Cover update and a withheld attribute for block-form permit_params - #21
Merged
Merged
Conversation
Follow-up to #19, which fixed the four findings in #18 but left two gaps in the e2e coverage of the block-form `permit_params` shape. `resolve_permitted` gates `update` as well as `create`, and only `create` had an example. Reverting the fix leaves the new update example failing, so the second call site is now covered by something that can see it. Both branches of `Assignment`'s block permitted only columns the fixture already wrote, so no example could tell a block that filters from one whose result is ignored. `secret_note` is a column neither branch permits, and an example now asserts a write never reaches it. Mutating the block to permit it fails that example and no other. The README gains the two behaviours #19 changed but did not describe: an association's fields are reported under `nested` whether declared with `has_many` or `inputs for:`, and a form block declaring no inputs of its own is described from the permitted params. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #19, which fixed all four findings in #18. This closes two gaps in the e2e coverage of the block-form
permit_paramsshape, and documents two behaviours #19 changed but did not describe. No library changes.1.
updatewas not coveredresolve_permittedgatesupdateas well ascreate, and #19 added only acreateexample againstAssignment. Reverting the fix inRecordWriterleaves the new update example failing, so the second call site is now covered by something that can actually see it.2. Nothing proved the block filters
Both branches of
Assignment's block —%i[name notes]and%i[name]— permit only columns the fixture already writes, so every example passed whether the block's result was honoured or ignored entirely.secret_noteis a new column neither branch permits, and an example asserts a write never reaches it. Mutating the block to permitsecret_notefails that example and no other.3. Two behaviours left undocumented
The README now says that an associated record's fields are reported under
nestedwhether declared withhas_manyor withinputs for:, and that a form block declaring no inputs of its own is described frompermit_params— both changed by #19, neither described. It also notes that a block-formpermit_paramsis evaluated as the authenticated MCP user.Testing
rake e2e— 69 examples, 0 failures (67 onmain, plus 2).Both new examples were verified against two separate mutations:
resolve_permittedto@config.controller.newfails both;secret_noteto the block's permitted list fails only the withholding example.Note on #20
I had an in-flight branch fixing all four findings independently, opened as #20 before #19 landed. Its library diff turned out to be line-for-line equivalent to #19's, so rather than resolve the conflicts and re-land a duplicate, #20 is closed and this carries only the part that was not already covered.
🤖 Generated with Claude Code