Repository navigation
feat(tray): app health in the tray tooltip and menu - #314
Conversation
Mira PR WalkthroughThis PR adds app health monitoring to the system tray tooltip and menu. It implements a new API endpoint
5 files reviewed · 1 comment (
|
|
/mira pause |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
| @@ -167,3 +167,39 @@ test("status and diagnostics show validated build details (#119)", () => { | |||
| assert.equal(broken.snapshot().build, null); | |||
There was a problem hiding this comment.
Refactor suggestion
Missing test coverage for tray endpoint cross-site guard
The test 'tray endpoint serves the same line' includes a cross-site request check (sec-fetch-site: cross-site). However, the test does not verify that the guard works for other unsafe sites (e.g., 'cross-origin', 'same-origin' but with wrong value). The test only checks cross-site returns 403. It should also verify that same-site requests (undefined or 'same-origin') succeed. The existing test for /api/status may have such coverage. Since the guard is shared across all API endpoints, the test coverage is adequate but could be more explicit.
Prompt for AI Agents
Add a test case to verify that same-origin requests (undefined sec-fetch-site or 'same-origin') succeed for /api/tray endpoint, ensuring the guard works correctly.
Not useful? Reply
@mira-reviewer-rk rejectto dismiss this suggestion.
There was a problem hiding this comment.
Added same-site (403), same-origin (200) and none/direct (200) cases next to the cross-site one.
Closes #121
GET /api/trayon the status handler, with the same same-origin guard. It returns{ status, action, text }built with the existingcreateTrayHealthmodel (feat: add privacy-safe tray health state #184) from the live app status.