[follow-up] app password issuance swallows Stalwart notCreated reason

closed
#71a97a6 opened by agent Sep 13

Context

Found while diagnosing the order-dependent TestIntegrationAppViewUI 500 (bug 1344bf0): the dev harness held a stale account at Stalwart’s 5-app-password quota, so x:AppPassword/set answered notCreated: {ap0: {type: "overQuota", ...}} — but neither issuance path decodes notCreated, so both surfaced the opaque server returned no created app password and the UI returned a bare 500. The real reason was only visible via a manual JMAP probe.

Task

  • Decode notCreated in the x:AppPassword/set responses in internal/appwd/appwd.go (Issue) and internal/account/account.go (IssuePassword); when created.ap0 is absent but notCreated.ap0 is present, return an error carrying its type + description (keep the existing message as the fallback when neither is present).
  • Cover with unit tests using the existing stub-server pattern (internal/account/account_test.go newStub; new internal/appwd/appwd_test.go — the package has none): a notCreated/overQuota response must surface overQuota and the server description in the returned error.
  • Re-run go test ./internal/appwd/ ./internal/account/ plus the full integration package to green.

Acceptance

  • Unit tests prove a notCreated refusal surfaces its type/description instead of the generic message; suites green. No behavior change on the success path.

1 Comment

agent 7a1ea19 Sep 13

Fixed (commit cc18d45f, TDD: failing tests first)

internal/appwd/appwd.go (Issue) and internal/account/account.go (IssuePassword) now decode notCreated on the x:AppPassword/set response. When created.ap0 is absent but notCreated.ap0 is present, the error carries the server type + description, e.g. appwd: app password not created (overQuota): You have exceeded your quota of 5 app passwords. The old generic message remains as the fallback when neither map has the key. No behavior change on the success path.

Tests: new internal/appwd/appwd_test.go (package previously had none; minimal stub server) plus TestIssuePasswordNotCreatedSurfacesReason in internal/account/account_test.go — both watched fail with the swallowed message before the fix.

Verification: go test ./... (unit) green, full SOVRN_INTEGRATION=1 integration package 8⁄8 PASS, gofmt/vet clean. Left open for your review.