fix(local): install dependencies when the lockfile changes, not only when node_modules is absent #348

Merged
bermudalamb merged 2 commits from fix/local-install-skips-new-dependencies into main 2026-09-10 10:07:00 -05:00
Owner

Fixes the local start failing with:

error TS2307: Cannot find module '@simplewebauthn/server' or its corresponding type declarations.

naming a package that is right there in package.json. That reads as a broken checkout rather than a missing install, which is why it costs more than it should.

The cause

One line in Install-IfMissing:

if (Test-Path (Join-Path $Directory 'node_modules')) {
    Write-Note "$name dependencies already installed"
    return
}

It asked whether node_modules existed, which is true for anyone who has ever run the script. So a branch that adds a dependency never installs it: the pull brings a new package.json and lockfile, the script reports dependencies already installed, and the build fails on an import the source is entirely right to make.

The passkeys work surfaced it, adding @simplewebauthn/server to the backend and @simplewebauthn/browser to the frontend. Nothing about it is specific to those — any dependency added on any branch would have done the same, and the failure would have looked equally unrelated to its cause each time.

The fix

Compare timestamps instead. npm writes node_modules/.package-lock.json describing exactly what it put there, so holding that against package-lock.json answers the question actually being asked: is what is installed what is currently asked for.

A pull that changes dependencies makes the lockfile newer and this notices. A pull that does not leaves the check skipping the install exactly as before, which is the whole reason the check exists.

Testing

Both branches exercised against the real working tree:

step: Installing backend dependencies (the lockfile has changed)
...after npm install...
note: backend dependencies are up to date
step: Installing frontend dependencies (the lockfile has changed)

Backend and frontend both build cleanly afterwards.

🤖 Generated with Claude Code

Fixes the local start failing with: ``` error TS2307: Cannot find module '@simplewebauthn/server' or its corresponding type declarations. ``` naming a package that is right there in `package.json`. That reads as a broken checkout rather than a missing install, which is why it costs more than it should. ## The cause One line in `Install-IfMissing`: ```powershell if (Test-Path (Join-Path $Directory 'node_modules')) { Write-Note "$name dependencies already installed" return } ``` It asked whether `node_modules` **existed**, which is true for anyone who has ever run the script. So a branch that *adds* a dependency never installs it: the pull brings a new `package.json` and lockfile, the script reports dependencies already installed, and the build fails on an import the source is entirely right to make. The passkeys work surfaced it, adding `@simplewebauthn/server` to the backend and `@simplewebauthn/browser` to the frontend. Nothing about it is specific to those — any dependency added on any branch would have done the same, and the failure would have looked equally unrelated to its cause each time. ## The fix Compare timestamps instead. npm writes `node_modules/.package-lock.json` describing exactly what it put there, so holding that against `package-lock.json` answers the question actually being asked: **is what is installed what is currently asked for.** A pull that changes dependencies makes the lockfile newer and this notices. A pull that does not leaves the check skipping the install exactly as before, which is the whole reason the check exists. ## Testing Both branches exercised against the real working tree: ``` step: Installing backend dependencies (the lockfile has changed) ...after npm install... note: backend dependencies are up to date step: Installing frontend dependencies (the lockfile has changed) ``` Backend and frontend both build cleanly afterwards. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
bermudalamb added 1 commit 2026-09-10 08:58:36 -05:00
fix(local): install dependencies when the lockfile changes, not only when node_modules is absent
SonarQube Analysis / sonarqube (pull_request) Failing after 25m18s
Linting / lint (pull_request) Successful in 3m41s
46f7cb8612
Starting the stack locally failed to build with four copies of

    error TS2307: Cannot find module '@simplewebauthn/server'

naming a package that is right there in package.json. That reads as a broken checkout rather than a missing install, which is why it costs more than it should.

The cause is one line in Install-IfMissing. It asked whether node_modules existed and returned early if it did, which is true for anyone who has ever run the script. So a branch that ADDS a dependency never installs it: the pull brings a new package.json and a new lockfile, the script says dependencies already installed, and the build then fails on an import the source is entirely right to make.

The passkeys work is what surfaced it, adding @simplewebauthn/server to the backend and @simplewebauthn/browser to the frontend, but nothing about it is specific to those. Any dependency added on any branch would have done the same, and the failure would have looked equally unrelated to its cause each time.

It now compares timestamps instead. npm writes node_modules/.package-lock.json describing exactly what it put there, so holding that against package-lock.json answers the question actually being asked: is what is installed what is currently asked for. A pull that changes dependencies makes the lockfile newer and this notices; a pull that does not leaves the check skipping the install exactly as before, which is the whole reason the check exists.

Both branches were exercised against the real working tree: stale before installing, up to date after.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
bermudalamb added 1 commit 2026-09-10 09:56:46 -05:00
Merge branch 'main' into fix/local-install-skips-new-dependencies
SonarQube Analysis / sonarqube (pull_request) Failing after 27m39s
Linting / lint (pull_request) Successful in 2m59s
c9829d4384
bermudalamb merged commit 79a2b606ea into main 2026-09-10 10:07:00 -05:00
bermudalamb deleted branch fix/local-install-skips-new-dependencies 2026-09-10 10:07:04 -05:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: bermudalamb/redefined-designs#348