mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-09-30 06:33:13 +00:00
Update retrospective with session 5: automated QA and 18-bug fix sweep
Documents the parallel 4-agent QA run (~145 test cases), the 18 bugs found, and all fixes applied in the preceding 4 commits. Adds session 5 changelog and QA coverage summary table.
This commit is contained in:
parent
5e89e42e6a
commit
a978fdd292
1 changed files with 42 additions and 3 deletions
|
|
@ -1,4 +1,4 @@
|
|||
# Proposal System — Retrospective (2026-05-19, updated 2026-05-20)
|
||||
# Proposal System — Retrospective (2026-05-19, updated 2026-05-20, session 5 added 2026-05-20)
|
||||
|
||||
## Executive Summary
|
||||
|
||||
|
|
@ -8,7 +8,9 @@ Across four sessions (2026-05-18, 2026-05-19, and two on 2026-05-20), the projec
|
|||
|
||||
**Session 4 (Web):** Full local web testing exposed six bugs in the API and frontend: enum serialization failures, identity/role confusion in dev-login, incorrect proposal ownership filtering, Autocomplete binding issues, audit log format errors on Postgres jsonb columns, and missing API idempotency. All were fixed in four logical commits. The web app's core workflow — submit as dispatcher, review/edit/approve/send as admin — is now functional end-to-end in dev mode.
|
||||
|
||||
**Systemic findings:** The web session revealed two architectural gaps: (1) audit logging was fragile — a format error in a non-critical audit write could roll back an otherwise successful save, and (2) state machine transitions lacked idempotency, meaning retries or UI double-clicks could produce 500 errors instead of graceful no-ops. Both are patterns that would have surfaced in production under real load.
|
||||
**Session 5 (Automated QA):** Ran 4 parallel test agents covering ~145 test cases across every API endpoint and every frontend page. Found 18 bugs (2 critical, 4 high, 7 medium, 5 low). All 16 actionable bugs fixed in 4 commits. Critical: admin dashboard LINQ crash (EF Core can't translate TimeSpan.TotalHours to SQL) and revision endpoint 500 (unique constraint on ProposalNumber). High: dispatcher dashboard data exposure (missing mine filter), no frontend role guards on admin routes, submittedByName null on mutation responses, invalid role silently defaulting to Admin. Also extracted duplicated STATUS_COLORS and format utilities into shared modules, wired the admin dashboard filter dropdowns, and added debounce to customer search.
|
||||
|
||||
**Systemic findings:** The web session revealed two architectural gaps: (1) audit logging was fragile — a format error in a non-critical audit write could roll back an otherwise successful save, and (2) state machine transitions lacked idempotency, meaning retries or UI double-clicks could produce 500 errors instead of graceful no-ops. Both are patterns that would have surfaced in production under real load. Session 5 added a third: the frontend had no authorization enforcement — `ProtectedRoute` checked authentication but not role, so any logged-in user could navigate to admin pages by URL.
|
||||
|
||||
## Standards Compliance Status
|
||||
|
||||
|
|
@ -133,7 +135,7 @@ Ranked by impact-to-effort:
|
|||
| **HIGH** | Dev API_URL is `localhost:5000` — all API calls fail on device | Proposals can't be created, viewed, or searched on device | `config.ts` |
|
||||
| **HIGH** | Placeholder app icons (solid blue squares) | Unprofessional for TestFlight / App Store | `ios/ProposalSystem/Images.xcassets` |
|
||||
| **HIGH** | No web dev-mode setup documentation | New developer can't run the system locally | Root README / api/ docs |
|
||||
| **HIGH** | Audit isolation is ad-hoc, not systematic | Only `LineItemService` has try/catch on audit; `ProposalService` does not | All services calling `_audit.LogAsync` |
|
||||
| ~~HIGH~~ | ~~Audit isolation is ad-hoc, not systematic~~ | ~~Fixed session 4; session 5 verified via testing~~ | ~~LineItemService, ProposalService~~ |
|
||||
| **MEDIUM** | Confluence Architecture Map still missing mobile pipeline | Documentation debt per CLAUDE.md | Page 1540098 |
|
||||
| **MEDIUM** | `react-native-paper` has known issues with RN 0.85 | May surface as bugs in production | GitHub issues #4889, #4905 |
|
||||
| **MEDIUM** | netinfo patch needs monitoring for upstream fix | Patches can silently break on version bumps | `patches/@react-native-community+netinfo+12.0.1.patch` |
|
||||
|
|
@ -142,6 +144,43 @@ Ranked by impact-to-effort:
|
|||
| **LOW** | Cognito test user password in memory file | Acceptable for internal test account | `reference_mobile_testflight.md` |
|
||||
| **LOW** | 4 Dependabot vulnerabilities open | Adam deferred these | GitHub Security tab |
|
||||
|
||||
## Session 5 Changelog — Automated QA & Bug Fixes (2026-05-20)
|
||||
|
||||
All fixes on `mobile/fix-react-version-and-ui` (4 commits, not yet on main):
|
||||
|
||||
### `d00c552` Fix admin dashboard LINQ crash, revise unique constraint, and mutation response data
|
||||
- **`AdminController.cs`** — Rewrote avgTurnaround query to fetch approved times to memory before computing TotalHours (EF Core/Npgsql cannot translate TimeSpan.TotalHours)
|
||||
- **`ProposalService.cs` ReviseAsync** — Append `-R{n}` suffix to revision ProposalNumber to avoid unique index violation
|
||||
- **`ProposalService.cs` Update/Approve/MarkSent** — Added `.Include(p => p.SubmittedBy)` so mutation responses return submittedByName
|
||||
|
||||
### `8666010` Validate dev-login input: reject empty email and invalid role
|
||||
- **`AuthController.cs`** — Return 400 for empty/whitespace email and invalid role strings; default role changed from Admin to Dispatcher (least privilege)
|
||||
|
||||
### `4d72b63` Add frontend role guards, fix dashboard data exposure, and harden UX
|
||||
- **`ProtectedRoute.tsx`** — New `RoleGuard` component for role-based route protection
|
||||
- **`App.tsx`** — Wrapped admin routes with `RoleGuard`; `/admin/*` requires Admin/SysAdmin, `/admin/users` requires SysAdmin
|
||||
- **`Dashboard.tsx`** — Added `mine: true` to dashboard query so dispatchers only see their own proposals
|
||||
- **`AdminWorkspace.tsx`** — Auto-save dirty changes before approving (was silently discarding edits)
|
||||
- **`ProposalFormPage.tsx`** — Added onError toast handler; added 300ms debounce on customer autocomplete search
|
||||
- **`admin.ts`** — Stopped swallowing errors in getPdf; fixed AuditEntry.details type to `string | null`
|
||||
- **`LoginPage.tsx`** — Fixed pre-existing TS error with noUncheckedIndexedAccess
|
||||
|
||||
### `5e89e42` Extract shared constants and format utils, wire admin dashboard filters
|
||||
- **`constants/index.ts`** — Added shared `STATUS_COLORS` and `PRIORITY_COLORS` (removed from 5 files)
|
||||
- **`lib/format.ts`** — New shared `formatCurrency`, `formatDate`, `formatDateTime` (removed from 4 files)
|
||||
- **`AdminDashboard.tsx`** — Wired Category and Priority filter dropdowns to `usePaginatedList` extraParams
|
||||
- **`ProposalDetailPage.tsx`** — Added 'Revised' to STATUS_ORDER so stepper renders correctly
|
||||
|
||||
### QA Coverage Summary
|
||||
|
||||
| Test Area | Tests | Pass | Fail | Agent |
|
||||
|-----------|-------|------|------|-------|
|
||||
| Auth & RBAC | 35 | 31 | 4 | Auth agent |
|
||||
| Proposal CRUD & State Machine | 38 | 35 | 3 | Proposal agent |
|
||||
| Line Items, Customers & Misc | 42 | 39 | 3 | Misc agent |
|
||||
| Web Frontend Code Review + API | ~30 | ~25 | ~5 | Frontend agent |
|
||||
| **Total** | **~145** | **~130** | **~15** | — |
|
||||
|
||||
## Session 3 Changelog — Mobile Device Testing (2026-05-20)
|
||||
|
||||
Fixes on `mobile/fix-react-version-and-ui` (not yet on main):
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue