Skip to content

fix: schema dump integration cleanup and webui npm audit - #80

Merged
zx06 merged 1 commit into
mainfrom
cursor/integration-cleanup-npm-audit-8ee7
Oct 10, 2026
Merged

zx06 merged 1 commit into
mainfrom
cursor/integration-cleanup-npm-audit-8ee7

Conversation

@zx06

@zx06 zx06 commented Oct 10, 2026

Copy link
Copy Markdown
Owner

Summary

Fixes two maintenance items: integration test resource leaks in schema dump tests, and three high-severity npm audit findings in webui/.

1. Schema dump integration test cleanup

Root cause: t.Cleanup used the test’s 20s timeout context and the same *sql.DB that defer conn.Close() already closed. Cleanup runs after defers, so DROP failed silently and left xsql_schema_* MySQL tables / PostgreSQL schemas behind. A second run then failed TestSchemaDump_Pg_RealDB at the ListTables assertion because the xsql_* pattern matched tables in leftover schemas.

Fix:

  • Open a fresh connection with a dedicated cleanup context (30s, not tied to the test ctx) inside t.Cleanup.
  • Proactively remove stale xsql_schema_* artifacts at test start (from prior failed cleanups).
  • PG ListTables assertion counts only tables in the current test schema so unrelated leftovers do not fail the test.

Verified locally against MySQL 8.0 and PostgreSQL 16 (Docker): full integration suite run twice in a row, zero xsql_schema_* leftovers afterward.

2. webui npm audit

Ran npm audit fix in webui/ to resolve high-severity issues in transitive deps: devalue, nanoid, source-map-js. npm audit now reports 0 high vulnerabilities. This supersedes open Dependabot PR #74 (devalue bump).

Verification

  • npm audit (webui): 0 high
  • npm run build (webui)
  • go build ./...
  • go vet ./...
  • go test ./...
  • go test -tags=e2e ./tests/e2e/...
  • go test -tags=integration ./tests/integration/... (×2)
  • golangci-lint run ./...

中文摘要

  1. 集成测试清理:schema dump 集成测试在 t.Cleanup 中使用了已取消的测试 context 和已被 defer 关闭的连接,导致 DROP 未执行、数据库残留 xsql_schema_* 对象;第二次运行 PG 测试会在 ListTables 处失败。现已改为 cleanup 使用独立连接与 context,并在测试开始时清理历史残留;PG 断言限定在当前 schema。
  2. webui 安全依赖:通过 npm audit fix 修复 devalue / nanoid / source-map-js 三个高危漏洞,替代 Dependabot PR chore(deps): bump devalue from 5.8.1 to 5.9.4 in /webui #74。
Open in Web Open in Cursor 

- Use a fresh DB connection and non-cancelled context in t.Cleanup so
  DROP runs after defer conn.Close and after the test context expires.
- Remove stale xsql_schema_* artifacts at test start; scope PG ListTables
  assertions to the test schema for leftover tolerance.
- npm audit fix for devalue, nanoid, and source-map-js (supersedes #74).

Co-authored-by: x_zhuo <zx06@users.noreply.github.com>
@sonarqubecloud

Copy link
Copy Markdown

@codecov

codecov Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.69%. Comparing base (cf876ab) to head (a6100f6).
⚠️ Report is 2 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff             @@
##             main      #80      +/-   ##
==========================================
+ Coverage   82.65%   82.69%   +0.03%     
==========================================
  Files          65       65              
  Lines        6349     6349              
==========================================
+ Hits         5248     5250       +2     
+ Misses        824      823       -1     
+ Partials      277      276       -1     
Flag Coverage Δ
e2e 27.72% <ø> (ø)
integration 27.72% <ø> (ø)
unittests 75.94% <ø> (+0.03%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@zx06
zx06 marked this pull request as ready for review October 10, 2026 05:11
@zx06
zx06 merged commit a1cc4f0 into main Oct 10, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants