Follow-ups from the round-2 re-review of #266 (#233, merged as 81b13b20). Details are in the review comment on #266.
- N1 — the bare-
/api arm of the shadow guard is not pinned. If tmpl == "/api" is dropped from apiRoutesShadowedByFallback, the suite stays green (mutant D). Add a test.
- N2 — the self-dispatch guard in
getRouteHandler is not pinned. This is the guard where GetMethods() errors, the matched route is the fallback itself, and the result is nil. Removing it leaves the suite green (mutant L). Add a test.
- N3 —
TestPostPacketsRemovedFallsThroughToSPAInProductionRouter now asserts 405 + Allow. Rename it to match.
- N4 — the API-only banner in
cmd/server/main.go (~662) still says "API available at /api/". That path is now a JSON 404. Point it to an existing endpoint such as /api/docs or /api/spec.
Follow-ups from the round-2 re-review of #266 (#233, merged as
81b13b20). Details are in the review comment on #266./apiarm of the shadow guard is not pinned. Iftmpl == "/api"is dropped fromapiRoutesShadowedByFallback, the suite stays green (mutant D). Add a test.getRouteHandleris not pinned. This is the guard whereGetMethods()errors, the matched route is the fallback itself, and the result isnil. Removing it leaves the suite green (mutant L). Add a test.TestPostPacketsRemovedFallsThroughToSPAInProductionRouternow asserts 405 +Allow. Rename it to match.cmd/server/main.go(~662) still says "API available at/api/". That path is now a JSON 404. Point it to an existing endpoint such as/api/docsor/api/spec.