Skip to content

chore: 릴리즈 — 관리자 알림 이력·카테고리 null 필터 500 수정 - #486

Merged
chanwoo7 merged 3 commits into
mainfrom
develop
Oct 4, 2026
Merged

chanwoo7 merged 3 commits into
mainfrom
develop

Conversation

@chanwoo7

@chanwoo7 chanwoo7 commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

#484 릴리즈입니다. 운영 관리자 웹 '알림' 메뉴의 서버 오류와 구매자 앱 카테고리 조회의 같은 유형 500을 고칩니다. 마이그레이션은 없습니다.

머지 뒤 develop을 재생성합니다.

Summary by CodeRabbit

  • 개선 사항
    • 알림 발송 이력에서 필터 값으로 null을 전달하면 해당 필터를 적용하지 않고 전체 목록을 조회합니다.
    • 상품 카테고리 조회에서 유형을 null로 전달하면 유형 제한 없이 전체 카테고리를 조회합니다.
  • 테스트
    • nullable 입력값을 사용하는 관리자 GraphQL 조회와 전체 카테고리 조회 동작을 검증하는 테스트를 추가했습니다.

관리자 FE가 알림 이력 '전체' 필터를 type: null, targetKind: null로 보내면 service가 null을 그대로 repository로
넘겨 Prisma where에 type: null이 들어가 500(Argument `type` must not be null). 매장·상품·배너 isActive(#434)에 이은
두 번째 같은 유형이라, 이번에는 admin Query 전수를 SDL에서 읽어 실제 앱으로 보내는 게이트로 막는다.

- adminNotificationBroadcasts: type·targetKind를 ?? undefined로 정규화, DTO를 | null로 선언해 다음 누락은 tsc가 잡게 함
- 전수 점검: input 객체를 받는 admin Query 17개, nullable 입력 필드 70자리
  - 고침 2(알림 이력 type·targetKind)
  - 그대로 둠 68: 페이지 limit·cursor 27, keyword trim 7, ID parseOptionalId 13, 기본값 false 불리언 4, 날짜 toDate 5,
    repository가 truthy·일치 비교로 거르는 enum 8, 명시적 null = 전체인 신고 status 1, 이미 정규화된 isActive 3
- 게이트 src/test/admin-query-null-inputs.spec.ts
  - nullable 필드 전부 null, input 인자 자체 null 두 경우를 main.ts와 같은 파이프·필터·가드·실DB로 보내 5xx·INTERNAL_ERROR 없음,
    리졸버까지 닿아 data가 옴을 단언(17 + 16건)
  - 대상 수 17 고정, 입력 오류는 VALIDATION_FAILED(400)로 나가는지 대조, 판정기·입력 생성기 반증
  - 반증 실측: 알림 정규화를 되돌리면 adminNotificationBroadcasts 1건만 실패(운영과 같은 Prisma 오류),
    isActive 3자리를 되돌리면 adminStores·adminProducts·adminBanners 3건 실패
- createTestingModuleWithRealDb가 PrismaService를 override해 AppModule 트리도 실DB 테스트 클라이언트를 쓰게 함
- 회귀: 알림 service spec·DTO spec에 null 필터 케이스 추가
- 전수 점검 중 발견: categories(input: { type: null })이 category_type: null을 Prisma에 넘겨 500(홈 칩·카테고리 진입 화면이 쓰는 조회)
- service ?? undefined 정규화 + DTO | null
- 회귀: type null이면 전체(수정 전 'category_type must not be null'로 실패 확인)
fix: 관리자 알림 이력·공개 카테고리의 null 필터 500 수정과 관리자 Query null 입력 게이트
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: CaQuick/caquick-be/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2304588e-3d8f-4874-ba25-c5e90058d975
📥 Commits

Reviewing files that changed from the base of the PR and between 3483e34 and 9c15e94.

📒 Files selected for processing (9)
  • src/features/notification/dto/inputs/admin-notification-broadcast-list.input.spec.ts
  • src/features/notification/dto/inputs/admin-notification-broadcast-list.input.ts
  • src/features/notification/services/notification-admin.service.spec.ts
  • src/features/notification/services/notification-admin.service.ts
  • src/features/product/dto/inputs/categories.input.ts
  • src/features/product/services/product-category.service.spec.ts
  • src/features/product/services/product-category.service.ts
  • src/test/admin-query-null-inputs.spec.ts
  • src/test/modules/testing-module.builder.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

알림 및 카테고리 조회에서 null 필터를 미지정 필터로 처리하도록 변경했습니다. 관리자 GraphQL 쿼리에 null 입력을 전달하는 실제 DB 통합 테스트와 테스트용 Prisma 서비스 재정의를 추가했습니다.

Changes

nullable 입력 처리

Layer / File(s) Summary
null 필터 정규화
src/features/notification/dto/inputs/admin-notification-broadcast-list.input.ts, src/features/notification/services/notification-admin.service.ts, src/features/notification/dto/inputs/admin-notification-broadcast-list.input.spec.ts, src/features/notification/services/notification-admin.service.spec.ts, src/features/product/dto/inputs/categories.input.ts, src/features/product/services/product-category.service.ts, src/features/product/services/product-category.service.spec.ts
알림 입력의 type과 targetKind, 카테고리 입력의 type에 null을 허용합니다. 조회 서비스는 null 필터를 undefined로 바꿉니다. 테스트는 null 입력에서 전체 결과가 반환되는지 확인합니다.
관리자 쿼리 null 입력 통합 테스트
src/test/admin-query-null-inputs.spec.ts, src/test/modules/testing-module.builder.ts
SDL에서 관리자 쿼리의 입력값을 생성하고, 실제 API 앱에 nullable 필드와 입력 인자 자체가 null인 요청을 보냅니다. HTTP 5xx 및 GraphQL 오류를 검사하고, 테스트 모듈의 PrismaService를 테스트 클라이언트로 재정의합니다.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to 9c15e

Null filters are handled as unfiltered queries, and no outstanding merge-blocking issue was identified. The PR is mergeable after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 9c15e

The filter correction preserves existing access restrictions and does not expose more data than omitting the filters already did. Remaining uncertainty concerns test isolation and cleanup under interrupted or concurrent runs, rather than a demonstrated production security regression.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — On the inspected production paths, explicit null reaches no broader data set than omission already allowed: administrator-wide notification broadcast history and active category metadata. Normalization does not add a writer, remove the active-category predicate, or create a new privilege transition.

Trust Boundaries and Controls

  • observed — The notification resolver retains JWT authentication and ADMIN role enforcement. Before repository access, the service independently checks account existence, ADMIN account type, and ACTIVE status. Caller-controlled null filters are normalized only after that database-backed administrator check.
  • observed — The full-app test explicitly disables outbox dispatch. Both the outbox relay and RabbitMQ consumer host return without starting background work when dispatch is disabled, and the API role does not load the scheduler.

Resilience and Maintainability Implications

  • observed — Configured Jest setup starts MySQL and Redis test containers and records their endpoints. Database helpers select a worker-specific schema, and destructive reset uses that cached test database URL. Normal suite teardown closes application and database connections; global teardown stops containers and removes state and schema markers. Independent concurrent runs and complete interrupted-startup cleanup remain unverified.
🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 42.86% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 9 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed 관리자 알림 이력과 카테고리 조회의 null 필터로 발생하는 500 오류 수정 내용을 간결하게 설명합니다.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🧹 knip — dead-code 리포트

Unused exported types (1)
전체 리포트
Unused exported types (1)
RateLimitPolicy  type  src/global/rate-limit/index.ts:4:8

청소 후보(오탐 가능) · 기준 docs/guide/architecture-conventions.md

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🩺 NestJS Doctor — 90/100 (Excellent)

진단 470건 (error 12).

Category error warning info
architecture 1 1 42
correctness 0 261 0
performance 0 30 28
schema 0 0 75
security 11 21 0
architecture / security 상위 항목
  • error architecture/architecture/no-manual-instantiation: Manual instantiation of 'OutboxRepository' detected. Use dependency injection instead.
  • info architecture/architecture/no-barrel-export-internals: Barrel file re-exports internal type 'IAuditLogRepository'.
  • warning security/security/no-exposed-env-vars: Direct 'process.env.NODE_ENV' access in 'AuthController'. Use ConfigService instead.
  • warning security/security/require-guards-on-endpoints: Endpoint 'start' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'callback' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'refresh' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'logout' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'sellerLogin' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'sellerRefresh' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'sellerLogout' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'devIssueToken' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'adminLogin' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'adminRefresh' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'adminLogout' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'getJwks' has no @UseGuards() at class or method level.

오탐 포함 가능 · 기준 docs/guide/architecture-conventions.md

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

Coverage report

St.❔
Category Percentage Covered / Total
🟢 Statements 97.9% 10043/10258
🟢 Branches 92.4% 3783/4094
🟢 Functions 97.4% 2020/2074
🟢 Lines 98.5% 9137/9276

Test suite run success

3723 tests passing in 355 suites.

Report generated by 🧪jest coverage report action from 9c15e94

@codecov

codecov Bot commented Oct 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@chanwoo7
chanwoo7 merged commit 234063b into main Oct 4, 2026
17 checks passed
@chanwoo7
chanwoo7 deleted the develop branch October 4, 2026 12:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant