Skip to content

chore(release): prepare 5.5.1 - #75

Merged
Systerr merged 4 commits into
mainfrom
release/5.5.1
Oct 6, 2026
Merged

Systerr merged 4 commits into
mainfrom
release/5.5.1

Conversation

@Systerr

@Systerr Systerr commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Summary

Prepares 5.5.1, a patch with two fixes from an app-side review of 5.5.0. Nothing is published or tagged by this PR.

  • Fix: login racing a password change (a2a2ec3). When the stored password changed after the user was read, user.generateToken() threw a raw Mongoose VersionError/DocumentNotFoundError, so a custom login without its own catch answered 500. It now rejects with a BadRequestError that answers exactly like a wrong password (400 { message: 'User/password not valid' }, via auth.errorUPValid, no code). The built-in Auth controller's catch is removed.
  • Fix: Auth/Role subclass return type (a2a2ec3). 5.5.0 made both only throw, so TypeScript inferred Promise<void>. A subclass whose middleware() returns res.status(…).json(…) failed with TS2416. Both declare the base Promise<void | Response> again. RateLimiter still has a res.json path and was never affected.
  • Dependencies (47d11c9): the optional oxc-parser peer and dev dependency move to ^0.153.0 (codegen output byte-identical; projects that run npm run gen update with npm i -D oxc-parser@^0.153.0, noted in CHANGELOG and README). mongoose 9.11.0 (mongodb driver 7.7.0) and lefthook 2.1.17 are lockfile-only.
  • Release prep (3924c96): package.json and the root of package-lock.json go to 5.5.1; dated ## [5.5.1] - 2026-10-06 notes; README "Upgrade notes (5.5.1)".
  • 5.5.0 notes amended: an app's own controllers/Health.ts replaces the built-in controller, so /health/live and /health/ready are not served until it extends the built-in one; the Role/RateLimiter bodies gain an error field (messages and statuses unchanged).
  • Plans: done/consumer-review-fixes.md and done/release-5.5.1.md. Routing request-validation 400s through the error registry is held back for 5.6 (queued/validation-errors-registry.md): it changes behavior for catch-all Error handlers. That plan now also tracks an older bug left out of this patch (879c74b): the emitted ValidationError.d.ts fails under skipLibCheck: false.

Docs: adaptivestone/framework-documentation#24 (05-models, 13-deploy, 10-cli).

Verification

  • npm run check, npm run check:types, npm run check:types:tests: clean
    All results below are after the dependency updates.

  • Node 26.9.0, npm test: 925/925, no skips; codegen tests 122/122

  • npm run smoke: passes

  • Bun 1.4.2, npm run test:bun: 900/900

  • Bun packed consumer, SMOKE_REQUIRE_MONGO=1 against a disposable mongo:8: boot, HTTP, CRUD, password hash and shutdown all pass

  • Docs site with the two docs edits: builds

  • npm pack: 5.5.1, 350,808 bytes, 409 entries, the same file list as the published 5.5.0

New tests: a subclass of each of Auth, Role, RateLimiter answering with a response (compile-time guard plus runtime check); generateToken on a stale document for both Mongoose errors; a full login request with the password changed mid-request, whose body must equal a wrong-password response.

After merge

  1. Publish 5.5.1 to npm.
  2. GitHub release for 5.5.1; paste the two amended bullets into the 5.5.0 release.
  3. Update the example project to oxc-parser ^0.153.0.

…class return type

- generateToken rethrows the stale-password VersionError/DocumentNotFoundError
  as a BadRequestError with the exact wrong-password body, so a custom login
  needs no catch to avoid a 500. The Auth controller's own catch is removed.
- Auth and Role declare the base Promise<void | Response> again: 5.5.0
  inferred Promise<void>, so a subclass answering with res.json() failed
  to compile (TS2416).
- Plans: consumer-review-fixes card; the validation-registry change is
  queued for 5.6 (behavior change for catch-all handlers).
Bump to 5.5.1, date the release notes, add README upgrade notes and the
release card with the verification results. The 5.5.0 notes also say that
an app's own controllers/Health.ts replaces the built-in controller and
that the Role/RateLimiter bodies gain an error field.
- oxc-parser: dev dependency and optional peer move to ^0.153.0. Codegen
  output is unchanged; projects that run `npm run gen` update with
  `npm i -D oxc-parser@^0.153.0` (CHANGELOG and README upgrade notes).
- mongoose 9.11.0 (with its mongodb 7.7.0 driver) and lefthook 2.1.17:
  lockfile only, within the existing ranges.
The emitted ValidationError.d.ts fails under `skipLibCheck: false`
(TS2416 on `message`). It predates 5.5.1 and was left out of it without
being assessed; the 5.6 validation-registry plan now carries the fix and
a smoke-test import. The 5.5.1 card records the omission, the dependency
updates and the re-run verification.
@Systerr
Systerr merged commit 5eeef1f into main Oct 6, 2026
32 checks passed
@Systerr
Systerr deleted the release/5.5.1 branch October 6, 2026 22:27
@codecov

codecov Bot commented Oct 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant