test(ci): скрипт test, тесты в pr-check, фикс sporadic 403 в trackUserActivity

Шаг A3 (из 1.6) плана production-готовности:
- package.json: скрипт "test": "vitest run"
- pr-check.yml: шаг Tests после type check
- server/utils/userActivity.ts: try/catch в trackUserActivity — синхронная
  ошибка трекинга активности больше не срывает authenticateToken (ложный 403
  на первом запросе пользователя за минуту)
- tests/auto-transitions.test.ts: 3 устаревших теста обновлены под намеренное
  поведение (forward-only position, синк assignee, аудит вместо системного сообщения)

45/45 тестов зелёные, npm run check чисто.
This commit is contained in:
2026-09-07 20:28:44 +03:00
parent 76a0d859a5
commit b3d7923b23
5 changed files with 67 additions and 22 deletions

View File

@@ -20,15 +20,22 @@ export function trackUserActivity(userId: number): void {
lastActivityUpdate.set(userId, now);
// Run async without awaiting so the request is not delayed.
db.update(users)
.set({ lastActivityAt: new Date() })
.where(eq(users.id, userId))
.then(() => {
// No-op on success
})
.catch((err) => {
// Reset the throttle timestamp on error so the next request retries.
lastActivityUpdate.delete(userId);
console.error("[trackUserActivity] failed to update user activity:", err);
});
// Синхронные ошибки (например, недоступный пул соединений) тоже не должны
// срывать аутентификацию — трекинг активности некритичен.
try {
db.update(users)
.set({ lastActivityAt: new Date() })
.where(eq(users.id, userId))
.then(() => {
// No-op on success
})
.catch((err) => {
// Reset the throttle timestamp on error so the next request retries.
lastActivityUpdate.delete(userId);
console.error("[trackUserActivity] failed to update user activity:", err);
});
} catch (err) {
lastActivityUpdate.delete(userId);
console.error("[trackUserActivity] failed to update user activity:", err);
}
}