Repository navigation
chore(release): prepare 5.5.1 - #75
Merged
Merged
Conversation
…class return type - generateToken rethrows the stale-password VersionError/DocumentNotFoundError as a BadRequestError with the exact wrong-password body, so a custom login needs no catch to avoid a 500. The Auth controller's own catch is removed. - Auth and Role declare the base Promise<void | Response> again: 5.5.0 inferred Promise<void>, so a subclass answering with res.json() failed to compile (TS2416). - Plans: consumer-review-fixes card; the validation-registry change is queued for 5.6 (behavior change for catch-all handlers).
Bump to 5.5.1, date the release notes, add README upgrade notes and the release card with the verification results. The 5.5.0 notes also say that an app's own controllers/Health.ts replaces the built-in controller and that the Role/RateLimiter bodies gain an error field.
- oxc-parser: dev dependency and optional peer move to ^0.153.0. Codegen output is unchanged; projects that run `npm run gen` update with `npm i -D oxc-parser@^0.153.0` (CHANGELOG and README upgrade notes). - mongoose 9.11.0 (with its mongodb 7.7.0 driver) and lefthook 2.1.17: lockfile only, within the existing ranges.
The emitted ValidationError.d.ts fails under `skipLibCheck: false` (TS2416 on `message`). It predates 5.5.1 and was left out of it without being assessed; the 5.6 validation-registry plan now carries the fix and a smoke-test import. The 5.5.1 card records the omission, the dependency updates and the re-run verification.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prepares 5.5.1, a patch with two fixes from an app-side review of 5.5.0. Nothing is published or tagged by this PR.
a2a2ec3). When the stored password changed after the user was read,user.generateToken()threw a raw MongooseVersionError/DocumentNotFoundError, so a custom login without its own catch answered 500. It now rejects with aBadRequestErrorthat answers exactly like a wrong password (400 { message: 'User/password not valid' }, viaauth.errorUPValid, no code). The built-inAuthcontroller's catch is removed.Auth/Rolesubclass return type (a2a2ec3). 5.5.0 made both only throw, so TypeScript inferredPromise<void>. A subclass whosemiddleware()returnsres.status(…).json(…)failed with TS2416. Both declare the basePromise<void | Response>again.RateLimiterstill has ares.jsonpath and was never affected.47d11c9): the optionaloxc-parserpeer and dev dependency move to^0.153.0(codegen output byte-identical; projects that runnpm run genupdate withnpm i -D oxc-parser@^0.153.0, noted in CHANGELOG and README).mongoose9.11.0 (mongodb driver 7.7.0) andlefthook2.1.17 are lockfile-only.3924c96):package.jsonand the root ofpackage-lock.jsongo to 5.5.1; dated## [5.5.1] - 2026-10-06notes; README "Upgrade notes (5.5.1)".controllers/Health.tsreplaces the built-in controller, so/health/liveand/health/readyare not served until it extends the built-in one; theRole/RateLimiterbodies gain anerrorfield (messages and statuses unchanged).done/consumer-review-fixes.mdanddone/release-5.5.1.md. Routing request-validation 400s through the error registry is held back for 5.6 (queued/validation-errors-registry.md): it changes behavior for catch-allErrorhandlers. That plan now also tracks an older bug left out of this patch (879c74b): the emittedValidationError.d.tsfails underskipLibCheck: false.Docs: adaptivestone/framework-documentation#24 (
05-models,13-deploy,10-cli).Verification
npm run check,npm run check:types,npm run check:types:tests: cleanAll results below are after the dependency updates.
Node 26.9.0,
npm test: 925/925, no skips; codegen tests 122/122npm run smoke: passesBun 1.4.2,
npm run test:bun: 900/900Bun packed consumer,
SMOKE_REQUIRE_MONGO=1against a disposablemongo:8: boot, HTTP, CRUD, password hash and shutdown all passDocs site with the two docs edits: builds
npm pack: 5.5.1, 350,808 bytes, 409 entries, the same file list as the published 5.5.0New tests: a subclass of each of
Auth,Role,RateLimiteranswering with a response (compile-time guard plus runtime check);generateTokenon a stale document for both Mongoose errors; a full login request with the password changed mid-request, whose body must equal a wrong-password response.After merge
oxc-parser^0.153.0.