Skip to content

chore: codebase-review cleanups — concurrency, keychain memoization, registry-owned tiers, postApply hook, dead code (#35) - #41

Merged
2000game merged 5 commits into
mainfrom
chore/codebase-cleanups-35
Jul 9, 2026
Merged

2000game merged 5 commits into
mainfrom
chore/codebase-cleanups-35

Conversation

@2000game

@2000game 2000game commented Jul 9, 2026

Copy link
Copy Markdown
Member

Implements #35 items 1–12 plus addendum items 14–15. Item 13 (permission revocation state-tracking) is deliberately left open as a feature; item 16 (changelog note) waits for a changelog to exist.

Efficiency (items 1–4)

  • Dynamic fold fetches per-group ruleset+status via mapConcurrent (8) — kept ruleset→status sequential per group (the status GET's 404/sentinel semantics depend on the ruleset GET's outcome).
  • buildPlan + buildPermissionPlan now run under Promise.all in plan and apply.
  • Permission writes pooled at concurrency 6, deterministic collection — PR fix: enforce token↔host binding; resolve permission scopes against desired ∪ state with apply-time re-resolution #39's per-tuple re-resolution and pending-guard preserved.
  • Keychain read memoized per process (was 3 security spawns per run) with exported cache reset, invalidated on store/clear.

Altitude (items 5–7)

  • SyntheticField.postApply hook: --refresh no longer hardcodes the dynamic field + demote sentinel in the command layer.
  • Registry entries own their apply tier; TYPE_TIER is derived, phantom types dropped; registry↔ConfigContext sync locked by test.
  • computePlan throws on duplicate desired keys instead of silently last-winning.

Dead code / micro (items 8–12) + addendum

  • refreshCsrfToken reuses this.get; authenticate unwrap aligned with request().
  • Unreachable host check removed; single-pass opt-in folds; no-op sort dropped; CATALOG exported as a constant.
  • Item 14: permission apply reports which tuples failed with a clean resumable summary instead of a raw stack.
  • Item 15: a pure status flip no longer re-PUTs the byte-identical ruleset.

Rebased onto main after PR #40; the one overlap (applyHierarchy single-pass, done independently on both branches) resolved keeping the variant with the explicit managed-type guard.

Verification: 272 passed / 4 skipped, typecheck + lint clean.

Closes #35.

2000game added 5 commits July 9, 2026 08:11
…UT, dup-key guard (#35)

- item 1: dynamicField.fold fetches each group's ruleset+status via mapConcurrent
  (concurrency 8) instead of 2N serial round-trips; per-group errors collected in
  input order so plan degradation stays deterministic.
- item 10: fold + applyHierarchy iterate desired opt-ins once (state lookup) instead
  of build-a-Set-then-invert-over-state; one copy of the predicate, managed-type guard kept.
- item 15: dynamicField.apply skips the byte-identical ruleset re-PUT on a pure status
  flip (deepEqual, now exported from plan.ts); still PUTs both when the ruleset changed.
- item 7: computePlan throws on duplicate desired keys instead of silently last-wins.
- item 5 (partial): SyntheticField.postApply hook + runPostApplyHooks driver; the dynamic
  refresh moves off the command layer onto the dynamic field.
…erm apply (#35)

- item 2: buildPlan + buildPermissionPlan run via Promise.all in plan/apply — the slow
  instance-wide /permissions/<domainType> fetch hides behind the resource fetches.
- item 3: permission writes fan out at concurrency 6 (independent rows); result counts
  collected in flattened op order, deterministic regardless of completion order. Preserves
  PR #39's per-tuple re-resolution against post-execute state.
- item 14: a failed permission write is captured in `failed` instead of aborting the batch;
  apply prints a clean resumable summary (which tuples failed) and exits non-zero, mirroring
  executePlan's 'Stopped at ...' stance.
- item 4: keychain read memoized per process with resetKeychainCache() (invalidated on
  store/clear) — one `security` spawn per run instead of up to three.
- item 5/9 wiring: apply drives runPostApplyHooks for --refresh; plan drops the unreachable
  host check (loadState already throws on mismatch).
… drop phantoms (#35 item 6)

Each RESOURCES entry now carries its `tier`; engine/graph.ts derives TYPE_TIER from the
registry instead of a parallel hand-maintained table. Removes the phantom entries
(group-status, group-hierarchy, permission, dynamic-group) that were never DesiredResource
types. Export shape (Record<string, number>) unchanged so computePlan keeps working.
Tests lock registry<->TYPE_TIER and registry<->ConfigContext in sync.
- item 8: refreshCsrfToken is now `this.get('/csrftoken')` (GET skips the CSRF branch, so no
  recursion) and reuses request()'s guarded unwrap; authenticate aligns to the same tolerant
  `.data ?? body` unwrap. Preserves assertMinVersion + guarded 2xx parsing.
- item 11: drop the no-op dataId sort in normalizeActual (dataId is [] or single-element;
  tupleKey sorts defensively anyway).
- item 12: export the catalog as the CATALOG constant instead of a loadCatalog() wrapper that
  loads nothing; update callers.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore: codebase-review cleanups — serial I/O, keychain triple-read, type-registration drift, dead code

1 participant