Skip to content

PM-5788: Allow Autopilot to sync profile points - #150

Merged
jmgasper merged 1 commit into
developfrom
PM-5788
Aug 1, 2026
Merged

PM-5788: Allow Autopilot to sync profile points#150
jmgasper merged 1 commit into
developfrom
PM-5788

Conversation

@jmgasper

@jmgasper jmgasper commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

What was broken

Completed point challenges generated finance winnings, but winning member profiles retained an empty challengePoints summary. Profiles therefore hid the Points section, including for the reported member.

Root cause

Autopilot uses its existing refresh:member_stats M2M scope when it calls the member challenge-points endpoint after challenge completion. The endpoint accepted only update:user_profiles or all:user_profiles, so the automatic sync was rejected before member point rows could be stored.

What was changed

  • Allowed refresh:member_stats on PUT /members/challenge-points/:challengeId while preserving the existing profile scopes.
  • Restricted user-token access on this internal write route to the existing administrator roles; M2M authorization remains scope-based.
  • Updated the README and Swagger authorization documentation.

Any added/updated tests

  • Added a route contract regression test covering the accepted M2M scopes and admin-only user access.
  • Focused AppRoutes tests: 2 passing.
  • Existing challenge-point persistence tests: 2 passing.
  • pnpm lint: passed.
  • pnpm build: passed.
  • Full pnpm test: 205 passing and 28 unrelated existing failures. Those failures require bus Auth0 credentials or update stale Joi error-message expectations; none exercise the changed route or challenge-point persistence.

What was broken
Completed point challenges generated finance winnings, but winning member profiles retained an empty challengePoints summary, so Profiles hid the Points section.

Root cause
Autopilot calls the member challenge-points endpoint with its refresh:member_stats M2M scope. The endpoint accepted only update:user_profiles or all:user_profiles, so automatic synchronization was rejected before point rows could be stored.

What was changed
Allowed refresh:member_stats on the challenge-points update route while preserving the existing profile scopes. Restricted user-token access to administrators and updated the README and Swagger authorization contract.

Any added/updated tests
Added a route contract regression test for the accepted M2M scopes and admin-only user access. Focused route and challenge-point persistence tests, lint, and build pass. The full suite reports 205 passing tests and 28 unrelated existing failures caused by missing bus credentials and outdated Joi error-message expectations.
@jmgasper
jmgasper merged commit a80568d into develop Aug 1, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant