Skip to content

refactor: clear 19 SonarCloud code smells - #621

Merged
osanderson merged 3 commits into
mainfrom
refactor/sonar-2026-10-09
Oct 9, 2026
Merged

osanderson merged 3 commits into
mainfrom
refactor/sonar-2026-10-09

Conversation

@osanderson

Copy link
Copy Markdown
Collaborator

Summary

Clears the 19 fixable SonarCloud code smells open on main. These are pure refactors: no behaviour change and no release entry.

The 5 godre:S8196 single-method interface naming issues are left alone: they're public API names, and are being marked Won't Fix.

Merge after the v0.52.0 release PR (#616).

Fixed

go:S3776, cognitive complexity in production code (3)

  • server/claims_parameter.go, validateClaimsParameter: per-member checks moved to validateClaimsLocationValue.
  • server/essential_acr.go, essentialACRValues: split into idTokenACREntry, acrEntryEssential, acrEntryValues and dedupeStrings.
  • server/metadata.go, Server.Metadata: the OIDC-only fields moved to addOIDCMetadata.

Check order, error messages and results are unchanged.

go:S3776, cognitive complexity in tests (7)

  • server/begin_authorization_audit_test.go
  • server/essential_acr_test.go
  • resource/bundled_resolver_validation_test.go
  • serverresource/sign_userinfo_test.go: its lookup and signing cases are now a separate test sharing a fixture.
  • server/prompt_test.go: two tests.
  • client/production_urls_test.go

go:S1186, empty function (1): server/interaction_result.go's marker method gets an explanatory comment.

godre:S8193, unnecessary variable (7): in the typ_test.go files under internal/clientassertion, internal/jarm, internal/jose and internal/token; internal/nofollow/nofollow_test.go; and server/refresh_registration_test.go (×2).

shelldre:S7688 (1): conformance/scripts/run-all.sh uses [[ ]].

Verification

  • Mutation checks on the refactored claims and acr parsers: 10 mutants, 9 caught. The survivor drops an entry == nil check that's unreachable, because a null entry returns earlier; the check itself is unchanged from main.
  • Case counts (go test -v passes per flagged test, before and after): audit 5/5, essential acr 11/11, bundled resolvers 18/18, prompt=login 11/11, InteractionNeeded 6/6, loopback 3/3. sign-UserInfo was 11 and is now 5 + 7 = 12: every subtest is kept, plus one top-level test.
  • Checks: go vet, go test ./... on Go 1.27 and 1.26.9, golangci-lint (0 issues), the GOOS=linux GOARCH=arm vet, bash -n run-all.sh, and every example module's go vet.

🤖 Generated with Claude Code

@codecov

codecov Bot commented Oct 9, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 97.87234% with 1 line in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
server/interaction_result.go 0.00% 1 Missing ⚠️

📢 Thoughts on this report? Let us know!

osanderson and others added 3 commits October 9, 2026 20:50
SonarCloud S3776 flagged validateClaimsParameter, essentialACRValues
and Server.Metadata as over the cognitive-complexity limit. Each now
delegates to small helpers: validateClaimsLocationValue for one
id_token/userinfo member; idTokenACREntry, acrEntryEssential,
acrEntryValues and dedupeStrings for the acr entry; addOIDCMetadata for
the OIDC-only fields an OAuthOnly server leaves out. Checks, their
order, error messages and results are unchanged. The empty
interactionNeededResult marker method gets the comment S1186 asks for.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Seven tests over the cognitive-complexity limit (S3776) now move their
per-case bodies or repeated assertions into named helpers, and
TestSignUserInfoResponseIsForTheTokensClient's client-lookup and
signing cases move to their own test sharing a fixture; no case is
dropped or weakened. Seven conditions that bound a variable only to
compare it (S8193) now compare the expression directly.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SonarCloud S7688: bash's [[ ]] in place of [ ] for the
FEDERATION_TRUST_ANCHOR_ADMIN_TOKEN emptiness check. Same behaviour.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@osanderson
osanderson force-pushed the refactor/sonar-2026-10-09 branch from 3a44cef to 86e8513 Compare October 9, 2026 12:50
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@osanderson
osanderson merged commit bae77e8 into main Oct 9, 2026
18 checks passed
@osanderson
osanderson deleted the refactor/sonar-2026-10-09 branch October 9, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant