📦 chore: npm audit fixes and Mongoose 8.23 TypeScript follow-ups (#12996)

* chore: Update axios dependency to version 1.16.0 across multiple package files

* chore: Update express-rate-limit and ip-address dependencies to versions 8.5.1 and 10.2.0 in package-lock.json and package.json

* chore: Update mongoose and hono dependencies to versions 8.23.1 and 4.12.18 across multiple package files

* fix: Add type parameters to mongoose lean queries in accessRole and aclEntry methods

* fix: Add type parameters to mongoose lean queries in action, agent, and agentCategory methods

* chore: Update moduleResolution to 'bundler' in tsconfig.json for api and data-schemas packages

* fix: Update mongoose lean queries to include type parameters across various methods for improved type safety
This commit is contained in:
Danny Avila 2026-05-07 09:47:40 -04:00 • committed by GitHub
parent 1bc2692a15
commit 40a05bbf83
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
35 changed files with 243 additions and 194 deletions

View file

@ -15,15 +15,14 @@ jest.mock('@librechat/data-schemas', () => ({
let mongoServer: MongoMemoryServer;
let Balance: mongoose.Model<IBalance>;
const findBalanceByUser = (userId: string) =>
Balance.findOne({ user: userId }).lean() as Promise<IBalance | null>;
const findBalanceByUser = (userId: string) => Balance.findOne({ user: userId }).lean<IBalance>();
const upsertBalanceFields = (userId: string, fields: IBalanceUpdate) =>
Balance.findOneAndUpdate(
{ user: userId },
{ $set: fields },
{ upsert: true, new: true },
).lean() as Promise<IBalance | null>;
).lean<IBalance>();
beforeAll(async () => {
mongoServer = await MongoMemoryServer.create();

View file

@ -28,6 +28,17 @@ jest.mock('@librechat/data-schemas', () => ({
let mongoServer: MongoMemoryServer;
let methods: AllMethods;
const mockGetUserPrincipals = () =>
jest.fn<ReturnType<AllMethods['getUserPrincipals']>, Parameters<AllMethods['getUserPrincipals']>>(
methods.getUserPrincipals,
);
const mockHasCapabilityForPrincipals = () =>
jest.fn<
ReturnType<AllMethods['hasCapabilityForPrincipals']>,
Parameters<AllMethods['hasCapabilityForPrincipals']>
>(methods.hasCapabilityForPrincipals);
beforeAll(async () => {
mongoServer = await MongoMemoryServer.create();
await mongoose.connect(mongoServer.getUri());
@ -229,7 +240,7 @@ describe('capabilities integration (real MongoDB)', () => {
describe('AsyncLocalStorage per-request caching', () => {
it('caches getUserPrincipals within a single request context', async () => {
await methods.seedSystemGrants();
const getUserPrincipals = jest.fn(methods.getUserPrincipals);
const getUserPrincipals = mockGetUserPrincipals();
const { hasCapability } = generateCapabilityCheck({
getUserPrincipals,
@ -247,7 +258,7 @@ describe('capabilities integration (real MongoDB)', () => {
it('caches capability results within a single request context', async () => {
await methods.seedSystemGrants();
const hasCapabilityForPrincipals = jest.fn(methods.hasCapabilityForPrincipals);
const hasCapabilityForPrincipals = mockHasCapabilityForPrincipals();
const { hasCapability } = generateCapabilityCheck({
getUserPrincipals: methods.getUserPrincipals,
@ -262,14 +273,16 @@ describe('capabilities integration (real MongoDB)', () => {
});
const accessAdminCalls = hasCapabilityForPrincipals.mock.calls.filter(
(args) => args[0].capability === SystemCapabilities.ACCESS_ADMIN,
(args) =>
(args[0] as { capability: SystemCapability }).capability ===
SystemCapabilities.ACCESS_ADMIN,
);
expect(accessAdminCalls).toHaveLength(1);
});
it('does NOT share cache across separate request contexts', async () => {
await methods.seedSystemGrants();
const getUserPrincipals = jest.fn(methods.getUserPrincipals);
const getUserPrincipals = mockGetUserPrincipals();
const { hasCapability } = generateCapabilityCheck({
getUserPrincipals,
@ -325,7 +338,7 @@ describe('capabilities integration (real MongoDB)', () => {
it('falls through to DB when outside request context (no ALS)', async () => {
await methods.seedSystemGrants();
const getUserPrincipals = jest.fn(methods.getUserPrincipals);
const getUserPrincipals = mockGetUserPrincipals();
const { hasCapability } = generateCapabilityCheck({
getUserPrincipals,
@ -339,7 +352,7 @@ describe('capabilities integration (real MongoDB)', () => {
});
it('caches false results correctly (negative caching)', async () => {
const hasCapabilityForPrincipals = jest.fn(methods.hasCapabilityForPrincipals);
const hasCapabilityForPrincipals = mockHasCapabilityForPrincipals();
const { hasCapability } = generateCapabilityCheck({
getUserPrincipals: methods.getUserPrincipals,
@ -354,14 +367,16 @@ describe('capabilities integration (real MongoDB)', () => {
});
const manageUserCalls = hasCapabilityForPrincipals.mock.calls.filter(
(args) => args[0].capability === SystemCapabilities.MANAGE_USERS,
(args) =>
(args[0] as { capability: SystemCapability }).capability ===
SystemCapabilities.MANAGE_USERS,
);
expect(manageUserCalls).toHaveLength(1);
});
it('uses separate principal cache keys for different users in same context', async () => {
await methods.seedSystemGrants();
const getUserPrincipals = jest.fn(methods.getUserPrincipals);
const getUserPrincipals = mockGetUserPrincipals();
const { hasCapability } = generateCapabilityCheck({
getUserPrincipals,
@ -378,7 +393,7 @@ describe('capabilities integration (real MongoDB)', () => {
it('uses separate principal cache keys for different tenantIds (same user)', async () => {
await methods.seedSystemGrants();
const getUserPrincipals = jest.fn(methods.getUserPrincipals);
const getUserPrincipals = mockGetUserPrincipals();
const { hasCapability } = generateCapabilityCheck({
getUserPrincipals,
@ -465,8 +480,8 @@ describe('capabilities integration (real MongoDB)', () => {
it('every DB call executes (no caching) when ALS context is missing', async () => {
await methods.seedSystemGrants();
const getUserPrincipals = jest.fn(methods.getUserPrincipals);
const hasCapabilityForPrincipals = jest.fn(methods.hasCapabilityForPrincipals);
const getUserPrincipals = mockGetUserPrincipals();
const hasCapabilityForPrincipals = mockHasCapabilityForPrincipals();
const { hasCapability } = generateCapabilityCheck({
getUserPrincipals,
@ -485,7 +500,7 @@ describe('capabilities integration (real MongoDB)', () => {
it('nested capabilityContextMiddleware creates an independent inner context', async () => {
await methods.seedSystemGrants();
const getUserPrincipals = jest.fn(methods.getUserPrincipals);
const getUserPrincipals = mockGetUserPrincipals();
const { hasCapability } = generateCapabilityCheck({
getUserPrincipals,
@ -581,7 +596,7 @@ describe('capabilities integration (real MongoDB)', () => {
capability: SystemCapabilities.READ_AGENTS,
});
const getUserPrincipals = jest.fn(methods.getUserPrincipals);
const getUserPrincipals = mockGetUserPrincipals();
const { hasCapability } = generateCapabilityCheck({
getUserPrincipals,