Skip to content

refactor(stage): migrate module from server - #2496

Merged
shikanime merged 17 commits into
mainfrom
pr/stage-migration
Oct 2, 2026
Merged

shikanime merged 17 commits into
mainfrom
pr/stage-migration

Conversation

@shikanime

@shikanime shikanime commented Aug 13, 2026 •

Copy link
Copy Markdown
Member

Issues liées

Refs #2493


Quel est le comportement actuel ?

Le module stage (stages, environnements par stage) est servi par l'ancienne application Fastify apps/server.

Quel est le nouveau comportement ?

Migration du module stage vers apps/server-nestjs :

  • StageController, StageService, StageModule.
  • stage-queries.utils.ts : sélections Prisma typées.
  • stage-testing.utils.ts : fabriques faker pour les tests.
  • Enregistrement du module dans main.module.ts.
  • Parité des contrats et codes HTTP contre apps/server/src/resources/stage/.

Cette PR introduit-elle un breaking change ?

Non.

Autres informations

@shikanime

Copy link
Copy Markdown
Member Author

Réouverte : couverture des familles restantes pour #1889 — le fermeture précédente était un tri, pas un rejet du travail.

@shikanime
shikanime restored the pr/stage-migration branch September 17, 2026 09:51
@shikanime

Copy link
Copy Markdown
Member Author

Réouverte : famille requise pour #1889. Branche recréée depuis le SHA d'origine (l'ancienne ref avait été supprimée).

Comment thread apps/server-nestjs/src/modules/stage/stage.service.ts Outdated
Comment thread apps/server-nestjs/src/modules/stage/stage.service.ts Outdated
Comment thread apps/server-nestjs/src/modules/stage/stage-queries.utils.ts Outdated
Comment thread apps/server-nestjs/src/modules/stage/stage-testing.utils.ts Outdated
Comment thread apps/server-nestjs/src/modules/stage/stage.service.spec.ts Outdated
Comment thread apps/server-nestjs/src/modules/stage/stage.service.ts Outdated
Comment thread apps/server-nestjs/src/modules/stage/stage.controller.ts
@shikanime

Copy link
Copy Markdown
Member Author

apps/nginx-strangler/conf.d/routing.conf: 🟡 risk: Aucun location /api/v1/stages ajouté : le trafic tombe dans location /api/ → server-legacy, le module NestJS reste injoignable derrière nginx, la migration est inerte. Ajouter le bloc (proxy_pass server-nestjs, mêmes proxy_set_header), comme la PR zone.

@shikanime

Copy link
Copy Markdown
Member Author

Traité dans 1fcd77e : bloc /api/v1/stages ajouté en section migrée (envsubst restreint + nginx -t ok).

@shikanime shikanime left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict : Commentaire

Constat de la revue du 01/10 levé : le commit de tête n'est plus placeholder — 5151b0a3 refactor(stage): migrate module from server respecte Conventional Commits. Les 11 fils sont résolus, la lecture publique de GET /api/v1/stages est couverte par le test HTTP anonyme (75f79678, garde qui throw si UserGuard revient), CI verte à la tête (runs 37003853092 / 37003856845). Scan de sécurité du diff : néant.

✨ La garde « environnement attaché » et la suppression regroupées dans une seule $transaction éliminent la TOCTOU du deleteStage legacy — le fix est dans le service, tous les appelants en profitent.

Comment thread apps/server-nestjs/src/modules/stage/stage.controller.ts Outdated

@StephaneTrebel StephaneTrebel left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

La migration stage restaure bien la route publique et ajoute les conversions au contrat, mais les paramètres UUID ne sont plus validés avant Prisma. Le ledger #2493 ne fournit pas de checklist ; les anciens fils sont résolus, la CI est verte et ce nouveau fil important reste à traiter.

@StephaneTrebel StephaneTrebel left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Le paramètre stageId est maintenant validé sur les deux mutations avant Prisma. Les fils sont résolus et la CI est verte.

shikanime and others added 17 commits October 2, 2026 17:09
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Change-Id: I0f12f505675c289e395ded0acf6974946a6a6964

Co-authored-by: Automata <automata@shikanime.studio>
Type les fonctions de `stage-queries.utils.ts` sur
`Prisma.TransactionClient` (`tx`), réutilise les fabriques du module
environment et expose `CreateStageBodySchema`/`UpdateStageBodySchema`
depuis le contrat partagé avec alias `z.infer`.

Refs #2493

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Change-Id: I20758c24ffff649d2e2e38a61d1185bf6a6a6964
…action

`createStage`, `updateStage`, `deleteStage` et `linkClusterToStages`
exécutent désormais leurs séquences dans `prisma.$transaction`.

Refs #2493

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Change-Id: I56bd2f18c7b7e247b11fc62f6b2d4a896a6a6964
Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
UserGuard on the stage routes resolves AuthService through the importing module; without AuthModule the backend crashed at boot.

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
UserGuard resolves UserPermissionService through the importing module as well; the guard crashed at boot with only AuthModule imported.

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Les fabriques `makeCluster` et `makeEnvironment` de stage-testing.utils
dupliquaient celles de environment-testing.utils ; réutilisation des
fabriques existantes pour éviter la dérive.

Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>

Co-authored-by: Automata <automata@shikanime.studio>
The class-level guard required authentication for `GET /api/v1/stages`,
while the legacy router serves `listStages` without auth and the shared
contract announces no 401. Move `@UseGuards(UserGuard)` to the four
protected routes and lock the public list in the controller spec.

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Change-Id: Iff3ffe4528e1e5a00acc14772c039c2a6a6a6964
The guard-metadata assertions read `__guards__` runtime metadata that
never matches at HEAD and re-assert permission strings already covered
by the service; the `as never` casts erased the contract shapes at the
controller boundary. Type the fixtures against
`StageAssociatedEnvironments` and `UpdateStageBody` instead.

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Change-Id: I896bf4241b9ed6f601fa37caf3cb67d46a6a6964
Reflect-based guard metadata assertions pass whether or not the guard is
enforced and add no behavioural coverage; the guard spec and the controller
delegation tests are untouched.

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Change-Id: I2531092df02ab78c1dbb29c4176a19526a6a6964
…ecords

toStage and toStageAssociatedEnvironments apply the contract shape in
StageController; StageService returns raw query records.

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Change-Id: Iabaa9863ac20ef96fa635f1d87305b246a6a6964
Co-authored-by: Automata <automata@shikanime.studio>
…roller

Co-authored-by: Automata <automata@shikanime.studio>
Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Change-Id: I30ec3521f38f8f20c55081a5eb3c981f6a6a6964
Co-authored-by: Automata <automata@shikanime.studio>
Co-authored-by: Automata <automata@shikanime.studio>
Co-authored-by: Automata <automata@shikanime.studio>
@cloud-pi-native-sonarqube

Copy link
Copy Markdown

@shikanime
shikanime added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit 00eebae Oct 2, 2026
34 checks passed
@shikanime
shikanime deleted the pr/stage-migration branch October 2, 2026 16:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

built refactor Refactor code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants