
```text
same command
Test Files 1 passed (1)
Tests 1 passed | 8 skipped (9)
```
## Verification
```text
pnpm exec vitest run --coverage.enabled=false src/features/housekeeping/domains/people/routes.test.ts src/features/housekeeping/domains/people/models.test.ts src/features/housekeeping/domains/people/queries/people-queries.test.ts src/features/housekeeping/domains/people/queries/people-adapters-production.test.ts
Test Files 4 passed (4)
Tests 35 passed (35)
Tests 40 passed (40)
pnpm exec vitest run --coverage.enabled=false src/features/housekeeping/domains/people src/features/housekeeping/foundation/foundation-source-contract.test.ts src/features/housekeeping/foundation/authorization.test.ts src/features/housekeeping/foundation/capability-context.test.ts src/features/housekeeping/foundation/server-capability-context.test.ts src/features/housekeeping/foundation/contracts/contracts.test.ts
Test Files 9 passed (9)
Tests 81 passed (81)
Tests 86 passed (86)
pnpm test:housekeeping
Test Files 49 passed (49)
Tests 430 passed (430)
Tests 435 passed (435)
pnpm typecheck
tsc --noEmit
Exit 0
pnpm exec biome check --formatter-enabled=false <11 exact changed Task 11 TypeScript files>
Checked 11 files. No fixes applied.
pnpm exec biome check --formatter-enabled=false <7 exact changed Task 11 TypeScript files>
Checked 7 files. No fixes applied.
git diff --check
Exit 0
@@ -1,5 +1,6 @@
import { describe, expect, it } from "vitest";
import {
assertPeopleSerializable,
createPeoplePage,
normalizePeopleListInput,
normalizePeopleUser,
@@ -171,5 +172,12 @@ describe("People canonical models", () => {
expect(() => peopleUserHref(Number.MAX_SAFE_INTEGER + 1)).toThrow();
expect(() => peopleGuildHref(-4)).toThrow();
expect(() => toPeopleIsoDate("not-a-date")).toThrow();
expect(() =>
assertPeopleSerializable({
id: 7,
userId: 0,
href: "/ase/people/users/7",
}),
).toThrow();
});
});
@@ -92,15 +92,15 @@ export interface PeopleGuildSummary {
readonly id: number;
readonly name: string;
readonly description: string;
readonly ownerId: number;
readonly userId: number;
readonly ownerUsername: string | null;
readonly roomId: number;
readonly memberCount: number;
readonly createdAt: string | null;
readonly href: `/ase/people/community/guilds/${number}`;
}
export interface PeopleGuildDetail extends PeopleGuildSummary {
readonly roomId: number;
readonly threadCount: number;
readonly members: readonly {
readonly id: number;
@@ -166,6 +166,13 @@ export interface PeopleTicketSummary {
| `/ase/people/support/help-tickets/${number}`;
}
export interface PeopleTicketDeskSummary extends PeopleTicketSummary {
readonly source: "cms";
readonly category: string;
readonly assigneeId: number | null;
readonly messageCount: number;
}
export interface PeopleTicketDetail extends PeopleTicketSummary {
readonly category: string;
readonly assigneeId: number | null;
@@ -188,6 +195,7 @@ export interface PeopleHelpTicketSummary {
readonly userId: number | null;
readonly username: string | null;
readonly updatedAt: string | null;
readonly replyCount: number;
readonly href: `/ase/people/support/help-tickets/${number}`;
}
@@ -462,7 +470,25 @@ const DATE_KEYS = new Set([
]);
export function assertPeopleSerializable(value: unknown): void {
function visit(current: unknown, key = ""): void {
function permitsZeroSentinel(parent: unknown, key: string): boolean {
if (typeof parent !== "object" || parent === null) return false;
const href = Reflect.get(parent, "href");
if (typeof href !== "string") return false;
if (href.startsWith("/ase/people/community/guilds/")) {
return key === "userId" || key === "roomId";
}
if (href.startsWith("/ase/people/moderation/cfh/")) {
return (
key === "senderId" ||
key === "reportedId" ||
key === "roomId" ||
key === "moderatorId"
);
}
return false;
}
function visit(current: unknown, key = "", parent?: unknown): void {
if (
current === null ||
typeof current === "string" ||
@@ -480,13 +506,17 @@ export function assertPeopleSerializable(value: unknown): void {
if (typeof current === "number") {
if (!Number.isSafeInteger(current))
throw new Error("invalid People number");
if ((key === "id" || key.endsWith("Id")) && current <= 0) {
if (
(key === "id" || key.endsWith("Id")) &&
current <= 0 &&
!(current === 0 && permitsZeroSentinel(parent, key))
) {
throw new Error("invalid People identifier");
}
return;
}
if (Array.isArray(current)) {
for (const item of current) visit(item);
for (const item of current) visit(item, "", current);
return;
}
if (typeof current !== "object" || current instanceof Date) {
@@ -494,7 +524,7 @@ export function assertPeopleSerializable(value: unknown): void {
}
for (const [childKey, child] of Object.entries(current)) {
if (child === undefined) throw new Error("undefined People value");
visit(child, childKey);
visit(child, childKey, current);
}
}
visit(value);
@@ -183,14 +183,16 @@ const peopleCommunityAdapters: PeopleCommunityAdapters = {
: sql``;
const [rowsResult, countResult] = await Promise.all([
db.execute(sql`
SELECT g.id, g.name, g.description, g.user_id AS ownerId,
u.username AS ownerUsername, g.date_created AS createdAt,
SELECT g.id, g.name, g.description, g.user_id AS userId,
u.username AS ownerUsername, g.room_id AS roomId,
g.date_created AS createdAt,
COUNT(gm.id) AS memberCount
FROM guilds g
LEFT JOIN users u ON u.id = g.user_id
LEFT JOIN guilds_members gm ON gm.guild_id = g.id
${where}
GROUP BY g.id, g.name, g.description, g.user_id, u.username, g.date_created
GROUP BY g.id, g.name, g.description, g.user_id, u.username,
g.room_id, g.date_created
ORDER BY ${input.sort === "name" ? sql`g.name` : sql`g.id`} ${
input.order === "desc" ? sql`DESC` : sql`ASC`
}, g.id ASC
@@ -206,16 +208,18 @@ const peopleCommunityAdapters: PeopleCommunityAdapters = {
id: number;
name: string;
description: string;
ownerId: number;
userId: number;
ownerUsername: string | null;
roomId: number;
memberCount: number;
createdAt: number;
}>(rowsResult).map((row) => ({
id: Number(row.id),
name: row.name,
description: row.description,
ownerId: Number(row.ownerId),
userId: Number(row.userId),
ownerUsername: row.ownerUsername,
roomId: Number(row.roomId),
memberCount: Number(row.memberCount),
createdAt: toPeopleIsoDate(row.createdAt),
href: peopleGuildHref(Number(row.id)),
@@ -232,7 +236,7 @@ const peopleCommunityAdapters: PeopleCommunityAdapters = {
]);
const [guildResult, membersResult, threadsResult] = await Promise.all([
db.execute(sql`
SELECT g.id, g.name, g.description, g.user_id AS ownerId,
SELECT g.id, g.name, g.description, g.user_id AS userId,
u.username AS ownerUsername, g.room_id AS roomId,
g.date_created AS createdAt, COUNT(gm.id) AS memberCount
FROM guilds g
@@ -257,7 +261,7 @@ const peopleCommunityAdapters: PeopleCommunityAdapters = {
id: number;
name: string;
description: string;
ownerId: number;
userId: number;
ownerUsername: string | null;
roomId: number;
createdAt: number;
@@ -268,7 +272,7 @@ const peopleCommunityAdapters: PeopleCommunityAdapters = {
id: Number(row.id),
name: row.name,
description: row.description,
ownerId: Number(row.ownerId),
userId: Number(row.userId),
ownerUsername: row.ownerUsername,
memberCount: Number(row.memberCount),
createdAt: toPeopleIsoDate(row.createdAt),
@@ -52,6 +52,17 @@ describe("People production authorization boundary", () => {
expect(inboxSource).toContain("UNION ALL");
expect(inboxSource).toMatch(/LIMIT \$\{perPage\} OFFSET \$\{offset\}/);
expect(inboxSource).toContain(".catch(() => [])");
const deskStart = supportSource.indexOf("async loadTicketDesk");
const deskEnd = supportSource.indexOf("async loadTicket(", deskStart);
const deskSource = supportSource.slice(deskStart, deskEnd);
expect(deskStart).toBeGreaterThan(0);
expect(deskSource).toContain("FROM website_tickets t");
expect(deskSource).toContain("COUNT(m.id) AS messageCount");
expect(deskSource).toContain("t.category");
expect(deskSource).toContain("t.priority");
expect(deskSource).toContain("t.assignee_id AS assigneeId");
expect(deskSource).not.toContain("website_help_center_tickets");
expect(supportSource).toContain("COUNT(r.id) AS replyCount");
});
it("pages multi-account groups and loads their accounts in one bounded batch", async () => {
@@ -162,6 +173,45 @@ describe("People production authorization boundary", () => {
).not.toContain("WHERE ip_current = ?");
});
it("returns the independent multi-account total beyond the last page", async () => {
vi.resetModules();
const sql = (strings: TemplateStringsArray, ...values: unknown[]) => ({
strings: [...strings],
values,
});
const execute = vi.fn(async (query: { strings: readonly string[] }) => {
const text = query.strings.join("?");
if (text.includes("SELECT COUNT(*) AS total FROM (")) {
return [[{ total: 4 }]];
}
if (text.includes("ROW_NUMBER() OVER")) return [[]];
return { malformed: true };
});
vi.doMock("drizzle-orm", () => ({ sql }));
vi.doMock("@/lib/db", () => ({ db: { execute } }));
const permissions = new Set<string>([PERMS.USERS_VIEW]);
const capability: HousekeepingCapabilityContext = {
actor: { id: 42, username: "operator", rank: 99 },
isSuperAdmin: false,
has: (slug) => permissions.has(slug),
hasAny: (...slugs) => slugs.some((slug) => permissions.has(slug)),
hasAll: (...slugs) => slugs.every((slug) => permissions.has(slug)),
};
const { peopleUsersQuery } = await import("./users");
const result = await peopleUsersQuery.run(capability, {
routeId: "people.users.multi-accounts",
list: { offset: 100, pageSize: 20 },
});
expect(result).toMatchObject({
ok: true,
data: { page: { items: [], total: 4, offset: 100 } },
});
expect(execute).toHaveBeenCalledTimes(2);
expect(
execute.mock.calls.map(([query]) => query.strings.join("?")).join("\n"),
).not.toContain("WHERE ip_current = ?");
});
it("maps a malformed driver result to dependency unavailable", async () => {
vi.resetModules();
const sql = (strings: TemplateStringsArray, ...values: unknown[]) => ({
@@ -334,4 +384,65 @@ describe("People production authorization boundary", () => {
},
});
});
it("populates help-ticket reply counts and fails closed on malformed rows", async () => {
vi.resetModules();
const sql = (strings: TemplateStringsArray, ...values: unknown[]) => ({
strings: [...strings],
values,
});
const execute = vi.fn(async (query: { strings: readonly string[] }) => {
const text = query.strings.join("?");
if (text.includes("COUNT(*) AS total FROM website_help_center_tickets")) {
return [[{ total: 1 }]];
}
return [
[
{
id: 12,
title: "Help ticket",
open: 1,
userId: 7,
username: "Seven",
updatedAt: "2026-08-20T00:00:00.000Z",
replyCount: 3,
},
],
];
});
vi.doMock("drizzle-orm", () => ({ sql }));
vi.doMock("@/lib/db", () => ({ db: { execute } }));
const permissions = new Set<string>([PERMS.TICKETS_VIEW]);
const capability: HousekeepingCapabilityContext = {
actor: { id: 42, username: "operator", rank: 99 },
isSuperAdmin: false,
has: (slug) => permissions.has(slug),
hasAny: (...slugs) => slugs.some((slug) => permissions.has(slug)),
hasAll: (...slugs) => slugs.every((slug) => permissions.has(slug)),
};
const { peopleSupportQuery } = await import("./support");
const result = await peopleSupportQuery.run(capability, {
routeId: "people.support.help-tickets",
list: {},
});
expect(result).toMatchObject({
ok: true,
data: { page: { items: [{ id: 12, replyCount: 3 }] } },
});
vi.resetModules();
vi.doMock("drizzle-orm", () => ({ sql }));
vi.doMock("@/lib/db", () => ({
db: { execute: vi.fn(async () => ({ malformed: true })) },
}));
const { peopleSupportQuery: malformedQuery } = await import("./support");
const malformed = await malformedQuery.run(capability, {
routeId: "people.support.help-tickets",
list: {},
});
expect(malformed).toMatchObject({
ok: false,
error: { code: "DEPENDENCY_UNAVAILABLE" },
});
});
});
@@ -283,6 +283,52 @@ describe("People users query", () => {
});
describe("People community and staff queries", () => {
it("accepts only the guild user and room zero sentinels", async () => {
const guild = {
id: 12,
name: "Unassigned guild",
description: "",
userId: 0,
ownerUsername: null,
roomId: 0,
memberCount: 0,
threadCount: 0,
createdAt: null,
href: "/ase/people/community/guilds/12" as const,
members: [],
};
const query = createPeopleCommunityQuery({
loadOnline: async () => ({ rows: [], total: 0 }),
loadGuilds: async () => ({ rows: [], total: 0 }),
loadGuild: async () => guild as never,
});
expect(
await query.run(context([PERMS.USERS_VIEW]), {
routeId: "people.community.guild-detail",
id: 12,
}),
).toMatchObject({
ok: true,
data: { guild: { id: 12, userId: 0, roomId: 0 } },
});
const invalidQuery = createPeopleCommunityQuery({
loadOnline: async () => ({ rows: [], total: 0 }),
loadGuilds: async () => ({ rows: [], total: 0 }),
loadGuild: async () => ({ ...guild, userId: -1 }) as never,
});
expect(
await invalidQuery.run(context([PERMS.USERS_VIEW]), {
routeId: "people.community.guild-detail",
id: 12,
}),
).toMatchObject({
ok: false,
error: { code: "DEPENDENCY_UNAVAILABLE" },
});
});
it("fails closed when a community adapter returns a corrupt entity id", async () => {
const query = createPeopleCommunityQuery({
loadOnline: async () => ({ rows: [], total: 0 }),
@@ -292,7 +338,7 @@ describe("People community and staff queries", () => {
id: 0,
name: "Corrupt",
description: "",
ownerId: -1,
userId: -1,
ownerUsername: null,
memberCount: 0,
createdAt: null,
@@ -320,8 +366,9 @@ describe("People community and staff queries", () => {
id: 2,
name: "Builders",
description: "Build",
ownerId: 4,
userId: 4,
ownerUsername: "Owner",
roomId: 7,
memberCount: 3,
createdAt: "2026-08-01T00:00:00.000Z",
href: "/ase/people/community/guilds/2" as const,
@@ -335,7 +382,7 @@ describe("People community and staff queries", () => {
id: 2,
name: "Builders",
description: "Build",
ownerId: 4,
userId: 4,
ownerUsername: "Owner",
memberCount: 3,
createdAt: "2026-08-01T00:00:00.000Z",
@@ -421,6 +468,103 @@ describe("People community and staff queries", () => {
});
describe("People support query", () => {
it("routes the ticket desk to its CMS-only context loader", async () => {
const loadTickets = vi.fn(async () => ({
rows: [
{
source: "help" as const,
id: 12,
subject: "Help row",
status: "open",
priority: "normal",
creatorId: 7,
creatorUsername: "Seven",
updatedAt: null,
href: "/ase/people/support/help-tickets/12" as const,
},
],
total: 1,
}));
const loadTicketDesk = vi.fn(async () => ({
rows: [
{
source: "cms" as const,
id: 91,
subject: "Urgent CMS ticket",
status: "open",
priority: "urgent",
creatorId: 7,
creatorUsername: "Seven",
updatedAt: null,
href: "/ase/people/support/tickets/91" as const,
category: "safety",
assigneeId: 8,
messageCount: 4,
},
{
source: "cms" as const,
id: 92,
subject: "High-priority CMS ticket",
status: "open",
priority: "high",
creatorId: 9,
creatorUsername: "Nine",
updatedAt: null,
href: "/ase/people/support/tickets/92" as const,
category: "account",
assigneeId: null,
messageCount: 2,
},
],
total: 2,
}));
const query = createPeopleSupportQuery({
loadQueue: async () => ({
tickets: 1,
helpTickets: 1,
cfh: 0,
activeBans: 0,
}),
loadTickets,
loadTicketDesk,
loadTicket: async () => null,
loadTemplates: async () => ({ rows: [], total: 0 }),
loadHelpTickets: async () => ({ rows: [], total: 0 }),
loadHelpTicket: async () => null,
loadSupportStaff: async () => [],
loadActiveBan: async () => null,
} as never);
const result = await query.run(context([PERMS.TICKETS_VIEW]), {
routeId: "people.support.ticket-desk",
list: {},
});
expect(result).toMatchObject({
ok: true,
data: {
page: {
items: [
{
id: 91,
priority: "urgent",
category: "safety",
assigneeId: 8,
messageCount: 4,
},
{
id: 92,
priority: "high",
category: "account",
assigneeId: null,
messageCount: 2,
},
],
},
},
});
expect(loadTicketDesk).toHaveBeenCalledOnce();
expect(loadTickets).not.toHaveBeenCalled();
});
it("hydrates desk/detail support context and the help-ticket active ban", async () => {
const queue = { tickets: 2, helpTickets: 1, cfh: 3, activeBans: 4 };
const staff = [
@@ -446,6 +590,7 @@ describe("People support query", () => {
const query = createPeopleSupportQuery({
loadQueue: async () => queue,
loadTickets: async () => ({ rows: [], total: 0 }),
loadTicketDesk: async () => ({ rows: [], total: 0 }),
loadTicket: async () => ({
id: 11,
subject: "CMS ticket",
@@ -454,6 +599,7 @@ describe("People support query", () => {
creatorId: 7,
creatorUsername: "Seven",
updatedAt: "2026-08-20T00:00:00.000Z",
replyCount: 0,
href: "/ase/people/support/tickets/11",
category: "general",
assigneeId: null,
@@ -513,6 +659,7 @@ describe("People support query", () => {
activeBans: 0,
}),
loadTickets: async () => ({ rows: [], total: 0 }),
loadTicketDesk: async () => ({ rows: [], total: 0 }),
loadTicket: async () =>
({ id: 0, href: "/ase/people/support/tickets/0" }) as never,
loadTemplates: async () => ({ rows: [], total: 0 }),
@@ -556,6 +703,15 @@ describe("People support query", () => {
activeBans: 0,
}),
loadTickets: async () => ({ rows, total: 40 }),
loadTicketDesk: async () => ({
rows: rows.map((row) => ({
...row,
category: "general",
assigneeId: null,
messageCount: 0,
})),
total: 40,
}),
loadTicket: async () => null,
loadTemplates: async () => ({ rows: [], total: 0 }),
loadHelpTickets: async () => ({ rows: [], total: 0 }),
@@ -589,6 +745,7 @@ describe("People support query", () => {
const query = createPeopleSupportQuery({
loadQueue,
loadTickets: async () => ({ rows: [], total: 0 }),
loadTicketDesk: async () => ({ rows: [], total: 0 }),
loadTicket: async () => null,
loadTemplates: async () => ({ rows: [], total: 0 }),
loadHelpTickets: async () => ({ rows: [], total: 0 }),
@@ -627,6 +784,7 @@ describe("People support query", () => {
activeBans: 0,
}),
loadTickets: async () => ({ rows: [], total: 0 }),
loadTicketDesk: async () => ({ rows: [], total: 0 }),
loadTicket: async () => null,
loadTemplates: async () => ({ rows: [], total: 0 }),
loadHelpTickets: async () => ({ rows: [], total: 0 }),
@@ -665,6 +823,71 @@ describe("People support query", () => {
});
describe("People moderation query", () => {
it("accepts only the CFH participant and room zero sentinels", async () => {
const ticket = {
id: 41,
state: 0,
senderId: 0,
senderUsername: null,
reportedId: 0,
reportedUsername: null,
moderatorId: 0,
issue: "unassigned",
createdAt: null,
href: "/ase/people/moderation/cfh/41" as const,
roomId: 0,
activeBan: null,
};
const adapters = {
loadOverview: async () => ({
tickets: 0,
helpTickets: 0,
cfh: 0,
activeBans: 0,
staffOnline: 0,
recentActions: 0,
}),
loadCfh: async () => ({ rows: [], total: 0 }),
loadCfhDetail: async () => ticket,
loadBans: async () => ({ rows: [], total: 0 }),
loadIpRules: async () => ({ blacklist: [], whitelist: [] }),
loadVpnSettings: async () => [],
loadWordFilter: async () => ({ rows: [], total: 0 }),
};
const query = createPeopleModerationQuery(adapters);
expect(
await query.run(context([PERMS.MOD_CFH_VIEW]), {
routeId: "people.moderation.cfh-detail",
id: 41,
}),
).toMatchObject({
ok: true,
data: {
ticket: {
id: 41,
senderId: 0,
reportedId: 0,
moderatorId: 0,
roomId: 0,
},
},
});
const invalidQuery = createPeopleModerationQuery({
...adapters,
loadCfhDetail: async () => ({ ...ticket, reportedId: -1 }),
});
expect(
await invalidQuery.run(context([PERMS.MOD_CFH_VIEW]), {
routeId: "people.moderation.cfh-detail",
id: 41,
}),
).toMatchObject({
ok: false,
error: { code: "DEPENDENCY_UNAVAILABLE" },
});
});
it("declares exactly the same eleven-permission union as the moderation overview route", () => {
const query = createPeopleModerationQuery({
loadOverview: async () => ({
@@ -19,6 +19,7 @@ import {
type PeopleHelpTicketSummary,
type PeopleQueueSnapshot,
type PeopleSupportStaff,
type PeopleTicketDeskSummary,
type PeopleTicketDetail,
type PeopleTicketSummary,
type PeopleTicketTemplate,
@@ -43,6 +44,9 @@ export interface PeopleSupportAdapters {
loadTickets(
input: ReturnType<typeof normalizePeopleListInput>,
): Promise<SupportRows<PeopleTicketSummary>>;
loadTicketDesk(
input: ReturnType<typeof normalizePeopleListInput>,
): Promise<SupportRows<PeopleTicketDeskSummary>>;
loadTicket(id: number): Promise<PeopleTicketRecord | null>;
loadTemplates(
input: ReturnType<typeof normalizePeopleListInput>,
@@ -78,7 +82,7 @@ export type PeopleSupportQueryData =
| { readonly kind: "tickets"; readonly page: Page<PeopleTicketSummary> }
| {
readonly kind: "ticket-desk";
readonly page: Page<PeopleTicketSummary>;
readonly page: Page<PeopleTicketDeskSummary>;
readonly queue: PeopleQueueSnapshot;
readonly staff: readonly PeopleSupportStaff[];
}
@@ -222,7 +226,7 @@ export function createPeopleSupportQuery(
if (input.routeId === "people.support.ticket-desk") {
const [result, queue, staff] = await Promise.all([
adapters.loadTickets(list),
adapters.loadTicketDesk(list),
adapters.loadQueue(),
adapters.loadSupportStaff(),
]);
@@ -324,6 +328,69 @@ const peopleSupportAdapters: PeopleSupportAdapters = {
total: result.total,
};
},
async loadTicketDesk(input) {
const [{ sql }, { db }] = await Promise.all([
import("drizzle-orm"),
import("@/lib/db"),
]);
const pattern = `%${input.search}%`;
const where = input.search
? sql`WHERE t.subject LIKE ${pattern} OR t.status LIKE ${pattern}
OR t.category LIKE ${pattern} OR creator.username LIKE ${pattern}`
: sql``;
const [rowsResult, countResult] = await Promise.all([
db.execute(sql`
SELECT t.id, t.subject, t.category, t.priority, t.status,
t.creator_id AS creatorId, creator.username AS creatorUsername,
t.assignee_id AS assigneeId, t.updated_at AS updatedAt,
COUNT(m.id) AS messageCount
FROM website_tickets t
LEFT JOIN users creator ON creator.id = t.creator_id
LEFT JOIN website_ticket_messages m ON m.ticket_id = t.id
${where}
GROUP BY t.id, t.subject, t.category, t.priority, t.status,
t.creator_id, creator.username, t.assignee_id, t.updated_at
ORDER BY ${input.sort === "subject" ? sql`t.subject` : input.sort === "status" ? sql`t.status` : input.sort === "updatedAt" ? sql`t.updated_at` : sql`t.id`} ${
input.order === "asc" ? sql`ASC` : sql`DESC`
}, t.id ASC
LIMIT ${input.pageSize} OFFSET ${input.offset}
`),
db.execute(sql`
SELECT COUNT(*) AS total FROM website_tickets t
LEFT JOIN users creator ON creator.id = t.creator_id
${where}
`),
]);
const rows = resultRows<{
id: number;
subject: string;
category: string;
priority: string;
status: string;
creatorId: number;
creatorUsername: string | null;
assigneeId: number | null;
updatedAt: Date | string | null;
messageCount: number | bigint;
}>(rowsResult).map((row) => ({
source: "cms" as const,
id: Number(row.id),
subject: row.subject,
category: row.category,
priority: row.priority,
status: row.status,
creatorId: Number(row.creatorId),
creatorUsername: row.creatorUsername,
assigneeId: row.assigneeId === null ? null : Number(row.assigneeId),
updatedAt: toPeopleIsoDate(row.updatedAt),
messageCount: Number(row.messageCount),
href: peopleTicketHref(Number(row.id)),
}));
return {
rows,
total: Number(resultRows<{ total: number }>(countResult)[0]?.total ?? 0),
};
},
async loadTicket(id) {
const [{ sql }, { db }] = await Promise.all([
import("drizzle-orm"),
@@ -435,10 +502,12 @@ const peopleSupportAdapters: PeopleSupportAdapters = {
const [rowsResult, countResult] = await Promise.all([
db.execute(sql`
SELECT t.id, t.title, t.open, t.user_id AS userId, u.username,
t.updated_at AS updatedAt
t.updated_at AS updatedAt, COUNT(r.id) AS replyCount
FROM website_help_center_tickets t
LEFT JOIN users u ON u.id = t.user_id
LEFT JOIN website_help_center_ticket_replies r ON r.ticket_id = t.id
${where}
GROUP BY t.id, t.title, t.open, t.user_id, u.username, t.updated_at
ORDER BY ${input.sort === "title" ? sql`t.title` : input.sort === "updatedAt" ? sql`t.updated_at` : sql`t.id`} ${
input.order === "asc" ? sql`ASC` : sql`DESC`
}, t.id ASC
@@ -456,6 +525,7 @@ const peopleSupportAdapters: PeopleSupportAdapters = {
userId: number | null;
username: string | null;
updatedAt: Date | string | null;
replyCount: number | bigint;
}>(rowsResult).map((row) => ({
id: Number(row.id),
title: row.title,
@@ -463,6 +533,7 @@ const peopleSupportAdapters: PeopleSupportAdapters = {
userId: row.userId === null ? null : Number(row.userId),
username: row.username,
updatedAt: toPeopleIsoDate(row.updatedAt),
replyCount: Number(row.replyCount),
href: peopleHelpTicketHref(Number(row.id)),
}));
return {
@@ -517,6 +588,7 @@ const peopleSupportAdapters: PeopleSupportAdapters = {
categoryId: row.categoryId === null ? null : Number(row.categoryId),
categoryName: row.categoryName,
updatedAt: toPeopleIsoDate(row.updatedAt),
replyCount: resultRows<unknown>(repliesResult).length,
href: peopleHelpTicketHref(Number(row.id)),
replies: resultRows<{
id: bigint | number;
@@ -385,16 +385,16 @@ const peopleUsersAdapters: PeopleUsersAdapters = {
const sortColumn =
input.sort === "accountCount" ? sql`accountCount` : sql`ipCurrent`;
const direction = input.order === "desc" ? sql`DESC` : sql`ASC`;
const result = await db.execute(sql`
const [result, countResult] = await Promise.all([
db.execute(sql`
WITH grouped AS (
SELECT ip_current AS ipCurrent, COUNT(*) AS accountCount,
COUNT(*) OVER () AS total
SELECT ip_current AS ipCurrent, COUNT(*) AS accountCount
FROM users
WHERE ip_current <> '' ${search}
GROUP BY ip_current
HAVING COUNT(*) >= 2
), paged AS (
SELECT ipCurrent, accountCount, total
SELECT ipCurrent, accountCount
FROM grouped
ORDER BY ${sortColumn} ${direction}, ipCurrent ASC
LIMIT ${input.pageSize} OFFSET ${input.offset}
@@ -404,17 +404,26 @@ const peopleUsersAdapters: PeopleUsersAdapters = {
FROM users u
INNER JOIN paged p ON p.ipCurrent = u.ip_current
)
SELECT p.ipCurrent, p.accountCount, p.total,
SELECT p.ipCurrent, p.accountCount,
a.id, a.username, a.rank, a.online
FROM paged p
INNER JOIN ranked_accounts a ON a.ipCurrent = p.ipCurrent
WHERE a.accountPosition <= 100
ORDER BY ${sortColumn} ${direction}, p.ipCurrent ASC, a.id ASC
`);
`),
db.execute(sql`
SELECT COUNT(*) AS total FROM (
SELECT ip_current
FROM users
WHERE ip_current <> '' ${search}
GROUP BY ip_current
HAVING COUNT(*) >= 2
) AS matching_clusters
`),
]);
const records = resultRows<{
ipCurrent: string;
accountCount: number | bigint;
total: number | bigint;
id: number;
username: string;
rank: number;
@@ -440,9 +449,14 @@ const peopleUsersAdapters: PeopleUsersAdapters = {
});
}
}
const totalRow = resultRows<{ total: number | bigint }>(countResult)[0];
const total = Number(totalRow?.total);
if (!Number.isSafeInteger(total) || total < 0) {
throw new Error("invalid People multi-account total");
}
return {
rows: [...clusters.values()],
total: Number(records[0]?.total ?? 0),
total,
};
},
async loadSanctions(userId) {