Repository navigation
refactor: clear 19 SonarCloud code smells - #621
Merged
Merged
Conversation
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
SonarCloud S3776 flagged validateClaimsParameter, essentialACRValues and Server.Metadata as over the cognitive-complexity limit. Each now delegates to small helpers: validateClaimsLocationValue for one id_token/userinfo member; idTokenACREntry, acrEntryEssential, acrEntryValues and dedupeStrings for the acr entry; addOIDCMetadata for the OIDC-only fields an OAuthOnly server leaves out. Checks, their order, error messages and results are unchanged. The empty interactionNeededResult marker method gets the comment S1186 asks for. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Seven tests over the cognitive-complexity limit (S3776) now move their per-case bodies or repeated assertions into named helpers, and TestSignUserInfoResponseIsForTheTokensClient's client-lookup and signing cases move to their own test sharing a fixture; no case is dropped or weakened. Seven conditions that bound a variable only to compare it (S8193) now compare the expression directly. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SonarCloud S7688: bash's [[ ]] in place of [ ] for the FEDERATION_TRUST_ANCHOR_ADMIN_TOKEN emptiness check. Same behaviour. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
osanderson
force-pushed
the
refactor/sonar-2026-10-09
branch
from
October 9, 2026 12:50
3a44cef to
86e8513
Compare
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Clears the 19 fixable SonarCloud code smells open on main. These are pure refactors: no behaviour change and no release entry.
The 5
godre:S8196single-method interface naming issues are left alone: they're public API names, and are being marked Won't Fix.Merge after the v0.52.0 release PR (#616).
Fixed
go:S3776, cognitive complexity in production code (3)
server/claims_parameter.go,validateClaimsParameter: per-member checks moved tovalidateClaimsLocationValue.server/essential_acr.go,essentialACRValues: split intoidTokenACREntry,acrEntryEssential,acrEntryValuesanddedupeStrings.server/metadata.go,Server.Metadata: the OIDC-only fields moved toaddOIDCMetadata.Check order, error messages and results are unchanged.
go:S3776, cognitive complexity in tests (7)
server/begin_authorization_audit_test.goserver/essential_acr_test.goresource/bundled_resolver_validation_test.goserverresource/sign_userinfo_test.go: its lookup and signing cases are now a separate test sharing a fixture.server/prompt_test.go: two tests.client/production_urls_test.gogo:S1186, empty function (1):
server/interaction_result.go's marker method gets an explanatory comment.godre:S8193, unnecessary variable (7): in the
typ_test.gofiles underinternal/clientassertion,internal/jarm,internal/joseandinternal/token;internal/nofollow/nofollow_test.go; andserver/refresh_registration_test.go(×2).shelldre:S7688 (1):
conformance/scripts/run-all.shuses[[ ]].Verification
entry == nilcheck that's unreachable, because a null entry returns earlier; the check itself is unchanged from main.go test -vpasses per flagged test, before and after): audit 5/5, essential acr 11/11, bundled resolvers 18/18, prompt=login 11/11, InteractionNeeded 6/6, loopback 3/3. sign-UserInfo was 11 and is now 5 + 7 = 12: every subtest is kept, plus one top-level test.go vet,go test ./...on Go 1.27 and 1.26.9,golangci-lint(0 issues), theGOOS=linux GOARCH=armvet,bash -n run-all.sh, and every example module'sgo vet.🤖 Generated with Claude Code