Skip to content

refactor(lib): use real subdir paths in exports - #1077

Merged
2witstudios merged 3 commits into
masterfrom
pu/removing-barrel-imports
Apr 23, 2026
Merged

2witstudios merged 3 commits into
masterfrom
pu/removing-barrel-imports

Conversation

@2witstudios

@2witstudios 2witstudios commented Apr 23, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Replaces 12 flat export aliases in `@pagespace/lib` with paths that mirror the actual source directory layout
  • Updates both `exports` and `typesVersions` fields in `packages/lib/package.json` in lockstep
  • Rewrites 114 import statements across `apps/web`, `apps/realtime`, and `apps/processor`
  • Follow-up: rewrites `vi.mock()`, `vi.doMock()`, dynamic imports, and `vitest.config` alias maps (first pass only caught static `from '...'` imports)
  • Fix: masks email in all three `trackAuthEvent` calls in the Google OAuth callback (web, desktop, iOS paths)
Old flat alias New nested path Source
`./secure-compare` `./auth/secure-compare` `src/auth/`
`./device-auth-utils` `./auth/device-auth-utils` `src/auth/`
`./broadcast-auth` `./auth/broadcast-auth` `src/auth/`
`./verification-utils` `./auth/verification-utils` `src/auth/`
`./activity-tracker` `./monitoring/activity-tracker` `src/monitoring/`
`./ai-monitoring` `./monitoring/ai-monitoring` `src/monitoring/`
`./ai-context-calculator` `./monitoring/ai-context-calculator` `src/monitoring/`
`./logger-config` `./logging/logger-config` `src/logging/`
`./logger-database` `./logging/logger-database` `src/logging/`
`./logger-browser` `./logging/logger-browser` `src/logging/`
`./logger` `./logging/logger` `src/logging/`
`./api-utils` `./utils/api-utils` `src/utils/`

Test plan

  • `grep -rn "from '@pagespace/lib/(secure-compare|broadcast-auth|activity-tracker|ai-monitoring|ai-context-calculator|logger-config|logger-database|logger-browser|api-utils|verification-utils|device-auth-utils)'" apps/ packages/` returns 0 matches
  • `pnpm typecheck` passes
  • `pnpm test:unit` passes (CI green)

🤖 Generated with Claude Code

Replace 12 flat export aliases in @pagespace/lib with paths
that match the actual source layout:
- ./secure-compare, ./device-auth-utils, ./broadcast-auth,
  ./verification-utils → ./auth/*
- ./activity-tracker, ./ai-monitoring,
  ./ai-context-calculator → ./monitoring/*
- ./logger-config, ./logger-database, ./logger-browser,
  ./logger → ./logging/*
- ./api-utils → ./utils/api-utils

Updates 114 import statements across apps/web, apps/realtime,
and apps/processor. Both exports and typesVersions fields in
package.json updated in lockstep.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Apr 23, 2026 •

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

The PR reorganizes the @pagespace/lib package structure by introducing namespace-based subdirectories (logging, monitoring, auth, utils) and updates all consuming files across apps/processor, apps/realtime, and apps/web to use the new import paths. The package.json exports and typesVersions are updated to reflect these changes.

Changes

Cohort / File(s) Summary
Logger Configuration
apps/processor/src/..., apps/realtime/src/..., apps/web/src/...
Updated imports for loggers and browserLoggers from @pagespace/lib/logger* to @pagespace/lib/logging/logger*.
Activity Tracking
apps/web/src/app/api/auth/..., apps/web/src/app/api/drives/..., apps/web/src/app/api/pages/..., apps/web/src/app/api/track/...
Updated imports for trackAuthEvent, trackDriveOperation, and trackPageOperation from @pagespace/lib/activity-tracker to @pagespace/lib/monitoring/activity-tracker.
AI Monitoring & Context
apps/web/src/app/api/ai/..., apps/web/src/app/api/pulse/..., apps/web/src/hooks/useAiUsage.ts, apps/web/src/lib/ai/..., apps/web/src/lib/workflows/workflow-executor.ts
Updated imports for AIMonitoring, getContextWindow, and estimateSystemPromptTokens from @pagespace/lib/ai-monitoring* and @pagespace/lib/ai-context-calculator* to @pagespace/lib/monitoring/*.
Broadcast Authentication
apps/realtime/src/..., apps/web/src/app/api/..., apps/web/src/lib/...
Updated imports for createSignedBroadcastHeaders and verifyBroadcastSignature from @pagespace/lib/broadcast-auth to @pagespace/lib/auth/broadcast-auth.
Device Authentication
apps/web/src/app/api/account/devices/...
Updated imports for secureCompare, revokeDeviceToken, and device token utilities from @pagespace/lib/device-* to @pagespace/lib/auth/device-*.
Email Verification
apps/web/src/app/api/auth/...
Updated imports for verifyToken and markEmailVerified from @pagespace/lib/verification-utils to @pagespace/lib/auth/verification-utils.
Secure Compare
apps/web/src/app/api/auth/magic-link/send/route.ts
Updated import for secureCompare from @pagespace/lib/secure-compare to @pagespace/lib/auth/secure-compare.
API Utilities
apps/web/src/app/api/..., apps/web/src/app/api/pages/...
Updated imports for jsonResponse from @pagespace/lib/api-utils to @pagespace/lib/utils/api-utils.
Package Exports
packages/lib/package.json
Updated subpath exports and typesVersions mappings to reorganize all public entry points under namespace directories: logging/*, monitoring/*, auth/*, and utils/*.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • PR #260: Adds comprehensive mobile auth tests (including apps/web/src/app/api/auth/__tests__/mobile-oauth-google-exchange.test.ts), which this PR later updates import paths within to match renamed package subpaths.
  • PR #1065: Introduces use and import of secureCompare in the magic-link send route; this PR updates that same import's module path to the new auth namespace.
  • PR #99: Adds new monitoring/auth/logging module structure and imports those new subpaths, which this PR's wholesale subpath renames directly enable.

Poem

🐰 Module paths reshuffled neat,
Logging bundled, monitoring sweet,
Auth and utils find their place,
Organize this code-base space! ✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title 'refactor(lib): use real subdir paths in exports' accurately and concisely describes the main change: refactoring the lib package to use nested export paths that match the actual source directory structure instead of flat aliases.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch pu/removing-barrel-imports

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

The first pass only caught static `from '...'` imports.
vi.mock(), vi.doMock(), await import(), and vitest.config
alias maps also contained the old flat paths. Replace all
remaining occurrences across apps/web, apps/realtime, and
apps/processor.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9accee14e0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/lib/package.json

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (21)
apps/web/src/app/api/auth/google/__tests__/one-tap.test.ts (1)

101-124: ⚠️ Potential issue | 🔴 Critical

Point the Vitest mock at the same subpath as the import.

The test now imports trackAuthEvent from @pagespace/lib/monitoring/activity-tracker, but the mock still registers the old @pagespace/lib/activity-tracker specifier, so the assertion can hit the real module instead of a spy.

🐛 Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackAuthEvent: vi.fn(),
 }));

Verify remaining stale mocks:

#!/bin/bash
rg -n -C2 "vi\.mock\('@pagespace/lib/activity-tracker'|from '@pagespace/lib/monitoring/activity-tracker'" --type=ts
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/auth/google/__tests__/one-tap.test.ts` around lines 101
- 124, The test registers a Vitest mock for the wrong module specifier so the
imported trackAuthEvent (imported from
'@pagespace/lib/monitoring/activity-tracker') can be the real module; update the
vi.mock call to target the same subpath used by the import (replace the existing
vi.mock('@pagespace/lib/activity-tracker', ...) with
vi.mock('@pagespace/lib/monitoring/activity-tracker', ...) so trackAuthEvent is
a spy), then run the provided rg check to find any other stale vi.mock entries.
apps/web/src/app/api/pages/[pageId]/export/xlsx/__tests__/route.test.ts (1)

43-58: ⚠️ Potential issue | 🟠 Major

Update the mock path alongside the import path.

Line 58 imports trackPageOperation from the new monitoring subpath, but Lines 43-45 still mock the old flat subpath. The trackPageOperation assertion will not be using this mock.

Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackPageOperation: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/pages/`[pageId]/export/xlsx/__tests__/route.test.ts
around lines 43 - 58, The test is mocking the old path for trackPageOperation so
the imported trackPageOperation used in the test isn't the mock; update the
vi.mock call to match the import path by replacing
vi.mock('@pagespace/lib/activity-tracker', ...) with
vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
trackPageOperation: vi.fn() })), ensuring the mock exports the same symbol name
trackPageOperation so assertions against trackPageOperation in the tests use the
mock.
apps/web/src/app/api/auth/apple/native/__tests__/route.test.ts (1)

87-121: ⚠️ Potential issue | 🟠 Major

Update the mock to match the new activity tracker import.

Line 121 imports @pagespace/lib/monitoring/activity-tracker, but Lines 87-89 still mock the old @pagespace/lib/activity-tracker subpath. This leaves trackAuthEvent unmocked for the assertions below.

Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackAuthEvent: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/auth/apple/native/__tests__/route.test.ts` around lines
87 - 121, The test's mock targets the old import path so trackAuthEvent (used by
POST route tests) isn't being mocked; update the vi.mock call that currently
targets '@pagespace/lib/activity-tracker' to mock the new import
'@pagespace/lib/monitoring/activity-tracker' and export trackAuthEvent: vi.fn()
(matching the imported symbol trackAuthEvent) so assertions referencing
trackAuthEvent are properly stubbed.
apps/web/src/app/api/auth/passkey/[passkeyId]/__tests__/route.test.ts (1)

29-43: ⚠️ Potential issue | 🔴 Critical

Critical: vi.mock specifier was not updated to match the new import path.

Line 43 now imports trackAuthEvent from @pagespace/lib/monitoring/activity-tracker, but the vi.mock(...) on line 29 still points at @pagespace/lib/activity-tracker. The mock is keyed by exact module specifier, so it won't apply — the real trackAuthEvent will be pulled into both the test and the route under test, and expect(trackAuthEvent).toHaveBeenCalledWith(...) assertions will fail (or worse, exercise real side effects).

Note: the AI summary claims this mock path was updated, but the submitted code shows it was not.

🔧 Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackAuthEvent: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/auth/passkey/`[passkeyId]/__tests__/route.test.ts around
lines 29 - 43, The mocked module specifier is wrong: update the vi.mock call
that currently targets "@pagespace/lib/activity-tracker" to the new import path
"@pagespace/lib/monitoring/activity-tracker" so the mock applies to the same
module used by the route and tests, ensuring trackAuthEvent is the mocked
vi.fn() referenced by imports of trackAuthEvent and preventing real side
effects.
apps/web/src/app/api/auth/__tests__/mobile-oauth-google-exchange.test.ts (1)

63-113: ⚠️ Potential issue | 🔴 Critical

Critical: vi.mock path was not updated alongside the import — mock is now inert.

Line 113 imports trackAuthEvent from @pagespace/lib/monitoring/activity-tracker, but the vi.mock(...) at line 63 still targets the old @pagespace/lib/activity-tracker specifier. Vitest resolves mocks by exact module specifier, so the real trackAuthEvent will be imported here (and inside the route module under test), causing expect(trackAuthEvent).toHaveBeenCalledWith(...) assertions to break and potentially triggering real DB writes during the unit test.

🔧 Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackAuthEvent: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/auth/__tests__/mobile-oauth-google-exchange.test.ts`
around lines 63 - 113, The vi.mock for the activity tracker uses the old
specifier and is therefore inert; update the mock call to target the new module
specifier '@pagespace/lib/monitoring/activity-tracker' (providing
trackAuthEvent: vi.fn()) and ensure this vi.mock appears before the import of
trackAuthEvent/route under test so the imported trackAuthEvent is the mocked fn
used in assertions.
apps/processor/src/__tests__/cors-validation.test.ts (1)

12-23: ⚠️ Potential issue | 🔴 Critical

Critical: vi.mock target is stale and won't intercept the new import path.

Line 12 still mocks @pagespace/lib/logger-config, but line 23 (and presumably ../utils/cors-validation) now imports from @pagespace/lib/logging/logger-config. Vitest keys mocks by module specifier, so the old-path mock no longer applies: loggers will be the real module, and the expect(loggers.processor.warn).toHaveBeenCalledWith(...) assertions will either fail or invoke the real logger.

🔧 Proposed fix
-vi.mock('@pagespace/lib/logger-config', () => ({
+vi.mock('@pagespace/lib/logging/logger-config', () => ({
   loggers: {
     processor: {
       debug: vi.fn(),
       info: vi.fn(),
       warn: vi.fn(),
       error: vi.fn(),
     },
   },
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/processor/src/__tests__/cors-validation.test.ts` around lines 12 - 23,
The test's vi.mock currently targets '@pagespace/lib/logger-config' but the code
under test imports from '@pagespace/lib/logging/logger-config', so update the
vi.mock call to mock the exact module specifier
'@pagespace/lib/logging/logger-config' and keep the same mocked shape
(loggers.processor.{debug,info,warn,error}); also ensure the vi.mock is declared
before importing the module-under-test or the named import `loggers` so that
`expect(loggers.processor.warn).toHaveBeenCalledWith(...)` asserts against the
mock.
apps/web/src/app/api/auth/google/one-tap/__tests__/route.test.ts (1)

102-104: ⚠️ Potential issue | 🔴 Critical

Fix the mock path to match the new import path.

The mock at line 102 uses the old path @pagespace/lib/activity-tracker, but the import at line 133 uses the new path @pagespace/lib/monitoring/activity-tracker. This mismatch will cause the mock to fail to intercept the import, leading to test failures or unexpected behavior.

🐛 Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackAuthEvent: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/auth/google/one-tap/__tests__/route.test.ts` around
lines 102 - 104, The test mock path is outdated: update the vi.mock call to use
the new module path '@pagespace/lib/monitoring/activity-tracker' so it correctly
intercepts imports; specifically change the mock that provides trackAuthEvent
(vi.mock(..., () => ({ trackAuthEvent: vi.fn() }))) to target
'@pagespace/lib/monitoring/activity-tracker' to match the actual import used in
the test.
apps/web/src/app/api/drives/[driveId]/members/invite/__tests__/route.test.ts (1)

63-76: ⚠️ Potential issue | 🟠 Major

vi.mock path out of sync with import — trackDriveOperation will not be mocked.

Line 76 imports trackDriveOperation from @pagespace/lib/monitoring/activity-tracker, but the vi.mock(...) on line 63 still targets the legacy alias @pagespace/lib/activity-tracker. Since this PR removes that old alias from packages/lib/package.json exports, the mock registration targets a path that no longer exists while the actual import resolves to the new module — so the real trackDriveOperation will run in the test and expect(trackDriveOperation).toHaveBeenCalledWith(...) in the "boundary obligations" suite will fail (or throw on module-resolution errors).

🛠️ Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackDriveOperation: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/drives/`[driveId]/members/invite/__tests__/route.test.ts
around lines 63 - 76, The vi.mock call is targeting the old module path so
trackDriveOperation is not being mocked; update the mock to match the actual
import path used in the test (replace the '@pagespace/lib/activity-tracker'
argument to vi.mock with '@pagespace/lib/monitoring/activity-tracker') so that
the imported trackDriveOperation used by POST and assertions is a mocked
vi.fn(); ensure the mock is declared before the import of POST and any other
modules that import trackDriveOperation.
apps/web/src/app/api/pages/__tests__/route.test.ts (1)

59-67: ⚠️ Potential issue | 🟠 Major

vi.mock target still points to removed alias @pagespace/lib/activity-tracker.

Line 67 now imports trackPageOperation from @pagespace/lib/monitoring/activity-tracker, but the vi.mock(...) factory on line 59 still registers against the old path. With the old alias removed from packages/lib/package.json, the mock no longer intercepts the real module — the "activity tracking" test that asserts expect(trackPageOperation).toHaveBeenCalledWith(...) will exercise the real implementation (which writes to the DB via logger-database) and likely fail.

🛠️ Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackPageOperation: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/pages/__tests__/route.test.ts` around lines 59 - 67, The
test's vi.mock target is still the removed alias
'@pagespace/lib/activity-tracker' so the imported trackPageOperation (from
`@pagespace/lib/monitoring/activity-tracker`) isn't being mocked; update the
vi.mock call to mock the correct module path
'@pagespace/lib/monitoring/activity-tracker' and ensure the factory returns {
trackPageOperation: vi.fn() } so the imported function used in the test
(trackPageOperation) is intercepted and the
expect(trackPageOperation).toHaveBeenCalledWith(...) assertion uses the mock.
apps/web/src/app/api/auth/google/callback/__tests__/route.test.ts (1)

120-153: ⚠️ Potential issue | 🟠 Major

vi.mock path not updated alongside the import — mock is effectively dead.

Line 153 imports trackAuthEvent from @pagespace/lib/monitoring/activity-tracker, but vi.mock(...) on line 120 still targets the legacy @pagespace/lib/activity-tracker alias that this PR removes. The mock won’t intercept the production module, so assertions like expect(trackAuthEvent).toHaveBeenCalledWith(...) in the "auth event logging", "tracks desktop auth events", and "tracks iOS auth events" tests will fail, and the real tracker (with DB writes) may run during unit tests.

🛠️ Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackAuthEvent: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/auth/google/callback/__tests__/route.test.ts` around
lines 120 - 153, The vi.mock target is pointing at the removed alias
'@pagespace/lib/activity-tracker' so the actual imported symbol trackAuthEvent
(imported from '@pagespace/lib/monitoring/activity-tracker') is not being
mocked; update the vi.mock call to mock
'@pagespace/lib/monitoring/activity-tracker' instead and ensure the mock exports
trackAuthEvent (vi.fn()) so tests that call and assert on trackAuthEvent, and
any other exported helpers from that module, are intercepted by the mock rather
than hitting production code.
apps/web/src/app/api/pages/[pageId]/export/markdown/__tests__/route.test.ts (1)

38-58: ⚠️ Potential issue | 🔴 Critical

vi.mock specifier not migrated — same issue as the DOCX/CSV/XLSX export tests.

Line 38 mocks @pagespace/lib/activity-tracker, but line 58 imports from @pagespace/lib/monitoring/activity-tracker. Mock won't intercept the new import; the "activity tracking" assertion on line 217 will run against the real trackPageOperation.

🐛 Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackPageOperation: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/pages/`[pageId]/export/markdown/__tests__/route.test.ts
around lines 38 - 58, The test's vi.mock for activity tracking uses the wrong
module specifier so the real trackPageOperation is imported; update the mock to
target the actual import '@pagespace/lib/monitoring/activity-tracker' (and
ensure it exports trackPageOperation as vi.fn()) so the imported
trackPageOperation used in the test is mocked and the assertion around
trackPageOperation will run against the mock.
apps/web/src/app/api/auth/apple/callback/__tests__/route.test.ts (1)

90-128: ⚠️ Potential issue | 🔴 Critical

vi.mock path not migrated — trackAuthEvent assertions will not be observing a spy.

Line 90 mocks @pagespace/lib/activity-tracker, but line 128 imports trackAuthEvent from @pagespace/lib/monitoring/activity-tracker. The mock specifier doesn't match the real import specifier, so the "auth event logging" suite's expect(trackAuthEvent).toHaveBeenCalledWith(...) will be asserting against the real function rather than a vi.fn().

🐛 Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackAuthEvent: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/auth/apple/callback/__tests__/route.test.ts` around
lines 90 - 128, The test mocks the wrong module path so trackAuthEvent isn't a
spy; change the vi.mock call that currently targets
'@pagespace/lib/activity-tracker' to match the actual import
'@pagespace/lib/monitoring/activity-tracker' and ensure the mock exports
trackAuthEvent: vi.fn() so the imported trackAuthEvent used in the tests (from
'@pagespace/lib/monitoring/activity-tracker') is the mocked spy being asserted
against.
apps/web/src/lib/websocket/__tests__/socket-utils.test.ts (1)

9-52: ⚠️ Potential issue | 🔴 Critical

vi.mock specifier for broadcast-auth not updated to the new auth/ subpath.

Line 9 mocks @pagespace/lib/broadcast-auth, but line 52 imports createSignedBroadcastHeaders from @pagespace/lib/auth/broadcast-auth. The assertion on line 257 (expect(createSignedBroadcastHeaders).toHaveBeenCalled()) and the mocked signature header value on line 12 will no longer apply — the real implementation will be used, and if the old flat export was removed the vi.mock resolution itself may fail at setup.

Note: @pagespace/lib/logger-browser on line 16 should likewise be reviewed against the current package.json exports — if it was renamed to ./logging/logger-browser, that mock is stale too.

🐛 Proposed fix
-vi.mock('@pagespace/lib/broadcast-auth', () => ({
+vi.mock('@pagespace/lib/auth/broadcast-auth', () => ({
   createSignedBroadcastHeaders: vi.fn((body: string) => ({
     'Content-Type': 'application/json',
     'X-Broadcast-Signature': `t=1234567890,v1=mocksignature_${body.length}`,
   })),
 }));

-vi.mock('@pagespace/lib/logger-browser', () => ({
+vi.mock('@pagespace/lib/logging/logger-browser', () => ({
   browserLoggers: { /* ... */ },
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/lib/websocket/__tests__/socket-utils.test.ts` around lines 9 -
52, Update the stale vi.mock specifier so the mocked export matches the actual
import: change the mock that currently targets '@pagespace/lib/broadcast-auth'
to '@pagespace/lib/auth/broadcast-auth' so createSignedBroadcastHeaders (used in
tests and asserted with expect(createSignedBroadcastHeaders).toHaveBeenCalled())
is properly mocked; also verify and, if necessary, update the logger mock
specifier (currently '@pagespace/lib/logger-browser') to the package's current
export (e.g. './logging/logger-browser') so the browserLoggers.child mock
remains effective.
apps/web/src/app/api/account/devices/[deviceId]/__tests__/route.test.ts (1)

36-58: ⚠️ Potential issue | 🔴 Critical

Two vi.mock specifiers not migrated to the new subpaths.

Lines 36 and 44 still mock the flat paths @pagespace/lib/secure-compare and @pagespace/lib/device-auth-utils, while lines 56 and 58 import secureCompare and revokeDeviceToken from the new @pagespace/lib/auth/* subpaths. Because the mock and import specifiers no longer match, the imported symbols will be the real implementations. Tests that call vi.mocked(secureCompare).mockReturnValue(...) and vi.mocked(revokeDeviceToken).mockResolvedValue(...) will throw ("mockReturnValue is not a function") or — worse — invoke real code paths (real DB mutation in revokeDeviceToken).

🐛 Proposed fix
-vi.mock('@pagespace/lib/secure-compare', () => ({
+vi.mock('@pagespace/lib/auth/secure-compare', () => ({
   secureCompare: vi.fn(),
 }));

-vi.mock('@pagespace/lib/device-auth-utils', () => ({
+vi.mock('@pagespace/lib/auth/device-auth-utils', () => ({
   revokeDeviceToken: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/account/devices/`[deviceId]/__tests__/route.test.ts
around lines 36 - 58, The test mocks use outdated module specifiers so the
imported symbols secureCompare and revokeDeviceToken are not being mocked;
update the vi.mock calls to the new subpaths used by the imports (replace
'@pagespace/lib/secure-compare' with '@pagespace/lib/auth/secure-compare' and
'@pagespace/lib/device-auth-utils' with '@pagespace/lib/auth/device-auth-utils')
and keep the mocked exports named secureCompare and revokeDeviceToken
respectively so vi.mocked(secureCompare) and vi.mocked(revokeDeviceToken)
operate on the mocked functions.
apps/web/src/app/api/pages/[pageId]/export/csv/__tests__/route.test.ts (1)

43-58: ⚠️ Potential issue | 🟠 Major

Point the activity-tracker mock at the renamed module.

The import moved to @pagespace/lib/monitoring/activity-tracker, but the mock stayed on the old flat path, so trackPageOperation is no longer mocked for these assertions.

🧪 Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackPageOperation: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/pages/`[pageId]/export/csv/__tests__/route.test.ts
around lines 43 - 58, The activity-tracker mock targets the old module path so
trackPageOperation isn't being mocked; update the mock declaration to use the
renamed module '@pagespace/lib/monitoring/activity-tracker' (the same module
imported as trackPageOperation in the test) so vi.mock(...) replaces
trackPageOperation; ensure the mocked export name matches the imported symbol
trackPageOperation and keep the existing vi.fn() implementation used in the test
assertions.
apps/realtime/src/__tests__/auth.test.ts (1)

24-76: ⚠️ Potential issue | 🟠 Major

Update the broadcast-auth mock to the renamed subpath.

The import now uses @pagespace/lib/auth/broadcast-auth, but the mock is still registered for @pagespace/lib/broadcast-auth. This bypasses the mock and may also fail once the old export path is removed.

🧪 Proposed fix
- * `@scaffold` - broadcast-auth lives in `@pagespace/lib` and may not resolve
+ * `@scaffold` - broadcast-auth lives in `@pagespace/lib/auth` and may not resolve
@@
- * `@REVIEW` This test mocks `@pagespace/lib/broadcast-auth` and then tests the
+ * `@REVIEW` This test mocks `@pagespace/lib/auth/broadcast-auth` and then tests the
@@
-vi.mock('@pagespace/lib/broadcast-auth', async () => {
+vi.mock('@pagespace/lib/auth/broadcast-auth', async () => {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/realtime/src/__tests__/auth.test.ts` around lines 24 - 76, The mock
registration path is still '@pagespace/lib/broadcast-auth' so the imported
symbols verifyBroadcastSignature, generateBroadcastSignature, and
formatSignatureHeader (imported from '@pagespace/lib/auth/broadcast-auth')
bypass the mock; update the vi.mock call to register the same renamed subpath by
changing the module string to '@pagespace/lib/auth/broadcast-auth' (keeping the
existing mock factory that defines generateBroadcastSignature,
formatSignatureHeader, and verifyBroadcastSignature) so the mock and the import
match.
apps/web/src/app/api/drives/[driveId]/members/[userId]/__tests__/route.test.ts (1)

63-120: ⚠️ Potential issue | 🟠 Major

Keep the activity-tracker mock in sync with the renamed import.

Line 120 imports the monitoring subpath, but the mock is still registered for the old flat path. That makes trackDriveOperation a real import instead of the vi.fn() asserted later.

🧪 Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackDriveOperation: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In
`@apps/web/src/app/api/drives/`[driveId]/members/[userId]/__tests__/route.test.ts
around lines 63 - 120, The test mocks trackDriveOperation from
'@pagespace/lib/activity-tracker' but the test imports trackDriveOperation from
'@pagespace/lib/monitoring/activity-tracker', causing the mock to not apply;
update the vi.mock call to target the same module path used in the import
(monitoring/activity-tracker) so that trackDriveOperation is a vi.fn() in tests,
or change the import to match the mocked path—ensure the module path in the
vi.mock and the import for trackDriveOperation are identical.
apps/web/src/app/api/auth/device/refresh/__tests__/route.test.ts (1)

89-105: ⚠️ Potential issue | 🟠 Major

Update the mock to the new activity-tracker subpath.

Line 105 imports @pagespace/lib/monitoring/activity-tracker, but the test still mocks @pagespace/lib/activity-tracker. The spy assertions can hit the real module or fail once the legacy export is removed.

🧪 Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackAuthEvent: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/auth/device/refresh/__tests__/route.test.ts` around
lines 89 - 105, The test's mock for activity tracking uses the old module path;
update the vi.mock call to mock the new subpath
'@pagespace/lib/monitoring/activity-tracker' so the imported symbol
trackAuthEvent (used in the test via import { trackAuthEvent } from
'@pagespace/lib/monitoring/activity-tracker') is properly stubbed; specifically
replace the existing vi.mock('@pagespace/lib/activity-tracker', ...) with
vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({ trackAuthEvent:
vi.fn() })) so spy assertions reference the mocked trackAuthEvent.
apps/web/src/app/api/track/__tests__/route.test.ts (1)

24-47: ⚠️ Potential issue | 🔴 Critical

Mock path mismatch — test will exercise real implementation.

vi.mock('@pagespace/lib/activity-tracker', ...) on line 24 still references the old subpath, but the import at line 47 now resolves @pagespace/lib/monitoring/activity-tracker. Since Vitest keys mocks by the resolved module specifier, the real trackActivity/trackFeature/trackError will be imported and the vi.fn() assertions (toHaveBeenCalledWith(...), not.toHaveBeenCalled()) will fail or cause real side effects (DB writes via writeUserActivity).

Proposed fix
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackActivity: vi.fn(),
   trackFeature: vi.fn(),
   trackError: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/track/__tests__/route.test.ts` around lines 24 - 47, The
test's vi.mock call uses the old module specifier and doesn't match the actual
imported module, so replace the mock key '@pagespace/lib/activity-tracker' with
the resolved specifier '@pagespace/lib/monitoring/activity-tracker' (keeping the
mocked exports trackActivity, trackFeature, trackError) so the imported symbols
trackActivity/trackFeature/trackError are properly mocked and the vi.fn()
assertions and side-effect prevention work as intended.
apps/web/src/app/api/ai/global/[id]/usage/__tests__/route.test.ts (1)

42-52: ⚠️ Potential issue | 🔴 Critical

Mock path mismatch — getContextWindow mock will not take effect.

vi.mock('@pagespace/lib/ai-monitoring', ...) at line 42 still uses the old specifier, while the actual import at line 52 (and the route under test) now resolves @pagespace/lib/monitoring/ai-monitoring. The mock factory will not intercept the real module, so getContextWindow will return its real value rather than the stubbed 200000, and expect(mockedCalculateUsageSummary).toHaveBeenCalledWith(usageLogs, getContextWindow) at line 259 compares against the real function reference instead of the mock.

Proposed fix
-vi.mock('@pagespace/lib/ai-monitoring', () => ({
+vi.mock('@pagespace/lib/monitoring/ai-monitoring', () => ({
   getContextWindow: vi.fn(() => 200000),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/ai/global/`[id]/usage/__tests__/route.test.ts around
lines 42 - 52, The test is mocking the wrong module specifier so
getContextWindow isn't stubbed; update the vi.mock call to target the actual
module specifier used in the code under test (change
vi.mock('@pagespace/lib/ai-monitoring', ...) to
vi.mock('@pagespace/lib/monitoring/ai-monitoring', ...)) so the exported
getContextWindow is replaced with the mock returning 200000, then rerun
assertions that use getContextWindow (e.g., the expect on
mockedCalculateUsageSummary receiving getContextWindow) to reference the mocked
function.
apps/web/src/app/api/auth/__tests__/verify-email.test.ts (1)

6-33: ⚠️ Potential issue | 🔴 Critical

vi.mock paths don't match the new import paths — mocks won't apply.

The imports at lines 31 and 33 now use the nested subpaths (@pagespace/lib/auth/verification-utils, @pagespace/lib/monitoring/activity-tracker), but the vi.mock calls at lines 6 and 27 still target the old flat paths (@pagespace/lib/verification-utils, @pagespace/lib/activity-tracker). Since the old aliases were removed from packages/lib/package.json, these mocks either fail to resolve or register against non-existent specifiers, leaving the real modules loaded for the actual imports. That will break the test suite (e.g., vi.mocked(verifyToken).mockResolvedValue(...) in beforeEach won't control a mock).

🛠️ Proposed fix
-vi.mock('@pagespace/lib/verification-utils', () => ({
+vi.mock('@pagespace/lib/auth/verification-utils', () => ({
   verifyToken: vi.fn(),
   markEmailVerified: vi.fn().mockResolvedValue(undefined),
 }));
@@
-vi.mock('@pagespace/lib/activity-tracker', () => ({
+vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
   trackAuthEvent: vi.fn(),
 }));
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@apps/web/src/app/api/auth/__tests__/verify-email.test.ts` around lines 6 -
33, Update the vi.mock specifiers to match the new nested import paths so the
mocks actually apply: replace the old '@pagespace/lib/verification-utils' mock
with one for '@pagespace/lib/auth/verification-utils' (providing verifyToken and
markEmailVerified), and replace '@pagespace/lib/activity-tracker' with
'@pagespace/lib/monitoring/activity-tracker' (providing trackAuthEvent); keep
the existing '@pagespace/lib/server' mock for loggers and ensure the mocked
symbol names (verifyToken, markEmailVerified, trackAuthEvent, loggers) exactly
match the imported identifiers used later in the test.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@apps/realtime/src/__tests__/index.test.ts`:
- Around line 223-224: Update the test's vi.mock specifiers to match the new
nested import paths so the dynamic import picks up the mocks: change the
existing vi.mock(...) entries that target the old flat aliases to instead mock
'@pagespace/lib/logging/logger-config' for the loggers mock and
'@pagespace/lib/auth/broadcast-auth' for the verifyBroadcastSignature mock
(referencing the symbols loggers and verifyBroadcastSignature) so the dynamic
../index import loads the mocked implementations.

In `@apps/web/src/app/api/auth/google/callback/route.ts`:
- Line 10: The three calls to trackAuthEvent in the Google callback route are
sending raw email PII; update each payload to pass maskEmail(email) instead of
email (reuse the already-imported maskEmail helper) so trackAuthEvent never
receives raw emails — locate the trackAuthEvent invocations in route.ts (the
blocks around the login success/failure and account-creation events, e.g., the
calls currently passing email) and replace the email argument with
maskEmail(email) consistently (also apply the same change to the other instances
noted around the same file).

In `@apps/web/src/app/api/auth/magic-link/verify/__tests__/route.test.ts`:
- Around line 85-87: The Vitest mocks at the top of route.test.ts still target
the old flat aliases, so update them to mock the new nested import paths used in
the file: replace mocks for the old module names with mocks for
'@pagespace/lib/auth/verification-utils' (to mock markEmailVerified),
'@pagespace/lib/server' (to mock loggers and auditRequest), and
'@pagespace/lib/monitoring/activity-tracker' (to mock trackAuthEvent); ensure
vi.mock(...) calls use those exact subpaths and then use vi.mocked(...) against
the exported symbols markEmailVerified, loggers, auditRequest, and
trackAuthEvent so the test uses the mocked implementations.

In `@apps/web/src/app/api/pages/`[pageId]/__tests__/route.test.ts:
- Around line 73-74: The test's vi.mock calls still target the old module
aliases and therefore don't intercept the actual imports; update the vi.mock
targets to the new subpaths used by the imports—replace the old mock targets
with '@pagespace/lib/monitoring/activity-tracker' for trackPageOperation and
'@pagespace/lib/utils/api-utils' for jsonResponse (keeping the existing mock
implementations/returns intact) so the mocks apply to the imported symbols in
the test and the route.

---

Outside diff comments:
In `@apps/processor/src/__tests__/cors-validation.test.ts`:
- Around line 12-23: The test's vi.mock currently targets
'@pagespace/lib/logger-config' but the code under test imports from
'@pagespace/lib/logging/logger-config', so update the vi.mock call to mock the
exact module specifier '@pagespace/lib/logging/logger-config' and keep the same
mocked shape (loggers.processor.{debug,info,warn,error}); also ensure the
vi.mock is declared before importing the module-under-test or the named import
`loggers` so that `expect(loggers.processor.warn).toHaveBeenCalledWith(...)`
asserts against the mock.

In `@apps/realtime/src/__tests__/auth.test.ts`:
- Around line 24-76: The mock registration path is still
'@pagespace/lib/broadcast-auth' so the imported symbols
verifyBroadcastSignature, generateBroadcastSignature, and formatSignatureHeader
(imported from '@pagespace/lib/auth/broadcast-auth') bypass the mock; update the
vi.mock call to register the same renamed subpath by changing the module string
to '@pagespace/lib/auth/broadcast-auth' (keeping the existing mock factory that
defines generateBroadcastSignature, formatSignatureHeader, and
verifyBroadcastSignature) so the mock and the import match.

In `@apps/web/src/app/api/account/devices/`[deviceId]/__tests__/route.test.ts:
- Around line 36-58: The test mocks use outdated module specifiers so the
imported symbols secureCompare and revokeDeviceToken are not being mocked;
update the vi.mock calls to the new subpaths used by the imports (replace
'@pagespace/lib/secure-compare' with '@pagespace/lib/auth/secure-compare' and
'@pagespace/lib/device-auth-utils' with '@pagespace/lib/auth/device-auth-utils')
and keep the mocked exports named secureCompare and revokeDeviceToken
respectively so vi.mocked(secureCompare) and vi.mocked(revokeDeviceToken)
operate on the mocked functions.

In `@apps/web/src/app/api/ai/global/`[id]/usage/__tests__/route.test.ts:
- Around line 42-52: The test is mocking the wrong module specifier so
getContextWindow isn't stubbed; update the vi.mock call to target the actual
module specifier used in the code under test (change
vi.mock('@pagespace/lib/ai-monitoring', ...) to
vi.mock('@pagespace/lib/monitoring/ai-monitoring', ...)) so the exported
getContextWindow is replaced with the mock returning 200000, then rerun
assertions that use getContextWindow (e.g., the expect on
mockedCalculateUsageSummary receiving getContextWindow) to reference the mocked
function.

In `@apps/web/src/app/api/auth/__tests__/mobile-oauth-google-exchange.test.ts`:
- Around line 63-113: The vi.mock for the activity tracker uses the old
specifier and is therefore inert; update the mock call to target the new module
specifier '@pagespace/lib/monitoring/activity-tracker' (providing
trackAuthEvent: vi.fn()) and ensure this vi.mock appears before the import of
trackAuthEvent/route under test so the imported trackAuthEvent is the mocked fn
used in assertions.

In `@apps/web/src/app/api/auth/__tests__/verify-email.test.ts`:
- Around line 6-33: Update the vi.mock specifiers to match the new nested import
paths so the mocks actually apply: replace the old
'@pagespace/lib/verification-utils' mock with one for
'@pagespace/lib/auth/verification-utils' (providing verifyToken and
markEmailVerified), and replace '@pagespace/lib/activity-tracker' with
'@pagespace/lib/monitoring/activity-tracker' (providing trackAuthEvent); keep
the existing '@pagespace/lib/server' mock for loggers and ensure the mocked
symbol names (verifyToken, markEmailVerified, trackAuthEvent, loggers) exactly
match the imported identifiers used later in the test.

In `@apps/web/src/app/api/auth/apple/callback/__tests__/route.test.ts`:
- Around line 90-128: The test mocks the wrong module path so trackAuthEvent
isn't a spy; change the vi.mock call that currently targets
'@pagespace/lib/activity-tracker' to match the actual import
'@pagespace/lib/monitoring/activity-tracker' and ensure the mock exports
trackAuthEvent: vi.fn() so the imported trackAuthEvent used in the tests (from
'@pagespace/lib/monitoring/activity-tracker') is the mocked spy being asserted
against.

In `@apps/web/src/app/api/auth/apple/native/__tests__/route.test.ts`:
- Around line 87-121: The test's mock targets the old import path so
trackAuthEvent (used by POST route tests) isn't being mocked; update the vi.mock
call that currently targets '@pagespace/lib/activity-tracker' to mock the new
import '@pagespace/lib/monitoring/activity-tracker' and export trackAuthEvent:
vi.fn() (matching the imported symbol trackAuthEvent) so assertions referencing
trackAuthEvent are properly stubbed.

In `@apps/web/src/app/api/auth/device/refresh/__tests__/route.test.ts`:
- Around line 89-105: The test's mock for activity tracking uses the old module
path; update the vi.mock call to mock the new subpath
'@pagespace/lib/monitoring/activity-tracker' so the imported symbol
trackAuthEvent (used in the test via import { trackAuthEvent } from
'@pagespace/lib/monitoring/activity-tracker') is properly stubbed; specifically
replace the existing vi.mock('@pagespace/lib/activity-tracker', ...) with
vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({ trackAuthEvent:
vi.fn() })) so spy assertions reference the mocked trackAuthEvent.

In `@apps/web/src/app/api/auth/google/__tests__/one-tap.test.ts`:
- Around line 101-124: The test registers a Vitest mock for the wrong module
specifier so the imported trackAuthEvent (imported from
'@pagespace/lib/monitoring/activity-tracker') can be the real module; update the
vi.mock call to target the same subpath used by the import (replace the existing
vi.mock('@pagespace/lib/activity-tracker', ...) with
vi.mock('@pagespace/lib/monitoring/activity-tracker', ...) so trackAuthEvent is
a spy), then run the provided rg check to find any other stale vi.mock entries.

In `@apps/web/src/app/api/auth/google/callback/__tests__/route.test.ts`:
- Around line 120-153: The vi.mock target is pointing at the removed alias
'@pagespace/lib/activity-tracker' so the actual imported symbol trackAuthEvent
(imported from '@pagespace/lib/monitoring/activity-tracker') is not being
mocked; update the vi.mock call to mock
'@pagespace/lib/monitoring/activity-tracker' instead and ensure the mock exports
trackAuthEvent (vi.fn()) so tests that call and assert on trackAuthEvent, and
any other exported helpers from that module, are intercepted by the mock rather
than hitting production code.

In `@apps/web/src/app/api/auth/google/one-tap/__tests__/route.test.ts`:
- Around line 102-104: The test mock path is outdated: update the vi.mock call
to use the new module path '@pagespace/lib/monitoring/activity-tracker' so it
correctly intercepts imports; specifically change the mock that provides
trackAuthEvent (vi.mock(..., () => ({ trackAuthEvent: vi.fn() }))) to target
'@pagespace/lib/monitoring/activity-tracker' to match the actual import used in
the test.

In `@apps/web/src/app/api/auth/passkey/`[passkeyId]/__tests__/route.test.ts:
- Around line 29-43: The mocked module specifier is wrong: update the vi.mock
call that currently targets "@pagespace/lib/activity-tracker" to the new import
path "@pagespace/lib/monitoring/activity-tracker" so the mock applies to the
same module used by the route and tests, ensuring trackAuthEvent is the mocked
vi.fn() referenced by imports of trackAuthEvent and preventing real side
effects.

In
`@apps/web/src/app/api/drives/`[driveId]/members/[userId]/__tests__/route.test.ts:
- Around line 63-120: The test mocks trackDriveOperation from
'@pagespace/lib/activity-tracker' but the test imports trackDriveOperation from
'@pagespace/lib/monitoring/activity-tracker', causing the mock to not apply;
update the vi.mock call to target the same module path used in the import
(monitoring/activity-tracker) so that trackDriveOperation is a vi.fn() in tests,
or change the import to match the mocked path—ensure the module path in the
vi.mock and the import for trackDriveOperation are identical.

In
`@apps/web/src/app/api/drives/`[driveId]/members/invite/__tests__/route.test.ts:
- Around line 63-76: The vi.mock call is targeting the old module path so
trackDriveOperation is not being mocked; update the mock to match the actual
import path used in the test (replace the '@pagespace/lib/activity-tracker'
argument to vi.mock with '@pagespace/lib/monitoring/activity-tracker') so that
the imported trackDriveOperation used by POST and assertions is a mocked
vi.fn(); ensure the mock is declared before the import of POST and any other
modules that import trackDriveOperation.

In `@apps/web/src/app/api/pages/__tests__/route.test.ts`:
- Around line 59-67: The test's vi.mock target is still the removed alias
'@pagespace/lib/activity-tracker' so the imported trackPageOperation (from
`@pagespace/lib/monitoring/activity-tracker`) isn't being mocked; update the
vi.mock call to mock the correct module path
'@pagespace/lib/monitoring/activity-tracker' and ensure the factory returns {
trackPageOperation: vi.fn() } so the imported function used in the test
(trackPageOperation) is intercepted and the
expect(trackPageOperation).toHaveBeenCalledWith(...) assertion uses the mock.

In `@apps/web/src/app/api/pages/`[pageId]/export/csv/__tests__/route.test.ts:
- Around line 43-58: The activity-tracker mock targets the old module path so
trackPageOperation isn't being mocked; update the mock declaration to use the
renamed module '@pagespace/lib/monitoring/activity-tracker' (the same module
imported as trackPageOperation in the test) so vi.mock(...) replaces
trackPageOperation; ensure the mocked export name matches the imported symbol
trackPageOperation and keep the existing vi.fn() implementation used in the test
assertions.

In `@apps/web/src/app/api/pages/`[pageId]/export/markdown/__tests__/route.test.ts:
- Around line 38-58: The test's vi.mock for activity tracking uses the wrong
module specifier so the real trackPageOperation is imported; update the mock to
target the actual import '@pagespace/lib/monitoring/activity-tracker' (and
ensure it exports trackPageOperation as vi.fn()) so the imported
trackPageOperation used in the test is mocked and the assertion around
trackPageOperation will run against the mock.

In `@apps/web/src/app/api/pages/`[pageId]/export/xlsx/__tests__/route.test.ts:
- Around line 43-58: The test is mocking the old path for trackPageOperation so
the imported trackPageOperation used in the test isn't the mock; update the
vi.mock call to match the import path by replacing
vi.mock('@pagespace/lib/activity-tracker', ...) with
vi.mock('@pagespace/lib/monitoring/activity-tracker', () => ({
trackPageOperation: vi.fn() })), ensuring the mock exports the same symbol name
trackPageOperation so assertions against trackPageOperation in the tests use the
mock.

In `@apps/web/src/app/api/track/__tests__/route.test.ts`:
- Around line 24-47: The test's vi.mock call uses the old module specifier and
doesn't match the actual imported module, so replace the mock key
'@pagespace/lib/activity-tracker' with the resolved specifier
'@pagespace/lib/monitoring/activity-tracker' (keeping the mocked exports
trackActivity, trackFeature, trackError) so the imported symbols
trackActivity/trackFeature/trackError are properly mocked and the vi.fn()
assertions and side-effect prevention work as intended.

In `@apps/web/src/lib/websocket/__tests__/socket-utils.test.ts`:
- Around line 9-52: Update the stale vi.mock specifier so the mocked export
matches the actual import: change the mock that currently targets
'@pagespace/lib/broadcast-auth' to '@pagespace/lib/auth/broadcast-auth' so
createSignedBroadcastHeaders (used in tests and asserted with
expect(createSignedBroadcastHeaders).toHaveBeenCalled()) is properly mocked;
also verify and, if necessary, update the logger mock specifier (currently
'@pagespace/lib/logger-browser') to the package's current export (e.g.
'./logging/logger-browser') so the browserLoggers.child mock remains effective.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: a1ebb432-229a-4e88-ab4d-a40b84dc5462

📥 Commits

Reviewing files that changed from the base of the PR and between 5b109f1 and 9accee1.

📒 Files selected for processing (98)
  • apps/processor/src/__tests__/cors-validation.test.ts
  • apps/processor/src/api/ingest.ts
  • apps/processor/src/middleware/auth.ts
  • apps/processor/src/middleware/resource-binding.ts
  • apps/processor/src/services/authorization.ts
  • apps/processor/src/services/rbac.ts
  • apps/processor/src/utils/cors-validation.ts
  • apps/processor/src/workers/ocr-processor.ts
  • apps/processor/src/workers/text-extractor.ts
  • apps/realtime/src/__tests__/auth.test.ts
  • apps/realtime/src/__tests__/index.test.ts
  • apps/realtime/src/__tests__/origin-validation.test.ts
  • apps/realtime/src/index.ts
  • apps/realtime/src/kick-handler.ts
  • apps/realtime/src/per-event-auth.ts
  • apps/web/src/app/api/account/devices/[deviceId]/__tests__/route.test.ts
  • apps/web/src/app/api/account/devices/[deviceId]/route.ts
  • apps/web/src/app/api/account/devices/__tests__/route.test.ts
  • apps/web/src/app/api/account/devices/route.ts
  • apps/web/src/app/api/activities/[activityId]/rollback/route.ts
  • apps/web/src/app/api/admin/global-prompt/route.ts
  • apps/web/src/app/api/ai/chat/messages/[messageId]/undo/route.ts
  • apps/web/src/app/api/ai/chat/route.ts
  • apps/web/src/app/api/ai/global/[id]/messages/route.ts
  • apps/web/src/app/api/ai/global/[id]/usage/__tests__/route.test.ts
  • apps/web/src/app/api/ai/global/[id]/usage/route.ts
  • apps/web/src/app/api/ai/page-agents/consult/route.ts
  • apps/web/src/app/api/auth/__tests__/device-refresh.test.ts
  • apps/web/src/app/api/auth/__tests__/logout.test.ts
  • apps/web/src/app/api/auth/__tests__/mobile-oauth-google-exchange.test.ts
  • apps/web/src/app/api/auth/__tests__/verify-email.test.ts
  • apps/web/src/app/api/auth/apple/callback/__tests__/route.test.ts
  • apps/web/src/app/api/auth/apple/callback/route.ts
  • apps/web/src/app/api/auth/apple/native/__tests__/route.test.ts
  • apps/web/src/app/api/auth/apple/native/route.ts
  • apps/web/src/app/api/auth/device/refresh/__tests__/route.test.ts
  • apps/web/src/app/api/auth/device/refresh/route.ts
  • apps/web/src/app/api/auth/google/__tests__/one-tap.test.ts
  • apps/web/src/app/api/auth/google/callback/__tests__/route.test.ts
  • apps/web/src/app/api/auth/google/callback/route.ts
  • apps/web/src/app/api/auth/google/native/__tests__/route.test.ts
  • apps/web/src/app/api/auth/google/native/route.ts
  • apps/web/src/app/api/auth/google/one-tap/__tests__/route.test.ts
  • apps/web/src/app/api/auth/google/one-tap/route.ts
  • apps/web/src/app/api/auth/logout/route.ts
  • apps/web/src/app/api/auth/magic-link/send/route.ts
  • apps/web/src/app/api/auth/magic-link/verify/__tests__/route.test.ts
  • apps/web/src/app/api/auth/magic-link/verify/route.ts
  • apps/web/src/app/api/auth/mobile/oauth/google/exchange/route.ts
  • apps/web/src/app/api/auth/passkey/[passkeyId]/__tests__/route.test.ts
  • apps/web/src/app/api/auth/passkey/[passkeyId]/route.ts
  • apps/web/src/app/api/auth/passkey/authenticate/__tests__/route.test.ts
  • apps/web/src/app/api/auth/passkey/authenticate/route.ts
  • apps/web/src/app/api/auth/passkey/register/__tests__/route.test.ts
  • apps/web/src/app/api/auth/passkey/register/route.ts
  • apps/web/src/app/api/auth/signup-passkey/__tests__/route.test.ts
  • apps/web/src/app/api/auth/signup-passkey/route.ts
  • apps/web/src/app/api/auth/verify-email/route.ts
  • apps/web/src/app/api/channels/[pageId]/messages/[messageId]/reactions/route.ts
  • apps/web/src/app/api/channels/[pageId]/messages/route.ts
  • apps/web/src/app/api/drives/[driveId]/members/[userId]/__tests__/route.test.ts
  • apps/web/src/app/api/drives/[driveId]/members/[userId]/route.ts
  • apps/web/src/app/api/drives/[driveId]/members/invite/__tests__/route.test.ts
  • apps/web/src/app/api/drives/[driveId]/members/invite/route.ts
  • apps/web/src/app/api/drives/[driveId]/pages/route.ts
  • apps/web/src/app/api/drives/[driveId]/route.ts
  • apps/web/src/app/api/drives/__tests__/route.test.ts
  • apps/web/src/app/api/drives/route.ts
  • apps/web/src/app/api/internal/monitoring/ingest/route.ts
  • apps/web/src/app/api/messages/[conversationId]/route.ts
  • apps/web/src/app/api/pages/[pageId]/__tests__/route.test.ts
  • apps/web/src/app/api/pages/[pageId]/ai-usage/route.ts
  • apps/web/src/app/api/pages/[pageId]/children/route.ts
  • apps/web/src/app/api/pages/[pageId]/export/csv/__tests__/route.test.ts
  • apps/web/src/app/api/pages/[pageId]/export/csv/route.ts
  • apps/web/src/app/api/pages/[pageId]/export/docx/__tests__/route.test.ts
  • apps/web/src/app/api/pages/[pageId]/export/docx/route.ts
  • apps/web/src/app/api/pages/[pageId]/export/markdown/__tests__/route.test.ts
  • apps/web/src/app/api/pages/[pageId]/export/markdown/route.ts
  • apps/web/src/app/api/pages/[pageId]/export/xlsx/__tests__/route.test.ts
  • apps/web/src/app/api/pages/[pageId]/export/xlsx/route.ts
  • apps/web/src/app/api/pages/[pageId]/restore/route.ts
  • apps/web/src/app/api/pages/[pageId]/route.ts
  • apps/web/src/app/api/pages/[pageId]/view/route.ts
  • apps/web/src/app/api/pages/__tests__/route.test.ts
  • apps/web/src/app/api/pages/route.ts
  • apps/web/src/app/api/pulse/cron/route.ts
  • apps/web/src/app/api/pulse/generate/route.ts
  • apps/web/src/app/api/track/__tests__/route.test.ts
  • apps/web/src/app/api/track/route.ts
  • apps/web/src/hooks/useAiUsage.ts
  • apps/web/src/lib/ai/core/complete-request-builder.ts
  • apps/web/src/lib/ai/tools/channel-tools.ts
  • apps/web/src/lib/websocket/__tests__/socket-utils.test.ts
  • apps/web/src/lib/websocket/calendar-events.ts
  • apps/web/src/lib/websocket/socket-utils.ts
  • apps/web/src/lib/workflows/workflow-executor.ts
  • packages/lib/package.json

Comment thread apps/realtime/src/__tests__/index.test.ts
Comment thread apps/web/src/app/api/auth/google/callback/route.ts
Comment thread apps/web/src/app/api/auth/magic-link/verify/__tests__/route.test.ts
Comment thread apps/web/src/app/api/pages/[pageId]/__tests__/route.test.ts
All three trackAuthEvent calls (web, desktop, iOS platforms) were passing
the raw email address. maskEmail was already imported from @pagespace/lib/server
and used in logger calls in the same file.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@2witstudios
2witstudios merged commit 6b45463 into master Apr 23, 2026
10 checks passed
2witstudios added a commit that referenced this pull request May 15, 2026
* refactor(lib): use real subdir paths in exports

Replace 12 flat export aliases in @pagespace/lib with paths
that match the actual source layout:
- ./secure-compare, ./device-auth-utils, ./broadcast-auth,
  ./verification-utils → ./auth/*
- ./activity-tracker, ./ai-monitoring,
  ./ai-context-calculator → ./monitoring/*
- ./logger-config, ./logger-database, ./logger-browser,
  ./logger → ./logging/*
- ./api-utils → ./utils/api-utils

Updates 114 import statements across apps/web, apps/realtime,
and apps/processor. Both exports and typesVersions fields in
package.json updated in lockstep.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(lib): replace flat aliases in mocks and vitest configs

The first pass only caught static `from '...'` imports.
vi.mock(), vi.doMock(), await import(), and vitest.config
alias maps also contained the old flat paths. Replace all
remaining occurrences across apps/web, apps/realtime, and
apps/processor.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(auth): mask email in trackAuthEvent calls in Google OAuth callback

All three trackAuthEvent calls (web, desktop, iOS platforms) were passing
the raw email address. maskEmail was already imported from @pagespace/lib/server
and used in logger calls in the same file.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant