Repository navigation
refactor(imports): direct subpath imports — PR C: Web Auth + Security - #1090
Conversation
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 17 minutes and 52 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (95)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🔬 Code Review — PR #1090: Direct Subpath Imports — Web Auth + Security SurfacePR C of 6 | 95 files | +1072 / -755 OverviewThis PR is a mechanical refactor: every 1. Subpath Target VerificationAll new import targets were cross-checked against the live
No phantom subpaths, no typos detected. 2. Auth Subsystem CorrectnessSpot-checked the highest-value targets: Each symbol is routed to the correct module:
The 3. Next.js Edge Middleware —
|
8ef722d to
fe89786
Compare
Follow-up: Dynamic Import FixesAfter posting the initial review, a secondary pass with Files fixed:
Branch also rebased onto updated |
…surface Replaces barrel imports in the authentication and security layer of apps/web: - apps/web/src/app/api/auth/** (routes + tests) - apps/web/src/lib/auth/** (source + tests) - apps/web/middleware.ts - apps/web/src/lib/subscription/ (rate-limit-middleware, usage-service) Part of the barrel-import removal series — PR C of 6. Depends on barrel/foundation (#1088) being merged first. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…gger stubs
- Standardize vi.mock callback bodies to 2-space indent (was 4-space in all
newly-added @pagespace/lib/* mock blocks)
- Add missing trailing semicolons to import statements across 32 source files
- Remove unnecessary `logger: { child: vi.fn() }` stubs from
@pagespace/lib/logging/logger-config mocks — source files only import
`loggers`, not `logger` directly
No logic changes. All 95 files remain pure import-path swaps.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Replace remaining old barrel references in dynamic await import() calls inside test bodies — session-fixation, device-refresh, mobile-refresh, mobile-oauth-google-exchange, and device/refresh route tests. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
fe89786 to
4b7e5c3
Compare
Fix: gift-subscription security testThe CI Unit Tests run exposed a failing test caused by a cascading effect of our barrel refactor: Root cause: Fix: Added a This file wasn't in the original PR diff because it lives in |
…#1090) * refactor(imports): use direct subpath imports in web auth + security surface Replaces barrel imports in the authentication and security layer of apps/web: - apps/web/src/app/api/auth/** (routes + tests) - apps/web/src/lib/auth/** (source + tests) - apps/web/middleware.ts - apps/web/src/lib/subscription/ (rate-limit-middleware, usage-service) Part of the barrel-import removal series — PR C of 6. Depends on barrel/foundation (#1088) being merged first. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * style: normalize vi.mock indentation, semicolons, and remove stale logger stubs - Standardize vi.mock callback bodies to 2-space indent (was 4-space in all newly-added @pagespace/lib/* mock blocks) - Add missing trailing semicolons to import statements across 32 source files - Remove unnecessary `logger: { child: vi.fn() }` stubs from @pagespace/lib/logging/logger-config mocks — source files only import `loggers`, not `logger` directly No logic changes. All 95 files remain pure import-path swaps. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(tests): migrate dynamic import() calls to direct subpath imports Replace remaining old barrel references in dynamic await import() calls inside test bodies — session-fixation, device-refresh, mobile-refresh, mobile-oauth-google-exchange, and device/refresh route tests. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Summary
Replaces barrel imports with direct subpath imports across the web app's auth and security surface:
apps/web/src/app/api/auth/**— all auth API routes and their testsapps/web/src/lib/auth/**— auth utilities, session service, admin role, middlewareapps/web/middleware.ts— Next.js edge middlewareapps/web/src/lib/subscription/— rate-limit middleware, usage service95 files total — all mechanical import-path swaps. No logic changes.
Context
PR C of 6 in the barrel-import removal series.
barrel/foundationbeing merged first.Base branch is
barrel/foundationso CI resolves the new subpath exports.After A merges, this PR's base will be updated to
master.Why auth is grouped together
The auth routes, auth lib, and middleware form a coherent security surface. Grouping them lets reviewers verify the entire auth path in one pass — ensuring no session handling, token validation, or permission logic was accidentally altered.
Changes pattern
Test mocks are updated in the same PR to match:
Verification
pnpm --filter web typecheckpasses (no auth-related TS errors)pnpm --filter web exec vitest run src/app/api/auth src/lib/authReview
Please use
/aidd:reviewfor AI-assisted review. Key questions:apps/web/middleware.tsstill correctly import from the right auth modules?🤖 Generated with Claude Code