Files
pedwfrontend/memory-bank/change-log.md
T

19 KiB

Change Log (AI/Human Curated)

Entry Template

date: YYYY-MM-DD
author: <agent|name>
scope: <files/routes/features>
type: change
rationale: <why change was made>
impact: <user/system/security/i18n/a11y>
status: completed|rolled-back|partial

Summary:
Validation:
Follow-ups:

CL-001: TASK22211 endpoint search-document contract consistency slice

date: 2026-03-23
author: Cline
scope: pages/api/endpoint/{getsearchdocumenthistory_api,getsearchdocumenthistorypaged_api,getsearchdocumentdetails_api,getsearchdocumentdetailspaged_api,getsearchdocumentTypes_api}.js, tests/phase21/endpoint-handler-contract.test.cjs
type: change
rationale: Continue the endpoint contract-consistency stream by normalizing a coherent search-document handler cluster that still used raw error passthrough and noisy legacy logging patterns.
impact: Improved negative-path consistency and safer error contract handling in search-document endpoints while preserving success payload behavior.
status: completed

Summary:

  • Branch created from SIPS-Development: TASK22211-endpoint-search-document-contract-consistency.
  • Standardized five search-document handlers to respondError/respondSuccess usage.
  • Added explicit required-input guards:
    • DOCUMENT_ID_REQUIRED for history/historypaged
    • INCIDENT_ID_REQUIRED for details/detailspaged/types
    • ORDER_BY_REQUIRED, FIELD_SORT_REQUIRED, SHOW_NUMBER_OF_RECORDS_REQUIRED for details-paged query requirements
  • Removed noisy direct logging in paged/details code paths.
  • Preserved success contract patterns (pass-through or transformed payloads where already established).
  • Expanded phase21 endpoint tests with missing-input, catch-path, and success parity assertions for this cluster.

Validation:

  • node tests/phase21/api-contract-slice1.test.cjs -> pass
    • helper: 4/4
    • file-handler: 11/11
    • email-handler: 12/12
    • endpoint-handler: 53/53
  • npm run lint -> warnings only (pre-existing react-hooks/exhaustive-deps warnings; no new lint errors)

Follow-ups:

  • Continue the next endpoint cluster using the same pattern (bounded slice + phase21 test expansion).
  • Keep response success payloads contract-stable and avoid broad relay/auth refactors in this stream.

CL-002: TASK22211 endpoint token handler contract consistency slice

date: 2026-03-23
author: Cline
scope: pages/api/endpoint/getToken.js, tests/phase21/endpoint-handler-contract.test.cjs
type: change
rationale: Close out remaining non-standard endpoint contract handling by normalizing the legacy token endpoint to shared API response helpers and explicit error coding.
impact: Improved endpoint error consistency and test coverage for token acquisition failures while preserving successful token payload passthrough.
status: completed

Summary:

  • Refactored getToken.js to use respondSuccess and respondError from pages/api/middleware/apiResponse.
  • Removed legacy raw res.status(...).json(...)/bare status assignment pattern and dead logging artifacts.
  • Added explicit catch-path contract: TOKEN_FETCH_FAILED with 400 status.
  • Added endpoint phase21 tests for:
    • success token payload passthrough
    • catch-path error contract assertion

Validation:

  • node tests/phase21/api-contract-slice1.test.cjs -> pass
    • helper: 4/4
    • file-handler: 11/11
    • email-handler: 12/12
    • endpoint-handler: 147/147
  • npm run lint -> warnings only (pre-existing react-hooks/exhaustive-deps warnings; no new lint errors)

Follow-ups:

  • Remaining outlier API handler for this consistency stream is pages/api/file/generateappealpdfcopy.js (not yet on shared response helpers).

CL-003: TASK22211 endpoint contract-hardening stream backfill (all known slices)

date: 2026-03-23
author: Cline
scope: pages/api/endpoint/*_api.js, pages/api/endpoint/getToken.js, tests/phase21/endpoint-handler-contract.test.cjs
type: change
rationale: Backfill memory-bank traceability so the complete known TASK22211 contract-consistency stream is documented in one place now that memory-bank is being versioned.
impact: Improves governance/auditability of API contract hardening, makes rollout and rollback analysis easier, and records exactly which endpoint clusters were normalized.
status: completed

Summary:

  • Backfilled all known TASK22211 slices currently on branch (in commit order):
    • b57f3de search-document endpoint contracts + phase21 coverage
    • 9af541a my-portal retrieval endpoint contracts
    • b880364 basic search endpoint contracts
    • a106dea DNS basic search endpoint contracts
    • b5a3a62 portal module + LPA case endpoint contracts
    • 4601d7c case detail endpoint contracts
    • 2959c7d delete/watched-case endpoint contracts
    • b59f13a metadata + linked-case endpoint contracts
    • bcf03a6 form + publication endpoint contracts
    • e0e91c8 DNS + representation endpoint contracts
    • 98e159d case creation + media endpoint contracts
    • 88e4586 advanced-search-paged endpoint contract
    • cb69bbe case update + CRM task endpoint contracts
    • 722ef98 hash + metadata endpoint contracts
    • 134f99c address-search endpoint contract
    • 8b6ed73 new-appeal appeal-types endpoint contract
    • eec59e8 token endpoint contract handling
  • Across the stream, handlers were standardized toward respondSuccess/respondError, required-input guards, and explicit negative-path error codes while preserving success payload compatibility.
  • Phase21 endpoint contract suite was expanded incrementally alongside each slice.

Validation:

  • Stream validation baseline (latest known run):
    • node tests/phase21/api-contract-slice1.test.cjs -> pass (endpoint-handler 147/147)
    • npm run lint -> warnings only (pre-existing react-hooks/exhaustive-deps; no new lint errors)

Follow-ups:

  • Continue with remaining non-standard API outlier(s), notably pages/api/file/generateappealpdfcopy.js.
  • Keep future slices logged in this file at commit-time now that memory-bank is versioned.

CL-004: TASK22224 file + static endpoint contract hardening bundle (phase21)

date: 2026-03-23
author: Cline
scope: pages/api/file/{downloadblob,generateappealpdfcopy}.js, pages/api/endpoint/{getsipsmedia_api,getappealtypesfornewappeal_api}.js, tests/phase21/{file-handler-contract,endpoint-handler-contract}.test.cjs
type: change
rationale: Deliver the agreed larger bounded slice for remaining non-standard file/static handlers, improving negative-path consistency while preserving current success payload behavior.
impact: Standardized error envelopes/codes for download and generated PDF copy flows, method guard parity for static endpoints, and expanded phase21 contract coverage for both file and endpoint handlers.
status: completed

Summary:

  • downloadblob.js:
    • added explicit catch-path response via respondError with DOWNLOAD_BLOB_FAILED
    • kept success behavior intact (attachment header + raw file body)
    • removed dead internal helper (streamToBuffer) and tightened local declarations
  • generateappealpdfcopy.js:
    • removed unused imports/noisy console warnings
    • standardized required-input and negative-path contracts:
      • INCIDENT_ID_REQUIRED (400)
      • CASE_NOT_FOUND (404)
      • FORM_COLLECTION_NOT_FOUND (400)
      • APPEAL_PDF_COPY_GENERATION_FAILED (400)
    • preserved success output contract (PDF content headers + buffer body)
  • getsipsmedia_api.js and getappealtypesfornewappeal_api.js:
    • added method guard for non-GET requests using METHOD_NOT_ALLOWED (405)
    • preserved existing GET success payloads
  • Expanded phase21 tests:
    • file-handler-contract.test.cjs: added coverage for download failure + full generated PDF copy contract/negative paths
    • endpoint-handler-contract.test.cjs: added method guard tests for both static endpoints

Validation:

  • node tests/phase21/api-contract-slice1.test.cjs -> pass
    • helper: 4/4
    • file-handler: 17/17
    • email-handler: 12/12
    • endpoint-handler: 149/149
  • npm run lint -> warnings only (pre-existing react-hooks/exhaustive-deps; no new lint errors)

Follow-ups:

  • If desired, next slice can target remaining file-route parity candidates outside this bundle, but this closes the planned TASK22224 scope.

CL-005: TASK22224 downloadblob hotfix closure (path normalization + hash compatibility)

date: 2026-03-23
author: Cline
scope: pages/api/file/downloadblob.js
type: change
rationale: Close post-merge runtime regressions reported on live links where download URLs alternated between filename-only/full-path blob names and mixed encoded/raw hash input variants.
impact: Restored reliable blob downloads without relaxing hash security guarantees (still HMAC validated), and preserved existing caller compatibility across legacy/new URL encodings.
status: completed

Summary:

  • Hotfix 1 (f09f3b7): normalized blob path resolution
    • accepts both forms of blobname input:
      • filename only (legacy)
      • full prefixed path (already includes casefolderID/...)
    • prevents double-prefix lookup failures
    • sets attachment filename from final path segment only
  • Hotfix 2 (bd3bf68): hash compatibility validation
    • validates against a bounded set of canonical query-path variants (raw/encoded combinations for casefolderID and blobname)
    • fixes INVALID_HASH false negatives for legitimate caller-generated links
    • keeps strict HMAC requirement in place (no unauthenticated bypass)

Validation:

  • node tests/phase21/file-handler-contract.test.cjs -> pass (17/17)
  • node tests/phase21/api-contract-slice1.test.cjs -> pass
    • helper: 4/4
    • file-handler: 17/17
    • email-handler: 12/12
    • endpoint-handler: 149/149
  • User confirmation: "downloadblob now works"

Follow-ups:

  • Next recommended slice on this branch: complete file-route guard parity for deleteblob.js, deleteblobcase.js, and deleteblobrep.js by aligning hash validation canonicalization and explicit respondError contracts (MISSING_REQUIRED_QUERY, INVALID_HASH, operation-specific *_FAILED).
  • Extend tests/phase21/file-handler-contract.test.cjs for the above routes with mixed encoded/raw hash cases to lock compatibility.

CL-006: TASK22224 file delete-route guard parity slice

date: 2026-03-23
author: Cline
scope: pages/api/file/{deleteblob,deleteblobcase,deleteblobrep}.js, tests/phase21/file-handler-contract.test.cjs
type: change
rationale: Execute the next planned slice to align hash/canonicalization behavior and negative-path contracts across high-risk file delete routes, matching the compatibility posture established for downloadblob.
impact: Reduces false INVALID_HASH failures for legitimate encoded/raw caller variants while preserving strict hash enforcement and improving resilience via explicit catch-path contracts.
status: completed

Summary:

  • deleteblob.js
    • added bounded hash candidate validation for encoded/raw combinations of casefolderID and blobname
    • normalized delete path handling for both filename-only and already-prefixed blob paths
    • added explicit catch-path contract: DELETE_BLOB_FAILED
  • deleteblobcase.js
    • added hash candidate validation for raw/encoded casefolderID
    • added explicit catch-path contract: DELETE_BLOB_CASE_FAILED
  • deleteblobrep.js
    • added hash candidate validation for encoded/raw casefolderID + repfile
    • added explicit catch-path contract: DELETE_BLOB_REP_FAILED
  • Phase21 tests expanded (file-handler-contract.test.cjs):
    • encoded hash-variant acceptance cases for all three delete routes
    • explicit dependency-failure contract assertions for all three delete routes

Validation:

  • node tests/phase21/file-handler-contract.test.cjs -> pass (23/23)
  • node tests/phase21/api-contract-slice1.test.cjs -> pass
    • helper: 4/4
    • file-handler: 23/23
    • email-handler: 12/12
    • endpoint-handler: 149/149

Follow-ups:

  • Optional next slice: apply same bounded hash-canonicalization parity to remaining high-sensitivity file routes where mixed encoded/raw callers may exist (getbloblist, getprogressobjblob) and add regression cases to phase21.

CL-007: TASK22224 getrepsblob stability hotfix after delete representation flow

date: 2026-03-23
author: Cline
scope: actions/azurestorage.js (getRepsBlobs), tests/phase21/file-handler-contract.test.cjs
type: change
rationale: Resolve reported runtime 400 (GET_REPS_BLOB_FAILED) after delete representation actions, caused by stale soft-deleted blob tag hits during representation blob enumeration.
impact: Prevents transient/stale Azure tag index entries from breaking representation retrieval, improving reliability of post-delete refresh without relaxing route security contracts.
status: completed

Summary:

  • Hardened getRepsBlobs(containerName) in actions/azurestorage.js:
    • fixed async misuse (blobClient.getProperties().contentLength without await)
    • added existence/property guard with explicit await blobClient.getProperties()
    • skips 404s (soft-deleted/stale tag index results) instead of throwing
    • preserves behavior for non-404 failures (rethrow for proper error visibility)
    • kept existing _rep.json/undefined name filtering intact
  • Added phase21 contract coverage for getrepsblob route:
    • success payload contract test
    • dependency failure contract test (GET_REPS_BLOB_FAILED)

Validation:

  • node tests/phase21/file-handler-contract.test.cjs -> pass (25/25)
  • node tests/phase21/api-contract-slice1.test.cjs -> pass
    • helper: 4/4
    • file-handler: 25/25
    • email-handler: 12/12
    • endpoint-handler: 149/149

Follow-ups:

  • Optional: add the same stale-tag existence guard pattern to any remaining Azure tag-list readers that still consume findBlobsByTags results without property existence verification.

CL-008: TASK22224 awaiting-submission route resilience parity hardening

date: 2026-03-23
author: Cline
scope: pages/api/file/getawaitingsubmissionfromblob.js, tests/phase21/file-handler-contract.test.cjs
type: change
rationale: Add explicit catch-path contract parity for awaiting-submission blob retrieval route so unexpected dependency failures return consistent, actionable error envelopes.
impact: Improves reliability/diagnostics for post-delete case refresh and aligns file-route error handling style without changing success payload contract or hash verification behavior.
status: completed

Summary:

  • Refactored getawaitingsubmissionfromblob handler to structured try/catch flow.
  • Preserved existing guard behavior:
    • MISSING_REQUIRED_QUERY for missing container/hash
    • INVALID_HASH for signature mismatch
  • Added explicit dependency failure contract:
    • GET_AWAITING_SUBMISSION_BLOB_FAILED (400)
    • message: Failed to retrieve awaiting submission blobs
  • Added phase21 coverage for this route:
    • success payload pass-through contract
    • dependency failure contract assertion

Validation:

  • node tests/phase21/file-handler-contract.test.cjs -> pass (27/27)
  • node tests/phase21/api-contract-slice1.test.cjs -> pass
    • helper: 4/4
    • file-handler: 27/27
    • email-handler: 12/12
    • endpoint-handler: 149/149

Follow-ups:

  • Optional parity sweep: apply the same explicit catch-path contract pattern to remaining file routes that still rely on implicit promise-chain errors.

CL-009: TASK22224 proxy-route resilience and encoding parity bundle

date: 2026-03-23 author: Cline scope: pages/api/file/{getbloblistproxy,getrepsblobproxy,getawaitingsubmissionfromblobproxy,createappealcompletemessageproxy_api}.js, tests/phase21/file-handler-contract.test.cjs type: change rationale: Continue larger-slice hardening by aligning proxy handlers with explicit async error handling and safer encoded upstream query forwarding for hash-based downstream calls. impact: Improves proxy reliability and compatibility for encoded query values while preserving existing proxy error contracts and response behavior. status: completed

Summary:

  • getbloblistproxy.js
    • converted .then/.catch chain to explicit try/catch
    • encoded forwarded container and casefolderID query values
    • preserved error contract: GET_BLOB_LIST_PROXY_FAILED
  • getrepsblobproxy.js
    • converted .then/.catch chain to explicit try/catch
    • encoded forwarded container
    • preserved error contract: GET_REPS_BLOB_PROXY_FAILED
  • getawaitingsubmissionfromblobproxy.js
    • converted .then/.catch chain to explicit try/catch
    • preserved error contract: GET_AWAITING_SUBMISSION_PROXY_FAILED
  • createappealcompletemessageproxy_api.js
    • converted .then/.catch chain to explicit try/catch
    • encoded forwarded container and tempcaseref
    • preserved error contract: CREATE_APPEAL_COMPLETE_MESSAGE_PROXY_FAILED
  • Phase21 tests expanded for proxy paths:
    • getbloblistproxy success + dependency failure
    • getrepsblobproxy success
    • getawaitingsubmissionfromblobproxy dependency failure
    • createappealcompletemessageproxy dependency failure

Validation:

  • node tests/phase21/file-handler-contract.test.cjs -> pass (46/46)
  • node tests/phase21/api-contract-slice1.test.cjs -> pass
    • helper: 4/4
    • file-handler: 46/46
    • email-handler: 12/12
    • endpoint-handler: 149/149

Follow-ups:

  • Optional next big slice: bring remaining proxy/message routes using raw axios promise chains (createcaseinvolvement_api.js, createrepinvolvement_api.js, updatecase_api.js) onto the same async/await + explicit contract pattern.

CL-010: TASK22224 involvement/update route async contract hardening bundle

date: 2026-03-23 author: Cline scope: pages/api/file/{createcaseinvolvement_api,createrepinvolvement_api,updatecase_api}.js, tests/phase21/file-handler-contract.test.cjs type: change rationale: Execute the next requested slice by modernizing remaining relay-backed involvement/update handlers that still used axios promise chains and legacy dead imports. impact: Improves reliability/readability and preserves existing response contracts, including 412 "record exists" semantics for involvement creation flows. status: completed

Summary:

  • createcaseinvolvement_api.js
    • removed unused CryptoJS import
    • refactored axios .then/.catch to explicit try/catch
    • preserved conflict behavior: status 412 -> success { record: "exists" }
    • preserved failure contract: CREATE_CASE_INVOLVEMENT_FAILED
  • createrepinvolvement_api.js
    • removed unused CryptoJS import
    • refactored axios .then/.catch to explicit try/catch
    • preserved conflict behavior: status 412 -> success { record: "exists" }
    • preserved failure contract: CREATE_REP_INVOLVEMENT_FAILED
  • updatecase_api.js
    • removed unused CryptoJS import
    • refactored axios .then/.catch to explicit try/catch
    • preserved failure contract: UPDATE_CASE_FAILED
  • Phase21 tests expanded:
    • createcaseinvolvement 412 conflict success contract
    • createrepinvolvement dependency failure contract
    • updatecase dependency failure contract

Validation:

  • node tests/phase21/file-handler-contract.test.cjs -> pass (49/49)
  • node tests/phase21/api-contract-slice1.test.cjs -> pass
    • helper: 4/4
    • file-handler: 49/49
    • email-handler: 12/12
    • endpoint-handler: 149/149

Follow-ups:

  • Optional: apply equivalent modernization to any remaining relay-backed handlers outside pages/api/file/ that still use raw axios promise chains and have no explicit phase21 contract assertions.