fix: address code review findings from 2026-08-17

- scope no-cache headers to non-static routes (restore immutable asset caching)
- reset cached rejected MongoDB promise so retries can succeed
- use last X-Forwarded-For entry in Content Editor rate limiter (anti-spoofing)
- remove weak Mongo defaults from compose files (fail loudly on missing env)
- move staging banner text to common.json content
- read APP_PORT from env file in deploy.sh healthcheck
- filter network noise from staging smoke console assertions

Closes MITHOME-48, MITHOME-49, MITHOME-50, MITHOME-51, MITHOME-52, MITHOME-53, MITHOME-54
This commit is contained in:
Do Siki
2026-08-18 12:21:32 +02:00
parent 93aaa10a36
commit bd7287aa58
14 changed files with 115 additions and 17 deletions
+5 -1
View File
@@ -10,7 +10,11 @@ test('SMOKE-01: health endpoint is available', async ({ request }) => {
test('SMOKE-02: homepage renders its critical shell without console errors', async ({ page }) => {
const consoleErrors: string[] = []
page.on('console', message => {
if (message.type() === 'error') consoleErrors.push(message.text())
if (message.type() !== 'error') return
// Chromium logs failed resource loads (e.g. favicon 404) as console errors.
// Those are network noise here; real JS errors must still fail the test.
if (message.text().startsWith('Failed to load resource')) return
consoleErrors.push(message.text())
})
await page.goto('/')