Found while preparing the tenant-registry enforcement flip: the deployed
portal image is from June 10, so the service-token code merged in #21
never shipped — flipping tenant-registry would have broken every portal
page. Three independent defects:
1. The image job's job-level hashFiles('Dockerfile') condition evaluates
BEFORE checkout against an empty workspace — always false, job
silently skipped on every main push. Same bug just fixed in
tenant-registry (#16).
2. The test job was red on #21's merge: this repo pins 100%
function/branch coverage and my local run skipped --coverage. Closed
for real, not lowered: two dead json() arrows removed from mocks the
code never reads (it throws on !ok before touching the body), and a
new test exercising the expires_in ?? 300 default-lifetime branch.
80 tests, 100/100/100/100.
3. The shared job's trivy gate was red on 14 real findings (3 CRITICAL):
@auth/core 0.37.2 -> 0.41.3 (CVE-2026-73420, Unicode-normalization
email homoglyph bypass — in the auth library this rollout depends on),
next 16.2.6 -> 16.2.11, nanoid + postcss via pnpm overrides.
next-auth 5.0.0-beta.25 -> beta.30; typecheck, lint and build clean
on the new versions.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
playwright.config.ts + tests/e2e/{apex,tenant,health}.spec.ts. make e2e for local. CI e2e job opt-in via RUN_E2E repo variable. OIDC click-through deferred to when stage is up.
Refs: M5.3
Next.js 16 + Auth.js v5 skeleton: host→slug middleware, tenant-context layout, OIDC sign-in flow against breakpilot-dev realm. 100% coverage on src/lib. Bumps next to 16.2.6 to clear trivy CVEs in 15.0.3.