Skip to content

Fix CORS issue for SPDX licenses - #438

Merged
maximiliani merged 18 commits into
mainfrom
fix-cors-issues
Sep 29, 2026
Merged

maximiliani merged 18 commits into
mainfrom
fix-cors-issues

Conversation

@maximiliani

Copy link
Copy Markdown
Member

This PR changes the way how SPDX licenses are fetched. Instead of using the SPDX.org website with corsproxy.io, we use the official SPDX GitHub repository.

SPDXType.init() now throws when license details cannot be fetched, letting
the caller fall back to another renderer rather than rendering a degraded
view with a 'Network Issue' item. Removes handleInitError, addBasicErrorInfo
and addNetworkIssueInfo, and adds an isResolvable() override so a failed
probe/init is not cached in IndexedDB.
Update SPDXType unit test to assert init() rejects on fetch failure and add
isResolvable() coverage. Add a Parser unit test verifying that an uncertain
renderer whose API check fails (e.g. SPDX network failure) yields to another
renderer instead of being selected.
Copilot AI lite review requested due to automatic review settings September 25, 2026 12:00
@github-actions

Copy link
Copy Markdown

🎨 Chromatic Visual Tests

🔍 Visual changes detected

Review

View in Chromatic

Chromatic provides automated visual testing and review for component changes.

@github-actions

Copy link
Copy Markdown

Test Results

Coverage Summary

Node Lines Statements Branches Functions
22 75.78% 74.57% 61.74% 77.99%
24 75.78% 74.57% 61.74% 77.99%
25 75.78% 74.57% 61.74% 77.99%

Coverage & Quality Reports

📊 Codecov Report
🎨 Chromatic Status


For more details, check the workflow run

@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 83.33333% with 3 lines in your changes missing coverage. Please review.
✅ Project coverage is 80.69%. Comparing base (57d642e) to head (6492454).
✅ All tests successful. No failed tests found.

Files with missing lines Patch % Lines
.../src/rendererModules/FallbackType/FallbackType.tsx 0.00% 1 Missing ⚠️
...il-library/src/rendererModules/RORType/RORType.tsx 0.00% 1 Missing ⚠️
...-library/src/rendererModules/SPDXType/SPDXType.tsx 85.71% 1 Missing ⚠️
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main     #438      +/-   ##
==========================================
+ Coverage   80.65%   80.69%   +0.04%     
==========================================
  Files          57       57              
  Lines        3809     3787      -22     
  Branches     1154     1168      +14     
==========================================
- Hits         3072     3056      -16     
+ Misses        733      727       -6     
  Partials        4        4              
Files with missing lines Coverage Δ
...rary/src/rendererModules/DOI/ResourceTypeIcons.tsx 100.00% <ø> (ø)
...-library/src/rendererModules/DateType/DateType.tsx 100.00% <100.00%> (ø)
...ibrary/src/rendererModules/EmailType/EmailType.tsx 100.00% <100.00%> (ø)
...-library/src/rendererModules/Handle/HandleType.tsx 91.89% <100.00%> (ø)
...-library/src/rendererModules/ISBNType/ISBNType.tsx 96.12% <100.00%> (ø)
...-library/src/rendererModules/JSONType/JSONType.tsx 88.67% <100.00%> (ø)
...rary/src/rendererModules/LocaleType/LocaleType.tsx 100.00% <100.00%> (ø)
...il-library/src/rendererModules/ORCiD/ORCIDType.tsx 79.76% <100.00%> (ø)
...il-library/src/rendererModules/URLType/URLType.tsx 100.00% <100.00%> (ø)
.../src/rendererModules/FallbackType/FallbackType.tsx 80.00% <0.00%> (ø)
... and 2 more
🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical parser fallback, Angular compatibility, and integration test issues remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 3 High severity · 2 Medium severity · 5 Low severity

Open (10)
What changed in this PR

This PR switches SPDX license fetching from a CORS proxy to the official SPDX GitHub repository and updates related tests, documentation, dependencies, and generated files.

Changes:

  • Uses raw GitHub SPDX JSON with fallback handling.
  • Adds unit, integration, and Playwright coverage.
  • Updates package versions, Angular tooling, and formatting configuration.
File Summary
README.md Documents SPDX fetching; requestTimeout is currently not configurable.
packages/​vue-library/​package.json Updates package metadata; release metadata remains at 0.4.4.
packages/​stencil-library/​web-types.json Updates generated package metadata.
packages/​stencil-library/​src/​utils/​__tests__/​Parser.unit.ts Tests renderer fallback behavior.
packages/​stencil-library/​src/​rendererModules/​SPDXType/​SPDXType.tsx Uses raw SPDX data; ordered resolution can abort fallback on errors, and failed fallbacks may be cached.
packages/​stencil-library/​src/​rendererModules/​SPDXType/​SPDX.mdx Documents the new SPDX source.
packages/​stencil-library/​src/​rendererModules/​SPDXType/​__tests__/​SPDXType.unit.ts Adds SPDX fetch and failure tests.
packages/​stencil-library/​src/​rendererModules/​SPDXType/​__tests__/​SPDXType.integration.unit.ts Live tests run in the default suite and access a private member, causing type-check failure.
packages/​stencil-library/​src/​components/​pid-tooltip/​readme.md Formatting update.
packages/​stencil-library/​src/​components/​pid-component/​__tests__/​spdx.e2e.playwright.ts Assertion does not distinguish resolved output from fallback output.
packages/​stencil-library/​src/​components/​pid-component/​__tests__/​spdx.e2e.html Adds the SPDX browser-test fixture.
packages/​stencil-library/​src/​components/​pid-collapsible/​readme.md Formatting update.
packages/​stencil-library/​src/​components.d.ts Updates generated component declarations.
packages/​stencil-library/​package.json Adds integration testing and updates dependencies; release metadata remains at 0.4.4.
packages/​stencil-library/​.prettierignore Ignores generated files.
packages/​react-library/​package.json Updates package metadata; release metadata remains at 0.4.4.
packages/​nextjs-app/​package.json Updates demo dependencies and versions.
packages/​angular-library/​package.json Updates dependencies; release metadata is stale and the peer range introduces an unrelated Angular compatibility break.
packages/​angular-library/​lib/​stencil-generated/​angular-component-lib/​boolean-attribute.ts Adds an unused helper under generated output.
package.json Bumps workspace version; synchronized release metadata remains at 0.4.4.
.prettierrc.json Updates Prettier configuration.
.prettierignore Ignores generated wrapper output.
.pre-commit-config.yaml Excludes generated files from whitespace checks.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages/angular-library/package.json Outdated
Comment thread packages/stencil-library/src/rendererModules/SPDXType/SPDXType.tsx
Comment thread README.md
Comment thread package.json Outdated
Comment thread packages/angular-library/package.json Outdated
Comment thread packages/react-library/package.json Outdated
Comment thread packages/stencil-library/package.json Outdated
Comment thread packages/vue-library/package.json Outdated
@github-actions

Copy link
Copy Markdown

🎨 Chromatic Visual Tests

✅ No visual changes

Review

View in Chromatic

Chromatic provides automated visual testing and review for component changes.

@github-actions

Copy link
Copy Markdown

Test Results

Coverage Summary

Node Lines Statements Branches Functions
22 78.02% 76.70% 63.15% 80.33%
24 78.02% 76.70% 63.15% 80.33%
26 78.02% 76.70% 63.15% 80.33%

Coverage & Quality Reports

📊 Codecov Report
🎨 Chromatic Status


For more details, check the workflow run

@github-actions

Copy link
Copy Markdown

🎨 Chromatic Visual Tests

✅ No visual changes

Review

View in Chromatic

Chromatic provides automated visual testing and review for component changes.

@github-actions

Copy link
Copy Markdown

Test Results

Coverage Summary

Node Lines Statements Branches Functions
22 79.91% 79.21% 66.65% 82.68%
24 79.91% 79.21% 66.65% 82.68%
26 79.91% 79.21% 66.65% 82.68%

Coverage & Quality Reports

📊 Codecov Report
🎨 Chromatic Status


For more details, check the workflow run

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread packages/stencil-library/package.json Outdated
These Angular packages are only used by the Angular Storybook/demo setup, so
they should not be published as runtime dependencies of the wrapper. Also
syncs the package-lock (workspace version 0.5.0 and stale spec updates).
…ions

Allow a single wrapper version to be consumed by the currently supported
framework versions: Angular 20/21/22 and React 18/19 (Vue already peers ^3.0.0).
The ranges are validated by a clean-room consumer matrix (see CI workflow).
The package.json had two conflicting 'test:integration' entries after the
integration suite moved to vitest; keep the vitest configuration and drop the
stale stencil-test one.
Run 'tsc -p <pkg> --noEmit' for the stencil, react, vue and angular packages
as part of CI via a new 'npm run typecheck' (lerna) script, so type errors
are caught before the test stage. The stencil-library tsconfig is adjusted
(strict:false, skipLibCheck, lib es2021, drop baseUrl) so its tsc check
passes under the package's own typescript 7.0.2 devDependency.
The wrappers are compiled with the latest toolchain but published with peer
ranges spanning the supported framework versions (Angular 20/21/22, React 18/19,
Vue 3). A new script packs the stencil library + wrapper from the current tree,
installs them into a throw-away consumer project together with a specific
framework version, and type-checks a consumer sample using the public API.
A GitHub Actions matrix runs it for every peer-range leg so the ranges are
continuously validated instead of assumed. All 6 legs pass locally.
@maximiliani
maximiliani added this pull request to stack #445 September 28, 2026 14:46
@maximiliani
maximiliani removed this pull request from stack #445 September 28, 2026 14:52
…rk-wrappers

Refactor/dedemo framework wrappers
@github-actions

Copy link
Copy Markdown

🎨 Chromatic Visual Tests

✅ No visual changes

Review

View in Chromatic

Chromatic provides automated visual testing and review for component changes.

@github-actions

Copy link
Copy Markdown

Test Results

Coverage Summary

Node Lines Statements Branches Functions
22 79.91% 79.21% 66.65% 82.68%
24 79.91% 79.21% 66.65% 82.68%
26 79.91% 79.21% 66.65% 82.68%

Coverage & Quality Reports

📊 Codecov Report
🎨 Chromatic Status


For more details, check the workflow run

@github-actions

Copy link
Copy Markdown

🎨 Chromatic Visual Tests

✅ No visual changes

Review

View in Chromatic

Chromatic provides automated visual testing and review for component changes.

@maximiliani
maximiliani requested a lite review from Copilot September 28, 2026 18:17
@github-actions

Copy link
Copy Markdown

🎨 Chromatic Visual Tests

✅ No visual changes

Review

View in Chromatic

Chromatic provides automated visual testing and review for component changes.

@github-actions

Copy link
Copy Markdown

Test Results

Coverage Summary

Node Lines Statements Branches Functions
22 79.91% 79.21% 66.65% 82.68%
24 79.91% 79.21% 66.65% 82.68%
26 79.91% 79.21% 66.65% 82.68%

Coverage & Quality Reports

📊 Codecov Report
🎨 Chromatic Status


For more details, check the workflow run

@github-actions

Copy link
Copy Markdown

Test Results

Coverage Summary

Node Lines Statements Branches Functions
22 79.91% 79.21% 66.65% 82.68%
24 79.91% 79.21% 66.65% 82.68%
26 79.91% 79.21% 66.65% 82.68%

Coverage & Quality Reports

📊 Codecov Report
🎨 Chromatic Status


For more details, check the workflow run

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread packages/stencil-library/vitest.config.mts
@maximiliani
maximiliani merged commit 9401bff into main Sep 29, 2026
18 checks passed
@maximiliani
maximiliani deleted the fix-cors-issues branch September 29, 2026 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants