Skip to content

test(ui): cover snapshot-replay privacy boundary (#8386) - #8439

Merged
loopover-orb[bot] merged 1 commit into
JSONbored:mainfrom
jsdevninja:test/snapshot-replay-privacy-coverage-v2
Jul 24, 2026
Merged

test(ui): cover snapshot-replay privacy boundary (#8386)#8439
loopover-orb[bot] merged 1 commit into
JSONbored:mainfrom
jsdevninja:test/snapshot-replay-privacy-coverage-v2

Conversation

@jsdevninja

Copy link
Copy Markdown
Contributor

Summary

Scope

  • The PR title follows type(scope): short summary Conventional Commit format, for example fix(api): restore profile access checks.
  • This PR is focused and does not mix unrelated backend, UI, MCP, docs, dependency, and deploy changes.
  • This follows CONTRIBUTING.md and does not reintroduce GitHub Pages, VitePress, site/, or CNAME.
  • I linked a currently open issue this PR resolves (e.g. Closes #123) — a linked open issue is required for every contributor PR.

Validation

  • git diff --check
  • npm run actionlint
  • npm run typecheck
  • npm run test:coverage locally; codecov/patch requires ≥99% coverage of the lines AND branches you changed (aim for 100% on your diff so CI variance does not fail near the threshold). Global coverage is a non-blocking trend with a loose 90% backstop, not the gate.
  • npm run test:workers
  • npm run build:mcp
  • npm run test:mcp-pack
  • npm run ui:openapi:check
  • npm run ui:lint
  • npm run ui:typecheck
  • npm run ui:test (via npm --workspace @loopover/ui run test -- src/lib/snapshot-replay.test.ts src/components/site/snapshot-replay.test.tsx — 17 passing)
  • npm audit --audit-level=moderate
  • New or changed behavior has unit/integration tests for new branches, fallback paths, and sanitizer boundaries

If any required check was skipped, explain why:

  • Test-only UI change under apps/** (Codecov ignore). No src/** backend changes. Focused vitest suite green (17 tests).

Safety

  • No secrets, wallet details, hotkeys, coldkeys, user PATs, private keys, raw trust scores, private rankings, or private maintainer evidence are exposed.
  • Public GitHub text stays sanitized, low-noise, and does not imply compensation guarantees or optimization tactics.
  • Auth, cookie, CORS, GitHub App, Cloudflare, or session changes include negative-path tests.
  • API/OpenAPI/MCP behavior is updated and tested where needed.
  • UI changes use live API data or real empty/error/loading states, not production mock/demo fallbacks.
  • Visible UI changes include a UI Evidence section below with JPG/JPEG or PNG screenshots arranged as organized, captioned, clickable thumbnails. SVG screenshots are not used as review evidence. Review-only screenshots or recordings are not committed to the repository.
  • Public docs/changelogs are updated where needed; changelogs are only edited for release-prep PRs.

UI Evidence

No rendered UI source changed — only *.test.ts / *.test.tsx were added. Before and after are identical captures of production / (dark-mode-only UI) so every required viewport × theme row is present. Light rows use the same dark rendering under prefers-color-scheme: light, matching the house convention that loopover-ui has no separate light theme.

State / title Before (main) After (this PR)
Homepage — no visual delta (test-only) — Desktop · Light before Desktop Light after Desktop Light
Homepage — no visual delta (test-only) — Desktop · Dark before Desktop Dark after Desktop Dark
Homepage — no visual delta (test-only) — Tablet · Light before Tablet Light after Tablet Light
Homepage — no visual delta (test-only) — Tablet · Dark before Tablet Dark after Tablet Dark
Homepage — no visual delta (test-only) — Mobile · Light before Mobile Light after Mobile Light
Homepage — no visual delta (test-only) — Mobile · Dark before Mobile Dark after Mobile Dark

Notes

@jsdevninja
jsdevninja requested a review from JSONbored as a code owner July 24, 2026 13:08
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 24, 2026
@loopover-orb

loopover-orb Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Tip

✅ LoopOver review result - approve/merge recommended

Review updated: 2026-07-24 13:19:55 UTC

2 files · 1 AI reviewer · no blockers · readiness 93/100 · CI green · clean

✅ Suggested Action - Approve/Merge

  • safe to merge

Review summary
This PR adds two pure test files covering `buildSnapshotReplayView` and the `SnapshotReplay`/`SnapshotReplayCard` components, targeting the public/authenticated privacy boundary for counterfactual reason/facts/assumptions fields. The tests exercise real exported functions/components against varied inputs (missing snapshot, partial snapshot, stale freshness, repo filtering, confidence narrowing) and assert on their actual output rather than fabricating unreachable states, so they look like genuine regression coverage rather than padding. No production code is touched in this diff.

Nits — 6 non-blocking
  • The repo-filtering test asserts case-insensitive matching (`ACME/WIDGET` vs `acme/widget`) but I can't see the source's normalization logic in this diff — worth a quick source-side comment noting that's intentional if not already documented.
  • Comment banners like `// (snapshot-replay.ts's public/authenticated privacy boundary has zero test coverage #8386) Regression coverage...` atop both test files are a bit verbose for a docstring-style header; a one-line comment would suffice per repo convention preferences for minimal comments.
  • Consider consolidating the repeated fixture builders (`freshProvenance`, `baseSnapshot`, `counterfactualFixture`) into a shared test-utils module if similar snapshot-replay fixtures show up in other test files later.
  • No changes needed to production code here — if `buildSnapshotReplayView`'s source isn't already covered for the `null`/`undefined`/array snapshot branches, this test now locks that behavior in, which is good regression insurance.
  • Possible screenshot-table issue: identical images (row 1) — Advisory only — verify the screenshot-table images against the stated change before deciding.
  • Possible screenshot-table issue: identical images (row 2) — Advisory only — verify the screenshot-table images against the stated change before deciding.

Decision drivers

  • ✅ Code review — No blockers (1 reviewer)
  • ✅ Gate result — Passing (No configured blocker found.)
Context & advisory signals — never blocks the verdict
Signal Result Evidence
Linked issue ✅ Linked #8386
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (1 linked issue).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 215 registered-repo PR(s), 130 merged, 39 issue(s).
Contributor context ✅ Confirmed Gittensor contributor jsdevninja; Gittensor profile; 215 PR(s), 39 issue(s).
Improvement ℹ️ Insufficient signal risk: clean · value: insufficient-signal · LLM: moderate
Linked issue satisfaction

Addressed
The PR adds both required test files with coverage matching every listed requirement: public stripping/withheldPrivateFields, authenticated pass-through, missing/partial snapshot handling, each stale trigger plus the all-clear case, repo filtering (including null-target keep-all), confidence/freshness narrowing, and the component-level audience toggle, missing-status notice-only render, and withhe

Review context
  • Author: jsdevninja
  • Role context: outside_contributor
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: JavaScript, Swift, C, CSS, MDX, Python, TypeScript, Vue
  • Official Gittensor activity: 215 PR(s), 39 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Start here: Triage stale or unlinked PRs.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.
🧪 Chat with LoopOver

Ask LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.

  • @loopover ask <question> answers contribution-quality Q&A with source citations and freshness.
  • @loopover chat <question> answers in natural prose from cached decision-pack facts via local inference (maintainer/collaborator; read-only).
  • A plain-language @loopover mention with a real question is routed to the closest matching read-only command automatically — no exact syntax required.

Full command reference: https://loopover.ai/docs/loopover-commands

🧪 Experimental — new and may change.

Visual preview
Route Viewport Before (production) After (this PR's preview) Diff
/ desktop before /
before /
after /
after /
/ mobile before / (mobile)
before / (mobile)
after / (mobile)
after / (mobile)

Click any thumbnail to open the full-size screenshot. Before = production · After = this PR's preview deploy.

Scroll preview
Route Before (production) After (this PR's preview)
/ before / (scroll)
before / (scroll)
after / (scroll)
after / (scroll)

A short scroll-through clip (desktop) — click either thumbnail to open the full animation. Evidence for scroll-linked behavior a single screenshot can't show.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.

  • Re-run LoopOver review

@loopover-orb loopover-orb Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LoopOver approves — the gate is satisfied and CI is green.

@loopover-orb
loopover-orb Bot merged commit 1dba0ec into JSONbored:main Jul 24, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

snapshot-replay.ts's public/authenticated privacy boundary has zero test coverage

1 participant