builtbykev cdb01f97a2 The ledger id is a UUID, and only an authenticated request could have found it
`ledger_entries.id` is a uuid. The ancestry route parsed it with
Number.parseInt, so every real row would have returned 400 "invalid ledger id" —
the endpoint had never successfully served anything.

The unauthenticated probe that "proved the route was live" returned 401 from
requireAuth BEFORE the handler ran, so it could not have seen this. A
route-existence check and an acceptance test are not the same evidence, which is
exactly why the acceptance step demands a real authenticated 200 against a real
row rather than a 401.

Fixed to a UUID match, and the test asserts the real production id shape passes
while '1' and a traversal string do not.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CQJeAG8vcDoL5zkiaJyVb8
2026-08-31 00:29:22 -04:00
S
Description
No description provided
35 MiB
Languages
JavaScript 68.3%
TypeScript 14.4%
HTML 11.5%
Python 4.6%
CSS 0.6%
Other 0.5%