Skip to content

refactor: remove dead EditPageLink.tsx duplicating DocsSourceActions security logic - #145

Merged
hivecommons-hive[bot] merged 3 commits into
mainfrom
arch/remove-dead-editpagelink
Oct 1, 2026
Merged

hivecommons-hive[bot] merged 3 commits into
mainfrom
arch/remove-dead-editpagelink

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Refactor

Removes src/components/docs/EditPageLink.tsx and its test
src/__tests__/EditPageLink.test.tsx. The component is dead code: it is
imported only by its own test, while production rendering
(DocsLayout.tsx) uses DocsSourceActions.tsx, which supersedes it.

The dead file carried an independently maintained copy of
security-sensitive logic (STATIC_EDIT_BASE_URLS,
isValidGitHubEditUrl(), buildGitHubEditUrl() including path-traversal
sanitization) that also lives in DocsSourceActions.tsx. A future fix to
the live validation/sanitization logic would not propagate here, leaving a
stale, still-passing copy that gives false confidence.

Verified: npm run type-check, npm test (726/726 passing), and
npm run lint (0 errors, pre-existing warnings only) all pass with the
files removed. No other file imports EditPageLink.

Closes #144


Filed by architect agent (ACMM L5 — hold-gated mode). Hold-gated: human review required.

— hive: agent=architect backend=copilot model=claude-sonnet-5 copilot=1.0.88

architect added 3 commits September 30, 2026 15:22
…logic

EditPageLink.tsx was only imported by its own test file; DocsLayout.tsx
renders DocsSourceActions.tsx instead, which supersedes it. The dead file
kept an independent copy of security-sensitive path-sanitization and
GitHub-edit-URL validation logic, risking silent drift from the live
implementation.

Signed-off-by: architect <architect@hive.kubestellar.io>
Signed-off-by: architect <architect@hive.kubestellar.io>
Signed-off-by: architect <architect@hive.kubestellar.io>
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "architect" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will automatically remove the hold label once current policy no longer requires a level hold for "architect". If this is an outreach PR, a human must review it and remove the label.

@kubestellar-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign clubanderson for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@netlify

netlify Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for hivecommons-docs ready!

Name Link
🔨 Latest commit af6892c
🔍 Latest deploy log https://app.netlify.com/projects/hivecommons-docs/deploys/6abdb24c6e1b6b0008d0e3a6
😎 Deploy Preview https://deploy-preview-145--hivecommons-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Read the tree at main, not just the diff. Looks correct to me.

  • EditPageLink (default + named exports) is imported nowhere except its own test — the only EditPageLink references in the repo are src/__tests__/EditPageLink.test.tsx and the component itself.
  • The one named export, buildGitHubEditUrl, is not shared: DocsSourceActions.tsx:29 declares its own private (non-exported) buildGitHubEditUrl, used at DocsSourceActions.tsx:106. So nothing loses behaviour here; the PR body's "duplicated security logic" description matches what the files contain.
  • DocsLayout.tsx renders DocsSourceActions, as the body says.
  • Coverage: deleting a 100%-covered file can lower global percentages, so I ran npx vitest run --coverage on this head: 77/77 files, 726/726 tests, all files 77.93% lines / 71.62% branches / 77.16% funcs / 79.31% stmts — comfortably above the vitest.config.ts:27 thresholds (68/54/65/67).

No findings. Pure dead-code removal; safe to merge from my read.

— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[architect] dead EditPageLink.tsx duplicates DocsSourceActions security logic (path sanitization, URL validation)

0 participants