Hardening 3/3 (stacked on #372): ErrorBoundary + 500 page, axios timeout, hook error contract, CI runs lint + jest - #373
Merged
Merged
Conversation
…0 page
A render error anywhere in a page blanked the whole app (NavBar and Footer
included) and there was no 500.js, so SSR failures showed Next's default
page. ErrorBoundary wraps ONLY <Component/> in _app.js (placeholders and the
NavBar/Footer invariants untouched) with resetKey={router.asPath} so a
client-side navigation clears the fallback; pages/500.js is static (no data,
auth or router) and noindex.
Tests: src/components/__tests__/ErrorBoundary.test.js, src/pages/__tests__/500.test.js.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ined on a backend error
There was no axios timeout, so a hung backend held every caller forever.
useHackathonEvents' makeRequest returns the axios error.response on a
non-2xx and the effect did setHackathons(data.hackathons) with it — a 429 or
5xx set undefined and crashed every consumer's .map (the backend PR turns
tripped rate limits into 429s, so this path is now reachable by design).
Failures yield [] plus an error {status, message}; 403 stays quiet as before.
Test: src/hooks/__tests__/use-hackathon-events.test.js.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The repo had no workflows at all, so nothing ran the 480-test suite before merge. ci.yml runs npm ci, eslint (warnings allowed, errors fail) and jest with dummy NEXT_PUBLIC_* env. next build is deliberately not run in CI: a build fires ~550 getStaticProps requests at the production backend. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… error contract, CI) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
…te and the Vercel build failed) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #372 (
hardening/2-seo-ssg), which is stacked on #371. Base is #372's branch, so this shows only the safety-net changes; merge #371 → #372 → this. Last of the three frontend hardening PRs (docs/plans/hardening-security-seo-reliability-2026-09.md, sections 3.4–3.5).What changed
src/components/ErrorBoundary.jswraps ONLY the page subtree in_app.js(NavBar/Footer and their CLS placeholders untouched), resets on client-side navigation viaresetKey={router.asPath}; new static,noindexpages/500.jsfor SSR failuresaxios.defaults.timeout = 30000(30 s: admin bulk operations are slow; the 401 retry doubles the worst case)useHackathonEventssethackathonstoundefinedon a 429/5xx (it assigneddata.hackathonsfrom the axios error response), crashing every consumer's.map— reachable by design now that the backend answers 429 instead of 500[]pluserror {status, message}; 403 stays quiet as before.github/workflows/ci.yml:npm ci,eslint(errors fail, warnings allowed),npm test -- --cion PRs + pushes to develop/main. Nonext buildin CI on purpose: Vercel is the build gate and a CI build fires ~550 requests at the production backendNew tests:
src/components/__tests__/ErrorBoundary.test.js,src/pages/__tests__/500.test.js,src/hooks/__tests__/use-hackathon-events.test.js. Full suite: 61 suites / 480 tests green. The Lint + Jest check on this PR is the new workflow running for the first time.Test plan (preview)
/some-page-that-does-not-exist→ still the sleeping-cat 404. Temporarily throw inside any page component on a local dev build → the calm "Something went wrong on this page." card renders with the NavBar still visible; navigating to another page via the nav clears it.curl -sI <preview>/500→ 200 with<meta name="robots" content="noindex, follow">in the body; the page has Reload + homepage actions.NEXT_PUBLIC_API_SERVER_URLpointed at a dead host locally),/and/hackrender with empty event lists instead of a client-side crash; requests give up after 30 s.🤖 Generated with Claude Code