Skip to content

Remove unreachable helpers and keep tests on live contracts - #481

Merged
OziinG merged 1 commit into
mainfrom
codex/ai-slop-audit
Oct 6, 2026
Merged

OziinG merged 1 commit into
mainfrom
codex/ai-slop-audit

Conversation

@OziinG

@OziinG OziinG commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Private API and Route Ops modules kept unused wrappers and policies alive solely through tests. This removes those unreachable paths and their dependent types/tests, moves the shared push fake into test support, and makes the retained tests exercise the actual runtime factories, diagnostic parser, token verifier, and dispatch ownership guard.

  • Net reduction: 1,416 product lines and 580 test lines across 54 files; no dependencies added.
  • All 341 HTTP route registrations and retained API function/class bodies are unchanged. Three transaction parameter types are simplified after deleting unused members.
  • The 10 Route Ops production artifact files have identical SHA-256 hashes before and after cleanup.
  • Auth/tenant/privacy, DTO shape, current token rejection, advisory-lock order, and fail-closed checks remain. Schema, migrations, deployment configuration, operational CLIs, and external API contracts are unchanged.

Validation: Prisma generation; API lint/typecheck/build and 3,020 passing tests; web lint/typecheck/build and 185 passing tests; 9 workflow/structure contracts; secret/ignore/diff checks. API tests have 240 existing environment-dependent skips locally. The exact commit passed CI, including 236 disposable-PostgreSQL tests and Compose validation, plus GitGuardian. Two pre-existing DB suites (operational-alert.repository.integration.test.ts and order-filters-v2.integration.test.ts, 8 tests total) are outside that CI profile and remain unexecuted; their implementation is unchanged. Independent backend safety and frontend/residual reviews approved the cleanup.

Remaining audit findings: keep buildDispatchImportPreview while its path overlaps #427. Keep isRouteVisibleToLinkedDriver: the existing Route Builder displays “Visible to driver” for an INVITE_PENDING driver assigned a published route, despite the helper returning false (SSR reproduced). That UI mismatch predates this PR and is separate from server authorization. Unused properties inside live locale objects and some source-string structural tests remain for a separate property/contract review. The two remaining static export candidates do not imply a complete semantic audit of all source files.

No deployment or merge is included.

Remove unused API and Route Ops helpers, dependent types, and their dedicated
checks. Exercise active runtime factories, diagnostic parsers, token guards,
and dispatch ownership instead; keep the shared push fake in test support.

Constraint: Preserve exposed routes, tenant boundaries, and driver compatibility.
Rejected: Delete every static candidate automatically | shorthand injection and disconnected UI intent require caller review.
Confidence: high
Scope-risk: moderate
Tested: API lint/typecheck/build and 3020 tests; web lint/typecheck/build and 185 tests; 341 route registrations and 10 web asset hashes unchanged.
Not-tested: Local disposable DB unavailable; PR CI must run the PostgreSQL profile. No production or authenticated device/browser smoke.
@OziinG
OziinG marked this pull request as ready for review October 6, 2026 04:49
@OziinG
OziinG merged commit 5bc861f into main Oct 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant