amal66 puts guardrails around Mike's riskiest backend work

This fork invests in the unglamorous checks that keep legal workspaces, documents and credentials from failing in expensive ways.

securityinfrastructure

amal66 has added focused safeguards around six places where a quiet mistake could have outsized consequences:

  • Account and project cleanup, including ownership boundaries and stored-file removal.
  • Document versions, to prevent one document from surfacing another's history.
  • Legal citations, including incomplete streamed responses and citation details.
  • Error handling, to keep provider keys out of messages and logs.
  • AI model selection, so default choices can be found reliably.
  • User records, including email normalisation and profile updates.

The team has also raised its testing baseline and published a prioritised backlog for the next coverage gaps. This is less a feature launch than a reliability programme with a clear next queue.

So what Legal teams considering Mike for sensitive matters should care because this work targets the places where data boundaries, source integrity and secret handling can go wrong.

View this fork on GitHub →

Spotted something wrong? Or know the PR text has fresher detail than the writeup above?

Commits in this thread

3 commits from amal66/mike, oldest first. Source extracted verbatim from the harvested git log.

SHA Subject Author Date
4039b949 test: minimal vitest harness for backend and frontend QA Runner 2026-07-20 ↗ GitHub
commit body
Ported from amal66/mike#24 onto current main; lockfiles regenerated against
this tree. Adds vitest as a dev dependency with a `test` script in both
packages, excludes test files from the backend tsc build, and seeds one
suite per package (backend: downloadTokens, 12 tests; frontend: cn() utils,
8 tests). Verified locally: backend 12/12, frontend 8/8 passing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
c139acc3 test: unit tests for access, storage, userApiKeys, chat doc resolution QA Runner 2026-07-20 ↗ GitHub
commit body
Ported from the amal66 fork (see index Open-Legal-Products/mike#205)
onto current main, adapted to this repo's backend/ layout
(apps/api/src/lib -> backend/src/lib), plus a v8 coverage ratchet.

Suites ported (51 new tests, verified locally):
- access.test.ts (7): owner/shared/private project access, doc access,
  review sharing, document-ID filtering. Dropped the fork's "org RBAC"
  describe block (7 cases) - org_id/org_members multi-tenancy and the
  role/canManage fields do not exist in this repo's access.ts.
- storage.test.ts (25): filename normalization/sanitization, RFC 5987
  encoding, Content-Disposition, storage key helpers. Dropped the fork's
  vi.mock of lib/env - this repo has no env module; storage reads
  process.env directly and the tested helpers are pure.
- userApiKeys.test.ts (10): normalizeApiKeyProvider + hasEnvApiKey.
  Added a beforeEach env clear so shell-exported API keys can't leak
  into assertions.
- chatTypes.test.ts (9): resolveDoc/resolveDocLabel, which live in
  lib/chat/types.ts here (the fork's lib/chatTools.ts equivalent).
  Dropped generateSpotlightNonce cases (2) - no such export here.

Suites dropped entirely (subject not present in this repo):
- upload.test.ts - tested hasMagicBytes; this repo's lib/upload.ts is
  only the multer middleware and exports no magic-byte checker.
- userSettings.test.ts - tested resolveTabularModel (fork-only keyed-
  provider fallback); this repo resolves tabular_model via
  resolveModel with a static default.

Coverage ratchet: vitest.config.mts adds v8 coverage over src/lib/**
with floors measured against this tree (2.58% stmts, 2.00% branches,
4.61% funcs, 2.58% lines -> floors 2/2/4/2). Full suite: 5 files,
63 tests passing (incl. the pre-existing 12 in downloadTokens.test.ts);
npm run test:coverage and npm run build both pass.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2053ca15 test: cover critical backend libs, raise coverage ratchet, add roadmap QA Runner 2026-07-20 ↗ GitHub
commit body
Six new unit suites (102 tests) for the highest-risk untested libs:
userDataCleanup (destructive account/project deletes), documentVersions
(document integrity), chat/citations (legal-citation parsing), safeError
(secret redaction), llm/models (model resolution), and userLookup
(profile email sync). Coverage floors ratchet up 2/2/4/2 ->
11/10/14/10 (measured 11.18/10.98/14.43/10.91), and
docs/testing-coverage.md gives contributors a prioritized backlog for
the remaining untested libs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

Capture this thread into my fork

Download a single Markdown prompt that tells Claude how to port every commit above into your working tree — adapting paths and structure to match your repo. Run it via claude -p < capture-thread-1344.md from inside the repo you want the changes in.

⬇ Download capture-thread-1344.md