Compare commits
84
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1d8858fbda | ||
|
|
eaf5e5d180 | ||
|
|
be780ebe13 | ||
|
|
b6c2cd5116 | ||
|
|
dc79d653e5 | ||
|
|
b0d5334e06 | ||
|
|
d65eb58883 | ||
|
|
7f5f0fb676 | ||
|
|
47f3591ed8 | ||
|
|
6fc7fce948 | ||
|
|
eb6d918650 | ||
|
|
d47ac71c47 | ||
|
|
17e5371e9c | ||
|
|
e2c63a9905 | ||
|
|
3f3c5953f6 | ||
|
|
124c6702a9 | ||
|
|
e25722d9ab | ||
|
|
07d586d0ad | ||
|
|
b793640507 | ||
|
|
21a5d18f59 | ||
|
|
f614414070 | ||
|
|
310b63b0cb | ||
|
|
c2c76c5817 | ||
|
|
c5a4d106da | ||
|
|
2437ffce42 | ||
|
|
eb648f3f76 | ||
|
|
74e5fffc10 | ||
|
|
748ef32180 | ||
|
|
b0c4ea8282 | ||
|
|
e236669fde | ||
|
|
fb5a0928bd | ||
|
|
264edd2e3a | ||
|
|
cd2cbe7be6 | ||
|
|
73182d0c0c | ||
|
|
cbe3a9a772 | ||
|
|
2e9b5c83c5 | ||
|
|
102397fe69 | ||
|
|
68a192e430 | ||
|
|
ccd5074c90 | ||
|
|
2b4cf20d75 | ||
|
|
cef2f77149 | ||
|
|
68b6417149 | ||
|
|
c5719ef362 | ||
|
|
5e5b61987a | ||
|
|
c564566432 | ||
|
|
9188626051 | ||
|
|
7ae9ecdc36 | ||
|
|
1980d79eee | ||
|
|
9423f11567 | ||
|
|
576013d627 | ||
|
|
7c08138fe4 | ||
|
|
a7829d591a | ||
|
|
1ed4470fc2 | ||
|
|
7a16b1b52f | ||
|
|
cf9d41b476 | ||
|
|
e820e7fecd | ||
|
|
4fdeb70a93 | ||
|
|
9a1f56c431 | ||
|
|
ade9dbb3ba | ||
|
|
d1a8596208 | ||
|
|
a3c09d9b67 | ||
|
|
a7f4c86464 | ||
|
|
0804566736 | ||
|
|
55363cbd18 | ||
|
|
868eb344f5 | ||
|
|
0b15497c09 | ||
|
|
d55f6cce23 | ||
|
|
3236efa846 | ||
|
|
d5a6db289d | ||
|
|
d8ccb5b733 | ||
|
|
0fa1a292c7 | ||
|
|
c3f044bd65 | ||
|
|
d2115364ae | ||
|
|
28cf0a342c | ||
|
|
d88e77f459 | ||
|
|
06eb433db5 | ||
|
|
1a6d349dad | ||
|
|
75d3534d82 | ||
|
|
ff041544f2 | ||
|
|
59265f78b6 | ||
|
|
6e0a278340 | ||
|
|
e651dd0d65 | ||
|
|
22c113fc29 | ||
|
|
e953ee7c5f |
No files matched your search
+13
-5
@@ -20,7 +20,7 @@ PORT=80
|
|||||||
# =============================================================================
|
# =============================================================================
|
||||||
# CORS
|
# CORS
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
# Comma-separated list of allowed origins
|
# JSON array of allowed origins (pydantic-settings format)
|
||||||
# In production, only include your actual domain
|
# In production, only include your actual domain
|
||||||
ALLOWED_ORIGINS=["https://schoolcompare.co.uk"]
|
ALLOWED_ORIGINS=["https://schoolcompare.co.uk"]
|
||||||
|
|
||||||
@@ -33,13 +33,21 @@ ADMIN_API_KEY=CHANGE_THIS_TO_A_SECURE_RANDOM_KEY
|
|||||||
|
|
||||||
# Rate limiting (requests per minute per IP)
|
# Rate limiting (requests per minute per IP)
|
||||||
RATE_LIMIT_PER_MINUTE=60
|
RATE_LIMIT_PER_MINUTE=60
|
||||||
RATE_LIMIT_BURST=10
|
GLOBAL_RATE_LIMIT_PER_MINUTE=3000
|
||||||
|
|
||||||
# Maximum request body size in bytes (default 1MB)
|
# Maximum request body size in bytes (default 1MB)
|
||||||
MAX_REQUEST_SIZE=1048576
|
MAX_REQUEST_SIZE=1048576
|
||||||
|
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
# API
|
# SEARCH AND OPTIONAL FEATURE FLAGS
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
DEFAULT_PAGE_SIZE=50
|
TYPESENSE_URL=http://localhost:8108
|
||||||
MAX_PAGE_SIZE=100
|
TYPESENSE_API_KEY=CHANGE_THIS_TO_YOUR_TYPESENSE_KEY
|
||||||
|
|
||||||
|
# Empty URL disables Unleash-backed flags. Match the managed environment when used.
|
||||||
|
UNLEASH_URL=
|
||||||
|
UNLEASH_API_TOKEN=
|
||||||
|
|
||||||
|
# Page-size limits are currently declared by route Query parameters.
|
||||||
|
# DEFAULT_PAGE_SIZE, MAX_PAGE_SIZE and RATE_LIMIT_BURST are not reliable tuning
|
||||||
|
# controls in the current routes; see docs/LEGACY_CODE.md.
|
||||||
+13
-187
@@ -1,191 +1,17 @@
|
|||||||
# Docker Deployment Guide
|
# Docker deployment
|
||||||
|
|
||||||
## Quick Start
|
The maintained deployment runbook is [docs/DEPLOY.md](docs/DEPLOY.md).
|
||||||
|
|
||||||
Deploy the complete SchoolCompare stack (PostgreSQL + FastAPI + Next.js) with one command:
|
- Production: `docker-compose.portainer.yml`, using `:prod` images.
|
||||||
|
- Staging: `docker-compose.portainer.staging.yml`, using `:staging` images.
|
||||||
|
- Builds and deployment: `.gitea/workflows/deploy.yml`.
|
||||||
|
- Human-approved production promotion: `.gitea/workflows/promote.yml`.
|
||||||
|
|
||||||
```bash
|
The generic `docker-compose.yml` is not a supported one-command onboarding path:
|
||||||
docker-compose up -d
|
it still uses `:latest` tags that the release workflow no longer publishes and
|
||||||
```
|
lacks the full current CMS setup. Review the [legacy inventory](docs/LEGACY_CODE.md)
|
||||||
|
before using old compose examples. Starting an empty database does not populate
|
||||||
|
school marts.
|
||||||
|
|
||||||
This will start:
|
For architecture, configuration and test commands, see
|
||||||
- **PostgreSQL** on port 5432 (database)
|
[ARCHITECTURE.md](docs/ARCHITECTURE.md) and [DEVELOPMENT.md](docs/DEVELOPMENT.md).
|
||||||
- **FastAPI** on port 8000 (backend API)
|
|
||||||
- **Next.js** on port 3000 (frontend)
|
|
||||||
|
|
||||||
## Service Details
|
|
||||||
|
|
||||||
### PostgreSQL Database
|
|
||||||
- **Port**: 5432
|
|
||||||
- **Container**: `schoolcompare_db`
|
|
||||||
- **Credentials**:
|
|
||||||
- User: `schoolcompare`
|
|
||||||
- Password: `schoolcompare`
|
|
||||||
- Database: `schoolcompare`
|
|
||||||
- **Volume**: `postgres_data` (persistent storage)
|
|
||||||
|
|
||||||
### FastAPI Backend
|
|
||||||
- **Port**: 8000 → 80 (container)
|
|
||||||
- **Container**: `schoolcompare_backend`
|
|
||||||
- **Built from**: Root `Dockerfile`
|
|
||||||
- **API Endpoint**: http://localhost:8000/api
|
|
||||||
- **Health Check**: http://localhost:8000/api/data-info
|
|
||||||
|
|
||||||
### Next.js Frontend
|
|
||||||
- **Port**: 3000
|
|
||||||
- **Container**: `schoolcompare_nextjs`
|
|
||||||
- **Built from**: `nextjs-app/Dockerfile`
|
|
||||||
- **URL**: http://localhost:3000
|
|
||||||
- **Connects to**: Backend via internal network
|
|
||||||
|
|
||||||
## Commands
|
|
||||||
|
|
||||||
### Start all services
|
|
||||||
```bash
|
|
||||||
docker-compose up -d
|
|
||||||
```
|
|
||||||
|
|
||||||
### View logs
|
|
||||||
```bash
|
|
||||||
# All services
|
|
||||||
docker-compose logs -f
|
|
||||||
|
|
||||||
# Specific service
|
|
||||||
docker-compose logs -f nextjs
|
|
||||||
docker-compose logs -f backend
|
|
||||||
docker-compose logs -f db
|
|
||||||
```
|
|
||||||
|
|
||||||
### Check status
|
|
||||||
```bash
|
|
||||||
docker-compose ps
|
|
||||||
```
|
|
||||||
|
|
||||||
### Stop all services
|
|
||||||
```bash
|
|
||||||
docker-compose down
|
|
||||||
```
|
|
||||||
|
|
||||||
### Rebuild after code changes
|
|
||||||
```bash
|
|
||||||
# Rebuild and restart specific service
|
|
||||||
docker-compose up -d --build nextjs
|
|
||||||
|
|
||||||
# Rebuild all services
|
|
||||||
docker-compose up -d --build
|
|
||||||
```
|
|
||||||
|
|
||||||
### Clean restart (remove volumes)
|
|
||||||
```bash
|
|
||||||
docker-compose down -v
|
|
||||||
docker-compose up -d
|
|
||||||
```
|
|
||||||
|
|
||||||
## Initial Database Setup
|
|
||||||
|
|
||||||
After first start, you may need to initialize the database:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Enter the backend container
|
|
||||||
docker exec -it schoolcompare_backend bash
|
|
||||||
|
|
||||||
# Run migrations or data loading
|
|
||||||
python -m backend.data_loader
|
|
||||||
```
|
|
||||||
|
|
||||||
## Accessing Services
|
|
||||||
|
|
||||||
Once running:
|
|
||||||
- **Frontend**: http://localhost:3000
|
|
||||||
- **Backend API**: http://localhost:8000/api
|
|
||||||
- **API Docs**: http://localhost:8000/docs (Swagger UI)
|
|
||||||
- **Database**: localhost:5432 (use any PostgreSQL client)
|
|
||||||
|
|
||||||
## Environment Variables
|
|
||||||
|
|
||||||
Create a `.env` file in the root directory to customize:
|
|
||||||
|
|
||||||
```env
|
|
||||||
# Database
|
|
||||||
POSTGRES_USER=schoolcompare
|
|
||||||
POSTGRES_PASSWORD=your_secure_password
|
|
||||||
POSTGRES_DB=schoolcompare
|
|
||||||
|
|
||||||
# Backend
|
|
||||||
DATABASE_URL=postgresql://schoolcompare:your_secure_password@db:5432/schoolcompare
|
|
||||||
|
|
||||||
# Frontend (for client-side access)
|
|
||||||
NEXT_PUBLIC_API_URL=http://localhost:8000/api
|
|
||||||
```
|
|
||||||
|
|
||||||
Then run:
|
|
||||||
```bash
|
|
||||||
docker-compose up -d
|
|
||||||
```
|
|
||||||
|
|
||||||
## Troubleshooting
|
|
||||||
|
|
||||||
### Backend not connecting to database
|
|
||||||
```bash
|
|
||||||
# Check database health
|
|
||||||
docker-compose ps
|
|
||||||
|
|
||||||
# View backend logs
|
|
||||||
docker-compose logs backend
|
|
||||||
|
|
||||||
# Restart backend
|
|
||||||
docker-compose restart backend
|
|
||||||
```
|
|
||||||
|
|
||||||
### Frontend not connecting to backend
|
|
||||||
```bash
|
|
||||||
# Check backend health
|
|
||||||
curl http://localhost:8000/api/data-info
|
|
||||||
|
|
||||||
# Check Next.js environment variables
|
|
||||||
docker exec schoolcompare_nextjs env | grep API
|
|
||||||
```
|
|
||||||
|
|
||||||
### Port already in use
|
|
||||||
```bash
|
|
||||||
# Change ports in docker-compose.yml
|
|
||||||
# For example, change "3000:3000" to "3001:3000"
|
|
||||||
```
|
|
||||||
|
|
||||||
### Rebuild from scratch
|
|
||||||
```bash
|
|
||||||
docker-compose down -v
|
|
||||||
docker system prune -a
|
|
||||||
docker-compose up -d --build
|
|
||||||
```
|
|
||||||
|
|
||||||
## Production Deployment
|
|
||||||
|
|
||||||
For production, update the following:
|
|
||||||
|
|
||||||
1. **Use secure passwords** in `.env` file
|
|
||||||
2. **Configure reverse proxy** (Nginx) in front of Next.js
|
|
||||||
3. **Enable HTTPS** with SSL certificates
|
|
||||||
4. **Set production environment variables**:
|
|
||||||
```env
|
|
||||||
NODE_ENV=production
|
|
||||||
POSTGRES_PASSWORD=<strong-password>
|
|
||||||
```
|
|
||||||
5. **Backup database** regularly:
|
|
||||||
```bash
|
|
||||||
docker exec schoolcompare_db pg_dump -U schoolcompare schoolcompare > backup.sql
|
|
||||||
```
|
|
||||||
|
|
||||||
## Network Architecture
|
|
||||||
|
|
||||||
```
|
|
||||||
Internet
|
|
||||||
↓
|
|
||||||
Next.js (port 3000) ← User browsers
|
|
||||||
↓ (internal network)
|
|
||||||
FastAPI (port 8000) ← API calls
|
|
||||||
↓ (internal network)
|
|
||||||
PostgreSQL (port 5432) ← Data queries
|
|
||||||
```
|
|
||||||
|
|
||||||
All services communicate via the `schoolcompare-network` Docker network.
|
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
|
> Historical migration record, retained for context. Setup and architecture claims below may be obsolete. Use [README.md](README.md), [architecture](docs/ARCHITECTURE.md) and [deployment](docs/DEPLOY.md) for current guidance.
|
||||||
|
|
||||||
# SchoolCompare: Vanilla JS → Next.js Migration Summary
|
# SchoolCompare: Vanilla JS → Next.js Migration Summary
|
||||||
|
|
||||||
## Overview
|
## Overview
|
||||||
|
|||||||
@@ -1,214 +1,67 @@
|
|||||||
# Primary School Compass 🧒📚
|
# SchoolCompare
|
||||||
|
|
||||||
A modern web application for comparing **primary school (KS2)** performance data in **Wandsworth and Merton** over the last 5 years. Built with FastAPI and vanilla JavaScript with Chart.js visualizations.
|
SchoolCompare compares schools across England: primary (KS2), secondary (KS4),
|
||||||
|
all-through and post-16 provision, with coverage depending on the source dataset.
|
||||||
|
It provides school search, postcode maps, comparisons, rankings, place pages,
|
||||||
|
Ofsted information, admissions and destination measures. Editorial content lives
|
||||||
|
in a Payload CMS blog.
|
||||||
|
|
||||||

|
## Start here
|
||||||

|
|
||||||

|
|
||||||
|
|
||||||
## Features
|
- [Architecture and data flow](docs/ARCHITECTURE.md)
|
||||||
|
- [Development and validation](docs/DEVELOPMENT.md)
|
||||||
|
- [Deployment and promotion](docs/DEPLOY.md)
|
||||||
|
- [Legacy and unused-code inventory](docs/LEGACY_CODE.md)
|
||||||
|
- [Frontend conventions](nextjs-app/README.md)
|
||||||
|
- [CMS publishing](nextjs-app/docs/PUBLISHING.md)
|
||||||
|
|
||||||
- 📊 **Interactive Charts** - Visualize KS2 performance trends over time
|
## Repository map
|
||||||
- 🔍 **Smart Search** - Find primary schools by name in Wandsworth & Merton
|
|
||||||
- ⚖️ **Side-by-Side Comparison** - Compare up to 5 schools simultaneously
|
|
||||||
- 🏆 **Rankings** - View top-performing primary schools by various KS2 metrics
|
|
||||||
- 📱 **Responsive Design** - Works beautifully on desktop and mobile
|
|
||||||
|
|
||||||
## Key Metrics (KS2)
|
| Path | Responsibility |
|
||||||
|
|---|---|
|
||||||
|
| `backend/` | FastAPI routes, cached school data, read-only SQLAlchemy mappings, feature flags |
|
||||||
|
| `nextjs-app/` | Next.js App Router, React UI, Payload CMS, frontend tests |
|
||||||
|
| `pipeline/plugins/extractors/` | Custom Singer taps for GIAS, EES, Ofsted and other datasets |
|
||||||
|
| `pipeline/transform/` | dbt staging/intermediate models, marts, seeds and data tests |
|
||||||
|
| `pipeline/dags/` | Airflow extraction, transformation and publication workflows |
|
||||||
|
| `pipeline/scripts/` | Search indexing, code generation and operational diagnostics |
|
||||||
|
| `e2e/` | Playwright journeys against a running environment |
|
||||||
|
| `.gitea/workflows/` | PR checks, staging deployment and manual production promotion |
|
||||||
|
| `scripts/` | CI review tooling and historical data utilities; see the legacy inventory |
|
||||||
|
| `docs/superpowers/`, `mockups/` | Design history and prototypes, not application entry points |
|
||||||
|
|
||||||
The application tracks these Key Stage 2 performance indicators:
|
## Runtime
|
||||||
|
|
||||||
| Metric | Description |
|
The public site is **Next.js**, not the FastAPI root page. Browser `/api/*`
|
||||||
|--------|-------------|
|
requests pass through a Next.js route handler to FastAPI. Server-rendered pages
|
||||||
| **Reading Progress** | Progress in reading from KS1 to KS2 |
|
call FastAPI directly using `FASTAPI_URL`, including its `/api` suffix.
|
||||||
| **Writing Progress** | Progress in writing from KS1 to KS2 |
|
|
||||||
| **Maths Progress** | Progress in maths from KS1 to KS2 |
|
|
||||||
| **Reading Expected %** | Percentage meeting expected standard in reading |
|
|
||||||
| **Writing Expected %** | Percentage meeting expected standard in writing |
|
|
||||||
| **Maths Expected %** | Percentage meeting expected standard in maths |
|
|
||||||
| **Reading, Writing & Maths Combined %** | Percentage meeting expected standard in all three subjects |
|
|
||||||
|
|
||||||
## Quick Start
|
PostgreSQL/PostGIS stores school data. Meltano/Singer extracts source data;
|
||||||
|
dbt builds `marts.*`; FastAPI reads those tables. Typesense serves text search
|
||||||
|
and autocomplete. Payload runs inside Next.js and owns a separate `payload`
|
||||||
|
database schema and uploaded media.
|
||||||
|
|
||||||
### 1. Clone and Setup
|
There is **no automatic CSV import or sample dataset on startup**. A working
|
||||||
|
school-data environment needs populated marts from the pipeline or an approved
|
||||||
|
database snapshot. See [development](docs/DEVELOPMENT.md) before choosing a setup.
|
||||||
|
|
||||||
```bash
|
## Validation
|
||||||
cd school_results
|
|
||||||
|
|
||||||
# Create virtual environment
|
```sh
|
||||||
python -m venv venv
|
cd nextjs-app
|
||||||
source venv/bin/activate # On Windows: venv\Scripts\activate
|
npm ci
|
||||||
|
npm run typecheck
|
||||||
# Install dependencies
|
npm test -- --runInBand
|
||||||
pip install -r requirements.txt
|
|
||||||
```
|
```
|
||||||
|
|
||||||
### 2. Run the Application
|
Backend checks, pipeline validation, runtime versions and E2E requirements are
|
||||||
|
listed in [DEVELOPMENT.md](docs/DEVELOPMENT.md). No `npm run lint` script is
|
||||||
|
currently defined.
|
||||||
|
|
||||||
```bash
|
## Deployment
|
||||||
# Start the server
|
|
||||||
python -m uvicorn backend.app:app --reload --port 8000
|
|
||||||
```
|
|
||||||
|
|
||||||
Then open http://localhost:8000 in your browser.
|
|
||||||
|
|
||||||
The app will run with **sample data** by default, showing **110 primary schools** (66 in Wandsworth, 44 in Merton) with 5 years of KS2 performance data.
|
|
||||||
|
|
||||||
### 3. (Optional) Use Real Data
|
|
||||||
|
|
||||||
To use real UK school performance data:
|
|
||||||
|
|
||||||
1. Visit [Compare School Performance - Download Data](https://www.compare-school-performance.service.gov.uk/download-data)
|
|
||||||
|
|
||||||
2. Download **Key Stage 2** data for the years you want (2019-2024)
|
|
||||||
- Select "Key Stage 2" as the data type
|
|
||||||
|
|
||||||
3. Place the CSV files in the `data/` folder
|
|
||||||
|
|
||||||
4. Restart the server - it will automatically load and filter to Wandsworth & Merton schools
|
|
||||||
|
|
||||||
**Note:** The app only displays schools in Wandsworth and Merton. Data from other areas will be filtered out.
|
|
||||||
|
|
||||||
See the helper script for more details:
|
|
||||||
```bash
|
|
||||||
python scripts/download_data.py
|
|
||||||
```
|
|
||||||
|
|
||||||
## Project Structure
|
|
||||||
|
|
||||||
```
|
|
||||||
school_results/
|
|
||||||
├── backend/
|
|
||||||
│ └── app.py # FastAPI application with all API endpoints
|
|
||||||
├── frontend/
|
|
||||||
│ ├── index.html # Main HTML page
|
|
||||||
│ ├── styles.css # Styling (warm, editorial design)
|
|
||||||
│ └── app.js # Frontend JavaScript
|
|
||||||
├── data/
|
|
||||||
│ └── .gitkeep # Place CSV data files here
|
|
||||||
├── scripts/
|
|
||||||
│ └── download_data.py # Helper for downloading/processing data
|
|
||||||
├── requirements.txt # Python dependencies
|
|
||||||
└── README.md
|
|
||||||
```
|
|
||||||
|
|
||||||
## API Endpoints
|
|
||||||
|
|
||||||
| Endpoint | Description |
|
|
||||||
|----------|-------------|
|
|
||||||
| `GET /api/schools` | List schools with optional search/filter |
|
|
||||||
| `GET /api/schools/{urn}` | Get detailed data for a specific school |
|
|
||||||
| `GET /api/compare?urns=...` | Compare multiple schools |
|
|
||||||
| `GET /api/rankings` | Get school rankings by metric |
|
|
||||||
| `GET /api/filters` | Get available filter options |
|
|
||||||
| `GET /api/metrics` | Get available performance metrics |
|
|
||||||
|
|
||||||
### Example API Usage
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Search for schools
|
|
||||||
curl "http://localhost:8000/api/schools?search=academy"
|
|
||||||
|
|
||||||
# Get school details
|
|
||||||
curl "http://localhost:8000/api/schools/100001"
|
|
||||||
|
|
||||||
# Compare schools
|
|
||||||
curl "http://localhost:8000/api/compare?urns=100001,100002,100003"
|
|
||||||
|
|
||||||
# Get rankings
|
|
||||||
curl "http://localhost:8000/api/rankings?metric=rwm_expected_pct&year=2024"
|
|
||||||
```
|
|
||||||
|
|
||||||
## Data Format
|
|
||||||
|
|
||||||
If using your own CSV data, ensure it includes these columns (or similar):
|
|
||||||
|
|
||||||
| Column | Type | Description |
|
|
||||||
|--------|------|-------------|
|
|
||||||
| URN | Integer | Unique Reference Number |
|
|
||||||
| SCHNAME | String | School name |
|
|
||||||
| LA | String | Local Authority (must be Wandsworth or Merton) |
|
|
||||||
| READPROG | Float | Reading progress score |
|
|
||||||
| WRITPROG | Float | Writing progress score |
|
|
||||||
| MATPROG | Float | Maths progress score |
|
|
||||||
| PTRWM_EXP | Float | % meeting expected standard in reading, writing & maths |
|
|
||||||
| PTREAD_EXP | Float | % meeting expected standard in reading |
|
|
||||||
| PTWRIT_EXP | Float | % meeting expected standard in writing |
|
|
||||||
| PTMAT_EXP | Float | % meeting expected standard in maths |
|
|
||||||
|
|
||||||
The application normalizes column names automatically and filters to only show Wandsworth and Merton schools.
|
|
||||||
|
|
||||||
## Technology Stack
|
|
||||||
|
|
||||||
- **Backend**: FastAPI (Python) - High-performance async API framework
|
|
||||||
- **Frontend**: Vanilla JavaScript with Chart.js
|
|
||||||
- **Styling**: Custom CSS with CSS variables for theming
|
|
||||||
- **Data**: Pandas for CSV processing
|
|
||||||
|
|
||||||
## Design Philosophy
|
|
||||||
|
|
||||||
The UI features a warm, editorial design inspired by quality publications:
|
|
||||||
- **Typography**: DM Sans for body text, Playfair Display for headings
|
|
||||||
- **Color Palette**: Warm cream background with coral and teal accents
|
|
||||||
- **Interactions**: Smooth animations and hover effects
|
|
||||||
- **Charts**: Clean, readable data visualizations
|
|
||||||
|
|
||||||
## Development
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Run with auto-reload
|
|
||||||
python -m uvicorn backend.app:app --reload --port 8000
|
|
||||||
|
|
||||||
# Or run directly
|
|
||||||
python backend/app.py
|
|
||||||
```
|
|
||||||
|
|
||||||
## Coverage
|
|
||||||
|
|
||||||
This application is specifically designed for:
|
|
||||||
|
|
||||||
- **School Phase**: Primary schools only (Key Stage 2)
|
|
||||||
- **Geographic Area**: Wandsworth and Merton (London boroughs)
|
|
||||||
- **Time Period**: Last 5 years of data (2020-2024)
|
|
||||||
|
|
||||||
Note: 2021 data shows as unavailable because SATs were cancelled due to COVID-19.
|
|
||||||
|
|
||||||
## Data Source
|
|
||||||
|
|
||||||
Data is sourced from the UK Government's [Compare School Performance](https://www.compare-school-performance.service.gov.uk/) service, which provides official school performance data for England.
|
|
||||||
|
|
||||||
**Important**: When using real data, please comply with the [terms of use](https://www.compare-school-performance.service.gov.uk/download-data) and data protection regulations.
|
|
||||||
|
|
||||||
## Scheduled Jobs
|
|
||||||
|
|
||||||
### Geocoding Schools (Cron Job)
|
|
||||||
|
|
||||||
School postcodes are geocoded by a scheduled job, not on-demand. This improves performance and reduces API calls.
|
|
||||||
|
|
||||||
**Setup the cron job** (runs weekly on Sunday at 2am):
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Edit crontab
|
|
||||||
crontab -e
|
|
||||||
|
|
||||||
# Add this line (adjust paths as needed):
|
|
||||||
0 2 * * 0 cd /path/to/school_compare && /path/to/venv/bin/python scripts/geocode_schools.py >> /var/log/geocode_schools.log 2>&1
|
|
||||||
```
|
|
||||||
|
|
||||||
**Manual run:**
|
|
||||||
```bash
|
|
||||||
# Geocode only schools missing coordinates
|
|
||||||
python scripts/geocode_schools.py
|
|
||||||
|
|
||||||
# Force re-geocode all schools
|
|
||||||
python scripts/geocode_schools.py --force
|
|
||||||
```
|
|
||||||
|
|
||||||
## License
|
|
||||||
|
|
||||||
MIT License - feel free to use this project for educational purposes.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
Built with ❤️ for Wandsworth & Merton families
|
|
||||||
|
|
||||||
|
Work on a feature branch and open a PR. Merging to `main` builds images and
|
||||||
|
deploys staging. Production promotion is a separate, human-triggered Gitea
|
||||||
|
workflow. Use [DEPLOY.md](docs/DEPLOY.md) and the Portainer compose files as the
|
||||||
|
operational references. The generic compose examples still reference `:latest`,
|
||||||
|
which the current release workflow does not publish.
|
||||||
+221
-7
@@ -6,6 +6,7 @@ Uses real data from UK Government Compare School Performance downloads.
|
|||||||
|
|
||||||
import hashlib
|
import hashlib
|
||||||
import re
|
import re
|
||||||
|
import time
|
||||||
from contextlib import asynccontextmanager
|
from contextlib import asynccontextmanager
|
||||||
from datetime import datetime, timezone
|
from datetime import datetime, timezone
|
||||||
from typing import Optional
|
from typing import Optional
|
||||||
@@ -15,7 +16,7 @@ import pandas as pd
|
|||||||
from fastapi import FastAPI, HTTPException, Query, Request, Depends, Header
|
from fastapi import FastAPI, HTTPException, Query, Request, Depends, Header
|
||||||
from fastapi.middleware.cors import CORSMiddleware
|
from fastapi.middleware.cors import CORSMiddleware
|
||||||
from fastapi.middleware.gzip import GZipMiddleware
|
from fastapi.middleware.gzip import GZipMiddleware
|
||||||
from fastapi.responses import FileResponse, Response
|
from fastapi.responses import FileResponse, JSONResponse, Response
|
||||||
from fastapi.staticfiles import StaticFiles
|
from fastapi.staticfiles import StaticFiles
|
||||||
from slowapi import Limiter, _rate_limit_exceeded_handler
|
from slowapi import Limiter, _rate_limit_exceeded_handler
|
||||||
from slowapi.util import get_remote_address
|
from slowapi.util import get_remote_address
|
||||||
@@ -33,10 +34,11 @@ from .data_loader import (
|
|||||||
get_supplementary_data,
|
get_supplementary_data,
|
||||||
get_supplementary_data_batch,
|
get_supplementary_data_batch,
|
||||||
search_schools_typesense,
|
search_schools_typesense,
|
||||||
|
suggest_schools_typesense,
|
||||||
)
|
)
|
||||||
from .data_loader import get_data_info as get_db_info
|
from .data_loader import get_data_info as get_db_info
|
||||||
from . import flags
|
from . import flags
|
||||||
from .places import build_place_registry
|
from .places import build_place_index, build_place_registry, places_for_urn
|
||||||
from .schemas import METRIC_DEFINITIONS, RANKING_COLUMNS, SCHOOL_COLUMNS
|
from .schemas import METRIC_DEFINITIONS, RANKING_COLUMNS, SCHOOL_COLUMNS
|
||||||
from .utils import clean_for_json, convert_to_native
|
from .utils import clean_for_json, convert_to_native
|
||||||
|
|
||||||
@@ -63,6 +65,10 @@ _sitemaps: dict[str, str] | None = None
|
|||||||
# Built from the same DataFrame the sitemap uses, so places and sitemap can
|
# Built from the same DataFrame the sitemap uses, so places and sitemap can
|
||||||
# never describe different corpora. Reset by the same admin endpoint.
|
# never describe different corpora. Reset by the same admin endpoint.
|
||||||
_place_registry: dict | None = None
|
_place_registry: dict | None = None
|
||||||
|
# Cached beside the registry, and invalidated by identity against it — see
|
||||||
|
# get_place_index. Never cleared independently.
|
||||||
|
_place_index: dict | None = None
|
||||||
|
_place_index_source: dict | None = None
|
||||||
|
|
||||||
VALID_PLACE_KINDS = ("town", "locality", "authority", "outcode")
|
VALID_PLACE_KINDS = ("town", "locality", "authority", "outcode")
|
||||||
|
|
||||||
@@ -186,6 +192,24 @@ def get_place_registry() -> dict:
|
|||||||
return _place_registry
|
return _place_registry
|
||||||
|
|
||||||
|
|
||||||
|
def get_place_index() -> dict:
|
||||||
|
"""URN → its published places, cached against the registry it came from.
|
||||||
|
|
||||||
|
Invalidation is an identity check rather than a second flag to remember to
|
||||||
|
clear. Anything that drops `_place_registry` — the tests all do — gets a
|
||||||
|
fresh registry object here, which no longer matches the one the index was
|
||||||
|
built from, so the index rebuilds with it. A separate `_place_index = None`
|
||||||
|
would be one more thing to forget, and a stale reverse index is exactly the
|
||||||
|
bug that would put links to another dataset's places on a school page.
|
||||||
|
"""
|
||||||
|
global _place_index, _place_index_source
|
||||||
|
registry = get_place_registry()
|
||||||
|
if _place_index is None or _place_index_source is not registry:
|
||||||
|
_place_index = build_place_index(registry)
|
||||||
|
_place_index_source = registry
|
||||||
|
return _place_index
|
||||||
|
|
||||||
|
|
||||||
def _urlset(rows: list[str]) -> str:
|
def _urlset(rows: list[str]) -> str:
|
||||||
return "\n".join([
|
return "\n".join([
|
||||||
'<?xml version="1.0" encoding="UTF-8"?>',
|
'<?xml version="1.0" encoding="UTF-8"?>',
|
||||||
@@ -209,6 +233,45 @@ def _place_url(place) -> str:
|
|||||||
return f"/schools/{place.slug}"
|
return f"/schools/{place.slug}"
|
||||||
|
|
||||||
|
|
||||||
|
def _places_payload(urn: int) -> list[dict]:
|
||||||
|
"""The published places containing this school, as the school page needs
|
||||||
|
them: a name to write in the link, a count so the anchor can say what it
|
||||||
|
leads to, and the canonical path.
|
||||||
|
|
||||||
|
`phases` carries the phase variants this school actually appears on, which
|
||||||
|
is usually one and is two for an all-through school — it is listed on both
|
||||||
|
pages, so there is no tie to break.
|
||||||
|
|
||||||
|
Membership is read straight from the registry's own `phase_urns` rather
|
||||||
|
than re-derived from the school's phase string. The registry is the one
|
||||||
|
place that decides which phases a place publishes and who is on them;
|
||||||
|
computing it a second time here is how a page comes to link a school to a
|
||||||
|
phase page that does not list it, or to a route that does not exist. That
|
||||||
|
is also why outcodes need no special case: they carry empty `phase_urns`,
|
||||||
|
so they report no phase links on their own.
|
||||||
|
"""
|
||||||
|
payload = []
|
||||||
|
for place in places_for_urn(get_place_index(), int(urn)):
|
||||||
|
phases = [
|
||||||
|
{
|
||||||
|
"phase": phase,
|
||||||
|
"count": len(phase_urns),
|
||||||
|
"url": f"{_place_url(place)}/{phase}",
|
||||||
|
}
|
||||||
|
for phase, phase_urns in sorted(place.phase_urns.items())
|
||||||
|
if int(urn) in phase_urns
|
||||||
|
]
|
||||||
|
payload.append({
|
||||||
|
"kind": place.kind,
|
||||||
|
"slug": place.slug,
|
||||||
|
"name": place.name,
|
||||||
|
"count": len(place.urns),
|
||||||
|
"url": _place_url(place),
|
||||||
|
"phases": phases,
|
||||||
|
})
|
||||||
|
return payload
|
||||||
|
|
||||||
|
|
||||||
def _place_sitemap_rows(kinds: tuple[str, ...]) -> list[str]:
|
def _place_sitemap_rows(kinds: tuple[str, ...]) -> list[str]:
|
||||||
"""A <url> per place, plus a phase variant wherever that phase clears the
|
"""A <url> per place, plus a phase variant wherever that phase clears the
|
||||||
threshold on its own.
|
threshold on its own.
|
||||||
@@ -296,8 +359,101 @@ def clean_filter_values(series: pd.Series) -> list[str]:
|
|||||||
# SECURITY MIDDLEWARE & HELPERS
|
# SECURITY MIDDLEWARE & HELPERS
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
|
|
||||||
# Rate limiter
|
def client_key(request: Request) -> str:
|
||||||
limiter = Limiter(key_func=get_remote_address)
|
"""The rate-limit bucket: the real caller, not the proxy in front of them.
|
||||||
|
|
||||||
|
`get_remote_address` reads request.client.host. In staging and production
|
||||||
|
the backend has no published ports and sits on the internal network, so its
|
||||||
|
only caller is the Next proxy — meaning every browser user on the site
|
||||||
|
shared one bucket. Measured before this fix: 70 concurrent requests to
|
||||||
|
/api/schools returned 60 OK and 10 refused.
|
||||||
|
|
||||||
|
CF-Connecting-IP first, because Cloudflare (in front of both environments)
|
||||||
|
sets it on every origin request and *overwrites* any client-supplied value,
|
||||||
|
which a parsed X-Forwarded-For chain does not guarantee. The XFF fallback is
|
||||||
|
forgeable, but only by a caller already inside the Docker network, which is
|
||||||
|
the one place nothing untrusted can reach.
|
||||||
|
"""
|
||||||
|
cf = request.headers.get("cf-connecting-ip")
|
||||||
|
if cf:
|
||||||
|
return cf.strip()
|
||||||
|
xff = request.headers.get("x-forwarded-for")
|
||||||
|
if xff:
|
||||||
|
return xff.split(",")[0].strip()
|
||||||
|
return get_remote_address(request)
|
||||||
|
|
||||||
|
|
||||||
|
# Per-client limiter. Paired with the global ceiling below — the two do
|
||||||
|
# different jobs and neither substitutes for the other.
|
||||||
|
limiter = Limiter(key_func=client_key)
|
||||||
|
|
||||||
|
|
||||||
|
# --- The ceiling no header can raise ----------------------------------------
|
||||||
|
#
|
||||||
|
# client_key trusts CF-Connecting-IP, and nothing in this process can tell an
|
||||||
|
# edge-set header from an attacker-set one. That distinction can only be made
|
||||||
|
# at Cloudflare, with Authenticated Origin Pulls or an origin firewall. A
|
||||||
|
# caller reaching the origin directly could otherwise mint a fresh rate-limit
|
||||||
|
# bucket per request and evade per-client limits entirely — which would make
|
||||||
|
# correct keying a net regression against abuse, since the single shared bucket
|
||||||
|
# it replaced at least capped everyone at 60/minute together.
|
||||||
|
#
|
||||||
|
# So per-client limits give fairness, and this gives the origin a hard total.
|
||||||
|
# It does not make the header trustworthy; it bounds what trusting it can cost.
|
||||||
|
# The header problem itself is closed at Cloudflare, not here.
|
||||||
|
#
|
||||||
|
# [window_start_monotonic, count], or None before the first request. A fixed
|
||||||
|
# window is crude, which is right for a backstop: it has to be obviously
|
||||||
|
# correct rather than fair.
|
||||||
|
_global_window: Optional[list] = None
|
||||||
|
|
||||||
|
# The container healthcheck runs `curl http://localhost:80/api/data-info` from
|
||||||
|
# inside the container. Starving it would fail the check, restart the
|
||||||
|
# container, and turn a load spike into an outage loop — the ceiling exists to
|
||||||
|
# protect the origin, not to kill it.
|
||||||
|
_LOCAL_HOSTS = frozenset({"127.0.0.1", "::1", "localhost"})
|
||||||
|
|
||||||
|
|
||||||
|
def exempt_from_ceiling(request: Request) -> bool:
|
||||||
|
"""Whether the ceiling should ignore this request.
|
||||||
|
|
||||||
|
Its own function so the rule is testable without standing up a server —
|
||||||
|
and so the healthcheck exemption is somewhere a reader can find it.
|
||||||
|
"""
|
||||||
|
if not request.url.path.startswith("/api/"):
|
||||||
|
return True
|
||||||
|
# The peer address, never the Host header: Host is set by the caller and
|
||||||
|
# would hand every attacker an exemption.
|
||||||
|
return (request.client.host if request.client else "") in _LOCAL_HOSTS
|
||||||
|
|
||||||
|
|
||||||
|
class GlobalRateLimitMiddleware(BaseHTTPMiddleware):
|
||||||
|
"""A cap on total /api/ traffic, independent of any client identity."""
|
||||||
|
|
||||||
|
async def dispatch(self, request: Request, call_next):
|
||||||
|
global _global_window
|
||||||
|
|
||||||
|
if exempt_from_ceiling(request):
|
||||||
|
return await call_next(request)
|
||||||
|
|
||||||
|
now = time.monotonic()
|
||||||
|
# One event loop, and no await between the read and the write, so this
|
||||||
|
# sequence is atomic without a lock.
|
||||||
|
if _global_window is None or now - _global_window[0] >= 60:
|
||||||
|
_global_window = [now, 0]
|
||||||
|
_global_window[1] += 1
|
||||||
|
|
||||||
|
if _global_window[1] > settings.global_rate_limit_per_minute:
|
||||||
|
return JSONResponse(
|
||||||
|
# Distinguishable from slowapi's per-client 429: an operator
|
||||||
|
# reading logs has to be able to tell "one noisy client" from
|
||||||
|
# "the origin is saturated".
|
||||||
|
{"detail": "The service is at capacity. Please retry shortly."},
|
||||||
|
status_code=429,
|
||||||
|
headers={"Retry-After":
|
||||||
|
str(max(1, int(60 - (now - _global_window[0]))))},
|
||||||
|
)
|
||||||
|
return await call_next(request)
|
||||||
|
|
||||||
|
|
||||||
class SecurityHeadersMiddleware(BaseHTTPMiddleware):
|
class SecurityHeadersMiddleware(BaseHTTPMiddleware):
|
||||||
@@ -355,6 +511,7 @@ CACHE_RULES: list[tuple[str, tuple[int, int, int]]] = [
|
|||||||
("/api/schools/", (300, 3600, 86400)), # /api/schools/{urn}
|
("/api/schools/", (300, 3600, 86400)), # /api/schools/{urn}
|
||||||
("/api/rankings", (60, 600, 3600)),
|
("/api/rankings", (60, 600, 3600)),
|
||||||
("/api/compare", (60, 600, 3600)),
|
("/api/compare", (60, 600, 3600)),
|
||||||
|
("/api/suggest", (60, 3600, 86400)), # autosuggest
|
||||||
("/api/schools", (30, 300, 1800)), # search list
|
("/api/schools", (30, 300, 1800)), # search list
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -502,6 +659,10 @@ app.add_middleware(CacheAndETagMiddleware)
|
|||||||
app.add_middleware(SecurityHeadersMiddleware)
|
app.add_middleware(SecurityHeadersMiddleware)
|
||||||
app.add_middleware(RequestSizeLimitMiddleware)
|
app.add_middleware(RequestSizeLimitMiddleware)
|
||||||
app.add_middleware(GZipMiddleware, minimum_size=512)
|
app.add_middleware(GZipMiddleware, minimum_size=512)
|
||||||
|
# Added last, so it is outermost and refuses before anything downstream does
|
||||||
|
# work. A ceiling that only applies after the expensive part has run is not a
|
||||||
|
# ceiling.
|
||||||
|
app.add_middleware(GlobalRateLimitMiddleware)
|
||||||
|
|
||||||
# CORS middleware - restricted for production
|
# CORS middleware - restricted for production
|
||||||
app.add_middleware(
|
app.add_middleware(
|
||||||
@@ -802,6 +963,13 @@ async def get_school_details(request: Request, urn: int):
|
|||||||
|
|
||||||
return {
|
return {
|
||||||
"school_info": school_info,
|
"school_info": school_info,
|
||||||
|
# Where this school sits in the location layer, for the page's link
|
||||||
|
# module and breadcrumb. Derived from the same registry the place
|
||||||
|
# pages and the sitemap use, so a link is never offered for a page
|
||||||
|
# that does not exist. Empty is a valid answer: a school whose town
|
||||||
|
# and authority both fall below the publish threshold has nowhere to
|
||||||
|
# point, and the page renders without the module.
|
||||||
|
"places": _places_payload(urn),
|
||||||
"yearly_data": clean_for_json(school_data),
|
"yearly_data": clean_for_json(school_data),
|
||||||
# Supplementary data (null if not yet populated by Kestra)
|
# Supplementary data (null if not yet populated by Kestra)
|
||||||
"ofsted": supplementary.get("ofsted"),
|
"ofsted": supplementary.get("ofsted"),
|
||||||
@@ -819,6 +987,7 @@ async def get_school_details(request: Request, urn: int):
|
|||||||
"phonics": supplementary.get("phonics"),
|
"phonics": supplementary.get("phonics"),
|
||||||
"deprivation": supplementary.get("deprivation"),
|
"deprivation": supplementary.get("deprivation"),
|
||||||
"finance": supplementary.get("finance"),
|
"finance": supplementary.get("finance"),
|
||||||
|
"destinations": supplementary.get("destinations"),
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
@@ -1237,9 +1406,22 @@ async def get_place(request: Request, kind: str, slug: str,
|
|||||||
for m in ("rwm_expected_pct", "attainment_8_score")
|
for m in ("rwm_expected_pct", "attainment_8_score")
|
||||||
}
|
}
|
||||||
|
|
||||||
cols = [c for c in SCHOOL_COLUMNS + ["latitude", "longitude", "phase",
|
# dict.fromkeys, not a list: SCHOOL_COLUMNS already ends with latitude and
|
||||||
"rwm_expected_pct", "attainment_8_score",
|
# longitude, so concatenating them again selected each twice and pandas
|
||||||
"total_pupils"]
|
# dropped one of every duplicated pair with a "columns are not unique"
|
||||||
|
# warning. Ordered de-duplication keeps the column order and the warning
|
||||||
|
# cannot come back.
|
||||||
|
#
|
||||||
|
# nursery_provision and parliamentary_constituency are not in
|
||||||
|
# SCHOOL_COLUMNS and the place table shows both. The `in rows.columns`
|
||||||
|
# guard is what keeps a mart the pipeline has not rebuilt working: those
|
||||||
|
# two are the optional GIAS columns data_loader degrades to NULL.
|
||||||
|
cols = [c for c in dict.fromkeys(
|
||||||
|
SCHOOL_COLUMNS + ["latitude", "longitude", "phase",
|
||||||
|
"nursery_provision",
|
||||||
|
"parliamentary_constituency",
|
||||||
|
"rwm_expected_pct", "attainment_8_score",
|
||||||
|
"total_pupils"])
|
||||||
if c in rows.columns]
|
if c in rows.columns]
|
||||||
|
|
||||||
return {
|
return {
|
||||||
@@ -1271,6 +1453,38 @@ async def get_place(request: Request, kind: str, slug: str,
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
# Two characters. One is not a query — it matches thousands of schools and the
|
||||||
|
# response is useless, so it is not worth a round trip.
|
||||||
|
SUGGEST_MIN_QUERY = 2
|
||||||
|
|
||||||
|
|
||||||
|
@app.get("/api/suggest")
|
||||||
|
@limiter.limit("120/minute")
|
||||||
|
async def suggest_schools(
|
||||||
|
request: Request,
|
||||||
|
q: str = Query("", max_length=100),
|
||||||
|
limit: int = Query(8, ge=1, le=20),
|
||||||
|
):
|
||||||
|
"""School name suggestions, from Typesense alone.
|
||||||
|
|
||||||
|
Deliberately not a mode of /api/schools: that path filters and sorts the
|
||||||
|
full in-memory DataFrame, which is far too expensive to run per keystroke.
|
||||||
|
|
||||||
|
Nothing here returns an error for ordinary input. A short query, no
|
||||||
|
matches, or Typesense being unreachable are all 200 with an empty list —
|
||||||
|
a dropdown that quietly does not appear is the right failure for a
|
||||||
|
keystroke path, and there is no DataFrame fallback because the 25,000-row
|
||||||
|
substring scan is precisely what this endpoint exists to avoid.
|
||||||
|
|
||||||
|
120/minute rather than the default 60: a 200 ms debounce makes typing
|
||||||
|
legitimately bursty.
|
||||||
|
"""
|
||||||
|
query = q.strip()
|
||||||
|
if len(query) < SUGGEST_MIN_QUERY:
|
||||||
|
return {"suggestions": []}
|
||||||
|
return {"suggestions": suggest_schools_typesense(query, limit)}
|
||||||
|
|
||||||
|
|
||||||
@app.get("/api/flags")
|
@app.get("/api/flags")
|
||||||
@limiter.limit(f"{settings.rate_limit_per_minute}/minute")
|
@limiter.limit(f"{settings.rate_limit_per_minute}/minute")
|
||||||
async def get_feature_flags(request: Request):
|
async def get_feature_flags(request: Request):
|
||||||
|
|||||||
@@ -35,6 +35,11 @@ class Settings(BaseSettings):
|
|||||||
# Security
|
# Security
|
||||||
admin_api_key: str = Field(default_factory=lambda: secrets.token_urlsafe(32))
|
admin_api_key: str = Field(default_factory=lambda: secrets.token_urlsafe(32))
|
||||||
rate_limit_per_minute: int = 60 # Requests per minute per IP
|
rate_limit_per_minute: int = 60 # Requests per minute per IP
|
||||||
|
# A ceiling on total /api/ traffic, independent of any client identity.
|
||||||
|
# client_key trusts headers only Cloudflare can vouch for, so a caller
|
||||||
|
# reaching the origin directly could otherwise mint a fresh bucket per
|
||||||
|
# request. See GlobalRateLimitMiddleware in backend/app.py.
|
||||||
|
global_rate_limit_per_minute: int = 3000
|
||||||
rate_limit_burst: int = 10 # Allow burst of requests
|
rate_limit_burst: int = 10 # Allow burst of requests
|
||||||
max_request_size: int = 1024 * 1024 # 1MB max request size
|
max_request_size: int = 1024 * 1024 # 1MB max request size
|
||||||
|
|
||||||
|
|||||||
+298
-10
@@ -20,6 +20,7 @@ from .models import (
|
|||||||
DimSchool, DimLocation, KS2Performance,
|
DimSchool, DimLocation, KS2Performance,
|
||||||
FactOfstedInspection, FactAdmissions, FactAdmissionDistance,
|
FactOfstedInspection, FactAdmissions, FactAdmissionDistance,
|
||||||
FactDeprivation, FactFinance, FactPupilCharacteristics,
|
FactDeprivation, FactFinance, FactPupilCharacteristics,
|
||||||
|
FactKs4Destinations, FactKs5Destinations,
|
||||||
)
|
)
|
||||||
from .ofsted_codes import ofsted_page_url, report_card_labels
|
from .ofsted_codes import ofsted_page_url, report_card_labels
|
||||||
from .schemas import SCHOOL_TYPE_MAP
|
from .schemas import SCHOOL_TYPE_MAP
|
||||||
@@ -100,6 +101,58 @@ def search_schools_typesense(query: str, limit: int = 250) -> List[int]:
|
|||||||
return []
|
return []
|
||||||
|
|
||||||
|
|
||||||
|
# The most a public endpoint will return in one response.
|
||||||
|
SUGGEST_MAX_LIMIT = 20
|
||||||
|
|
||||||
|
# Fields a suggestion row carries, and the default when the document omits an
|
||||||
|
# optional one. phase and school_type are optional in the Typesense schema.
|
||||||
|
_SUGGEST_FIELDS = ("school_name", "local_authority", "postcode",
|
||||||
|
"phase", "school_type")
|
||||||
|
|
||||||
|
|
||||||
|
def suggest_schools_typesense(query: str, limit: int = 8) -> List[dict]:
|
||||||
|
"""Autosuggest rows straight from Typesense. Never raises.
|
||||||
|
|
||||||
|
Returns documents rather than URNs, unlike search_schools_typesense, so the
|
||||||
|
caller needs no DataFrame. Every field below is already in the index — see
|
||||||
|
pipeline/scripts/sync_typesense.py — which is what makes this cheap enough
|
||||||
|
to run per keystroke.
|
||||||
|
"""
|
||||||
|
client = _get_typesense_client()
|
||||||
|
if client is None:
|
||||||
|
return []
|
||||||
|
try:
|
||||||
|
result = client.collections["schools"].documents.search({
|
||||||
|
"q": query,
|
||||||
|
"query_by": "school_name,local_authority",
|
||||||
|
"per_page": max(1, min(limit, SUGGEST_MAX_LIMIT)),
|
||||||
|
"typo_tokens_threshold": 1,
|
||||||
|
})
|
||||||
|
except Exception:
|
||||||
|
# A dropdown that quietly stops appearing is the right failure here.
|
||||||
|
return []
|
||||||
|
|
||||||
|
rows = []
|
||||||
|
for hit in result.get("hits", []) or []:
|
||||||
|
doc = (hit or {}).get("document") or {}
|
||||||
|
try:
|
||||||
|
urn = int(doc["urn"])
|
||||||
|
except (KeyError, TypeError, ValueError):
|
||||||
|
# Skip the row, keep the rest. Typesense declares urn as int32 so
|
||||||
|
# this should be unreachable, but the index is a separate system
|
||||||
|
# that something other than this code can reindex — and "never
|
||||||
|
# raises" is a promise the keystroke path actually depends on.
|
||||||
|
# Dropping one malformed document is right; blanking the whole
|
||||||
|
# dropdown, or serving a suggestion pointing at /school/0, is not.
|
||||||
|
logging.getLogger(__name__).warning(
|
||||||
|
"skipping malformed suggestion document: %r", doc)
|
||||||
|
continue
|
||||||
|
row = {"urn": urn}
|
||||||
|
row.update({f: str(doc.get(f, "") or "") for f in _SUGGEST_FIELDS})
|
||||||
|
rows.append(row)
|
||||||
|
return rows
|
||||||
|
|
||||||
|
|
||||||
def normalize_school_type(school_type: Optional[str]) -> Optional[str]:
|
def normalize_school_type(school_type: Optional[str]) -> Optional[str]:
|
||||||
"""Convert cryptic school type codes to user-friendly names."""
|
"""Convert cryptic school type codes to user-friendly names."""
|
||||||
if not school_type:
|
if not school_type:
|
||||||
@@ -135,16 +188,6 @@ def geocode_single_postcode(postcode: str) -> Optional[Tuple[float, float]]:
|
|||||||
return None
|
return None
|
||||||
|
|
||||||
|
|
||||||
def haversine_distance(lat1: float, lon1: float, lat2: float, lon2: float) -> float:
|
|
||||||
"""Calculate great-circle distance between two points (miles)."""
|
|
||||||
from math import radians, cos, sin, asin, sqrt
|
|
||||||
lat1, lon1, lat2, lon2 = map(radians, [lat1, lon1, lat2, lon2])
|
|
||||||
dlat = lat2 - lat1
|
|
||||||
dlon = lon2 - lon1
|
|
||||||
a = sin(dlat / 2) ** 2 + cos(lat1) * cos(lat2) * sin(dlon / 2) ** 2
|
|
||||||
return 2 * asin(sqrt(a)) * 3956
|
|
||||||
|
|
||||||
|
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
# MAIN DATA LOAD — joins dim_school + dim_location + fact_performance
|
# MAIN DATA LOAD — joins dim_school + dim_location + fact_performance
|
||||||
# fact_performance is a merged KS2+KS4 table (one row per URN per year).
|
# fact_performance is a merged KS2+KS4 table (one row per URN per year).
|
||||||
@@ -764,6 +807,218 @@ def _finance_dict(f) -> dict:
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
# Destination measures that are totals DfE published itself, rather than one of
|
||||||
|
# the categories that partition the cohort.
|
||||||
|
_AGGREGATE_MEASURES = {"agg_sustained_education", "agg_sustained_all"}
|
||||||
|
|
||||||
|
|
||||||
|
def _format_cohort_year(year) -> str | None:
|
||||||
|
"""202223 -> '2022/23'.
|
||||||
|
|
||||||
|
The section has to date its own cohort. Destination measures run about two
|
||||||
|
GCSE years behind the results shown above them on the same page, so an
|
||||||
|
undated figure reads as stale data rather than as a different question.
|
||||||
|
"""
|
||||||
|
if not year:
|
||||||
|
return None
|
||||||
|
text = str(year)
|
||||||
|
if len(text) == 6:
|
||||||
|
return f"{text[:4]}/{text[4:6]}"
|
||||||
|
if len(text) == 8:
|
||||||
|
return f"{text[:4]}/{text[6:8]}"
|
||||||
|
return text
|
||||||
|
|
||||||
|
|
||||||
|
_PUPIL_GROUPS = ("disadvantaged", "other", "all")
|
||||||
|
|
||||||
|
|
||||||
|
def _lone_hidden_groups(groups: dict) -> list:
|
||||||
|
"""Pupil groups hiding exactly one category — solvable by subtraction."""
|
||||||
|
return [
|
||||||
|
key for key, group in groups.items()
|
||||||
|
if sum(1 for c in group["categories"] if c["status"] == "suppressed") == 1
|
||||||
|
]
|
||||||
|
|
||||||
|
|
||||||
|
def _lone_hidden_categories(groups: dict) -> list:
|
||||||
|
"""Categories hidden in exactly one of several pupil groups."""
|
||||||
|
lone = []
|
||||||
|
categories = {c["category"] for g in groups.values() for c in g["categories"]}
|
||||||
|
for category in categories:
|
||||||
|
found = [
|
||||||
|
c for g in groups.values() for c in g["categories"]
|
||||||
|
if c["category"] == category
|
||||||
|
]
|
||||||
|
hidden = [c for c in found if c["status"] == "suppressed"]
|
||||||
|
if len(hidden) == 1 and len(found) > 1:
|
||||||
|
lone.append(category)
|
||||||
|
return lone
|
||||||
|
|
||||||
|
|
||||||
|
def disclosure_invariant_holds(groups: dict) -> bool:
|
||||||
|
"""Every row and every column hides none, or at least two.
|
||||||
|
|
||||||
|
Public so the tests can assert it directly rather than re-deriving it.
|
||||||
|
"""
|
||||||
|
return not _lone_hidden_groups(groups) and not _lone_hidden_categories(groups)
|
||||||
|
|
||||||
|
|
||||||
|
def _mask_for_disclosure(groups: dict) -> None:
|
||||||
|
"""Withhold further cells until nothing suppressed can be solved for.
|
||||||
|
|
||||||
|
Not rendering a figure is not the same as not publishing it. This endpoint
|
||||||
|
is public and unauthenticated, so anything left in the payload is
|
||||||
|
published, whatever the UI chooses to draw — the same reasoning the
|
||||||
|
admission_distance field carries in app.py.
|
||||||
|
|
||||||
|
Two identities let a caller solve for a withheld cell:
|
||||||
|
|
||||||
|
* within a pupil group, the categories sum to the cohort, so a group with
|
||||||
|
exactly ONE suppressed category gives it away as cohort - sum(rest);
|
||||||
|
* across groups, disadvantaged + other = all for every category, so a
|
||||||
|
category suppressed in exactly ONE of the three gives itself away.
|
||||||
|
|
||||||
|
DfE's own answer is secondary suppression: withhold a second cell so the
|
||||||
|
residual spans two unknowns and identifies neither.
|
||||||
|
|
||||||
|
Where no companion can do that — a sparse cohort whose every other category
|
||||||
|
is `not_applicable`, which is common in special schools and alternative
|
||||||
|
provision — there is nothing left to withhold, so the pupil group is
|
||||||
|
DROPPED entirely. An earlier version simply gave up here and returned with
|
||||||
|
the violation intact and no signal, which is the one outcome this function
|
||||||
|
must never produce: a disclosure-control pass that fails silently is worse
|
||||||
|
than none, because everything downstream trusts it.
|
||||||
|
|
||||||
|
Mutates `groups` in place. Guaranteed to return with
|
||||||
|
disclosure_invariant_holds(groups) true.
|
||||||
|
"""
|
||||||
|
|
||||||
|
def suppress(cell):
|
||||||
|
if cell["status"] == "published":
|
||||||
|
cell["status"] = "suppressed"
|
||||||
|
cell["pupils"] = None
|
||||||
|
cell["percentage"] = None
|
||||||
|
return True
|
||||||
|
return False
|
||||||
|
|
||||||
|
def add_companion(candidates) -> bool:
|
||||||
|
"""Withhold a second cell so the residual spans two unknowns.
|
||||||
|
|
||||||
|
The companion must carry pupils. Suppressing a zero looks like
|
||||||
|
secondary suppression and protects nothing: the residual still equals
|
||||||
|
the original withheld figure exactly. Returns False when no cell can
|
||||||
|
do the job, which escalates to dropping the group.
|
||||||
|
"""
|
||||||
|
published = [c for c in candidates if c["status"] == "published"]
|
||||||
|
useful = sorted(
|
||||||
|
(c for c in published if (c["pupils"] or 0) > 0),
|
||||||
|
key=lambda c: c["pupils"],
|
||||||
|
)
|
||||||
|
if useful:
|
||||||
|
return suppress(useful[0])
|
||||||
|
# Every remaining cell is zero or not applicable: withholding any of
|
||||||
|
# them leaves the residual equal to the original figure.
|
||||||
|
return False
|
||||||
|
|
||||||
|
# Fixpoint: each new suppression can break the other identity. Terminates
|
||||||
|
# because every pass either adds a suppression, drops a group, or stops.
|
||||||
|
while not disclosure_invariant_holds(groups):
|
||||||
|
changed = False
|
||||||
|
|
||||||
|
for category in _lone_hidden_categories(groups):
|
||||||
|
siblings = [
|
||||||
|
c for g in groups.values() for c in g["categories"]
|
||||||
|
if c["category"] == category
|
||||||
|
]
|
||||||
|
if add_companion(siblings):
|
||||||
|
changed = True
|
||||||
|
|
||||||
|
for key in _lone_hidden_groups(groups):
|
||||||
|
if add_companion(groups[key]["categories"]):
|
||||||
|
changed = True
|
||||||
|
|
||||||
|
if changed:
|
||||||
|
continue
|
||||||
|
|
||||||
|
# Nothing left to withhold. Drop the groups that are still solvable,
|
||||||
|
# and any category still solvable across the groups that remain.
|
||||||
|
for key in _lone_hidden_groups(groups):
|
||||||
|
del groups[key]
|
||||||
|
changed = True
|
||||||
|
|
||||||
|
for category in _lone_hidden_categories(groups):
|
||||||
|
for group in groups.values():
|
||||||
|
for cell in group["categories"]:
|
||||||
|
if cell["category"] == category and suppress(cell):
|
||||||
|
changed = True
|
||||||
|
|
||||||
|
if not changed:
|
||||||
|
# Unreachable given the two escalations above, but a masking pass
|
||||||
|
# must never spin or exit unsafely. Withhold everything.
|
||||||
|
groups.clear()
|
||||||
|
return
|
||||||
|
|
||||||
|
|
||||||
|
def _destinations_block(rows: list) -> dict | None:
|
||||||
|
"""Shape destination rows for one phase into the API's block.
|
||||||
|
|
||||||
|
Applies secondary suppression before returning, so no caller of this public
|
||||||
|
endpoint can solve for a figure DfE withheld. See _mask_for_disclosure.
|
||||||
|
|
||||||
|
Aggregate measures are dropped entirely. DfE publishes them, and they would
|
||||||
|
be useful for a "what is published for this group" fallback, but nothing
|
||||||
|
renders them today and an aggregate spanning exactly one suppressed
|
||||||
|
component names that component. An unused field that leaks is not a
|
||||||
|
trade-off worth carrying — re-add them with their own guard if the fallback
|
||||||
|
is ever built.
|
||||||
|
|
||||||
|
Deliberately computes no residual, no "remaining pupils" figure, and no
|
||||||
|
total that would close a gap left by a suppressed category.
|
||||||
|
"""
|
||||||
|
if not rows:
|
||||||
|
return None
|
||||||
|
|
||||||
|
years = [r["year"] for r in rows if r.get("year") is not None]
|
||||||
|
if not years:
|
||||||
|
return None
|
||||||
|
latest_year = max(years)
|
||||||
|
rows = [r for r in rows if r.get("year") == latest_year]
|
||||||
|
|
||||||
|
groups: dict = {}
|
||||||
|
for row in rows:
|
||||||
|
group = groups.setdefault(
|
||||||
|
row["pupil_group"],
|
||||||
|
{"cohort": row.get("cohort_pupils"), "categories": []},
|
||||||
|
)
|
||||||
|
measure = row["destination_measure"]
|
||||||
|
published = row.get("status") == "published"
|
||||||
|
# Belt and braces: percentage is derived from the same source cell as
|
||||||
|
# pupils, but publishing one without the other would hand back the
|
||||||
|
# cohort (pupils / percentage) and with it the residual.
|
||||||
|
cell = {
|
||||||
|
"category": measure,
|
||||||
|
"pupils": row.get("pupils") if published else None,
|
||||||
|
"percentage": row.get("percentage") if published else None,
|
||||||
|
"status": row.get("status"),
|
||||||
|
}
|
||||||
|
if measure in _AGGREGATE_MEASURES:
|
||||||
|
continue
|
||||||
|
group["categories"].append(cell)
|
||||||
|
|
||||||
|
if not groups:
|
||||||
|
return None
|
||||||
|
|
||||||
|
_mask_for_disclosure(groups)
|
||||||
|
|
||||||
|
# Masking can empty the block entirely — a sparse cohort where no group
|
||||||
|
# could be made safe. Return None so the section is absent rather than
|
||||||
|
# rendering an empty shell.
|
||||||
|
if not groups:
|
||||||
|
return None
|
||||||
|
|
||||||
|
return {"cohort_year": _format_cohort_year(latest_year), "groups": groups}
|
||||||
|
|
||||||
|
|
||||||
def _empty_supplementary() -> dict:
|
def _empty_supplementary() -> dict:
|
||||||
return {
|
return {
|
||||||
"ofsted": None,
|
"ofsted": None,
|
||||||
@@ -775,6 +1030,7 @@ def _empty_supplementary() -> dict:
|
|||||||
"phonics": None,
|
"phonics": None,
|
||||||
"deprivation": None,
|
"deprivation": None,
|
||||||
"finance": None,
|
"finance": None,
|
||||||
|
"destinations": None,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
@@ -902,6 +1158,38 @@ def get_supplementary_data_batch(db: Session, urns: list[int]) -> dict:
|
|||||||
result[f.urn]["finance"] = _finance_dict(f)
|
result[f.urn]["finance"] = _finance_dict(f)
|
||||||
_safe(_finance)
|
_safe(_finance)
|
||||||
|
|
||||||
|
# Destinations — KS4 and 16-18. Both marts are long-format, so every row
|
||||||
|
# for a URN is collected and _destinations_block picks the latest year and
|
||||||
|
# shapes the pupil groups. A phase with no rows serialises as null rather
|
||||||
|
# than an empty shell, so the frontend renders nothing rather than an empty
|
||||||
|
# section.
|
||||||
|
def _destinations():
|
||||||
|
from collections import defaultdict
|
||||||
|
|
||||||
|
def _collect(model):
|
||||||
|
per_urn = defaultdict(list)
|
||||||
|
for r in db.query(model).filter(model.urn.in_(urns)).all():
|
||||||
|
per_urn[r.urn].append({
|
||||||
|
"year": r.year,
|
||||||
|
"pupil_group": r.pupil_group,
|
||||||
|
"destination_measure": r.destination_measure,
|
||||||
|
"cohort_pupils": r.cohort_pupils,
|
||||||
|
"pupils": r.pupils,
|
||||||
|
"percentage": r.percentage,
|
||||||
|
"status": r.status,
|
||||||
|
})
|
||||||
|
return per_urn
|
||||||
|
|
||||||
|
ks4_rows = _collect(FactKs4Destinations)
|
||||||
|
ks5_rows = _collect(FactKs5Destinations)
|
||||||
|
for urn in urns:
|
||||||
|
ks4 = _destinations_block(ks4_rows.get(urn, []))
|
||||||
|
ks5 = _destinations_block(ks5_rows.get(urn, []))
|
||||||
|
result[urn]["destinations"] = (
|
||||||
|
{"ks4": ks4, "ks5": ks5} if (ks4 or ks5) else None
|
||||||
|
)
|
||||||
|
_safe(_destinations)
|
||||||
|
|
||||||
return result
|
return result
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -50,6 +50,30 @@ REGISTRY: dict[str, Flag] = {
|
|||||||
),
|
),
|
||||||
added=date(2026, 8, 23),
|
added=date(2026, 8, 23),
|
||||||
),
|
),
|
||||||
|
Flag(
|
||||||
|
name="school_autosuggest",
|
||||||
|
description=(
|
||||||
|
"School name suggestions as you type in the main search box."
|
||||||
|
),
|
||||||
|
added=date(2026, 8, 26),
|
||||||
|
),
|
||||||
|
Flag(
|
||||||
|
name="about_page",
|
||||||
|
description=(
|
||||||
|
"The /about page, its footer link, its sitemap entry, and the "
|
||||||
|
"named-author byline on every blog post."
|
||||||
|
),
|
||||||
|
added=date(2026, 9, 8),
|
||||||
|
),
|
||||||
|
Flag(
|
||||||
|
name="blog",
|
||||||
|
description=(
|
||||||
|
"The /blog index, post pages, the RSS feed, their footer link "
|
||||||
|
"and their sitemap entries. Not /admin: posts must be "
|
||||||
|
"writable before the blog is readable."
|
||||||
|
),
|
||||||
|
added=date(2026, 9, 8),
|
||||||
|
),
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,512 +0,0 @@
|
|||||||
"""
|
|
||||||
Database migration logic for importing CSV data.
|
|
||||||
Used by both CLI script and automatic startup migration.
|
|
||||||
"""
|
|
||||||
|
|
||||||
import re
|
|
||||||
from pathlib import Path
|
|
||||||
from typing import Dict, Optional
|
|
||||||
|
|
||||||
import numpy as np
|
|
||||||
import pandas as pd
|
|
||||||
import requests
|
|
||||||
|
|
||||||
from .config import settings
|
|
||||||
from .database import Base, engine, get_db_session
|
|
||||||
from .models import School, SchoolResult
|
|
||||||
from .schemas import (
|
|
||||||
COLUMN_MAPPINGS,
|
|
||||||
LA_CODE_TO_NAME,
|
|
||||||
NULL_VALUES,
|
|
||||||
SCHOOL_TYPE_MAP,
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
def parse_numeric(value) -> Optional[float]:
|
|
||||||
"""Parse a numeric value, handling special cases."""
|
|
||||||
if pd.isna(value):
|
|
||||||
return None
|
|
||||||
if isinstance(value, (int, float)):
|
|
||||||
return float(value) if not np.isnan(value) else None
|
|
||||||
str_val = str(value).strip().upper()
|
|
||||||
if str_val in NULL_VALUES or str_val == "":
|
|
||||||
return None
|
|
||||||
# Remove percentage signs if present
|
|
||||||
str_val = str_val.replace("%", "")
|
|
||||||
try:
|
|
||||||
return float(str_val)
|
|
||||||
except ValueError:
|
|
||||||
return None
|
|
||||||
|
|
||||||
|
|
||||||
def extract_year_from_folder(folder_name: str) -> Optional[int]:
|
|
||||||
"""Extract year from folder name like '2023-2024'."""
|
|
||||||
match = re.search(r"(\d{4})-(\d{4})", folder_name)
|
|
||||||
if match:
|
|
||||||
return int(match.group(2))
|
|
||||||
match = re.search(r"(\d{4})", folder_name)
|
|
||||||
if match:
|
|
||||||
return int(match.group(1))
|
|
||||||
return None
|
|
||||||
|
|
||||||
|
|
||||||
def geocode_postcodes_bulk(postcodes: list) -> Dict[str, tuple]:
|
|
||||||
"""
|
|
||||||
Geocode postcodes in bulk using postcodes.io API.
|
|
||||||
Returns dict of postcode -> (latitude, longitude).
|
|
||||||
"""
|
|
||||||
results = {}
|
|
||||||
valid_postcodes = [
|
|
||||||
p.strip().upper()
|
|
||||||
for p in postcodes
|
|
||||||
if p and isinstance(p, str) and len(p.strip()) >= 5
|
|
||||||
]
|
|
||||||
valid_postcodes = list(set(valid_postcodes))
|
|
||||||
|
|
||||||
if not valid_postcodes:
|
|
||||||
return results
|
|
||||||
|
|
||||||
batch_size = 100
|
|
||||||
total_batches = (len(valid_postcodes) + batch_size - 1) // batch_size
|
|
||||||
|
|
||||||
for i, batch_start in enumerate(range(0, len(valid_postcodes), batch_size)):
|
|
||||||
batch = valid_postcodes[batch_start : batch_start + batch_size]
|
|
||||||
print(
|
|
||||||
f" Geocoding batch {i + 1}/{total_batches} ({len(batch)} postcodes)..."
|
|
||||||
)
|
|
||||||
|
|
||||||
try:
|
|
||||||
response = requests.post(
|
|
||||||
"https://api.postcodes.io/postcodes",
|
|
||||||
json={"postcodes": batch},
|
|
||||||
timeout=30,
|
|
||||||
)
|
|
||||||
if response.status_code == 200:
|
|
||||||
data = response.json()
|
|
||||||
for item in data.get("result", []):
|
|
||||||
if item and item.get("result"):
|
|
||||||
pc = item["query"].upper()
|
|
||||||
lat = item["result"].get("latitude")
|
|
||||||
lon = item["result"].get("longitude")
|
|
||||||
if lat and lon:
|
|
||||||
results[pc] = (lat, lon)
|
|
||||||
except Exception as e:
|
|
||||||
print(f" Warning: Geocoding batch failed: {e}")
|
|
||||||
|
|
||||||
return results
|
|
||||||
|
|
||||||
|
|
||||||
def load_csv_data(data_dir: Path) -> pd.DataFrame:
|
|
||||||
"""Load all CSV data from data directory."""
|
|
||||||
all_data = []
|
|
||||||
|
|
||||||
for folder in sorted(data_dir.iterdir()):
|
|
||||||
if not folder.is_dir():
|
|
||||||
continue
|
|
||||||
|
|
||||||
year = extract_year_from_folder(folder.name)
|
|
||||||
if not year:
|
|
||||||
continue
|
|
||||||
|
|
||||||
# Specifically look for the KS2 results file
|
|
||||||
ks2_file = folder / "england_ks2final.csv"
|
|
||||||
if not ks2_file.exists():
|
|
||||||
continue
|
|
||||||
|
|
||||||
csv_file = ks2_file
|
|
||||||
print(f" Loading {csv_file.name} (year {year})...")
|
|
||||||
|
|
||||||
try:
|
|
||||||
df = pd.read_csv(csv_file, encoding="latin-1", low_memory=False)
|
|
||||||
except Exception as e:
|
|
||||||
print(f" Error loading {csv_file}: {e}")
|
|
||||||
continue
|
|
||||||
|
|
||||||
# Rename columns
|
|
||||||
df.rename(columns=COLUMN_MAPPINGS, inplace=True)
|
|
||||||
df["year"] = year
|
|
||||||
|
|
||||||
# Handle local authority name
|
|
||||||
la_name_cols = ["LANAME", "LA (name)", "LA_NAME", "LA NAME"]
|
|
||||||
la_name_col = next((c for c in la_name_cols if c in df.columns), None)
|
|
||||||
|
|
||||||
if la_name_col and la_name_col != "local_authority":
|
|
||||||
df["local_authority"] = df[la_name_col]
|
|
||||||
elif "LEA" in df.columns:
|
|
||||||
df["local_authority_code"] = pd.to_numeric(df["LEA"], errors="coerce")
|
|
||||||
df["local_authority"] = (
|
|
||||||
df["local_authority_code"]
|
|
||||||
.map(LA_CODE_TO_NAME)
|
|
||||||
.fillna(df["LEA"].astype(str))
|
|
||||||
)
|
|
||||||
|
|
||||||
# Store LEA code
|
|
||||||
if "LEA" in df.columns:
|
|
||||||
df["local_authority_code"] = pd.to_numeric(df["LEA"], errors="coerce")
|
|
||||||
|
|
||||||
# Map school type
|
|
||||||
if "school_type_code" in df.columns:
|
|
||||||
df["school_type"] = (
|
|
||||||
df["school_type_code"]
|
|
||||||
.map(SCHOOL_TYPE_MAP)
|
|
||||||
.fillna(df["school_type_code"])
|
|
||||||
)
|
|
||||||
|
|
||||||
# Create combined address
|
|
||||||
addr_parts = ["address1", "address2", "town", "postcode"]
|
|
||||||
for col in addr_parts:
|
|
||||||
if col not in df.columns:
|
|
||||||
df[col] = None
|
|
||||||
|
|
||||||
df["address"] = df.apply(
|
|
||||||
lambda r: ", ".join(
|
|
||||||
str(v)
|
|
||||||
for v in [
|
|
||||||
r.get("address1"),
|
|
||||||
r.get("address2"),
|
|
||||||
r.get("town"),
|
|
||||||
r.get("postcode"),
|
|
||||||
]
|
|
||||||
if pd.notna(v) and str(v).strip()
|
|
||||||
),
|
|
||||||
axis=1,
|
|
||||||
)
|
|
||||||
|
|
||||||
all_data.append(df)
|
|
||||||
print(f" Loaded {len(df)} records")
|
|
||||||
|
|
||||||
if all_data:
|
|
||||||
result = pd.concat(all_data, ignore_index=True)
|
|
||||||
print(f"\nTotal records loaded: {len(result)}")
|
|
||||||
print(f"Unique schools: {result['urn'].nunique()}")
|
|
||||||
print(f"Years: {sorted(result['year'].unique())}")
|
|
||||||
return result
|
|
||||||
|
|
||||||
return pd.DataFrame()
|
|
||||||
|
|
||||||
|
|
||||||
def migrate_data(df: pd.DataFrame, geocode: bool = False, geocode_cache: dict = None):
|
|
||||||
"""Migrate DataFrame data to database."""
|
|
||||||
|
|
||||||
if geocode_cache is None:
|
|
||||||
geocode_cache = {}
|
|
||||||
|
|
||||||
# Clean URN column - convert to integer, drop invalid values
|
|
||||||
df = df.copy()
|
|
||||||
df["urn"] = pd.to_numeric(df["urn"], errors="coerce")
|
|
||||||
df = df.dropna(subset=["urn"])
|
|
||||||
df["urn"] = df["urn"].astype(int)
|
|
||||||
|
|
||||||
# Group by URN to get unique schools (use latest year's data)
|
|
||||||
school_data = (
|
|
||||||
df.sort_values("year", ascending=False).groupby("urn").first().reset_index()
|
|
||||||
)
|
|
||||||
print(f"\nMigrating {len(school_data)} unique schools...")
|
|
||||||
|
|
||||||
# Geocode postcodes that aren't already in the cache
|
|
||||||
geocoded = dict(geocode_cache) # start with preserved coordinates
|
|
||||||
if geocode and "postcode" in df.columns:
|
|
||||||
cached_postcodes = {
|
|
||||||
str(row.get("postcode", "")).strip().upper()
|
|
||||||
for _, row in school_data.iterrows()
|
|
||||||
if int(float(str(row.get("urn", 0) or 0))) in geocode_cache
|
|
||||||
}
|
|
||||||
postcodes_needed = [
|
|
||||||
p for p in df["postcode"].dropna().unique()
|
|
||||||
if str(p).strip().upper() not in cached_postcodes
|
|
||||||
]
|
|
||||||
if postcodes_needed:
|
|
||||||
print(f"\nGeocoding {len(postcodes_needed)} postcodes ({len(geocode_cache)} restored from cache)...")
|
|
||||||
fresh = geocode_postcodes_bulk(postcodes_needed)
|
|
||||||
geocoded.update(fresh)
|
|
||||||
print(f" Successfully geocoded {len(fresh)} new postcodes")
|
|
||||||
else:
|
|
||||||
print(f"\nAll {len(geocode_cache)} postcodes restored from cache, skipping geocoding.")
|
|
||||||
|
|
||||||
with get_db_session() as db:
|
|
||||||
# Create schools
|
|
||||||
urn_to_school_id = {}
|
|
||||||
schools_created = 0
|
|
||||||
|
|
||||||
for _, row in school_data.iterrows():
|
|
||||||
# Safely parse URN - handle None, NaN, whitespace, and invalid values
|
|
||||||
urn_val = row.get("urn")
|
|
||||||
urn = None
|
|
||||||
if pd.notna(urn_val):
|
|
||||||
try:
|
|
||||||
urn_str = str(urn_val).strip()
|
|
||||||
if urn_str:
|
|
||||||
urn = int(float(urn_str)) # Handle "12345.0" format
|
|
||||||
except (ValueError, TypeError):
|
|
||||||
pass
|
|
||||||
if not urn:
|
|
||||||
continue
|
|
||||||
|
|
||||||
# Skip if we've already added this URN (handles duplicates in source data)
|
|
||||||
if urn in urn_to_school_id:
|
|
||||||
continue
|
|
||||||
|
|
||||||
# Get geocoding data
|
|
||||||
postcode = row.get("postcode")
|
|
||||||
lat, lon = None, None
|
|
||||||
if postcode and pd.notna(postcode):
|
|
||||||
coords = geocoded.get(str(postcode).strip().upper())
|
|
||||||
if coords:
|
|
||||||
lat, lon = coords
|
|
||||||
|
|
||||||
# Safely parse local_authority_code
|
|
||||||
la_code = None
|
|
||||||
la_code_val = row.get("local_authority_code")
|
|
||||||
if pd.notna(la_code_val):
|
|
||||||
try:
|
|
||||||
la_code_str = str(la_code_val).strip()
|
|
||||||
if la_code_str:
|
|
||||||
la_code = int(float(la_code_str))
|
|
||||||
except (ValueError, TypeError):
|
|
||||||
pass
|
|
||||||
|
|
||||||
school = School(
|
|
||||||
urn=urn,
|
|
||||||
school_name=row.get("school_name")
|
|
||||||
if pd.notna(row.get("school_name"))
|
|
||||||
else "Unknown",
|
|
||||||
local_authority=row.get("local_authority")
|
|
||||||
if pd.notna(row.get("local_authority"))
|
|
||||||
else None,
|
|
||||||
local_authority_code=la_code,
|
|
||||||
school_type=row.get("school_type")
|
|
||||||
if pd.notna(row.get("school_type"))
|
|
||||||
else None,
|
|
||||||
school_type_code=row.get("school_type_code")
|
|
||||||
if pd.notna(row.get("school_type_code"))
|
|
||||||
else None,
|
|
||||||
religious_denomination=row.get("religious_denomination")
|
|
||||||
if pd.notna(row.get("religious_denomination"))
|
|
||||||
else None,
|
|
||||||
age_range=row.get("age_range")
|
|
||||||
if pd.notna(row.get("age_range"))
|
|
||||||
else None,
|
|
||||||
address1=row.get("address1") if pd.notna(row.get("address1")) else None,
|
|
||||||
address2=row.get("address2") if pd.notna(row.get("address2")) else None,
|
|
||||||
town=row.get("town") if pd.notna(row.get("town")) else None,
|
|
||||||
postcode=row.get("postcode") if pd.notna(row.get("postcode")) else None,
|
|
||||||
latitude=lat,
|
|
||||||
longitude=lon,
|
|
||||||
)
|
|
||||||
db.add(school)
|
|
||||||
db.flush() # Get the ID
|
|
||||||
urn_to_school_id[urn] = school.id
|
|
||||||
schools_created += 1
|
|
||||||
|
|
||||||
if schools_created % 1000 == 0:
|
|
||||||
print(f" Created {schools_created} schools...")
|
|
||||||
|
|
||||||
print(f" Created {schools_created} schools")
|
|
||||||
|
|
||||||
# Create results
|
|
||||||
print(f"\nMigrating {len(df)} yearly results...")
|
|
||||||
results_created = 0
|
|
||||||
|
|
||||||
for _, row in df.iterrows():
|
|
||||||
# Safely parse URN
|
|
||||||
urn_val = row.get("urn")
|
|
||||||
urn = None
|
|
||||||
if pd.notna(urn_val):
|
|
||||||
try:
|
|
||||||
urn_str = str(urn_val).strip()
|
|
||||||
if urn_str:
|
|
||||||
urn = int(float(urn_str))
|
|
||||||
except (ValueError, TypeError):
|
|
||||||
pass
|
|
||||||
if not urn or urn not in urn_to_school_id:
|
|
||||||
continue
|
|
||||||
|
|
||||||
school_id = urn_to_school_id[urn]
|
|
||||||
|
|
||||||
# Safely parse year
|
|
||||||
year_val = row.get("year")
|
|
||||||
year = None
|
|
||||||
if pd.notna(year_val):
|
|
||||||
try:
|
|
||||||
year = int(float(str(year_val).strip()))
|
|
||||||
except (ValueError, TypeError):
|
|
||||||
pass
|
|
||||||
if not year:
|
|
||||||
continue
|
|
||||||
|
|
||||||
result = SchoolResult(
|
|
||||||
school_id=school_id,
|
|
||||||
year=year,
|
|
||||||
total_pupils=parse_numeric(row.get("total_pupils")),
|
|
||||||
eligible_pupils=parse_numeric(row.get("eligible_pupils")),
|
|
||||||
# Expected Standard
|
|
||||||
rwm_expected_pct=parse_numeric(row.get("rwm_expected_pct")),
|
|
||||||
reading_expected_pct=parse_numeric(row.get("reading_expected_pct")),
|
|
||||||
writing_expected_pct=parse_numeric(row.get("writing_expected_pct")),
|
|
||||||
maths_expected_pct=parse_numeric(row.get("maths_expected_pct")),
|
|
||||||
gps_expected_pct=parse_numeric(row.get("gps_expected_pct")),
|
|
||||||
science_expected_pct=parse_numeric(row.get("science_expected_pct")),
|
|
||||||
# Higher Standard
|
|
||||||
rwm_high_pct=parse_numeric(row.get("rwm_high_pct")),
|
|
||||||
reading_high_pct=parse_numeric(row.get("reading_high_pct")),
|
|
||||||
writing_high_pct=parse_numeric(row.get("writing_high_pct")),
|
|
||||||
maths_high_pct=parse_numeric(row.get("maths_high_pct")),
|
|
||||||
gps_high_pct=parse_numeric(row.get("gps_high_pct")),
|
|
||||||
# Progress
|
|
||||||
reading_progress=parse_numeric(row.get("reading_progress")),
|
|
||||||
writing_progress=parse_numeric(row.get("writing_progress")),
|
|
||||||
maths_progress=parse_numeric(row.get("maths_progress")),
|
|
||||||
# Averages
|
|
||||||
reading_avg_score=parse_numeric(row.get("reading_avg_score")),
|
|
||||||
maths_avg_score=parse_numeric(row.get("maths_avg_score")),
|
|
||||||
gps_avg_score=parse_numeric(row.get("gps_avg_score")),
|
|
||||||
# Context
|
|
||||||
disadvantaged_pct=parse_numeric(row.get("disadvantaged_pct")),
|
|
||||||
eal_pct=parse_numeric(row.get("eal_pct")),
|
|
||||||
sen_support_pct=parse_numeric(row.get("sen_support_pct")),
|
|
||||||
sen_ehcp_pct=parse_numeric(row.get("sen_ehcp_pct")),
|
|
||||||
stability_pct=parse_numeric(row.get("stability_pct")),
|
|
||||||
# Absence
|
|
||||||
reading_absence_pct=parse_numeric(row.get("reading_absence_pct")),
|
|
||||||
gps_absence_pct=parse_numeric(row.get("gps_absence_pct")),
|
|
||||||
maths_absence_pct=parse_numeric(row.get("maths_absence_pct")),
|
|
||||||
writing_absence_pct=parse_numeric(row.get("writing_absence_pct")),
|
|
||||||
science_absence_pct=parse_numeric(row.get("science_absence_pct")),
|
|
||||||
# Gender
|
|
||||||
rwm_expected_boys_pct=parse_numeric(row.get("rwm_expected_boys_pct")),
|
|
||||||
rwm_expected_girls_pct=parse_numeric(row.get("rwm_expected_girls_pct")),
|
|
||||||
rwm_high_boys_pct=parse_numeric(row.get("rwm_high_boys_pct")),
|
|
||||||
rwm_high_girls_pct=parse_numeric(row.get("rwm_high_girls_pct")),
|
|
||||||
# Disadvantaged
|
|
||||||
rwm_expected_disadvantaged_pct=parse_numeric(
|
|
||||||
row.get("rwm_expected_disadvantaged_pct")
|
|
||||||
),
|
|
||||||
rwm_expected_non_disadvantaged_pct=parse_numeric(
|
|
||||||
row.get("rwm_expected_non_disadvantaged_pct")
|
|
||||||
),
|
|
||||||
disadvantaged_gap=parse_numeric(row.get("disadvantaged_gap")),
|
|
||||||
# 3-Year
|
|
||||||
rwm_expected_3yr_pct=parse_numeric(row.get("rwm_expected_3yr_pct")),
|
|
||||||
reading_avg_3yr=parse_numeric(row.get("reading_avg_3yr")),
|
|
||||||
maths_avg_3yr=parse_numeric(row.get("maths_avg_3yr")),
|
|
||||||
)
|
|
||||||
db.add(result)
|
|
||||||
results_created += 1
|
|
||||||
|
|
||||||
if results_created % 10000 == 0:
|
|
||||||
print(f" Created {results_created} results...")
|
|
||||||
db.flush()
|
|
||||||
|
|
||||||
print(f" Created {results_created} results")
|
|
||||||
|
|
||||||
# Commit all changes
|
|
||||||
db.commit()
|
|
||||||
print("\nMigration complete!")
|
|
||||||
|
|
||||||
|
|
||||||
def _apply_schema_alterations():
|
|
||||||
"""
|
|
||||||
Add new columns to existing tables using ALTER TABLE … ADD COLUMN IF NOT EXISTS.
|
|
||||||
Safe to run on every migration — no-ops if the column already exists.
|
|
||||||
Add entries here whenever models.py gains new columns on an existing table.
|
|
||||||
"""
|
|
||||||
alterations = [
|
|
||||||
# v4: Ofsted Report Card columns
|
|
||||||
"ALTER TABLE ofsted_inspections ADD COLUMN IF NOT EXISTS framework VARCHAR(20)",
|
|
||||||
"ALTER TABLE ofsted_inspections ADD COLUMN IF NOT EXISTS rc_safeguarding_met BOOLEAN",
|
|
||||||
"ALTER TABLE ofsted_inspections ADD COLUMN IF NOT EXISTS rc_inclusion INTEGER",
|
|
||||||
"ALTER TABLE ofsted_inspections ADD COLUMN IF NOT EXISTS rc_curriculum_teaching INTEGER",
|
|
||||||
"ALTER TABLE ofsted_inspections ADD COLUMN IF NOT EXISTS rc_achievement INTEGER",
|
|
||||||
"ALTER TABLE ofsted_inspections ADD COLUMN IF NOT EXISTS rc_attendance_behaviour INTEGER",
|
|
||||||
"ALTER TABLE ofsted_inspections ADD COLUMN IF NOT EXISTS rc_personal_development INTEGER",
|
|
||||||
"ALTER TABLE ofsted_inspections ADD COLUMN IF NOT EXISTS rc_leadership_governance INTEGER",
|
|
||||||
"ALTER TABLE ofsted_inspections ADD COLUMN IF NOT EXISTS rc_early_years INTEGER",
|
|
||||||
"ALTER TABLE ofsted_inspections ADD COLUMN IF NOT EXISTS rc_sixth_form INTEGER",
|
|
||||||
]
|
|
||||||
from sqlalchemy import text as sa_text
|
|
||||||
with engine.connect() as conn:
|
|
||||||
for stmt in alterations:
|
|
||||||
try:
|
|
||||||
conn.execute(sa_text(stmt))
|
|
||||||
except Exception as e:
|
|
||||||
print(f" Warning: alteration skipped ({e})")
|
|
||||||
conn.commit()
|
|
||||||
|
|
||||||
|
|
||||||
def _apply_schema_drops():
|
|
||||||
"""
|
|
||||||
Drop tables retired from the schema. Idempotent (DROP … IF EXISTS), so it's
|
|
||||||
safe to run on every migration. Add entries here when a model is removed.
|
|
||||||
"""
|
|
||||||
drops = [
|
|
||||||
# v6: Ofsted Parent View feature removed
|
|
||||||
"DROP TABLE IF EXISTS marts.fact_parent_view CASCADE",
|
|
||||||
]
|
|
||||||
from sqlalchemy import text as sa_text
|
|
||||||
with engine.connect() as conn:
|
|
||||||
for stmt in drops:
|
|
||||||
try:
|
|
||||||
conn.execute(sa_text(stmt))
|
|
||||||
except Exception as e:
|
|
||||||
print(f" Warning: drop skipped ({e})")
|
|
||||||
conn.commit()
|
|
||||||
|
|
||||||
|
|
||||||
def run_full_migration(geocode: bool = False) -> bool:
|
|
||||||
"""
|
|
||||||
Run a complete migration: drop all tables and reimport from CSV.
|
|
||||||
|
|
||||||
Returns True if successful, False if no data found.
|
|
||||||
Raises exception on error.
|
|
||||||
"""
|
|
||||||
# Preserve existing geocoding so a reimport doesn't throw away coordinates
|
|
||||||
# that took a long time to compute.
|
|
||||||
geocode_cache: dict[int, tuple[float, float]] = {}
|
|
||||||
inspector = __import__("sqlalchemy").inspect(engine)
|
|
||||||
if "schools" in inspector.get_table_names():
|
|
||||||
try:
|
|
||||||
with get_db_session() as db:
|
|
||||||
rows = db.execute(
|
|
||||||
__import__("sqlalchemy").text(
|
|
||||||
"SELECT urn, latitude, longitude FROM schools "
|
|
||||||
"WHERE latitude IS NOT NULL AND longitude IS NOT NULL"
|
|
||||||
)
|
|
||||||
).fetchall()
|
|
||||||
geocode_cache = {r.urn: (r.latitude, r.longitude) for r in rows}
|
|
||||||
print(f" Saved {len(geocode_cache)} existing geocoded coordinates.")
|
|
||||||
except Exception as e:
|
|
||||||
print(f" Warning: could not save geocode cache: {e}")
|
|
||||||
|
|
||||||
# Only drop the core KS2 tables — leave supplementary tables (ofsted, census,
|
|
||||||
# finance, etc.) intact so a reimport doesn't wipe integrator-populated data.
|
|
||||||
# schema_version is NOT dropped: it persists so restarts don't re-trigger migration.
|
|
||||||
ks2_tables = ["school_results", "schools"]
|
|
||||||
print(f"Dropping core tables: {ks2_tables} ...")
|
|
||||||
inspector = __import__("sqlalchemy").inspect(engine)
|
|
||||||
existing = set(inspector.get_table_names())
|
|
||||||
for tname in ks2_tables:
|
|
||||||
if tname in existing:
|
|
||||||
Base.metadata.tables[tname].drop(bind=engine)
|
|
||||||
|
|
||||||
print("Creating all tables...")
|
|
||||||
Base.metadata.create_all(bind=engine)
|
|
||||||
|
|
||||||
# ALTER existing supplementary tables to add any new columns.
|
|
||||||
# create_all() only creates missing tables; it won't add columns to tables
|
|
||||||
# that already exist from an older schema version. These statements are
|
|
||||||
# idempotent (IF NOT EXISTS) so they're safe to run on every migration.
|
|
||||||
print("Applying column additions to supplementary tables...")
|
|
||||||
_apply_schema_alterations()
|
|
||||||
|
|
||||||
print("Dropping retired tables...")
|
|
||||||
_apply_schema_drops()
|
|
||||||
|
|
||||||
print("\nLoading CSV data...")
|
|
||||||
df = load_csv_data(settings.data_dir)
|
|
||||||
|
|
||||||
if df.empty:
|
|
||||||
print("Warning: No CSV data found to migrate!")
|
|
||||||
return False
|
|
||||||
|
|
||||||
migrate_data(df, geocode=geocode, geocode_cache=geocode_cache)
|
|
||||||
return True
|
|
||||||
@@ -321,3 +321,48 @@ class Ks2NationalAverage(Base):
|
|||||||
gps_high_pct = Column(Float)
|
gps_high_pct = Column(Float)
|
||||||
gps_avg_score = Column(Float)
|
gps_avg_score = Column(Float)
|
||||||
science_expected_pct = Column(Float)
|
science_expected_pct = Column(Float)
|
||||||
|
|
||||||
|
|
||||||
|
class FactKs4Destinations(Base):
|
||||||
|
"""KS4 leavers destinations — one row per URN, year, pupil group, measure.
|
||||||
|
|
||||||
|
Long format rather than wide because pupil_group is a real third dimension.
|
||||||
|
`status` is load-bearing: 'suppressed' means DfE withheld a figure it
|
||||||
|
considered disclosive and the page must print "withheld"; 'not_applicable'
|
||||||
|
means the measure does not apply and the page must print nothing. `pupils`
|
||||||
|
is null for both, so collapsing status to a null check loses the
|
||||||
|
difference — and the categories sum to the cohort, so a consumer that
|
||||||
|
treats a withheld cell as zero republishes what DfE hid.
|
||||||
|
"""
|
||||||
|
__tablename__ = "fact_ks4_destinations"
|
||||||
|
__table_args__ = (
|
||||||
|
Index("ix_ks4_dest_urn_year", "urn", "year"),
|
||||||
|
MARTS,
|
||||||
|
)
|
||||||
|
|
||||||
|
urn = Column(Integer, primary_key=True)
|
||||||
|
year = Column(Integer, primary_key=True)
|
||||||
|
pupil_group = Column(String(20), primary_key=True)
|
||||||
|
destination_measure = Column(String(40), primary_key=True)
|
||||||
|
cohort_pupils = Column(Integer)
|
||||||
|
pupils = Column(Integer)
|
||||||
|
percentage = Column(Float)
|
||||||
|
status = Column(String(20))
|
||||||
|
|
||||||
|
|
||||||
|
class FactKs5Destinations(Base):
|
||||||
|
"""16-18 study leavers destinations — same grain as FactKs4Destinations."""
|
||||||
|
__tablename__ = "fact_ks5_destinations"
|
||||||
|
__table_args__ = (
|
||||||
|
Index("ix_ks5_dest_urn_year", "urn", "year"),
|
||||||
|
MARTS,
|
||||||
|
)
|
||||||
|
|
||||||
|
urn = Column(Integer, primary_key=True)
|
||||||
|
year = Column(Integer, primary_key=True)
|
||||||
|
pupil_group = Column(String(20), primary_key=True)
|
||||||
|
destination_measure = Column(String(40), primary_key=True)
|
||||||
|
cohort_pupils = Column(Integer)
|
||||||
|
pupils = Column(Integer)
|
||||||
|
percentage = Column(Float)
|
||||||
|
status = Column(String(20))
|
||||||
@@ -296,6 +296,48 @@ def _locality_places(df, publishable: set[int],
|
|||||||
return out
|
return out
|
||||||
|
|
||||||
|
|
||||||
|
# Ordered authority → town/locality → outcode, widest first, because that is
|
||||||
|
# the order a breadcrumb reads. The link module re-sorts for its own purposes.
|
||||||
|
_PLACE_ORDER = {"authority": 0, "town": 1, "locality": 2, "outcode": 3}
|
||||||
|
|
||||||
|
|
||||||
|
def build_place_index(registry: dict[str, Place]) -> dict[int, tuple[Place, ...]]:
|
||||||
|
"""URN → the published places containing it, built once per registry.
|
||||||
|
|
||||||
|
The reverse of the registry, and the thing school pages link out through.
|
||||||
|
Derived from the registry rather than maintained beside it, so the two
|
||||||
|
cannot disagree about which places exist: a place below the publish
|
||||||
|
threshold is absent from the registry, so it is absent from here too, and
|
||||||
|
a link is never offered for a page that does not exist.
|
||||||
|
|
||||||
|
Built as an index rather than scanned per call because /api/schools/{urn}
|
||||||
|
is the site's highest-traffic endpoint. Scanning meant walking every place
|
||||||
|
and doing a tuple membership test against each — on the order of 10^5
|
||||||
|
comparisons per request, repeated for every school page view. One pass at
|
||||||
|
registry-build time replaces all of it with a dict lookup.
|
||||||
|
"""
|
||||||
|
grouped: dict[int, list[Place]] = {}
|
||||||
|
for place in registry.values():
|
||||||
|
for urn in place.urns:
|
||||||
|
grouped.setdefault(int(urn), []).append(place)
|
||||||
|
|
||||||
|
return {
|
||||||
|
urn: tuple(sorted(places,
|
||||||
|
key=lambda p: (_PLACE_ORDER.get(p.kind, 9), p.slug)))
|
||||||
|
for urn, places in grouped.items()
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def places_for_urn(index: dict[int, tuple[Place, ...]], urn: int) -> tuple[Place, ...]:
|
||||||
|
"""The published places containing this school, widest first.
|
||||||
|
|
||||||
|
Empty is a real answer, not a failure: a school whose town and authority
|
||||||
|
both fall below the publish threshold has nowhere to link, and the page
|
||||||
|
renders without the module.
|
||||||
|
"""
|
||||||
|
return index.get(int(urn), ())
|
||||||
|
|
||||||
|
|
||||||
def build_place_registry(df) -> dict[str, Place]:
|
def build_place_registry(df) -> dict[str, Place]:
|
||||||
"""Every place the site publishes, keyed by "<kind>:<slug>"."""
|
"""Every place the site publishes, keyed by "<kind>:<slug>"."""
|
||||||
if df.empty or "urn" not in df.columns:
|
if df.empty or "urn" not in df.columns:
|
||||||
|
|||||||
@@ -0,0 +1,269 @@
|
|||||||
|
"""The destinations serialiser's contract.
|
||||||
|
|
||||||
|
Not rendering a figure is not the same as not publishing it. This endpoint is
|
||||||
|
public and unauthenticated, so whatever the payload carries is published,
|
||||||
|
whatever the UI draws. The categories sum to the cohort and the pupil groups
|
||||||
|
sum to each other, so a lone suppressed cell is solvable by subtraction — the
|
||||||
|
serialiser adds secondary suppression to prevent it.
|
||||||
|
|
||||||
|
See docs/superpowers/specs/2026-08-28-destination-measures-design.md.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from backend.data_loader import (
|
||||||
|
_destinations_block, _format_cohort_year, disclosure_invariant_holds,
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def _row(group, measure, pupils, status, cohort=180, percentage=None, year=202223):
|
||||||
|
return {
|
||||||
|
"pupil_group": group,
|
||||||
|
"destination_measure": measure,
|
||||||
|
"pupils": pupils,
|
||||||
|
"percentage": percentage,
|
||||||
|
"status": status,
|
||||||
|
"cohort_pupils": cohort,
|
||||||
|
"year": year,
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def test_suppressed_category_serialises_as_suppressed_with_null_pupils():
|
||||||
|
rows = [
|
||||||
|
_row("all", "school_sixth_form", 75, "published", percentage=41.7),
|
||||||
|
_row("all", "sixth_form_college", None, "suppressed"),
|
||||||
|
]
|
||||||
|
block = _destinations_block(rows)
|
||||||
|
cats = {c["category"]: c for c in block["groups"]["all"]["categories"]}
|
||||||
|
assert cats["sixth_form_college"]["status"] == "suppressed"
|
||||||
|
assert cats["sixth_form_college"]["pupils"] is None
|
||||||
|
assert cats["sixth_form_college"]["percentage"] is None
|
||||||
|
|
||||||
|
|
||||||
|
def test_published_category_keeps_its_figures():
|
||||||
|
block = _destinations_block([
|
||||||
|
_row("all", "school_sixth_form", 75, "published", percentage=41.7),
|
||||||
|
])
|
||||||
|
cat = block["groups"]["all"]["categories"][0]
|
||||||
|
assert cat["pupils"] == 75
|
||||||
|
assert cat["percentage"] == 41.7
|
||||||
|
assert cat["status"] == "published"
|
||||||
|
|
||||||
|
|
||||||
|
def test_only_the_latest_year_is_served():
|
||||||
|
rows = [
|
||||||
|
_row("all", "school_sixth_form", 60, "published", year=202122),
|
||||||
|
_row("all", "school_sixth_form", 75, "published", year=202223),
|
||||||
|
]
|
||||||
|
block = _destinations_block(rows)
|
||||||
|
assert block["cohort_year"] == "2022/23"
|
||||||
|
assert len(block["groups"]["all"]["categories"]) == 1
|
||||||
|
assert block["groups"]["all"]["categories"][0]["pupils"] == 75
|
||||||
|
|
||||||
|
|
||||||
|
def test_all_three_pupil_groups_are_carried():
|
||||||
|
rows = [
|
||||||
|
_row("all", "school_sixth_form", 75, "published"),
|
||||||
|
_row("disadvantaged", "school_sixth_form", 17, "published", cohort=62),
|
||||||
|
_row("other", "school_sixth_form", 58, "published", cohort=118),
|
||||||
|
]
|
||||||
|
block = _destinations_block(rows)
|
||||||
|
assert set(block["groups"]) == {"all", "disadvantaged", "other"}
|
||||||
|
assert block["groups"]["disadvantaged"]["cohort"] == 62
|
||||||
|
|
||||||
|
|
||||||
|
def test_cohort_year_is_reported_so_the_page_can_date_itself():
|
||||||
|
block = _destinations_block([_row("all", "school_sixth_form", 75, "published")])
|
||||||
|
assert block["cohort_year"] == "2022/23"
|
||||||
|
|
||||||
|
|
||||||
|
def test_format_cohort_year_handles_the_six_digit_form():
|
||||||
|
assert _format_cohort_year(202223) == "2022/23"
|
||||||
|
assert _format_cohort_year(None) is None
|
||||||
|
|
||||||
|
|
||||||
|
def test_empty_rows_yield_none_not_an_empty_shell():
|
||||||
|
assert _destinations_block([]) is None
|
||||||
|
|
||||||
|
|
||||||
|
# ── Disclosure control ──────────────────────────────────────────────────────
|
||||||
|
#
|
||||||
|
# The rendering guards in lib/destinations.ts stop a withheld figure being
|
||||||
|
# DRAWN. They do nothing about it being COMPUTED: this endpoint is public and
|
||||||
|
# unauthenticated, so whatever the payload carries is published. These tests
|
||||||
|
# are the ones that matter.
|
||||||
|
|
||||||
|
def _solve_residual(group):
|
||||||
|
"""What any caller can work out: cohort minus everything published."""
|
||||||
|
published = [c["pupils"] for c in group["categories"] if c["pupils"] is not None]
|
||||||
|
hidden = [c for c in group["categories"] if c["status"] == "suppressed"]
|
||||||
|
return group["cohort"] - sum(published), len(hidden)
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_lone_suppressed_category_cannot_be_solved_for():
|
||||||
|
"""Whitley Bay High School's real 2022/23 disadvantaged group: further
|
||||||
|
education withheld, everything else published, cohort 41. Before secondary
|
||||||
|
suppression the payload gave the answer away as 41 - 23 = 18."""
|
||||||
|
rows = [
|
||||||
|
_row("disadvantaged", "school_sixth_form", 15, "published", cohort=41),
|
||||||
|
_row("disadvantaged", "sixth_form_college", 0, "published", cohort=41),
|
||||||
|
_row("disadvantaged", "further_education", None, "suppressed", cohort=41),
|
||||||
|
_row("disadvantaged", "apprenticeship", 1, "published", cohort=41),
|
||||||
|
_row("disadvantaged", "employment", 2, "published", cohort=41),
|
||||||
|
_row("disadvantaged", "not_sustained", 3, "published", cohort=41),
|
||||||
|
_row("disadvantaged", "not_captured", 2, "published", cohort=41),
|
||||||
|
]
|
||||||
|
group = _destinations_block(rows)["groups"]["disadvantaged"]
|
||||||
|
residual, hidden = _solve_residual(group)
|
||||||
|
assert hidden >= 2, "a lone suppressed cell must gain a companion"
|
||||||
|
assert residual != 18, "the withheld figure is recoverable from the payload"
|
||||||
|
|
||||||
|
|
||||||
|
def test_every_group_hides_none_or_at_least_two_categories():
|
||||||
|
rows = [
|
||||||
|
_row("all", "school_sixth_form", 75, "published"),
|
||||||
|
_row("all", "sixth_form_college", None, "suppressed"),
|
||||||
|
_row("all", "further_education", 61, "published"),
|
||||||
|
_row("all", "apprenticeship", 8, "published"),
|
||||||
|
_row("all", "employment", 6, "published"),
|
||||||
|
_row("all", "not_sustained", 5, "published"),
|
||||||
|
_row("all", "not_captured", 4, "published"),
|
||||||
|
]
|
||||||
|
group = _destinations_block(rows)["groups"]["all"]
|
||||||
|
hidden = [c for c in group["categories"] if c["status"] == "suppressed"]
|
||||||
|
assert len(hidden) >= 2
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_category_hidden_in_one_group_is_hidden_in_a_second():
|
||||||
|
"""disadvantaged + other = all for every category, so a category withheld
|
||||||
|
in exactly one of the three is recoverable from the other two."""
|
||||||
|
rows = []
|
||||||
|
for measure, a, d, o in [
|
||||||
|
("school_sixth_form", 75, None, 58),
|
||||||
|
("further_education", 61, 27, 34),
|
||||||
|
("apprenticeship", 8, 4, 4),
|
||||||
|
("employment", 6, 1, 5),
|
||||||
|
("not_sustained", 5, 3, 2),
|
||||||
|
("not_captured", 4, 2, 2),
|
||||||
|
]:
|
||||||
|
rows.append(_row("all", measure, a, "published", cohort=159))
|
||||||
|
rows.append(_row("disadvantaged", measure, d,
|
||||||
|
"published" if d is not None else "suppressed", cohort=37))
|
||||||
|
rows.append(_row("other", measure, o, "published", cohort=122))
|
||||||
|
|
||||||
|
groups = _destinations_block(rows)["groups"]
|
||||||
|
measures = {c["category"] for g in groups.values() for c in g["categories"]}
|
||||||
|
assert len(measures) == 6, "the fixture's six measures must all be checked"
|
||||||
|
|
||||||
|
for measure in sorted(measures):
|
||||||
|
hidden = sum(
|
||||||
|
1 for g in groups.values() for c in g["categories"]
|
||||||
|
if c["category"] == measure and c["status"] == "suppressed"
|
||||||
|
)
|
||||||
|
# The invariant is "none, or at least two" — not "at least two".
|
||||||
|
assert hidden != 1, f"{measure} is solvable across the pupil groups"
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_suppressed_cell_never_keeps_its_percentage():
|
||||||
|
"""percentage / pupils would hand back the cohort, and with it the residual."""
|
||||||
|
rows = [
|
||||||
|
_row("all", "school_sixth_form", 75, "published", percentage=41.7),
|
||||||
|
_row("all", "sixth_form_college", None, "suppressed", percentage=11.7),
|
||||||
|
_row("all", "further_education", 61, "published", percentage=33.9),
|
||||||
|
]
|
||||||
|
group = _destinations_block(rows)["groups"]["all"]
|
||||||
|
for cell in group["categories"]:
|
||||||
|
if cell["status"] != "published":
|
||||||
|
assert cell["pupils"] is None
|
||||||
|
assert cell["percentage"] is None
|
||||||
|
|
||||||
|
|
||||||
|
def test_aggregates_are_not_served():
|
||||||
|
"""An aggregate spanning exactly one suppressed component names it, and
|
||||||
|
nothing renders them today."""
|
||||||
|
rows = [
|
||||||
|
_row("all", "school_sixth_form", 75, "published"),
|
||||||
|
_row("all", "agg_sustained_all", 171, "published"),
|
||||||
|
]
|
||||||
|
group = _destinations_block(rows)["groups"]["all"]
|
||||||
|
assert [c["category"] for c in group["categories"]] == ["school_sixth_form"]
|
||||||
|
assert "aggregates" not in group
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_fully_published_group_is_left_alone():
|
||||||
|
"""Secondary suppression must not cost anything where nothing is withheld —
|
||||||
|
this is the all-pupils view on every mainstream secondary."""
|
||||||
|
rows = [
|
||||||
|
_row("all", m, p, "published")
|
||||||
|
for m, p in [("school_sixth_form", 75), ("sixth_form_college", 21),
|
||||||
|
("further_education", 61), ("apprenticeship", 8),
|
||||||
|
("employment", 6), ("not_sustained", 5), ("not_captured", 4)]
|
||||||
|
]
|
||||||
|
group = _destinations_block(rows)["groups"]["all"]
|
||||||
|
assert all(c["status"] == "published" for c in group["categories"])
|
||||||
|
assert len(group["categories"]) == 7
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_invariant_is_asserted_directly_not_re_derived():
|
||||||
|
"""A group with one suppressed category and nothing else to withhold."""
|
||||||
|
rows = [
|
||||||
|
_row("all", "school_sixth_form", None, "suppressed", cohort=9),
|
||||||
|
_row("all", "sixth_form_college", None, "not_applicable", cohort=9),
|
||||||
|
_row("all", "further_education", None, "not_applicable", cohort=9),
|
||||||
|
]
|
||||||
|
block = _destinations_block(rows)
|
||||||
|
assert block is None or disclosure_invariant_holds(block["groups"])
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_sparse_cohort_with_no_companion_drops_the_group():
|
||||||
|
"""Special schools and AP routinely have one suppressed category and every
|
||||||
|
other one not applicable. There is nothing left to withhold, so the group
|
||||||
|
goes — an earlier version returned here with the violation intact."""
|
||||||
|
rows = [
|
||||||
|
_row("all", "school_sixth_form", None, "suppressed", cohort=9),
|
||||||
|
_row("all", "sixth_form_college", None, "not_applicable", cohort=9),
|
||||||
|
_row("all", "further_education", None, "not_applicable", cohort=9),
|
||||||
|
_row("all", "apprenticeship", None, "not_applicable", cohort=9),
|
||||||
|
_row("all", "employment", None, "not_applicable", cohort=9),
|
||||||
|
_row("all", "not_sustained", None, "not_applicable", cohort=9),
|
||||||
|
_row("all", "not_captured", None, "not_applicable", cohort=9),
|
||||||
|
]
|
||||||
|
block = _destinations_block(rows)
|
||||||
|
assert block is None or "all" not in block["groups"], (
|
||||||
|
"a group that cannot be made safe must not be served"
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def test_zeros_are_not_treated_as_a_usable_companion():
|
||||||
|
"""Suppressing a zero protects nothing — the residual is unchanged. With
|
||||||
|
only zeros available the group must be dropped, not falsely 'fixed'."""
|
||||||
|
rows = [
|
||||||
|
_row("all", "school_sixth_form", None, "suppressed", cohort=5),
|
||||||
|
_row("all", "sixth_form_college", 0, "published", cohort=5),
|
||||||
|
_row("all", "further_education", 0, "published", cohort=5),
|
||||||
|
]
|
||||||
|
block = _destinations_block(rows)
|
||||||
|
if block and "all" in block["groups"]:
|
||||||
|
group = block["groups"]["all"]
|
||||||
|
published = sum(c["pupils"] for c in group["categories"]
|
||||||
|
if c["pupils"] is not None)
|
||||||
|
hidden = [c for c in group["categories"] if c["status"] == "suppressed"]
|
||||||
|
assert len(hidden) != 1, "a zero companion leaves the figure solvable"
|
||||||
|
assert group["cohort"] - published != 5
|
||||||
|
|
||||||
|
|
||||||
|
def test_masking_always_terminates_in_a_safe_state():
|
||||||
|
"""Exhaustive over every suppression pattern of a four-category group."""
|
||||||
|
from itertools import product
|
||||||
|
MEASURES = ["school_sixth_form", "sixth_form_college",
|
||||||
|
"further_education", "apprenticeship"]
|
||||||
|
for statuses in product(["published", "suppressed", "not_applicable"],
|
||||||
|
repeat=len(MEASURES)):
|
||||||
|
rows = [
|
||||||
|
_row("all", m, 3 if st == "published" else None, st, cohort=12)
|
||||||
|
for m, st in zip(MEASURES, statuses)
|
||||||
|
]
|
||||||
|
block = _destinations_block(rows)
|
||||||
|
if block is None:
|
||||||
|
continue
|
||||||
|
assert disclosure_invariant_holds(block["groups"]), (
|
||||||
|
f"invariant broken for {statuses}"
|
||||||
|
)
|
||||||
@@ -8,7 +8,8 @@ import numpy as np
|
|||||||
import pandas as pd
|
import pandas as pd
|
||||||
import pytest
|
import pytest
|
||||||
|
|
||||||
from backend.places import MIN_SCHOOLS, build_place_registry
|
from backend.places import (MIN_SCHOOLS, build_place_index,
|
||||||
|
build_place_registry, places_for_urn)
|
||||||
|
|
||||||
|
|
||||||
def _df(rows: list[dict]) -> pd.DataFrame:
|
def _df(rows: list[dict]) -> pd.DataFrame:
|
||||||
@@ -418,3 +419,79 @@ def test_an_authority_still_publishes_phase_variants():
|
|||||||
and /schools/authority/[la]/[phase] is the route that serves it."""
|
and /schools/authority/[la]/[phase] is the route that serves it."""
|
||||||
reg = build_place_registry(_df(_town(MIN_SCHOOLS, "Maidstone", "Kent")))
|
reg = build_place_registry(_df(_town(MIN_SCHOOLS, "Maidstone", "Kent")))
|
||||||
assert reg["authority:kent"].publishes_phase("primary")
|
assert reg["authority:kent"].publishes_phase("primary")
|
||||||
|
|
||||||
|
|
||||||
|
# ── The reverse index: which published places contain a school ──────────────
|
||||||
|
#
|
||||||
|
# School pages link out to the location layer through this. It is the whole
|
||||||
|
# point of the index: before it, ~27k school pages linked to nothing on the
|
||||||
|
# site and stranded whatever authority they held.
|
||||||
|
|
||||||
|
def test_a_school_resolves_to_every_published_place_containing_it():
|
||||||
|
reg = build_place_registry(_df(_town(MIN_SCHOOLS, "Brentwood", "Essex")))
|
||||||
|
places = places_for_urn(build_place_index(reg), 100000)
|
||||||
|
|
||||||
|
kinds = {p.kind for p in places}
|
||||||
|
assert "town" in kinds
|
||||||
|
assert "authority" in kinds
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_school_in_an_unpublished_town_still_resolves_to_its_authority():
|
||||||
|
# A town below the threshold has no page, so there is no link to offer —
|
||||||
|
# but the authority above it clears the threshold on the same schools and
|
||||||
|
# is where that reader should be sent.
|
||||||
|
reg = build_place_registry(_df(
|
||||||
|
_town(MIN_SCHOOLS - 1, "Tinytown", "Essex")
|
||||||
|
+ _town(MIN_SCHOOLS, "Brentwood", "Essex", start=200000)
|
||||||
|
))
|
||||||
|
places = places_for_urn(build_place_index(reg), 100000)
|
||||||
|
|
||||||
|
# The town is below the threshold, so it has no page and must not be
|
||||||
|
# offered as a link. The authority above it does, and is the right target.
|
||||||
|
assert all(p.slug != "tinytown" for p in places)
|
||||||
|
assert "authority" in {p.kind for p in places}
|
||||||
|
|
||||||
|
|
||||||
|
def test_an_unknown_urn_resolves_to_nothing_rather_than_raising():
|
||||||
|
# A school page renders for any URN the API knows; the link module is not
|
||||||
|
# entitled to take the page down when it has nothing to say.
|
||||||
|
reg = build_place_registry(_df(_town(MIN_SCHOOLS, "Brentwood", "Essex")))
|
||||||
|
assert places_for_urn(build_place_index(reg), 999999) == ()
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_index_is_consistent_with_the_registry_it_was_built_from():
|
||||||
|
# The invariant that matters: a link module must never offer a place whose
|
||||||
|
# page does not exist, and never omit one that does.
|
||||||
|
reg = build_place_registry(_df(
|
||||||
|
_town(MIN_SCHOOLS, "Brentwood", "Essex")
|
||||||
|
+ _town(MIN_SCHOOLS, "Bedford", "Bedford", start=300000)
|
||||||
|
))
|
||||||
|
index = build_place_index(reg)
|
||||||
|
for key, place in reg.items():
|
||||||
|
for urn in place.urns:
|
||||||
|
assert place in places_for_urn(index, urn), (
|
||||||
|
f"{urn} is in {key} but the index does not say so")
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_index_holds_no_school_the_registry_does_not():
|
||||||
|
# The reverse direction of the invariant above. An index entry for a URN
|
||||||
|
# no published place contains would put a link on a page for a place that
|
||||||
|
# does not list that school.
|
||||||
|
reg = build_place_registry(_df(
|
||||||
|
_town(MIN_SCHOOLS, "Brentwood", "Essex")
|
||||||
|
+ _town(MIN_SCHOOLS - 1, "Tinytown", "Essex", start=400000)
|
||||||
|
))
|
||||||
|
index = build_place_index(reg)
|
||||||
|
|
||||||
|
for urn, places in index.items():
|
||||||
|
for place in places:
|
||||||
|
assert urn in place.urns
|
||||||
|
assert place.key in reg
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_index_preserves_the_widest_first_order():
|
||||||
|
# The breadcrumb reads authority then town, and takes this order as given.
|
||||||
|
reg = build_place_registry(_df(_town(MIN_SCHOOLS, "Brentwood", "Essex")))
|
||||||
|
kinds = [p.kind for p in places_for_urn(build_place_index(reg), 100000)]
|
||||||
|
|
||||||
|
assert kinds.index("authority") < kinds.index("town")
|
||||||
@@ -137,3 +137,49 @@ def test_an_authority_without_a_page_is_named_but_carries_no_slug(straddling_cli
|
|||||||
by_name = {a["name"]: a for a in body["place"]["authorities"]}
|
by_name = {a["name"]: a for a in body["place"]["authorities"]}
|
||||||
assert by_name["Essex"]["slug"] == "essex"
|
assert by_name["Essex"]["slug"] == "essex"
|
||||||
assert by_name["Isles Of Scilly"]["slug"] is None
|
assert by_name["Isles Of Scilly"]["slug"] is None
|
||||||
|
|
||||||
|
|
||||||
|
def _attributed_df() -> pd.DataFrame:
|
||||||
|
"""The same town, with the four attributes the place table now shows."""
|
||||||
|
df = _schools_df()
|
||||||
|
df["age_range"] = "4-11"
|
||||||
|
df["religious_denomination"] = "Church of England"
|
||||||
|
df["nursery_provision"] = True
|
||||||
|
df["parliamentary_constituency"] = "Brentwood and Ongar"
|
||||||
|
return df
|
||||||
|
|
||||||
|
|
||||||
|
@pytest.fixture()
|
||||||
|
def attributed_client(monkeypatch):
|
||||||
|
from backend import app as app_module
|
||||||
|
|
||||||
|
monkeypatch.setattr(app_module, "load_school_data", _attributed_df)
|
||||||
|
monkeypatch.setattr(app_module, "load_latest_school_data", _attributed_df)
|
||||||
|
monkeypatch.setattr(app_module, "_place_registry", None)
|
||||||
|
return TestClient(app_module.app, raise_server_exceptions=False)
|
||||||
|
|
||||||
|
|
||||||
|
def test_place_detail_carries_the_attributes_the_table_shows(attributed_client):
|
||||||
|
"""age_range and religious_denomination ride in on SCHOOL_COLUMNS.
|
||||||
|
|
||||||
|
nursery_provision and parliamentary_constituency do not, and the place
|
||||||
|
table needs all four — a column the response cannot fill is a column of
|
||||||
|
dashes on ~3,900 pages.
|
||||||
|
"""
|
||||||
|
body = attributed_client.get("/api/places/town/brentwood").json()
|
||||||
|
school = body["schools"][0]
|
||||||
|
assert school["age_range"] == "4-11"
|
||||||
|
assert school["religious_denomination"] == "Church of England"
|
||||||
|
assert school["nursery_provision"] is True
|
||||||
|
assert school["parliamentary_constituency"] == "Brentwood and Ongar"
|
||||||
|
|
||||||
|
|
||||||
|
def test_place_detail_survives_a_mart_without_the_optional_columns(client):
|
||||||
|
"""The base fixture has neither column, as an unrebuilt mart does not.
|
||||||
|
|
||||||
|
data_loader degrades those to NULL rather than failing the load, so the
|
||||||
|
endpoint must not assume they are present.
|
||||||
|
"""
|
||||||
|
res = client.get("/api/places/town/brentwood")
|
||||||
|
assert res.status_code == 200
|
||||||
|
assert "nursery_provision" not in res.json()["schools"][0]
|
||||||
@@ -0,0 +1,147 @@
|
|||||||
|
"""The rate-limit bucket must be the caller, not the proxy in front of them.
|
||||||
|
|
||||||
|
`get_remote_address` reads request.client.host. In staging and production the
|
||||||
|
backend has no published ports and its only caller is the Next proxy, so that
|
||||||
|
host is the Next container — one bucket for every browser user on the site.
|
||||||
|
Measured before this fix: 70 concurrent requests, 60 served and 10 refused.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from starlette.datastructures import Headers
|
||||||
|
|
||||||
|
from backend.app import client_key
|
||||||
|
|
||||||
|
|
||||||
|
class _Req:
|
||||||
|
"""Enough of a Request for the key function: headers and a client host."""
|
||||||
|
|
||||||
|
def __init__(self, headers: dict, host: str = "10.0.0.9"):
|
||||||
|
self.headers = Headers(headers)
|
||||||
|
self.client = type("C", (), {"host": host})()
|
||||||
|
self.scope = {"type": "http", "client": (host, 0),
|
||||||
|
"headers": [(k.lower().encode(), v.encode())
|
||||||
|
for k, v in headers.items()]}
|
||||||
|
|
||||||
|
|
||||||
|
def test_cloudflare_header_wins():
|
||||||
|
# Cloudflare sets CF-Connecting-IP and overwrites any client-supplied
|
||||||
|
# value, so it is trustworthy in a way a parsed XFF chain is not.
|
||||||
|
assert client_key(_Req({"cf-connecting-ip": "203.0.113.7"})) == "203.0.113.7"
|
||||||
|
|
||||||
|
|
||||||
|
def test_forwarded_for_is_the_fallback_and_takes_the_first_entry():
|
||||||
|
# Left-most is the original client; everything after it is proxies.
|
||||||
|
assert client_key(
|
||||||
|
_Req({"x-forwarded-for": "203.0.113.7, 10.0.0.2"})) == "203.0.113.7"
|
||||||
|
|
||||||
|
|
||||||
|
def test_remote_address_is_the_last_resort():
|
||||||
|
assert client_key(_Req({}, host="10.0.0.9")) == "10.0.0.9"
|
||||||
|
|
||||||
|
|
||||||
|
def test_cloudflare_header_beats_forwarded_for():
|
||||||
|
key = client_key(_Req({"cf-connecting-ip": "203.0.113.7",
|
||||||
|
"x-forwarded-for": "198.51.100.1"}))
|
||||||
|
assert key == "203.0.113.7"
|
||||||
|
|
||||||
|
|
||||||
|
def test_two_callers_get_two_buckets():
|
||||||
|
# The whole point: one user exhausting their limit must not refuse another.
|
||||||
|
a = client_key(_Req({"cf-connecting-ip": "203.0.113.7"}))
|
||||||
|
b = client_key(_Req({"cf-connecting-ip": "203.0.113.8"}))
|
||||||
|
assert a != b
|
||||||
|
|
||||||
|
|
||||||
|
def test_whitespace_is_stripped():
|
||||||
|
# "a, b" split on comma leaves a leading space on every entry but the
|
||||||
|
# first; an unstripped key silently creates a second bucket per client.
|
||||||
|
assert client_key(_Req({"x-forwarded-for": " 203.0.113.7 ,10.0.0.2"})) \
|
||||||
|
== "203.0.113.7"
|
||||||
|
|
||||||
|
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
# The ceiling that header rotation cannot raise.
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
import pytest
|
||||||
|
from fastapi.testclient import TestClient
|
||||||
|
|
||||||
|
|
||||||
|
@pytest.fixture()
|
||||||
|
def api(monkeypatch):
|
||||||
|
from backend import app as app_module
|
||||||
|
from backend.config import settings
|
||||||
|
|
||||||
|
monkeypatch.setattr(settings, "global_rate_limit_per_minute", 5)
|
||||||
|
monkeypatch.setattr(app_module, "_global_window", None)
|
||||||
|
return TestClient(app_module.app, raise_server_exceptions=False)
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
def _ceiling_req(path: str, host: str):
|
||||||
|
"""Enough of a Request for exempt_from_ceiling: a path and a peer host."""
|
||||||
|
return type("R", (), {
|
||||||
|
"url": type("U", (), {"path": path})(),
|
||||||
|
"client": type("C", (), {"host": host})(),
|
||||||
|
})()
|
||||||
|
|
||||||
|
|
||||||
|
def _get(client, path="/api/flags", cf=None):
|
||||||
|
headers = {"cf-connecting-ip": cf} if cf else {}
|
||||||
|
return client.get(path, headers=headers)
|
||||||
|
|
||||||
|
|
||||||
|
def test_rotating_the_cloudflare_header_cannot_buy_unlimited_requests(api):
|
||||||
|
"""The attack the per-client keying opened up.
|
||||||
|
|
||||||
|
client_key trusts CF-Connecting-IP, and nothing in this process can tell an
|
||||||
|
edge-set header from an attacker-set one — that distinction can only be
|
||||||
|
made at Cloudflare, with Authenticated Origin Pulls or an origin firewall.
|
||||||
|
A caller reaching the origin directly can therefore mint a fresh
|
||||||
|
rate-limit bucket per request and evade per-client limits entirely.
|
||||||
|
|
||||||
|
Per-client fairness is still the right default; this is the backstop that
|
||||||
|
bounds what evading it can achieve. Without it, correct keying would be a
|
||||||
|
net regression against abuse compared with the shared bucket it replaced.
|
||||||
|
"""
|
||||||
|
codes = [_get(api, cf=f"203.0.113.{i}").status_code for i in range(8)]
|
||||||
|
assert codes.count(200) == 5
|
||||||
|
assert codes.count(429) == 3
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_ceiling_says_which_limit_was_hit(api):
|
||||||
|
# Distinguishable from slowapi's per-client 429, or an operator reading
|
||||||
|
# logs cannot tell "one noisy client" from "the origin is saturated".
|
||||||
|
for i in range(5):
|
||||||
|
_get(api, cf=f"203.0.113.{i}")
|
||||||
|
refused = _get(api, cf="203.0.113.99")
|
||||||
|
assert refused.status_code == 429
|
||||||
|
assert "capacity" in refused.json()["detail"].lower()
|
||||||
|
assert refused.headers.get("retry-after")
|
||||||
|
|
||||||
|
|
||||||
|
def test_traffic_below_the_ceiling_is_untouched(api):
|
||||||
|
codes = [_get(api, cf=f"203.0.113.{i}").status_code for i in range(5)]
|
||||||
|
assert codes == [200] * 5
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_container_healthcheck_is_exempt(api):
|
||||||
|
"""The healthcheck runs `curl http://localhost:80/api/data-info` inside the
|
||||||
|
container. If the ceiling could starve it, saturation would fail the
|
||||||
|
healthcheck, restart the container, and turn a load spike into an outage
|
||||||
|
loop — the ceiling has to protect the origin, not kill it.
|
||||||
|
"""
|
||||||
|
from backend.app import exempt_from_ceiling
|
||||||
|
|
||||||
|
assert exempt_from_ceiling(_ceiling_req("/api/data-info", "127.0.0.1"))
|
||||||
|
assert exempt_from_ceiling(_ceiling_req("/api/data-info", "::1"))
|
||||||
|
# Everyone else is counted.
|
||||||
|
assert not exempt_from_ceiling(_ceiling_req("/api/data-info", "10.0.0.9"))
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_ceiling_ignores_non_api_paths():
|
||||||
|
# Sitemaps and robots.txt are served by this app too, and a crawler
|
||||||
|
# fetching them must not be refused because the API is busy.
|
||||||
|
from backend.app import exempt_from_ceiling
|
||||||
|
|
||||||
|
assert exempt_from_ceiling(_ceiling_req("/sitemap.xml", "10.0.0.9"))
|
||||||
|
assert exempt_from_ceiling(_ceiling_req("/robots.txt", "10.0.0.9"))
|
||||||
@@ -56,6 +56,11 @@ def client(monkeypatch):
|
|||||||
monkeypatch.setattr(
|
monkeypatch.setattr(
|
||||||
app_module, "get_supplementary_data", lambda db, urn: {}
|
app_module, "get_supplementary_data", lambda db, urn: {}
|
||||||
)
|
)
|
||||||
|
# The place registry is a module-level cache, so without this the endpoint
|
||||||
|
# answers from whatever registry an earlier test happened to leave behind
|
||||||
|
# — and a `places == []` assertion is satisfied by a stale registry just
|
||||||
|
# as well as by this fixture's own data, which makes it prove nothing.
|
||||||
|
monkeypatch.setattr(app_module, "_place_registry", None)
|
||||||
return TestClient(app_module.app, raise_server_exceptions=False)
|
return TestClient(app_module.app, raise_server_exceptions=False)
|
||||||
|
|
||||||
|
|
||||||
@@ -69,3 +74,174 @@ def test_nan_gias_fields_serialize_as_null(client):
|
|||||||
assert info["capacity"] is None
|
assert info["capacity"] is None
|
||||||
assert info["total_pupils"] is None
|
assert info["total_pupils"] is None
|
||||||
assert info["school_name"] == "West London Performing Arts Academy"
|
assert info["school_name"] == "West London Performing Arts Academy"
|
||||||
|
|
||||||
|
|
||||||
|
# ── Links out to the location layer ─────────────────────────────────────────
|
||||||
|
#
|
||||||
|
# School pages carried no link into the site at all: the only anchor on the
|
||||||
|
# template pointed at the school's own website, so ~27k pages received
|
||||||
|
# whatever authority the site had and sent it off-site. `places` is what the
|
||||||
|
# link module and the breadcrumb are built from.
|
||||||
|
|
||||||
|
def test_places_is_present_even_when_the_school_belongs_to_none(client):
|
||||||
|
# This fixture's single school cannot clear any publish threshold, so the
|
||||||
|
# honest answer is an empty list. The key must still be there: a missing
|
||||||
|
# key and "no places" are different things to the page rendering it.
|
||||||
|
body = client.get("/api/schools/150275").json()
|
||||||
|
assert body["places"] == []
|
||||||
|
|
||||||
|
|
||||||
|
def test_places_names_only_pages_that_exist(monkeypatch):
|
||||||
|
from backend import app as app_module
|
||||||
|
from backend.places import MIN_SCHOOLS
|
||||||
|
|
||||||
|
def _df():
|
||||||
|
return pd.DataFrame([
|
||||||
|
{
|
||||||
|
"urn": 100000 + i,
|
||||||
|
"school_name": f"Brentwood School {i}",
|
||||||
|
"town": "Brentwood",
|
||||||
|
"local_authority": "Essex",
|
||||||
|
"postcode": "CM15 8AA",
|
||||||
|
"phase": "Primary",
|
||||||
|
"year": 202425,
|
||||||
|
"rwm_expected_pct": 60.0,
|
||||||
|
"attainment_8_score": np.nan,
|
||||||
|
"ofsted_grade": 2.0,
|
||||||
|
"ofsted_date": None,
|
||||||
|
}
|
||||||
|
for i in range(MIN_SCHOOLS)
|
||||||
|
])
|
||||||
|
|
||||||
|
monkeypatch.setattr(app_module, "load_school_data", _df)
|
||||||
|
monkeypatch.setattr(app_module, "get_supplementary_data", lambda db, urn: {})
|
||||||
|
monkeypatch.setattr(app_module, "_place_registry", None)
|
||||||
|
client = TestClient(app_module.app, raise_server_exceptions=False)
|
||||||
|
|
||||||
|
places = client.get("/api/schools/100000").json()["places"]
|
||||||
|
assert places, "a school in a published town must offer links"
|
||||||
|
|
||||||
|
by_kind = {p["kind"]: p for p in places}
|
||||||
|
assert by_kind["town"]["url"] == "/schools/brentwood"
|
||||||
|
assert by_kind["authority"]["url"] == "/schools/authority/essex"
|
||||||
|
|
||||||
|
# Every entry carries what the link text needs, and a count, so the anchor
|
||||||
|
# can say what it leads to rather than "click here".
|
||||||
|
for place in places:
|
||||||
|
assert place["name"]
|
||||||
|
assert place["count"] >= 1
|
||||||
|
assert place["url"].startswith("/schools/")
|
||||||
|
|
||||||
|
|
||||||
|
def _brentwood_df(phase: str = "Primary", n: int = None):
|
||||||
|
from backend.places import MIN_SCHOOLS
|
||||||
|
n = n if n is not None else MIN_SCHOOLS
|
||||||
|
return lambda: pd.DataFrame([
|
||||||
|
{
|
||||||
|
"urn": 100000 + i,
|
||||||
|
"school_name": f"Brentwood School {i}",
|
||||||
|
"town": "Brentwood", "local_authority": "Essex",
|
||||||
|
"postcode": "CM15 8AA", "phase": phase, "year": 202425,
|
||||||
|
"rwm_expected_pct": 60.0, "attainment_8_score": 50.0,
|
||||||
|
"ofsted_grade": 2.0, "ofsted_date": None,
|
||||||
|
}
|
||||||
|
for i in range(n)
|
||||||
|
])
|
||||||
|
|
||||||
|
|
||||||
|
def _places_for(monkeypatch, df_factory, urn: int):
|
||||||
|
from backend import app as app_module
|
||||||
|
monkeypatch.setattr(app_module, "load_school_data", df_factory)
|
||||||
|
monkeypatch.setattr(app_module, "get_supplementary_data", lambda db, urn: {})
|
||||||
|
monkeypatch.setattr(app_module, "_place_registry", None)
|
||||||
|
client = TestClient(app_module.app, raise_server_exceptions=False)
|
||||||
|
return client.get(f"/api/schools/{urn}").json()["places"]
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_place_offers_the_phase_page_this_school_appears_on(monkeypatch):
|
||||||
|
# "primary schools in brentwood" is the query the phase pages exist for,
|
||||||
|
# and ~950 of them were once reachable by nothing at all.
|
||||||
|
places = _places_for(monkeypatch, _brentwood_df("Primary"), 100000)
|
||||||
|
town = next(p for p in places if p["kind"] == "town")
|
||||||
|
|
||||||
|
assert town["phases"], "a primary school in a published primary town has a link"
|
||||||
|
assert town["phases"][0]["url"] == "/schools/brentwood/primary"
|
||||||
|
assert town["phases"][0]["count"] >= 1
|
||||||
|
|
||||||
|
|
||||||
|
def test_an_all_through_school_offers_both_phase_pages(monkeypatch):
|
||||||
|
# It genuinely appears on both, so there is no tie to break.
|
||||||
|
places = _places_for(monkeypatch, _brentwood_df("All-through"), 100000)
|
||||||
|
town = next(p for p in places if p["kind"] == "town")
|
||||||
|
|
||||||
|
assert {p["phase"] for p in town["phases"]} == {"primary", "secondary"}
|
||||||
|
|
||||||
|
|
||||||
|
def test_outcodes_never_offer_a_phase_page(monkeypatch):
|
||||||
|
# The registry gives outcodes no phase route — nobody searches "primary
|
||||||
|
# schools in SW11" — and computing them anyway once put a link to a
|
||||||
|
# nonexistent route on all 1,720 outcode pages.
|
||||||
|
places = _places_for(monkeypatch, _brentwood_df("Primary"), 100000)
|
||||||
|
outcode = next((p for p in places if p["kind"] == "outcode"), None)
|
||||||
|
|
||||||
|
if outcode is not None:
|
||||||
|
assert outcode["phases"] == []
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_school_absent_from_the_phase_page_is_not_linked_to_it(monkeypatch):
|
||||||
|
# The check is URN membership in the registry's own phase list, not a
|
||||||
|
# re-derivation of the phase mapping. A secondary school must not be sent
|
||||||
|
# to a primary phase page that does not list it.
|
||||||
|
from backend.places import MIN_SCHOOLS
|
||||||
|
|
||||||
|
def df():
|
||||||
|
rows = [
|
||||||
|
{"urn": 100000 + i, "school_name": f"P{i}", "town": "Brentwood",
|
||||||
|
"local_authority": "Essex", "postcode": "CM15 8AA",
|
||||||
|
"phase": "Primary", "year": 202425, "rwm_expected_pct": 60.0,
|
||||||
|
"attainment_8_score": np.nan, "ofsted_grade": 2.0,
|
||||||
|
"ofsted_date": None}
|
||||||
|
for i in range(MIN_SCHOOLS)
|
||||||
|
]
|
||||||
|
rows.append({
|
||||||
|
"urn": 900000, "school_name": "Lone Secondary", "town": "Brentwood",
|
||||||
|
"local_authority": "Essex", "postcode": "CM15 8AA",
|
||||||
|
"phase": "Secondary", "year": 202425, "rwm_expected_pct": np.nan,
|
||||||
|
"attainment_8_score": 50.0, "ofsted_grade": 2.0, "ofsted_date": None,
|
||||||
|
})
|
||||||
|
return pd.DataFrame(rows)
|
||||||
|
|
||||||
|
places = _places_for(monkeypatch, df, 900000)
|
||||||
|
town = next(p for p in places if p["kind"] == "town")
|
||||||
|
|
||||||
|
# The town publishes a primary page, but this secondary school is not on
|
||||||
|
# it, and there are too few secondaries for a secondary page.
|
||||||
|
assert town["phases"] == []
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_place_index_rebuilds_when_the_registry_is_replaced(monkeypatch):
|
||||||
|
"""The reverse index is cached; a stale one would put another dataset's
|
||||||
|
places on a school page. Invalidation is an identity check against the
|
||||||
|
registry rather than a second flag, so this asserts the check works."""
|
||||||
|
from backend import app as app_module
|
||||||
|
|
||||||
|
monkeypatch.setattr(app_module, "_place_registry", None)
|
||||||
|
monkeypatch.setattr(app_module, "_place_index", None)
|
||||||
|
monkeypatch.setattr(app_module, "_place_index_source", None)
|
||||||
|
monkeypatch.setattr(app_module, "load_school_data", _brentwood_df("Primary"))
|
||||||
|
|
||||||
|
first = app_module.get_place_index()
|
||||||
|
assert 100000 in first
|
||||||
|
|
||||||
|
# Same registry object, so the index is reused rather than rebuilt.
|
||||||
|
assert app_module.get_place_index() is first
|
||||||
|
|
||||||
|
# Drop the registry the way every test that touches place data does. The
|
||||||
|
# index must follow it, not survive it.
|
||||||
|
app_module._place_registry = None
|
||||||
|
monkeypatch.setattr(app_module, "load_school_data",
|
||||||
|
_brentwood_df("Primary", n=0))
|
||||||
|
|
||||||
|
rebuilt = app_module.get_place_index()
|
||||||
|
assert rebuilt is not first
|
||||||
|
assert 100000 not in rebuilt, "the index outlived the registry it came from"
|
||||||
@@ -0,0 +1,157 @@
|
|||||||
|
"""Tests for school autosuggest (spec 2026-08-26)."""
|
||||||
|
|
||||||
|
from backend import data_loader
|
||||||
|
|
||||||
|
|
||||||
|
class _FakeDocs:
|
||||||
|
def __init__(self, hits, explode=False):
|
||||||
|
self._hits = hits
|
||||||
|
self._explode = explode
|
||||||
|
self.last_params = None
|
||||||
|
|
||||||
|
def search(self, params):
|
||||||
|
self.last_params = params
|
||||||
|
if self._explode:
|
||||||
|
raise RuntimeError("typesense is down")
|
||||||
|
return {"hits": [{"document": d} for d in self._hits]}
|
||||||
|
|
||||||
|
|
||||||
|
class _FakeClient:
|
||||||
|
def __init__(self, hits, explode=False):
|
||||||
|
self.docs = _FakeDocs(hits, explode)
|
||||||
|
self.collections = {"schools": type("C", (), {"documents": self.docs})()}
|
||||||
|
|
||||||
|
|
||||||
|
_HIT = {
|
||||||
|
"urn": 100010, "school_name": "Brecknock Primary School",
|
||||||
|
"local_authority": "Camden", "postcode": "NW1 1AA",
|
||||||
|
"phase": "Primary", "school_type": "Community school",
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def _use(monkeypatch, client):
|
||||||
|
monkeypatch.setattr(data_loader, "_get_typesense_client", lambda: client)
|
||||||
|
|
||||||
|
|
||||||
|
def test_returns_the_fields_a_suggestion_needs(monkeypatch):
|
||||||
|
# Local authority is not decoration: there are many schools called
|
||||||
|
# "St Mary's", and a list without it cannot be chosen between.
|
||||||
|
_use(monkeypatch, _FakeClient([_HIT]))
|
||||||
|
out = data_loader.suggest_schools_typesense("breck")
|
||||||
|
assert out == [{
|
||||||
|
"urn": 100010, "school_name": "Brecknock Primary School",
|
||||||
|
"local_authority": "Camden", "postcode": "NW1 1AA",
|
||||||
|
"phase": "Primary", "school_type": "Community school",
|
||||||
|
}]
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_missing_optional_field_becomes_an_empty_string(monkeypatch):
|
||||||
|
# phase and school_type are optional in the Typesense schema. A missing
|
||||||
|
# key must not KeyError in the keystroke path.
|
||||||
|
_use(monkeypatch, _FakeClient([{"urn": 1, "school_name": "X",
|
||||||
|
"local_authority": "Y", "postcode": "Z"}]))
|
||||||
|
out = data_loader.suggest_schools_typesense("x")
|
||||||
|
assert out[0]["phase"] == "" and out[0]["school_type"] == ""
|
||||||
|
|
||||||
|
|
||||||
|
def test_typesense_unavailable_gives_no_suggestions_rather_than_raising(monkeypatch):
|
||||||
|
_use(monkeypatch, None)
|
||||||
|
assert data_loader.suggest_schools_typesense("anything") == []
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_typesense_error_gives_no_suggestions_rather_than_raising(monkeypatch):
|
||||||
|
_use(monkeypatch, _FakeClient([], explode=True))
|
||||||
|
assert data_loader.suggest_schools_typesense("anything") == []
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_limit_is_passed_through_and_clamped(monkeypatch):
|
||||||
|
client = _FakeClient([])
|
||||||
|
_use(monkeypatch, client)
|
||||||
|
data_loader.suggest_schools_typesense("x", limit=500)
|
||||||
|
assert client.docs.last_params["per_page"] == 20
|
||||||
|
|
||||||
|
|
||||||
|
def _client(monkeypatch, rows, *, blow_up_dataframe=False):
|
||||||
|
from fastapi.testclient import TestClient
|
||||||
|
from backend import app as app_module
|
||||||
|
|
||||||
|
monkeypatch.setattr(app_module, "suggest_schools_typesense",
|
||||||
|
lambda q, limit=8: rows)
|
||||||
|
if blow_up_dataframe:
|
||||||
|
def _boom():
|
||||||
|
raise AssertionError("the suggest path must not load the DataFrame")
|
||||||
|
monkeypatch.setattr(app_module, "load_school_data", _boom)
|
||||||
|
monkeypatch.setattr(app_module, "load_latest_school_data", _boom)
|
||||||
|
return TestClient(app_module.app, raise_server_exceptions=False)
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_endpoint_returns_suggestions(monkeypatch):
|
||||||
|
body = _client(monkeypatch, [_HIT]).get("/api/suggest?q=breck").json()
|
||||||
|
assert body["suggestions"][0]["school_name"] == "Brecknock Primary School"
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_endpoint_never_touches_the_dataframe(monkeypatch):
|
||||||
|
"""The whole reason this is not a mode of /api/schools.
|
||||||
|
|
||||||
|
That endpoint filters and sorts 25,000 rows of pandas per query, holding
|
||||||
|
the GIL. Per keystroke, that is the cost this endpoint exists to avoid.
|
||||||
|
"""
|
||||||
|
res = _client(monkeypatch, [_HIT], blow_up_dataframe=True).get("/api/suggest?q=breck")
|
||||||
|
assert res.status_code == 200
|
||||||
|
assert res.json()["suggestions"]
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_one_character_query_returns_nothing_and_does_not_error(monkeypatch):
|
||||||
|
# The keystroke path never errors on ordinary input.
|
||||||
|
res = _client(monkeypatch, [_HIT]).get("/api/suggest?q=b")
|
||||||
|
assert res.status_code == 200
|
||||||
|
assert res.json() == {"suggestions": []}
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_blank_query_returns_nothing_and_does_not_error(monkeypatch):
|
||||||
|
res = _client(monkeypatch, [_HIT]).get("/api/suggest?q=")
|
||||||
|
assert res.status_code == 200
|
||||||
|
assert res.json() == {"suggestions": []}
|
||||||
|
|
||||||
|
|
||||||
|
def test_typesense_down_is_an_empty_list_not_a_500(monkeypatch):
|
||||||
|
res = _client(monkeypatch, []).get("/api/suggest?q=breck")
|
||||||
|
assert res.status_code == 200
|
||||||
|
assert res.json() == {"suggestions": []}
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_response_is_cacheable(monkeypatch):
|
||||||
|
# Prefix queries repeat enormously across users, and school names change
|
||||||
|
# once a year. Without this the endpoint pays full price every keystroke.
|
||||||
|
res = _client(monkeypatch, [_HIT]).get("/api/suggest?q=breck")
|
||||||
|
assert "s-maxage" in res.headers.get("cache-control", "")
|
||||||
|
assert res.headers.get("etag")
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_malformed_urn_does_not_raise(monkeypatch):
|
||||||
|
"""The docstring promises "never raises"; the parsing loop sat outside the
|
||||||
|
try, so int(None) or int("abc") would have turned a keystroke into a 500.
|
||||||
|
|
||||||
|
Typesense declares urn as int32, so this should be unreachable — but the
|
||||||
|
contract is what the caller relies on, and a search index is a separate
|
||||||
|
system that can be reindexed by something other than this code.
|
||||||
|
"""
|
||||||
|
_use(monkeypatch, _FakeClient([{"urn": None, "school_name": "X",
|
||||||
|
"local_authority": "Y", "postcode": "Z"}]))
|
||||||
|
assert data_loader.suggest_schools_typesense("x") == []
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_malformed_row_does_not_discard_the_good_ones(monkeypatch):
|
||||||
|
# One bad document must not blank the whole dropdown.
|
||||||
|
_use(monkeypatch, _FakeClient([
|
||||||
|
{"urn": "not-a-number", "school_name": "Bad", "local_authority": "Y",
|
||||||
|
"postcode": "Z"},
|
||||||
|
_HIT,
|
||||||
|
]))
|
||||||
|
out = data_loader.suggest_schools_typesense("x")
|
||||||
|
assert [r["urn"] for r in out] == [100010]
|
||||||
|
|
||||||
|
|
||||||
|
def test_a_hit_with_no_document_does_not_raise(monkeypatch):
|
||||||
|
_use(monkeypatch, _FakeClient([{}]))
|
||||||
|
assert data_loader.suggest_schools_typesense("x") == []
|
||||||
@@ -132,16 +132,23 @@ def test_one_query_per_table_and_latest_row_per_urn():
|
|||||||
"FactPupilCharacteristics": [],
|
"FactPupilCharacteristics": [],
|
||||||
"FactDeprivation": [],
|
"FactDeprivation": [],
|
||||||
"FactFinance": [],
|
"FactFinance": [],
|
||||||
|
"FactKs4Destinations": [],
|
||||||
|
"FactKs5Destinations": [],
|
||||||
}
|
}
|
||||||
session = _FakeSession(rows)
|
session = _FakeSession(rows)
|
||||||
out = get_supplementary_data_batch(session, [1, 2])
|
out = get_supplementary_data_batch(session, [1, 2])
|
||||||
|
|
||||||
# Exactly one query per table — six total, regardless of two URNs.
|
# Exactly one query per table — eight total, regardless of two URNs.
|
||||||
assert sorted(session.queries) == [
|
assert sorted(session.queries) == [
|
||||||
"FactAdmissionDistance", "FactAdmissions", "FactDeprivation",
|
"FactAdmissionDistance", "FactAdmissions", "FactDeprivation",
|
||||||
"FactFinance", "FactOfstedInspection", "FactPupilCharacteristics",
|
"FactFinance", "FactKs4Destinations", "FactKs5Destinations",
|
||||||
|
"FactOfstedInspection", "FactPupilCharacteristics",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
# A school with no destination rows gets null, not an empty shell — the
|
||||||
|
# frontend renders the section from the block's presence.
|
||||||
|
assert out[1]["destinations"] is None
|
||||||
|
|
||||||
# Latest Ofsted kept per URN
|
# Latest Ofsted kept per URN
|
||||||
assert out[1]["ofsted"]["overall_effectiveness"] == 2
|
assert out[1]["ofsted"]["overall_effectiveness"] == 2
|
||||||
assert out[2]["ofsted"]["overall_effectiveness"] == 1
|
assert out[2]["ofsted"]["overall_effectiveness"] == 1
|
||||||
|
|||||||
@@ -1,26 +0,0 @@
|
|||||||
"""
|
|
||||||
Schema versioning for database migrations.
|
|
||||||
|
|
||||||
HOW TO USE:
|
|
||||||
- Bump SCHEMA_VERSION when making changes to database models
|
|
||||||
- This triggers an automatic full data reimport on next app startup
|
|
||||||
|
|
||||||
WHEN TO BUMP:
|
|
||||||
- Adding/removing columns in models.py
|
|
||||||
- Changing column types or constraints
|
|
||||||
- Modifying CSV column mappings in schemas.py
|
|
||||||
- Any change that requires fresh data import
|
|
||||||
"""
|
|
||||||
|
|
||||||
# Current schema version - increment when models change
|
|
||||||
SCHEMA_VERSION = 6
|
|
||||||
|
|
||||||
# Changelog for documentation
|
|
||||||
SCHEMA_CHANGELOG = {
|
|
||||||
1: "Initial schema with School and SchoolResult tables",
|
|
||||||
2: "Added pupil absence fields (reading, maths, gps, writing, science)",
|
|
||||||
3: "Added supplementary data tables: ofsted, parent_view, census, admissions, sen_detail, phonics, deprivation, finance; GIAS columns on schools",
|
|
||||||
4: "Added Ofsted Report Card columns to ofsted_inspections (new framework from Nov 2025)",
|
|
||||||
5: "Apply ALTER TABLE additions for RC columns missed by create_all on existing tables",
|
|
||||||
6: "Removed the Ofsted Parent View feature: dropped fact_parent_view table and model",
|
|
||||||
}
|
|
||||||
@@ -1,134 +1,37 @@
|
|||||||
# SchoolCompare.co.uk - Project Context
|
# SchoolCompare project context
|
||||||
|
|
||||||
## Overview
|
## Maintained documentation
|
||||||
|
|
||||||
SchoolCompare is a web application for comparing UK primary school (KS2) performance data. It allows users to:
|
Read [README.md](README.md), [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md) and
|
||||||
- Search and browse schools by name, location (postcode), or local authority
|
[docs/DEVELOPMENT.md](docs/DEVELOPMENT.md) for the current implementation.
|
||||||
- Compare multiple schools side-by-side with charts and tables
|
[docs/LEGACY_CODE.md](docs/LEGACY_CODE.md) records obsolete paths and deliberate
|
||||||
- View school rankings by various KS2 metrics
|
compatibility code. Historical design documents are not current setup instructions.
|
||||||
- See historical performance trends across years
|
|
||||||
|
|
||||||
## Architecture
|
## Architecture constraints
|
||||||
|
|
||||||
### Backend (Python/FastAPI)
|
- Next.js serves the public UI. FastAPI serves school data from dbt-built `marts.*`.
|
||||||
- **Framework**: FastAPI with uvicorn
|
The backend does not create school tables or import CSVs at startup.
|
||||||
- **Database**: PostgreSQL with SQLAlchemy ORM
|
- School coverage spans England and multiple phases, not only primary schools in
|
||||||
- **Data Source**: UK Government "Compare School Performance" CSV downloads
|
Wandsworth and Merton.
|
||||||
|
- `/api/*` belongs to the FastAPI proxy. Payload uses `/cms-api` and `/admin`.
|
||||||
Key files:
|
- Payload runs inside Next.js, with its own `payload` schema and persistent media.
|
||||||
- `backend/app.py` - Main FastAPI application, API routes
|
Keep CMS migrations independent of school-data transformations.
|
||||||
- `backend/config.py` - Configuration via pydantic-settings (env vars, .env file)
|
- Public and Payload route groups have separate root layouts. Do not introduce
|
||||||
- `backend/database.py` - SQLAlchemy engine, session management
|
`app/layout.tsx`. Keep site-wide metadata files at the `app/` root.
|
||||||
- `backend/models.py` - Database models (School, SchoolResult)
|
- Builds must succeed with `DATABASE_URL` unset. Do not call `getCachedPayload()`
|
||||||
- `backend/data_loader.py` - Data queries, geocoding, legacy DataFrame compatibility
|
at module scope or add DB-backed `generateStaticParams`.
|
||||||
- `backend/schemas.py` - Column mappings, metric definitions, LA code mappings
|
- After changing CMS fields/editors, run `npm run generate:importmap` and commit
|
||||||
|
the generated import map. See `nextjs-app/docs/PUBLISHING.md`.
|
||||||
### Frontend (Vanilla JS)
|
- The backend and pipeline GIAS dictionary copies are generated together; preserve
|
||||||
- Single-page application with hash-based routing
|
their parity. Tests enforce it.
|
||||||
- Chart.js for data visualization
|
|
||||||
- No build step required
|
|
||||||
|
|
||||||
Key files:
|
|
||||||
- `frontend/index.html` - Main HTML structure
|
|
||||||
- `frontend/app.js` - All application logic, API calls, rendering
|
|
||||||
- `frontend/styles.css` - Styling (CSS variables, responsive design)
|
|
||||||
|
|
||||||
### Database Schema
|
|
||||||
|
|
||||||
```
|
|
||||||
schools school_results
|
|
||||||
├── id (PK) ├── id (PK)
|
|
||||||
├── urn (unique, indexed) ├── school_id (FK → schools.id)
|
|
||||||
├── school_name ├── year (indexed)
|
|
||||||
├── local_authority ├── rwm_expected_pct
|
|
||||||
├── school_type ├── reading_expected_pct
|
|
||||||
├── postcode ├── ... (all KS2 metrics)
|
|
||||||
├── latitude, longitude └── unique(school_id, year)
|
|
||||||
└── results → SchoolResult[]
|
|
||||||
```
|
|
||||||
|
|
||||||
## Configuration
|
|
||||||
|
|
||||||
Environment variables (or `.env` file):
|
|
||||||
- `DATABASE_URL` - PostgreSQL connection string (default: `postgresql://schoolcompare:schoolcompare@localhost:5432/schoolcompare`)
|
|
||||||
- `HOST`, `PORT` - Server binding (default: `0.0.0.0:80`)
|
|
||||||
- `ALLOWED_ORIGINS` - CORS origins
|
|
||||||
|
|
||||||
## Running Locally
|
|
||||||
|
|
||||||
1. Start PostgreSQL:
|
|
||||||
```bash
|
|
||||||
docker compose up -d db
|
|
||||||
```
|
|
||||||
|
|
||||||
2. Run migration to import CSV data:
|
|
||||||
```bash
|
|
||||||
python scripts/migrate_csv_to_db.py --drop
|
|
||||||
# Add --geocode to geocode postcodes (slower, adds lat/long)
|
|
||||||
```
|
|
||||||
|
|
||||||
3. Start the app:
|
|
||||||
```bash
|
|
||||||
uvicorn backend.app:app --host 0.0.0.0 --port 8000
|
|
||||||
```
|
|
||||||
|
|
||||||
## Docker Deployment
|
|
||||||
|
|
||||||
```bash
|
|
||||||
docker compose up -d
|
|
||||||
```
|
|
||||||
|
|
||||||
This starts:
|
|
||||||
- `db` - PostgreSQL 16 with persistent volume
|
|
||||||
- `app` - FastAPI application on port 80
|
|
||||||
|
|
||||||
## Data
|
|
||||||
|
|
||||||
- Source: UK Government Compare School Performance downloads
|
|
||||||
- Location: `data/` directory with year folders (e.g., `2023-2024/england_ks2final.csv`)
|
|
||||||
- The `scripts/download_data.py` can fetch data from the government website
|
|
||||||
|
|
||||||
## Key Features
|
|
||||||
|
|
||||||
- **Location Search**: Enter postcode to find nearby schools (uses postcodes.io API)
|
|
||||||
- **Multi-school Comparison**: Select multiple schools, view metrics across years
|
|
||||||
- **Rankings**: Top schools by any KS2 metric, filterable by local authority
|
|
||||||
- **Variability Analysis**: Shows standard deviation of scores across years
|
|
||||||
|
|
||||||
## API Endpoints
|
|
||||||
|
|
||||||
- `GET /api/schools` - List/search schools (supports pagination, location search)
|
|
||||||
- `GET /api/schools/{urn}` - School details with all yearly data
|
|
||||||
- `GET /api/compare?urns=123,456` - Compare multiple schools
|
|
||||||
- `GET /api/rankings` - School rankings by metric
|
|
||||||
- `GET /api/filters` - Available filter options (LAs, types, years)
|
|
||||||
- `GET /api/metrics` - Metric definitions (single source of truth)
|
|
||||||
- `GET /api/data-info` - Database stats
|
|
||||||
|
|
||||||
## SDLC
|
## SDLC
|
||||||
|
|
||||||
Full details in `docs/DEPLOY.md`. The short version:
|
Follow [docs/DEPLOY.md](docs/DEPLOY.md).
|
||||||
|
|
||||||
- **Never push to `main` directly.** Work on a feature branch and open a PR;
|
- Never push directly to `main`. Use a feature branch and a PR with passing checks.
|
||||||
branch protection requires the PR checks (typecheck, tests, builds, AI review)
|
- Merges deploy staging only. Production promotion is a separate human decision;
|
||||||
to pass before merge.
|
do not trigger the promotion workflow yourself.
|
||||||
- Merging to `main` deploys automatically **to staging only**: images are
|
- Update E2E journeys in the same PR when changing user-facing behaviour.
|
||||||
built once, deployed to the staging Portainer stack, and verified by the
|
- Do not attempt to start a local server to test the application; use unit checks
|
||||||
Playwright journeys in `e2e/`. Production is a second, manual approval:
|
and the configured integration environment.
|
||||||
the "Promote to Production (manual)" workflow in Gitea Actions, run after
|
|
||||||
testing the feature on staging. It refuses commits whose staging E2E gate
|
|
||||||
isn't green. Never trigger it yourself — promotion is the human's call.
|
|
||||||
- If you change user-facing behaviour, update or extend the `e2e/` journey
|
|
||||||
tests in the same PR — they gate whether staging is fit for human testing
|
|
||||||
and whether a commit is promotable.
|
|
||||||
|
|
||||||
## Recent Changes
|
|
||||||
|
|
||||||
- Added staging environment + automated staging→prod pipeline (Gitea Actions)
|
|
||||||
- Migrated from CSV file storage to PostgreSQL database
|
|
||||||
- Added location-based search using postcode geocoding
|
|
||||||
- Added local authority filter to rankings
|
|
||||||
- Improved frontend with featured schools, loading states, API caching
|
|
||||||
|
|
||||||
# Important
|
|
||||||
- Do not attempt to start a local server to test the application, it does not work
|
|
||||||
@@ -18,7 +18,14 @@
|
|||||||
# TYPESENSE_SEARCH_KEY — Typesense search-only key (exposed to frontend)
|
# TYPESENSE_SEARCH_KEY — Typesense search-only key (exposed to frontend)
|
||||||
# UNLEASH_URL — http://<unleash-ip>:4242/api (empty = all flags off)
|
# UNLEASH_URL — http://<unleash-ip>:4242/api (empty = all flags off)
|
||||||
# UNLEASH_API_TOKEN — Unleash *client* token, environment: development
|
# UNLEASH_API_TOKEN — Unleash *client* token, environment: development
|
||||||
# AIRFLOW_ADMIN_USER — Airflow admin username (password auto-generated, see api-server logs)
|
# PAYLOAD_SECRET — Payload CMS encryption secret. REQUIRED: long and
|
||||||
|
# random, and DIFFERENT from production's. Sharing
|
||||||
|
# it would let a staging session authenticate
|
||||||
|
# against production.
|
||||||
|
# AIRFLOW_ADMIN_USER — Airflow admin username (default: admin)
|
||||||
|
# AIRFLOW_ADMIN_PASSWORD — Airflow admin password. REQUIRED: the api-server
|
||||||
|
# refuses to start without it, rather than falling
|
||||||
|
# back to a generated one that changes on restart.
|
||||||
# STAGING_DB_IP — macvlan IP for staging Postgres (default 10.0.1.190)
|
# STAGING_DB_IP — macvlan IP for staging Postgres (default 10.0.1.190)
|
||||||
# STAGING_FRONTEND_IP — macvlan IP for staging frontend (default 10.0.1.151)
|
# STAGING_FRONTEND_IP — macvlan IP for staging frontend (default 10.0.1.151)
|
||||||
|
|
||||||
@@ -86,9 +93,20 @@ services:
|
|||||||
- FASTAPI_URL=http://backend:80/api
|
- FASTAPI_URL=http://backend:80/api
|
||||||
- TYPESENSE_URL=http://typesense:8108
|
- TYPESENSE_URL=http://typesense:8108
|
||||||
- TYPESENSE_API_KEY=${TYPESENSE_SEARCH_KEY:-changeme}
|
- TYPESENSE_API_KEY=${TYPESENSE_SEARCH_KEY:-changeme}
|
||||||
|
# Payload CMS runs inside this container, in the `payload` schema of the
|
||||||
|
# staging database. Staging has its own stack, its own Postgres and its
|
||||||
|
# own admin account — never production's.
|
||||||
|
- DATABASE_URL=postgresql://${DB_USERNAME}:${DB_PASSWORD}@sc_database:5432/${DB_DATABASE_NAME}
|
||||||
|
- PAYLOAD_SECRET=${PAYLOAD_SECRET:?set PAYLOAD_SECRET in the staging Portainer stack environment}
|
||||||
|
volumes:
|
||||||
|
# Portainer prefixes volume names with the stack name, so this is
|
||||||
|
# automatically isolated from production's media.
|
||||||
|
- payload_media:/app/media
|
||||||
depends_on:
|
depends_on:
|
||||||
backend:
|
backend:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
|
sc_database:
|
||||||
|
condition: service_healthy
|
||||||
networks:
|
networks:
|
||||||
backend: {}
|
backend: {}
|
||||||
macvlan:
|
macvlan:
|
||||||
@@ -124,7 +142,23 @@ services:
|
|||||||
airflow-api-server:
|
airflow-api-server:
|
||||||
image: privaterepo.sitaru.org/tudor/school_compare-pipeline:staging
|
image: privaterepo.sitaru.org/tudor/school_compare-pipeline:staging
|
||||||
container_name: sc_staging_airflow_api
|
container_name: sc_staging_airflow_api
|
||||||
command: airflow api-server --port 8080
|
# The simple auth manager generates a random password on first start and
|
||||||
|
# writes it to a file, so every container restart invalidates the last one.
|
||||||
|
# Writing the file ourselves from an environment variable makes the login
|
||||||
|
# deterministic. Airflow does not generate anything when the file exists.
|
||||||
|
#
|
||||||
|
# Built with python rather than echo/printf so a password containing quotes,
|
||||||
|
# backslashes or spaces is escaped correctly by json.dumps. An unset
|
||||||
|
# AIRFLOW_ADMIN_PASSWORD raises KeyError and the container exits: falling
|
||||||
|
# back to a generated password would silently undo the point of this.
|
||||||
|
command:
|
||||||
|
- bash
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
set -euo pipefail
|
||||||
|
mkdir -p /opt/airflow
|
||||||
|
python -c "import json, os, pathlib; pathlib.Path('/opt/airflow/simple_auth_manager_passwords.json').write_text(json.dumps({os.environ.get('AIRFLOW_ADMIN_USER', 'admin'): os.environ['AIRFLOW_ADMIN_PASSWORD']}))"
|
||||||
|
exec airflow api-server --port 8080
|
||||||
ports:
|
ports:
|
||||||
- "8081:8080"
|
- "8081:8080"
|
||||||
environment:
|
environment:
|
||||||
@@ -136,6 +170,8 @@ services:
|
|||||||
AIRFLOW__API_AUTH__JWT_SECRET: "school-compare-staging-airflow-jwt-secret-key-long-enough-for-sha512"
|
AIRFLOW__API_AUTH__JWT_SECRET: "school-compare-staging-airflow-jwt-secret-key-long-enough-for-sha512"
|
||||||
AIRFLOW__API_AUTH__JWT_ISSUER: airflow
|
AIRFLOW__API_AUTH__JWT_ISSUER: airflow
|
||||||
AIRFLOW__CORE__SIMPLE_AUTH_MANAGER_USERS: "${AIRFLOW_ADMIN_USER:-admin}:admin"
|
AIRFLOW__CORE__SIMPLE_AUTH_MANAGER_USERS: "${AIRFLOW_ADMIN_USER:-admin}:admin"
|
||||||
|
AIRFLOW__CORE__SIMPLE_AUTH_MANAGER_PASSWORDS_FILE: /opt/airflow/simple_auth_manager_passwords.json
|
||||||
|
AIRFLOW_ADMIN_PASSWORD: ${AIRFLOW_ADMIN_PASSWORD:?set AIRFLOW_ADMIN_PASSWORD in the Portainer stack environment}
|
||||||
AIRFLOW__LOGGING__BASE_LOG_FOLDER: /opt/airflow/logs
|
AIRFLOW__LOGGING__BASE_LOG_FOLDER: /opt/airflow/logs
|
||||||
PG_HOST: sc_database
|
PG_HOST: sc_database
|
||||||
PG_PORT: "5432"
|
PG_PORT: "5432"
|
||||||
@@ -221,3 +257,4 @@ volumes:
|
|||||||
typesense_data:
|
typesense_data:
|
||||||
airflow_logs:
|
airflow_logs:
|
||||||
unleash_cache:
|
unleash_cache:
|
||||||
|
payload_media:
|
||||||
@@ -9,7 +9,13 @@
|
|||||||
# TYPESENSE_SEARCH_KEY — Typesense search-only key (exposed to frontend)
|
# TYPESENSE_SEARCH_KEY — Typesense search-only key (exposed to frontend)
|
||||||
# UNLEASH_URL — http://<unleash-ip>:4242/api (empty = all flags off)
|
# UNLEASH_URL — http://<unleash-ip>:4242/api (empty = all flags off)
|
||||||
# UNLEASH_API_TOKEN — Unleash *client* token, environment: production
|
# UNLEASH_API_TOKEN — Unleash *client* token, environment: production
|
||||||
# AIRFLOW_ADMIN_USER — Airflow admin username (password auto-generated, see api-server logs)
|
# PAYLOAD_SECRET — Payload CMS encryption secret. REQUIRED: long and
|
||||||
|
# random. Changing it invalidates every admin
|
||||||
|
# session. Staging MUST use a different value.
|
||||||
|
# AIRFLOW_ADMIN_USER — Airflow admin username (default: admin)
|
||||||
|
# AIRFLOW_ADMIN_PASSWORD — Airflow admin password. REQUIRED: the api-server
|
||||||
|
# refuses to start without it, rather than falling
|
||||||
|
# back to a generated one that changes on restart.
|
||||||
|
|
||||||
services:
|
services:
|
||||||
|
|
||||||
@@ -75,9 +81,21 @@ services:
|
|||||||
- FASTAPI_URL=http://backend:80/api
|
- FASTAPI_URL=http://backend:80/api
|
||||||
- TYPESENSE_URL=http://typesense:8108
|
- TYPESENSE_URL=http://typesense:8108
|
||||||
- TYPESENSE_API_KEY=${TYPESENSE_SEARCH_KEY:-changeme}
|
- TYPESENSE_API_KEY=${TYPESENSE_SEARCH_KEY:-changeme}
|
||||||
|
# Payload CMS runs inside this container. It reaches Postgres over the
|
||||||
|
# `backend` network and keeps its tables in the `payload` schema, so no
|
||||||
|
# pipeline operation on `public` can touch blog content.
|
||||||
|
- DATABASE_URL=postgresql://${DB_USERNAME}:${DB_PASSWORD}@sc_database:5432/${DB_DATABASE_NAME}
|
||||||
|
# Same :? form as AIRFLOW_ADMIN_PASSWORD: refuse to start rather than
|
||||||
|
# boot with an empty secret and silently accept forged sessions.
|
||||||
|
- PAYLOAD_SECRET=${PAYLOAD_SECRET:?set PAYLOAD_SECRET in the Portainer stack environment}
|
||||||
|
volumes:
|
||||||
|
# Blog images. Not reproducible from the pipeline — must be backed up.
|
||||||
|
- payload_media:/app/media
|
||||||
depends_on:
|
depends_on:
|
||||||
backend:
|
backend:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
|
sc_database:
|
||||||
|
condition: service_healthy
|
||||||
networks:
|
networks:
|
||||||
backend: {}
|
backend: {}
|
||||||
macvlan:
|
macvlan:
|
||||||
@@ -113,7 +131,23 @@ services:
|
|||||||
airflow-api-server:
|
airflow-api-server:
|
||||||
image: privaterepo.sitaru.org/tudor/school_compare-pipeline:prod
|
image: privaterepo.sitaru.org/tudor/school_compare-pipeline:prod
|
||||||
container_name: schoolcompare_airflow_api
|
container_name: schoolcompare_airflow_api
|
||||||
command: airflow api-server --port 8080
|
# The simple auth manager generates a random password on first start and
|
||||||
|
# writes it to a file, so every container restart invalidates the last one.
|
||||||
|
# Writing the file ourselves from an environment variable makes the login
|
||||||
|
# deterministic. Airflow does not generate anything when the file exists.
|
||||||
|
#
|
||||||
|
# Built with python rather than echo/printf so a password containing quotes,
|
||||||
|
# backslashes or spaces is escaped correctly by json.dumps. An unset
|
||||||
|
# AIRFLOW_ADMIN_PASSWORD raises KeyError and the container exits: falling
|
||||||
|
# back to a generated password would silently undo the point of this.
|
||||||
|
command:
|
||||||
|
- bash
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
set -euo pipefail
|
||||||
|
mkdir -p /opt/airflow
|
||||||
|
python -c "import json, os, pathlib; pathlib.Path('/opt/airflow/simple_auth_manager_passwords.json').write_text(json.dumps({os.environ.get('AIRFLOW_ADMIN_USER', 'admin'): os.environ['AIRFLOW_ADMIN_PASSWORD']}))"
|
||||||
|
exec airflow api-server --port 8080
|
||||||
ports:
|
ports:
|
||||||
- "8080:8080"
|
- "8080:8080"
|
||||||
environment:
|
environment:
|
||||||
@@ -125,6 +159,8 @@ services:
|
|||||||
AIRFLOW__API_AUTH__JWT_SECRET: "school-compare-airflow-jwt-secret-key-long-enough-for-sha512"
|
AIRFLOW__API_AUTH__JWT_SECRET: "school-compare-airflow-jwt-secret-key-long-enough-for-sha512"
|
||||||
AIRFLOW__API_AUTH__JWT_ISSUER: airflow
|
AIRFLOW__API_AUTH__JWT_ISSUER: airflow
|
||||||
AIRFLOW__CORE__SIMPLE_AUTH_MANAGER_USERS: "${AIRFLOW_ADMIN_USER:-admin}:admin"
|
AIRFLOW__CORE__SIMPLE_AUTH_MANAGER_USERS: "${AIRFLOW_ADMIN_USER:-admin}:admin"
|
||||||
|
AIRFLOW__CORE__SIMPLE_AUTH_MANAGER_PASSWORDS_FILE: /opt/airflow/simple_auth_manager_passwords.json
|
||||||
|
AIRFLOW_ADMIN_PASSWORD: ${AIRFLOW_ADMIN_PASSWORD:?set AIRFLOW_ADMIN_PASSWORD in the Portainer stack environment}
|
||||||
AIRFLOW__LOGGING__BASE_LOG_FOLDER: /opt/airflow/logs
|
AIRFLOW__LOGGING__BASE_LOG_FOLDER: /opt/airflow/logs
|
||||||
PG_HOST: sc_database
|
PG_HOST: sc_database
|
||||||
PG_PORT: "5432"
|
PG_PORT: "5432"
|
||||||
@@ -210,3 +246,4 @@ volumes:
|
|||||||
typesense_data:
|
typesense_data:
|
||||||
airflow_logs:
|
airflow_logs:
|
||||||
unleash_cache:
|
unleash_cache:
|
||||||
|
payload_media:
|
||||||
+19
-1
@@ -105,7 +105,23 @@ services:
|
|||||||
airflow-api-server:
|
airflow-api-server:
|
||||||
image: privaterepo.sitaru.org/tudor/school_compare-pipeline:latest
|
image: privaterepo.sitaru.org/tudor/school_compare-pipeline:latest
|
||||||
container_name: schoolcompare_airflow_api
|
container_name: schoolcompare_airflow_api
|
||||||
command: airflow api-server --port 8080
|
# The simple auth manager generates a random password on first start and
|
||||||
|
# writes it to a file, so every container restart invalidates the last one.
|
||||||
|
# Writing the file ourselves from an environment variable makes the login
|
||||||
|
# deterministic. Airflow does not generate anything when the file exists.
|
||||||
|
#
|
||||||
|
# Built with python rather than echo/printf so a password containing quotes,
|
||||||
|
# backslashes or spaces is escaped correctly by json.dumps. An unset
|
||||||
|
# AIRFLOW_ADMIN_PASSWORD raises KeyError and the container exits: falling
|
||||||
|
# back to a generated password would silently undo the point of this.
|
||||||
|
command:
|
||||||
|
- bash
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
set -euo pipefail
|
||||||
|
mkdir -p /opt/airflow
|
||||||
|
python -c "import json, os, pathlib; pathlib.Path('/opt/airflow/simple_auth_manager_passwords.json').write_text(json.dumps({os.environ.get('AIRFLOW_ADMIN_USER', 'admin'): os.environ['AIRFLOW_ADMIN_PASSWORD']}))"
|
||||||
|
exec airflow api-server --port 8080
|
||||||
ports:
|
ports:
|
||||||
- "8080:8080"
|
- "8080:8080"
|
||||||
environment: &airflow-env
|
environment: &airflow-env
|
||||||
@@ -117,6 +133,8 @@ services:
|
|||||||
AIRFLOW__API_AUTH__JWT_SECRET: "school-compare-airflow-jwt-secret-key-long-enough-for-sha512"
|
AIRFLOW__API_AUTH__JWT_SECRET: "school-compare-airflow-jwt-secret-key-long-enough-for-sha512"
|
||||||
AIRFLOW__API_AUTH__JWT_ISSUER: airflow
|
AIRFLOW__API_AUTH__JWT_ISSUER: airflow
|
||||||
AIRFLOW__CORE__SIMPLE_AUTH_MANAGER_USERS: "admin:admin"
|
AIRFLOW__CORE__SIMPLE_AUTH_MANAGER_USERS: "admin:admin"
|
||||||
|
AIRFLOW__CORE__SIMPLE_AUTH_MANAGER_PASSWORDS_FILE: /opt/airflow/simple_auth_manager_passwords.json
|
||||||
|
AIRFLOW_ADMIN_PASSWORD: ${AIRFLOW_ADMIN_PASSWORD:-admin}
|
||||||
PG_HOST: db
|
PG_HOST: db
|
||||||
PG_PORT: "5432"
|
PG_PORT: "5432"
|
||||||
PG_USER: schoolcompare
|
PG_USER: schoolcompare
|
||||||
|
|||||||
@@ -0,0 +1,107 @@
|
|||||||
|
# Architecture
|
||||||
|
|
||||||
|
This describes the implementation as reviewed on 2026-09-14. It distinguishes
|
||||||
|
current behaviour from improvements still to be implemented.
|
||||||
|
|
||||||
|
## Request flow
|
||||||
|
|
||||||
|
```text
|
||||||
|
Browser → Next.js public routes
|
||||||
|
├─ /api/* proxy → FastAPI → cached DataFrames / PostgreSQL marts
|
||||||
|
│ ├─ Typesense (search and suggestions)
|
||||||
|
│ └─ postcodes.io (postcode lookup)
|
||||||
|
└─ /admin, /cms-api, /blog → Payload → payload schema + media volume
|
||||||
|
|
||||||
|
Next.js server rendering → FastAPI directly through FASTAPI_URL
|
||||||
|
```
|
||||||
|
|
||||||
|
`nextjs-app/lib/api.ts` contains typed fetch wrappers and revalidation defaults.
|
||||||
|
The proxy is `nextjs-app/app/(frontend)/api/[...path]/route.ts`. Payload uses
|
||||||
|
`/cms-api` so its routes do not collide with the FastAPI proxy. The proxy denies
|
||||||
|
`/api/flags`; server-side rendering reads flags directly from FastAPI.
|
||||||
|
|
||||||
|
## Data ownership
|
||||||
|
|
||||||
|
| Layer | Owner and role |
|
||||||
|
|---|---|
|
||||||
|
| Source data | GIAS, DfE EES, Ofsted, finance, deprivation and council admission-distance sources |
|
||||||
|
| `raw` | Singer taps and the PostgreSQL target configured in `pipeline/meltano.yml` |
|
||||||
|
| Staging/intermediate/marts | dbt models in `pipeline/transform`; marts are materialized tables |
|
||||||
|
| `marts.dim_school`, `marts.dim_location` | School identity and location, filtered to supported England establishments |
|
||||||
|
| `marts.fact_*` | Performance and supplementary datasets; coverage and years vary |
|
||||||
|
| Typesense `schools` alias | Search documents built by `pipeline/scripts/sync_typesense.py` |
|
||||||
|
| `payload` | CMS collections and migrations in `nextjs-app/`; independent of dbt |
|
||||||
|
| Media volume | Uploaded blog media; requires backup and cannot be regenerated from school datasets |
|
||||||
|
|
||||||
|
`backend/models.py` maps existing marts for reading. It does not create the school
|
||||||
|
schema. There is no startup schema-version migration or CSV reimport. Payload's
|
||||||
|
`nextjs-app/migrations/` is active and must not be confused with the removed
|
||||||
|
legacy backend migration code.
|
||||||
|
|
||||||
|
Coordinates normally come from GIAS British National Grid coordinates transformed
|
||||||
|
by PostGIS in `dim_location.sql`. `pipeline/scripts/geocode_postcodes.py` is a
|
||||||
|
manual fallback utility, not a task wired into the current school-data DAG.
|
||||||
|
Backend postcode searches also use postcodes.io; that lookup does not populate
|
||||||
|
school coordinates in the database.
|
||||||
|
|
||||||
|
## Backend boundaries
|
||||||
|
|
||||||
|
- `app.py`: routes, middleware, search filtering, sitemap/place publication and response assembly.
|
||||||
|
- `data_loader.py`: SQL loading, process-local DataFrame caches, Typesense calls,
|
||||||
|
postcode lookups, supplementary queries and benchmark calculation.
|
||||||
|
- `database.py`: synchronous SQLAlchemy engine and sessions.
|
||||||
|
- `schemas.py`: metric definitions, column mappings and display metadata; despite
|
||||||
|
its name this is not a collection of Pydantic API response models.
|
||||||
|
- `places.py` and `localities.py`: place registry and curated locality information.
|
||||||
|
- `flags.py`: Unleash-backed feature flags, disabled when no server is configured.
|
||||||
|
- `gias_codes.py` / `ofsted_codes.py`: source-code translation and display rules.
|
||||||
|
|
||||||
|
Search starts from a cached latest-row-per-school snapshot. Detail pages read
|
||||||
|
history from the full DataFrame and supplementary data from marts. Comparisons
|
||||||
|
batch supplementary queries across selected URNs. Async routes still contain
|
||||||
|
synchronous dependency calls; a fully asynchronous database layer is not present.
|
||||||
|
|
||||||
|
## Frontend boundaries
|
||||||
|
|
||||||
|
`app/(frontend)` owns the public root layout and pages. `app/(payload)` owns the
|
||||||
|
CMS root layout. Do not add a shared `app/layout.tsx`: these groups deliberately
|
||||||
|
have separate root layouts. Root metadata files remain in `app/`.
|
||||||
|
|
||||||
|
Server pages fetch initial data and pass it to client views. Client state uses
|
||||||
|
React hooks, URL search parameters and the comparison context/localStorage.
|
||||||
|
There is no SWR dependency. Leaflet maps are loaded through dynamic wrappers;
|
||||||
|
Chart.js renders performance and comparison charts.
|
||||||
|
|
||||||
|
`components/school/` contains detail sections, with section decisions and data
|
||||||
|
preparation in `lib/schoolSections.ts`. `lib/types.ts` contains manually maintained
|
||||||
|
API types. `payload-types.ts` and the Payload import map are generated artifacts.
|
||||||
|
|
||||||
|
## Publication and caching today
|
||||||
|
|
||||||
|
1. Airflow DAGs extract and validate source data, then run selected dbt builds.
|
||||||
|
2. Relevant DAGs rebuild Typesense and swap the `schools` alias.
|
||||||
|
3. They call `POST /api/admin/reload` with `X-API-Key` to refresh school DataFrames.
|
||||||
|
4. A separate weekly sitemap DAG calls `POST /api/admin/regenerate-sitemap`,
|
||||||
|
rebuilding places and sitemaps.
|
||||||
|
|
||||||
|
GIAS is scheduled daily, Ofsted monthly, and annual datasets are manually
|
||||||
|
triggered. The DAG definitions are authoritative for selectors and dependencies.
|
||||||
|
|
||||||
|
Caches exist in several independent layers: backend DataFrames and registries,
|
||||||
|
backend HTTP Cache-Control/ETags, Next.js fetch/page revalidation, and browser or
|
||||||
|
shared HTTP caches where configured. Place fetches request a one-week revalidation
|
||||||
|
interval. HTTP ETags are computed after route execution, not before database work.
|
||||||
|
|
||||||
|
Known limitations: reload clears the old DataFrames before verifying replacement
|
||||||
|
data; places/sitemaps refresh separately; Next.js caches are not explicitly purged
|
||||||
|
by the pipeline; Typesense import results are not validated before alias publication.
|
||||||
|
Do not describe this sequence as an atomic dataset release. These are follow-up
|
||||||
|
reliability tasks, not changes implemented by the documentation cleanup.
|
||||||
|
|
||||||
|
## Deployment references
|
||||||
|
|
||||||
|
See [DEPLOY.md](DEPLOY.md). PR checks include frontend typechecking/tests, backend
|
||||||
|
unit tests, image builds and AI review. Staging journeys run after merging.
|
||||||
|
Production promotion retags a selected commit's images. Current health polling
|
||||||
|
checks HTTP success, not the deployed commit identity; overlapping staging runs
|
||||||
|
remain a release-verification concern.
|
||||||
+58
-3
@@ -98,6 +98,12 @@ fail the E2E gate. That's the point: staging absorbs the risk.
|
|||||||
pr-checks status checks (frontend, backend, builds, ai-review) to pass.
|
pr-checks status checks (frontend, backend, builds, ai-review) to pass.
|
||||||
5. **Bootstrap staging data via Airflow** (no prod dump — staging populates
|
5. **Bootstrap staging data via Airflow** (no prod dump — staging populates
|
||||||
itself from source, exercising the pipeline image end-to-end):
|
itself from source, exercising the pipeline image end-to-end):
|
||||||
|
- Set `AIRFLOW_ADMIN_PASSWORD` in the stack environment first. The
|
||||||
|
api-server refuses to start without it. Airflow's simple auth manager
|
||||||
|
otherwise generates a password on first start and writes it to a file, so
|
||||||
|
the login changes every time the container restarts; the stack writes that
|
||||||
|
file itself from this variable instead. `AIRFLOW_ADMIN_USER` defaults to
|
||||||
|
`admin`.
|
||||||
- Open the staging Airflow UI (`http://<host>:8081`) and trigger, in order:
|
- Open the staging Airflow UI (`http://<host>:8081`) and trigger, in order:
|
||||||
`school_data_daily`, `school_data_monthly_ofsted`, then the manual-schedule
|
`school_data_daily`, `school_data_monthly_ofsted`, then the manual-schedule
|
||||||
`school_data_annual_ees` and `school_data_annual_idaci`.
|
`school_data_annual_ees` and `school_data_annual_idaci`.
|
||||||
@@ -151,6 +157,36 @@ needed), and fails the check only when a finding is rated
|
|||||||
**severe** (would break prod, leak data, or corrupt data). Minor findings are
|
**severe** (would break prod, leak data, or corrupt data). Minor findings are
|
||||||
informational and never block a merge.
|
informational and never block a merge.
|
||||||
|
|
||||||
|
## Rate limiting, and the Cloudflare gap
|
||||||
|
|
||||||
|
Two independent limits protect the API:
|
||||||
|
|
||||||
|
- **Per client**, via slowapi, keyed on `CF-Connecting-IP` (falling back to
|
||||||
|
`X-Forwarded-For`, then the peer address). 60/minute by default;
|
||||||
|
`/api/suggest` gets 120/minute because typing is bursty.
|
||||||
|
- **Globally**, via `GlobalRateLimitMiddleware`: a fixed 60-second window over
|
||||||
|
all `/api/` traffic, `GLOBAL_RATE_LIMIT_PER_MINUTE` (default 3000),
|
||||||
|
independent of any client identity. Requests from `127.0.0.1` are exempt so
|
||||||
|
the container healthcheck cannot be starved into a restart loop.
|
||||||
|
|
||||||
|
### Open: the origin must only accept Cloudflare
|
||||||
|
|
||||||
|
`CF-Connecting-IP` is only meaningful for requests that actually reached the
|
||||||
|
origin through Cloudflare, and **the application cannot verify that they did**.
|
||||||
|
Anything able to reach the origin directly can set that header freely and, by
|
||||||
|
rotating it, mint a fresh rate-limit bucket per request — defeating per-client
|
||||||
|
limits on every endpoint.
|
||||||
|
|
||||||
|
The global ceiling bounds the damage to total origin capacity. It does not fix
|
||||||
|
the underlying gap, and nothing in the code can. Closing it needs one of:
|
||||||
|
|
||||||
|
- **Authenticated Origin Pulls** — Cloudflare presents a client certificate the
|
||||||
|
origin requires, so non-Cloudflare traffic is refused at TLS.
|
||||||
|
- **An origin firewall** restricted to Cloudflare's published IP ranges.
|
||||||
|
|
||||||
|
Until one is in place, treat per-client limits as protection against accidents
|
||||||
|
and ordinary load, not against a determined caller.
|
||||||
|
|
||||||
## Feature flags (Unleash)
|
## Feature flags (Unleash)
|
||||||
|
|
||||||
Flag state lives in a self-hosted Unleash instance, deployed as its own
|
Flag state lives in a self-hosted Unleash instance, deployed as its own
|
||||||
@@ -176,11 +212,30 @@ registry is orphaned and nothing reads it.
|
|||||||
variable, and set `UNLEASH_URL` to `http://<UNLEASH_IP>:4242/api`.
|
variable, and set `UNLEASH_URL` to `http://<UNLEASH_IP>:4242/api`.
|
||||||
5. Redeploy the application stacks.
|
5. Redeploy the application stacks.
|
||||||
|
|
||||||
|
### Adding a flag to Unleash
|
||||||
|
|
||||||
|
**Unleash does not create flags by itself.** The SDK reads definitions from the
|
||||||
|
server and never registers anything, and metrics for a flag the server has
|
||||||
|
never heard of are discarded. So a flag declared in `backend/flags.py` will be
|
||||||
|
evaluated on every request, stay `False` forever, and never appear in the UI
|
||||||
|
until someone creates it there by hand.
|
||||||
|
|
||||||
|
For each flag in the registry, create one in Unleash with:
|
||||||
|
|
||||||
|
- **Name** — character for character what `backend/flags.py` declares.
|
||||||
|
snake_case, no hyphens or spaces. A typo produces a flag that looks correct
|
||||||
|
in the UI and is read by nothing.
|
||||||
|
- **Type** — Release. No strategies, constraints or variants: these are plain
|
||||||
|
on/off switches, by design.
|
||||||
|
|
||||||
### Turning a feature on
|
### Turning a feature on
|
||||||
|
|
||||||
Toggle the flag in the environment you want. Flags appear in the Unleash UI
|
Toggle the flag in the environment matching the stack you mean: **development**
|
||||||
after the backend has evaluated them once, so a newly declared flag shows up
|
for staging, **production** for prod. The token in each stack is scoped to one
|
||||||
shortly after the deploy that introduced it.
|
environment, so toggling the other one has no visible effect.
|
||||||
|
|
||||||
|
The SDK refreshes every 15 seconds, so the API reflects the change almost at
|
||||||
|
once; the pages follow on their own schedule, below.
|
||||||
|
|
||||||
A flip reaches school pages within about five minutes and place pages within
|
A flip reaches school pages within about five minutes and place pages within
|
||||||
the hour. Next's ISR does the propagating — it revalidates a route at the
|
the hour. Next's ISR does the propagating — it revalidates a route at the
|
||||||
|
|||||||
@@ -0,0 +1,94 @@
|
|||||||
|
# Development and validation
|
||||||
|
|
||||||
|
## Prerequisites and environment boundaries
|
||||||
|
|
||||||
|
Use a feature branch. The deployed stack is the integration environment; do not
|
||||||
|
assume a local server can run from a fresh checkout. This cleanup did not start
|
||||||
|
local servers or provision databases. Unit tests use fixtures and mocks.
|
||||||
|
|
||||||
|
The current versions are not yet aligned:
|
||||||
|
|
||||||
|
| Component | Container | PR checks |
|
||||||
|
|---|---|---|
|
||||||
|
| Backend | Python 3.11 | Python 3.12 |
|
||||||
|
| Frontend | Node 24 | Node 22 |
|
||||||
|
| Pipeline | Python 3.13 | Pipeline image build |
|
||||||
|
|
||||||
|
Use the component's container version when reproducing deployment behaviour.
|
||||||
|
The backend dependency pins predate Python 3.14; do not assume the system Python
|
||||||
|
can install or run them. Version alignment is a separate maintenance task.
|
||||||
|
|
||||||
|
## Frontend checks
|
||||||
|
|
||||||
|
```sh
|
||||||
|
cd nextjs-app
|
||||||
|
npm ci
|
||||||
|
npm run typecheck
|
||||||
|
npm test -- --runInBand
|
||||||
|
```
|
||||||
|
|
||||||
|
`npm run build` is the production build check. There is no `lint` script.
|
||||||
|
Tests live in `__tests__/` and use Jest/React Testing Library. These checks do not
|
||||||
|
prove that live PostgreSQL queries, Typesense or a deployed proxy work.
|
||||||
|
|
||||||
|
The frontend `.env.example` documents runtime variables. Browser traffic normally
|
||||||
|
uses `/api`; `FASTAPI_URL` is an absolute server-side URL ending in `/api`.
|
||||||
|
Payload additionally needs `DATABASE_URL` and `PAYLOAD_SECRET` when used at runtime.
|
||||||
|
Never commit credentials or real `.env` files.
|
||||||
|
|
||||||
|
## Backend checks
|
||||||
|
|
||||||
|
From the repository root, using an available Python 3.11 or 3.12 interpreter:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
python3.11 -m venv /tmp/schoolcompare-backend-venv
|
||||||
|
/tmp/schoolcompare-backend-venv/bin/python -m pip install -r requirements.txt pytest 'httpx<0.28'
|
||||||
|
/tmp/schoolcompare-backend-venv/bin/python -m pytest backend/tests -q
|
||||||
|
```
|
||||||
|
|
||||||
|
Substitute `python3.12` if matching PR CI. The test dependencies above match the
|
||||||
|
current workflow; they are not yet captured in a dedicated development lockfile.
|
||||||
|
Backend configuration is defined in `backend/config.py`; `.env.example` documents
|
||||||
|
commonly used values. `ALLOWED_ORIGINS` uses a JSON array, not a comma-separated string.
|
||||||
|
|
||||||
|
## Data and pipeline work
|
||||||
|
|
||||||
|
The app needs populated `marts.*` tables. A new Postgres instance alone is not a
|
||||||
|
working school-data environment. Use the existing managed pipeline or an approved
|
||||||
|
snapshot; the removed CSV importer cannot build the current schema.
|
||||||
|
|
||||||
|
The pipeline container includes Meltano, dbt/Postgres, Airflow and the custom taps.
|
||||||
|
Airflow commands/selectors live in `pipeline/dags/`. Schema tests live in
|
||||||
|
`pipeline/transform/tests/` and model YAML files. Run the relevant `dbt build`
|
||||||
|
selector in an isolated data environment for model changes; it writes tables and
|
||||||
|
is not a read-only smoke test. Prefer `python -m dbt.cli.main` as the DAGs do.
|
||||||
|
|
||||||
|
GIAS dictionaries are generated together by
|
||||||
|
`pipeline/scripts/generate_gias_codes.py`. The backend and pipeline copies are
|
||||||
|
intentional; `backend/tests/test_gias_codes.py` checks that they stay identical.
|
||||||
|
|
||||||
|
For Payload collection/editor changes, run `npm run generate:importmap` in
|
||||||
|
`nextjs-app/` and include the generated map. Preserve CMS migrations and the
|
||||||
|
separate `payload` schema. See [publishing](../nextjs-app/docs/PUBLISHING.md).
|
||||||
|
|
||||||
|
## End-to-end checks
|
||||||
|
|
||||||
|
Against an existing, authorised test environment:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
cd e2e
|
||||||
|
npm ci
|
||||||
|
npx playwright install chromium
|
||||||
|
BASE_URL=https://your-test-environment.example npx playwright test
|
||||||
|
```
|
||||||
|
|
||||||
|
The suite does not start a web server. CI installs Chromium with system dependencies
|
||||||
|
and runs against staging. Use the configured staging target: `docs/DEPLOY.md`
|
||||||
|
records the public staging proxy limitation. User-visible behaviour changes should
|
||||||
|
update the corresponding journeys.
|
||||||
|
|
||||||
|
## Before requesting review
|
||||||
|
|
||||||
|
Run checks relevant to the change, inspect `git diff --check`, and report checks
|
||||||
|
that could not run. Do not publish or promote as part of local validation.
|
||||||
|
[DEPLOY.md](DEPLOY.md) documents the PR and human promotion gates.
|
||||||
@@ -0,0 +1,89 @@
|
|||||||
|
# Legacy and unused-code inventory
|
||||||
|
|
||||||
|
Reviewed 2026-09-14. This inventory records source evidence, not production usage
|
||||||
|
telemetry. A command with no repository caller may still be run manually or from
|
||||||
|
an external scheduler. Historical specs and prototypes are not runtime imports.
|
||||||
|
|
||||||
|
## Method and scope
|
||||||
|
|
||||||
|
Searched backend imports, tests, CLI scripts, Airflow DAGs, Meltano configuration,
|
||||||
|
Gitea workflows, Dockerfiles and documentation. For frontend candidates, inspected
|
||||||
|
TypeScript imports, re-exports, literal dynamic imports and `require` calls,
|
||||||
|
resolving relative and `@/` paths while excluding tests, dependencies and build
|
||||||
|
output. Checked candidates again with text searches including tests.
|
||||||
|
|
||||||
|
Next.js route files, generated Payload import-map entries and plugin discovery
|
||||||
|
are entry points even without ordinary imports. This is why a zero-import count
|
||||||
|
alone is not sufficient grounds for deletion. Computed imports and external
|
||||||
|
operators are outside this static audit.
|
||||||
|
|
||||||
|
## Removed in this cleanup
|
||||||
|
|
||||||
|
These names are recorded for Git-history lookup; they are no longer file links.
|
||||||
|
|
||||||
|
| Removed path or symbol | Evidence and replacement |
|
||||||
|
|---|---|
|
||||||
|
| `backend/migration.py` | Imported `School` and `SchoolResult`, which no longer exist in `backend/models.py`. Only the legacy CSV CLI imported it. Current tables are built by dbt. |
|
||||||
|
| `backend/version.py` | Only the legacy importer consumed `SCHEMA_VERSION`. FastAPI lifespan does not perform version-triggered imports. This is unrelated to active Payload migrations. |
|
||||||
|
| `scripts/migrate_csv_to_db.py` | Imported removed `init_db`/`set_db_schema_version` helpers and the obsolete models indirectly. No runtime, DAG or workflow calls it. Use the managed pipeline for current marts. |
|
||||||
|
| `scripts/geocode_schools.py` | Imported the removed `School` ORM model. No pipeline/workflow calls it. Coordinates now come from GIAS/PostGIS; a separate mart-aware manual utility remains under `pipeline/scripts/`. |
|
||||||
|
| `backend.data_loader.haversine_distance` | No callers. Search uses its inline vectorised NumPy calculation. |
|
||||||
|
| `nextjs-app/lib/api.ts: fetcher` | No callers; SWR is not installed. Application fetches use the named API wrappers. |
|
||||||
|
| `nextjs-app/lib/api.ts: kmToMiles` | No callers. `calculateDistance` remains because `CutoffMapPanel` uses it. |
|
||||||
|
|
||||||
|
The removed command files could not import successfully against the current
|
||||||
|
backend. This cleanup does not run replacements, migrate data or modify databases.
|
||||||
|
Their previous implementations remain recoverable from Git history.
|
||||||
|
|
||||||
|
## Unused candidates retained for a separate cleanup
|
||||||
|
|
||||||
|
| Candidate | Evidence | Recommended next step |
|
||||||
|
|---|---|---|
|
||||||
|
| `nextjs-app/components/LoadingSkeleton.tsx` and its CSS | No application or test imports found. | Remove together after confirming no planned use. |
|
||||||
|
| `nextjs-app/components/Pagination.tsx` and its CSS | No application or test imports found; HomeView implements load-more behaviour. | Remove as a pair if numbered pagination will not return. |
|
||||||
|
| `nextjs-app/components/SchoolCard.tsx` and its CSS | Imported by its own tests, not application code. HomeView uses SchoolRow/SecondarySchoolRow. | Decide whether to retire the card design; if removed, remove its dedicated tests as well. Passing tests do not establish runtime use. |
|
||||||
|
| `backend/database.py: get_db`, `get_db_session` | No remaining callers after removing the importer. Current code creates SessionLocal directly. | Either adopt these helpers during session-lifecycle cleanup or remove them; do not rewrite active sessions in a documentation change. |
|
||||||
|
| `backend/schemas.py: COLUMN_MAPPINGS`, `NULL_VALUES`, `LA_CODE_TO_NAME` | No remaining Python consumers found after importer removal. Other constants in this module are active. | Remove individual constants after checking external data utilities; retain the module. |
|
||||||
|
| `backend/config.py: data_dir`, `max_page_size`, `rate_limit_burst` | No active consumers found. `default_page_size` appears only in a branch that expects None, although the route supplies a concrete default. | Reconcile settings with route validation in a focused API change. |
|
||||||
|
|
||||||
|
## Legacy/manual paths requiring operational verification
|
||||||
|
|
||||||
|
| Path | Status and reason to retain for now |
|
||||||
|
|---|---|
|
||||||
|
| FastAPI `/`, `/compare`, `/rankings`, `/favicon.svg`, `/robots.txt`, and conditional `/static` | Old frontend-serving routes reference a `frontend/` directory absent from the checkout and backend image. Next.js owns these public surfaces. Removal changes externally callable routes, so first check proxy/operator usage and define replacement responses. |
|
||||||
|
| `scripts/fetch_real_data.py`, `scripts/download_data.py` | Historical standalone CSV utilities. The fetch script targets Wandsworth/Merton; neither is wired into the managed pipeline. Marked historical, retained pending confirmation of manual use. |
|
||||||
|
| `pipeline/scripts/geocode_postcodes.py` | Mart-aware postcode fallback, not called by the current DAGs. Do not confuse it with the removed legacy ORM geocoder. Verify the target schema before manual use. |
|
||||||
|
| `docker-compose.yml` | Uses unpublished `:latest` release tags and lacks frontend Payload DB/secret/media configuration. Retained as an old development topology, not recommended onboarding. |
|
||||||
|
| `nextjs-app/docker-compose.yml` | Standalone legacy recipe with old backend port assumptions and no CMS persistence setup. Retained until its consumers are checked. |
|
||||||
|
| `MIGRATION_SUMMARY.md`, `docs/superpowers/`, `mockups/` | Historical designs and prototypes. Retain as history; do not follow as current deployment instructions. |
|
||||||
|
| `scripts/sql/drop_fact_parent_view.sql` | One-off maintenance SQL. Not an application entry point; repository call-site searches cannot establish whether it is still needed operationally. |
|
||||||
|
|
||||||
|
## Active code that can look obsolete
|
||||||
|
|
||||||
|
- `backend/data_loader.py` older-mart query fallbacks are covered by backend tests
|
||||||
|
and support databases at different migration stages. Remove only after verifying
|
||||||
|
the deployed schemas in every supported environment.
|
||||||
|
- `backend/gias_codes.py` and `pipeline/scripts/gias_codes.py` are intentionally
|
||||||
|
generated copies for separate runtime images. Their parity is tested.
|
||||||
|
- `nextjs-app/migrations/`, `payload-types.ts` and the Payload import map are active
|
||||||
|
CMS artifacts, not remnants of the removed school importer.
|
||||||
|
- `get_available_years`, `get_available_local_authorities` and `get_schools_count`
|
||||||
|
in `data_loader.py` are called through `get_data_info`, which serves the backend
|
||||||
|
data-info endpoint. They are not dead functions.
|
||||||
|
- `get_supplementary_data` is an intentional single-school wrapper around the
|
||||||
|
batch implementation.
|
||||||
|
- `pipeline/transform` models named `legacy` can be active data sources: annual
|
||||||
|
DAG selectors explicitly include legacy KS2/KS4 lineage. Names alone do not
|
||||||
|
establish obsolescence.
|
||||||
|
|
||||||
|
## Suggested next passes
|
||||||
|
|
||||||
|
1. Decide the fate of the three unused UI components and remove paired assets/tests.
|
||||||
|
2. Consolidate backend session usage and remove abandoned settings/constants.
|
||||||
|
3. Verify external consumers, then retire static-serving API routes and old compose recipes.
|
||||||
|
4. Audit manual data utilities with pipeline operators before deleting them.
|
||||||
|
5. Revisit compatibility fallbacks only after documenting supported schema versions.
|
||||||
|
|
||||||
|
Validation for this cleanup should include frontend typechecking/tests, Python
|
||||||
|
syntax checks, reference searches and documentation link checks. Live database,
|
||||||
|
external scheduler and deployed route usage require separate integration evidence.
|
||||||
File diff suppressed because it is too large.
Load diff
File diff suppressed because it is too large.
Load diff
File diff suppressed because it is too large.
Load diff
@@ -0,0 +1,294 @@
|
|||||||
|
# School Autosuggest — Design
|
||||||
|
|
||||||
|
**Date:** 2026-08-26
|
||||||
|
**Status:** approved for planning
|
||||||
|
**Depends on:** the feature-flag layer (PR #125, merged)
|
||||||
|
|
||||||
|
## Goal
|
||||||
|
|
||||||
|
Suggest schools by name as someone types in the site's main search box, so a
|
||||||
|
parent who knows the school they want reaches it in one step instead of
|
||||||
|
searching, scanning a result list, and clicking.
|
||||||
|
|
||||||
|
Scope is **schools only**. Places and postcodes were considered and excluded —
|
||||||
|
see *Out of scope*.
|
||||||
|
|
||||||
|
## The finding that shapes everything
|
||||||
|
|
||||||
|
The site's rate limiter does not do what it looks like it does.
|
||||||
|
|
||||||
|
`limiter = Limiter(key_func=get_remote_address)` with `60/minute` reads
|
||||||
|
`request.client.host`. In staging and production the backend has no published
|
||||||
|
ports and sits on the internal `backend` network, so its only caller is the
|
||||||
|
Next proxy — and `request.client.host` is therefore **the Next container**, for
|
||||||
|
every browser user on the site.
|
||||||
|
|
||||||
|
Measured against staging: 70 concurrent requests to `/api/schools` returned
|
||||||
|
**60 × 200 and 10 × 429**. One machine consumed the whole site's budget for
|
||||||
|
that minute.
|
||||||
|
|
||||||
|
Autosuggest is the worst possible feature to build on that. One person typing
|
||||||
|
"st marys primary" produces six to eight debounced requests; **eight concurrent
|
||||||
|
searchers would 429 the site.** The compare modal's search-as-you-type already
|
||||||
|
shares this bucket, so the exposure exists today — autosuggest makes it
|
||||||
|
certain.
|
||||||
|
|
||||||
|
Fixing the keying is therefore part of this work, not a follow-up.
|
||||||
|
|
||||||
|
## 1. Rate-limit keying
|
||||||
|
|
||||||
|
Both environments sit behind Cloudflare (`server: cloudflare`, `cf-ray` present
|
||||||
|
on staging and production). Cloudflare sets `CF-Connecting-IP` on every request
|
||||||
|
to the origin and **overwrites any client-supplied value**, which makes it
|
||||||
|
trustworthy in a way a parsed `X-Forwarded-For` chain is not.
|
||||||
|
|
||||||
|
```python
|
||||||
|
def client_key(request: Request) -> str:
|
||||||
|
"""Rate-limit bucket: the real caller, not the proxy in front of them."""
|
||||||
|
cf = request.headers.get("cf-connecting-ip")
|
||||||
|
if cf:
|
||||||
|
return cf.strip()
|
||||||
|
xff = request.headers.get("x-forwarded-for")
|
||||||
|
if xff:
|
||||||
|
return xff.split(",")[0].strip()
|
||||||
|
return get_remote_address(request)
|
||||||
|
```
|
||||||
|
|
||||||
|
`nextjs-app/app/api/[...path]/route.ts` already forwards every inbound header
|
||||||
|
except `host` and `connection`, so `CF-Connecting-IP` reaches the backend with
|
||||||
|
no proxy change.
|
||||||
|
|
||||||
|
**This header is trustworthy only for traffic that actually passed through
|
||||||
|
Cloudflare, and nothing in the application can verify that it did.** An earlier
|
||||||
|
draft of this section claimed Cloudflare "replaces the header, so a browser
|
||||||
|
cannot forge it", and that only the `X-Forwarded-For` fallback was forgeable.
|
||||||
|
That was wrong. Cloudflare does overwrite the header *on requests it handles* —
|
||||||
|
but a caller reaching the origin directly sets whatever it likes, and this
|
||||||
|
process cannot distinguish an edge-set header from an attacker-set one. Both
|
||||||
|
headers are equally forgeable in that scenario.
|
||||||
|
|
||||||
|
The consequence is sharper than a weakened defence. An attacker rotating
|
||||||
|
`CF-Connecting-IP` per request mints a fresh rate-limit bucket every time and
|
||||||
|
evades per-client limits entirely — including on the DataFrame-heavy
|
||||||
|
`/api/schools`. Against abuse that is *worse* than the shared bucket it
|
||||||
|
replaced, which at least capped everyone at 60/minute together.
|
||||||
|
|
||||||
|
Two mitigations, and they are not interchangeable:
|
||||||
|
|
||||||
|
1. **The real fix is at Cloudflare** — Authenticated Origin Pulls, or an origin
|
||||||
|
firewall that refuses connections not from Cloudflare's ranges. Only the
|
||||||
|
edge can vouch for its own header. This is infrastructure work and is not
|
||||||
|
part of this change; it is the thing that makes the header mean anything.
|
||||||
|
2. **The ceiling in §1.1 bounds what evading the keying can achieve** while
|
||||||
|
that remains open. It does not make the header trustworthy — it makes
|
||||||
|
trusting it survivable.
|
||||||
|
|
||||||
|
The backend being unreachable from outside the Docker network is a real second
|
||||||
|
layer, but it depends on the ingress path in front of the frontend, which this
|
||||||
|
design does not control and should not assume.
|
||||||
|
|
||||||
|
### 1.1 The ceiling, which is back
|
||||||
|
|
||||||
|
The shared bucket was acting as an accidental global throttle on a
|
||||||
|
single-process uvicorn backend that filters a 25,000-row DataFrame in-process.
|
||||||
|
Correct per-user keying removes it: the origin becomes reachable at 60/min *per
|
||||||
|
user* rather than 60/min in total, and — per above — at an unbounded rate by
|
||||||
|
anyone willing to rotate a header.
|
||||||
|
|
||||||
|
An earlier draft dropped the in-app ceiling, arguing it belonged at Cloudflare.
|
||||||
|
That argument assumed the keying was sound. It is not, so the ceiling is
|
||||||
|
load-bearing rather than redundant, and it ships here:
|
||||||
|
|
||||||
|
`GlobalRateLimitMiddleware` counts all `/api/` requests in a fixed 60-second
|
||||||
|
window against `global_rate_limit_per_minute` (3000), independent of any client
|
||||||
|
identity, and refuses with a 429 that names capacity rather than the client —
|
||||||
|
an operator has to be able to tell "one noisy client" from "the origin is
|
||||||
|
saturated". It is registered last so it is outermost: a ceiling that applies
|
||||||
|
after the expensive work has run is not a ceiling.
|
||||||
|
|
||||||
|
slowapi cannot express this. `default_limits` and `application_limits` are both
|
||||||
|
evaluated with the same `key_func`, making them per-client rather than global,
|
||||||
|
and `application_limits` only apply with `SlowAPIMiddleware` installed, which
|
||||||
|
this app does not use. Hence the explicit middleware — about thirty lines, and
|
||||||
|
obviously correct, which is what a backstop needs to be.
|
||||||
|
|
||||||
|
Requests from `127.0.0.1` are exempt. The container healthcheck runs
|
||||||
|
`curl http://localhost:80/api/data-info` from inside the container, and
|
||||||
|
starving it would fail the check, restart the container, and turn a load spike
|
||||||
|
into an outage loop. The exemption keys on the peer address, never the `Host`
|
||||||
|
header, which the caller sets.
|
||||||
|
|
||||||
|
3000/minute is an estimate, not a measurement, and worth revisiting against
|
||||||
|
real traffic.
|
||||||
|
|
||||||
|
### Per-user limits
|
||||||
|
|
||||||
|
Per-user fairness and origin protection are different jobs, and this design now
|
||||||
|
does both separately: the ceiling above for the origin, and per-route limits
|
||||||
|
for fairness. Conflating them is what produced the original behaviour, where
|
||||||
|
one bucket served the whole internet.
|
||||||
|
|
||||||
|
The existing 60/minute default is unchanged, and `/api/suggest` gets
|
||||||
|
120/minute. Both are estimates rather than measurements, and are a starting
|
||||||
|
point to revisit once the keying is correct enough for real per-user traffic to
|
||||||
|
be visible — which it was not before, because everyone shared one bucket.
|
||||||
|
|
||||||
|
## 2. `GET /api/suggest`
|
||||||
|
|
||||||
|
A dedicated endpoint, not a mode of `/api/schools`.
|
||||||
|
|
||||||
|
The existing search path calls Typesense for URNs and then filters, ranks and
|
||||||
|
sorts the full in-memory DataFrame — a pandas pass per keystroke, holding the
|
||||||
|
GIL and blocking other requests in the same worker. Suggestions need none of
|
||||||
|
it: `urn`, `school_name`, `phase`, `school_type`, `local_authority`,
|
||||||
|
`postcode` and `ofsted_rating` are all already in the Typesense document
|
||||||
|
(`pipeline/scripts/sync_typesense.py`).
|
||||||
|
|
||||||
|
```
|
||||||
|
GET /api/suggest?q=<query>&limit=8
|
||||||
|
→ 200 {"suggestions": [
|
||||||
|
{"urn": 100010, "school_name": "Brecknock Primary School",
|
||||||
|
"local_authority": "Camden", "postcode": "NW1 1AA",
|
||||||
|
"phase": "Primary", "school_type": "Community school"}
|
||||||
|
]}
|
||||||
|
```
|
||||||
|
|
||||||
|
- **Under two characters** returns `{"suggestions": []}` with 200. The
|
||||||
|
keystroke path never returns an error for ordinary input.
|
||||||
|
- **Typesense unavailable** returns `{"suggestions": []}` with 200. There is
|
||||||
|
deliberately **no DataFrame fallback**: the substring scan `/api/schools`
|
||||||
|
falls back to is precisely the cost this endpoint exists to avoid, and a
|
||||||
|
silent 25,000-row scan per keystroke is worse than no suggestions.
|
||||||
|
- **`limit` is clamped** to 20. It is a public endpoint.
|
||||||
|
- **Rate limit `120/minute`** per client, not the default 60. A 200 ms
|
||||||
|
debounce tops out near 5 requests/second while someone is actively typing,
|
||||||
|
but averages far below that across a real search; 120 leaves headroom for
|
||||||
|
bursts while still bounding one client.
|
||||||
|
- **Local authority is part of the payload, not decoration.** There are many
|
||||||
|
schools called "St Mary's"; a suggestion list without the authority is
|
||||||
|
unusable for exactly the queries autosuggest is meant to serve.
|
||||||
|
|
||||||
|
### Caching
|
||||||
|
|
||||||
|
`CACHE_RULES` gains `("/api/suggest", (60, 3600, 86400))`. Prefix queries
|
||||||
|
repeat enormously across users and school names change once a year.
|
||||||
|
|
||||||
|
The client fetch must **not** use `cache: "no-store"`. The compare modal does,
|
||||||
|
and copying that pattern would throw away both the browser cache and the ETag
|
||||||
|
304s the existing `CacheAndETagMiddleware` already provides.
|
||||||
|
|
||||||
|
Both environments currently report `cf-cache-status: DYNAMIC` — Cloudflare
|
||||||
|
ignores the `Cache-Control` the API already sends, because it does not cache
|
||||||
|
dynamic paths by default. **A Cloudflare Cache Rule for `/api/suggest*` would
|
||||||
|
let the edge absorb most of this traffic and never reach the origin.** That is
|
||||||
|
a dashboard change, it is optional, and nothing here depends on it.
|
||||||
|
|
||||||
|
## 3. The combobox
|
||||||
|
|
||||||
|
This is an ARIA combobox, not a text input with a list underneath.
|
||||||
|
|
||||||
|
**Files.** `FilterBar.tsx` is already long. The work splits three ways:
|
||||||
|
`hooks/useSchoolSuggest.ts` owns fetching, debouncing and cancellation;
|
||||||
|
`components/SuggestList.tsx` owns rendering and ARIA; `FilterBar.tsx` wires
|
||||||
|
them to the existing input and form.
|
||||||
|
|
||||||
|
**Fetching.** 200 ms debounce; minimum two characters; an `AbortController`
|
||||||
|
cancels the superseded request on every keystroke. Cancellation is not an
|
||||||
|
optimisation — without it, a slow response for `"st"` can land after the fast
|
||||||
|
one for `"st marys"` and replace a correct list with a stale one.
|
||||||
|
|
||||||
|
**Suppressed during postcode entry.** The box takes a school name *or* a
|
||||||
|
postcode, and `isValidPostcode` already distinguishes them. Suggestions do not
|
||||||
|
appear once the value parses as a postcode.
|
||||||
|
|
||||||
|
**Keyboard.** `ArrowDown`/`ArrowUp` move the active option, `Escape` closes and
|
||||||
|
keeps the typed text, `Tab` closes. `Enter` **with an option active** navigates
|
||||||
|
to that school's page. `Enter` **with none active** submits the free-text
|
||||||
|
search exactly as it does today — the existing behaviour is preserved, not
|
||||||
|
replaced.
|
||||||
|
|
||||||
|
**ARIA.** `role="combobox"` with `aria-expanded` and `aria-controls` on the
|
||||||
|
input, `aria-activedescendant` pointing at the active option, `role="listbox"`
|
||||||
|
on the list and `role="option"` on each row.
|
||||||
|
|
||||||
|
**Both instances get it.** `HomeView` renders `FilterBar` twice — hero and
|
||||||
|
sticky — from one component, so there is one implementation.
|
||||||
|
|
||||||
|
## 4. Behind a flag
|
||||||
|
|
||||||
|
Flag `school_autosuggest`, declared in `backend/flags.py`, default off.
|
||||||
|
|
||||||
|
This is the most-used control on the site and the first change to it in a
|
||||||
|
while. `app/page.tsx` is an async server component, so it reads the flag and
|
||||||
|
threads it to `FilterBar` through `HomeView` — two prop hops, explicit, no
|
||||||
|
client-side flag read.
|
||||||
|
|
||||||
|
Off means the input behaves exactly as it does today: no listener, no fetch, no
|
||||||
|
markup. Not a rendered-then-hidden dropdown.
|
||||||
|
|
||||||
|
The rate-limit keying is **not** flagged. It is a correctness fix that should
|
||||||
|
apply whether or not autosuggest is on, and flagging it would mean shipping a
|
||||||
|
known-wrong limiter into production deliberately.
|
||||||
|
|
||||||
|
## 5. Analytics
|
||||||
|
|
||||||
|
`search_submitted` already carries `via: 'input'`. Selecting a suggestion fires
|
||||||
|
it with `via: 'suggestion'` plus the chosen `urn`, so the obvious question —
|
||||||
|
does this actually help, or do people ignore it — has an answer in the data
|
||||||
|
rather than an opinion.
|
||||||
|
|
||||||
|
## 6. Testing
|
||||||
|
|
||||||
|
**Backend.** `client_key` prefers `CF-Connecting-IP`, falls back through
|
||||||
|
`X-Forwarded-For` to the remote address, and two different values get two
|
||||||
|
different buckets. `/api/suggest` returns matches, returns empty below two
|
||||||
|
characters, returns empty and 200 when Typesense is unavailable, and clamps
|
||||||
|
`limit`. That it never touches the DataFrame is asserted by making
|
||||||
|
`load_school_data` raise and requiring the endpoint to answer anyway.
|
||||||
|
|
||||||
|
**Frontend.** The hook debounces, aborts superseded requests, and drops a
|
||||||
|
late-arriving response for a stale query. The list renders the ARIA
|
||||||
|
attributes. Keyboard navigation moves the active option; `Enter` on an option
|
||||||
|
navigates; `Enter` on none submits the search.
|
||||||
|
|
||||||
|
**E2E.** With the flag on, typing a known school name shows it and selecting it
|
||||||
|
lands on that school's page. With the flag off, no combobox markup exists.
|
||||||
|
Gated on the flag the same way the distance journeys are — read the observable
|
||||||
|
effect, since `/api/flags` is denied to the public.
|
||||||
|
|
||||||
|
## 7. Risks
|
||||||
|
|
||||||
|
**Removing the accidental throttle.** Covered in §1. Correct per-user keying
|
||||||
|
means the origin is reachable at 60/minute *per user* where it was 60/minute
|
||||||
|
in total, and no in-app global cap replaces it — that job goes to Cloudflare,
|
||||||
|
which is not done as part of this change. Until it is, a determined caller
|
||||||
|
with many source addresses can put more load on a single-process origin than
|
||||||
|
they can today. Against this site's traffic that is a theoretical risk rather
|
||||||
|
than a live one, but it is a real one and it is the price of the fix.
|
||||||
|
|
||||||
|
**Cloudflare bypass — the open one.** If the origin is reachable without
|
||||||
|
passing through Cloudflare, `CF-Connecting-IP` is attacker-controlled, and
|
||||||
|
rotating it per request defeats per-client limits on every endpoint. The
|
||||||
|
ceiling in §1.1 bounds the damage to the origin's total capacity; it does not
|
||||||
|
restore per-client fairness under attack, and it cannot. Closing this properly
|
||||||
|
means Authenticated Origin Pulls or an origin firewall restricted to
|
||||||
|
Cloudflare's published ranges — infrastructure work, outside this change, and
|
||||||
|
the single most valuable follow-up here.
|
||||||
|
|
||||||
|
**Typesense becomes user-visible.** Today a Typesense outage degrades search to
|
||||||
|
a slow substring match. With autosuggest it also means the dropdown silently
|
||||||
|
stops appearing. That is the correct failure — quiet, not broken — but it makes
|
||||||
|
Typesense health worth monitoring in a way it was not before.
|
||||||
|
|
||||||
|
## Out of scope
|
||||||
|
|
||||||
|
- **Place suggestions.** The 2,646 town, authority and outcode pages are a
|
||||||
|
strong candidate and would route people onto the pages W2 built, but they
|
||||||
|
live in the place registry rather than Typesense, so it is a second index and
|
||||||
|
a ranking rule for comparing two kinds of result. Worth its own change.
|
||||||
|
- **Postcode completion.** Would put postcodes.io in the keystroke path, with
|
||||||
|
its own latency and rate limits.
|
||||||
|
- **The compare modal.** It already has search-as-you-type. Converting it to
|
||||||
|
this component is a reasonable follow-up, not part of this.
|
||||||
|
- **Recent or popular searches.** No storage for either, and no evidence yet
|
||||||
|
that they are wanted.
|
||||||
@@ -0,0 +1,399 @@
|
|||||||
|
# Destination Measures — Design
|
||||||
|
|
||||||
|
**Date:** 2026-08-28
|
||||||
|
**Status:** awaiting review
|
||||||
|
**Scope:** secondary school detail pages only
|
||||||
|
|
||||||
|
## Goal
|
||||||
|
|
||||||
|
Say what happened to a school's leavers after they left. Two sections on the
|
||||||
|
secondary template:
|
||||||
|
|
||||||
|
- **After Year 11** — every secondary, from the KS4 destination measures
|
||||||
|
- **After the sixth form** — sixth-form schools only, from the 16-18 measures
|
||||||
|
|
||||||
|
This replaces the "Post-16 destination data coming soon" placeholder standing in
|
||||||
|
`nextjs-app/components/school/SecondaryAdmissionsSection.tsx:117` since the exam
|
||||||
|
phase taxonomy work, and fills the `ks5_destinations_pct` slot specified but
|
||||||
|
never built in `2026-07-07-exam-phase-taxonomy-design.md:201`.
|
||||||
|
|
||||||
|
Mockup, with all three data states live:
|
||||||
|
<https://claude.ai/code/artifact/5be149d6-252f-473c-9a4f-4c36b05161b0>
|
||||||
|
|
||||||
|
## The finding that shapes everything
|
||||||
|
|
||||||
|
**Suppression is per cell, and the cells sum to the cohort.**
|
||||||
|
|
||||||
|
DfE withholds a figure it considers disclosive by writing `c`. It does this at
|
||||||
|
the level of an individual destination category, not the whole school, and it
|
||||||
|
publishes the cohort total alongside. The categories form a clean partition. So
|
||||||
|
where exactly one category is suppressed, subtracting the published ones from the
|
||||||
|
cohort recovers it exactly.
|
||||||
|
|
||||||
|
Verified against three real schools in the 2022/23 file:
|
||||||
|
|
||||||
|
| School | URN | Withheld | Recovers to |
|
||||||
|
|---|---|---|---|
|
||||||
|
| North East Futures UTC | 145900 | School sixth form | **3 pupils** |
|
||||||
|
| Whitley Bay High School | 108638 | Further education | **18 pupils** |
|
||||||
|
| St Matthew's RC High School | 148389 | School sixth form | **4 pupils** |
|
||||||
|
|
||||||
|
Those are the precise numbers the `c` exists to hide, and in a random 400-school
|
||||||
|
sample **22% of mainstream secondaries** have exactly one suppressed category in
|
||||||
|
their disadvantaged group. This is the normal case, not an edge case.
|
||||||
|
|
||||||
|
Three rules follow, and everything else in this document is downstream of them.
|
||||||
|
|
||||||
|
**R1 — Never *publish* enough to derive a remainder.**
|
||||||
|
|
||||||
|
An earlier draft of this rule said "never *render* a derived remainder", and
|
||||||
|
that was the defect code review caught in PR #137. Not drawing a number does
|
||||||
|
nothing to stop it being computed: `GET /api/schools/{urn}` is public and
|
||||||
|
unauthenticated, so anything in the payload is published whatever the UI
|
||||||
|
chooses to draw. The rendering guards shipped; the payload still carried the
|
||||||
|
cohort and every published category, and `cohort - sum(published)` returned
|
||||||
|
Whitley Bay's withheld figure exactly.
|
||||||
|
|
||||||
|
The rule is therefore about the serialiser, and the UI guards are a second line
|
||||||
|
of defence behind it. Two identities have to be closed:
|
||||||
|
|
||||||
|
- within a pupil group the categories sum to the cohort, so a group with
|
||||||
|
exactly **one** suppressed category gives it away;
|
||||||
|
- across groups, disadvantaged + other = all for every category, so a category
|
||||||
|
suppressed in exactly **one** of the three gives itself away.
|
||||||
|
|
||||||
|
`_mask_for_disclosure` applies DfE's own answer — secondary suppression —
|
||||||
|
withholding a companion cell until every row and every column hides either none
|
||||||
|
or at least two. It iterates, because each new suppression can break the other
|
||||||
|
identity, and terminates because cells are only ever added.
|
||||||
|
|
||||||
|
The companion must carry pupils. Suppressing a zero looks like secondary
|
||||||
|
suppression and protects nothing: the residual still equals the original
|
||||||
|
withheld figure.
|
||||||
|
|
||||||
|
Where no companion can do the job — a sparse cohort whose every other category
|
||||||
|
is `not_applicable`, routine in special schools and alternative provision — the
|
||||||
|
pupil group is **dropped from the payload entirely**. A first version simply
|
||||||
|
returned at that point with the violation intact and no signal, which review
|
||||||
|
caught: a disclosure-control pass that fails silently is worse than none,
|
||||||
|
because everything downstream trusts it. The function now cannot terminate
|
||||||
|
except in a state where `disclosure_invariant_holds()` is true, and an
|
||||||
|
exhaustive test sweeps all 81 suppression patterns of a four-category group to
|
||||||
|
prove it.
|
||||||
|
|
||||||
|
Measured cost on the 400-school sample: the all-pupils bar survives on **94%**
|
||||||
|
of mainstream secondaries rather than 100%. That is the price of not
|
||||||
|
republishing what DfE withheld.
|
||||||
|
|
||||||
|
**R2 — Never aggregate across a suppression boundary.** Summing published
|
||||||
|
components to fill a gap is R1 with extra steps.
|
||||||
|
|
||||||
|
DfE's own aggregates (`Sustained education destination`, `Sustained education,
|
||||||
|
employment & apprenticeships`) are ingested but **not served**. An aggregate
|
||||||
|
spanning exactly one suppressed component names it, and nothing renders them
|
||||||
|
today — an unused field that leaks is not a trade-off worth carrying. They can
|
||||||
|
be re-added with their own guard if the fallback ladder is ever built.
|
||||||
|
|
||||||
|
**R3 — The three pupil groups are one disclosure surface, not three.**
|
||||||
|
Disadvantaged and Not-known-to-be-disadvantaged partition All pupils, so
|
||||||
|
rendering any *two* of them recovers the third. Where a category is suppressed in
|
||||||
|
the disadvantaged group, it must therefore also be withheld from **all other
|
||||||
|
pupils** — the all-pupils view is the primary one and keeps it.
|
||||||
|
|
||||||
|
This costs almost nothing, because DfE already applies the same masking: across
|
||||||
|
the sample, 493 of 498 suppressed disadvantaged cells were suppressed in the
|
||||||
|
other group too. The mart enforces the remaining 5, which fell on 2 schools of
|
||||||
|
262. **The all-pupils bar is unaffected** — masking the whole page wherever the
|
||||||
|
disadvantaged group is thin would remove the bar from 80% of schools, and is not
|
||||||
|
what this rule says.
|
||||||
|
|
||||||
|
R1 and R2 both hold within a group and still leak across the switch, which is why
|
||||||
|
R3 is stated separately.
|
||||||
|
|
||||||
|
### The convention that would break this quietly
|
||||||
|
|
||||||
|
`macros/safe_numeric.sql` coerces every EES sentinel — `z`, `c`, `x`, `q`, `u` —
|
||||||
|
to `NULL`, deliberately and correctly for attainment, where "suppressed" and "no
|
||||||
|
data" are equally unrenderable. Here they are not the same thing: one must print
|
||||||
|
*withheld*, the other must print nothing at all, and the difference is what keeps
|
||||||
|
R1 enforceable.
|
||||||
|
|
||||||
|
**`safe_numeric` must not be used on destination counts.** The staging model
|
||||||
|
keeps the sentinel in a companion status column. This is the single most likely
|
||||||
|
way for this feature to regress into a disclosure, so it gets its own dbt test.
|
||||||
|
|
||||||
|
## What is actually available
|
||||||
|
|
||||||
|
Measured against the EES public API (open, no key). Both datasets carry
|
||||||
|
`geographicLevel: School` with `urn` on every location option, so the join to
|
||||||
|
`dim_school` is direct.
|
||||||
|
|
||||||
|
| | KS4 | 16-18 |
|
||||||
|
|---|---|---|
|
||||||
|
| Dataset id | `019d4f41-22d1-71b2-a1a7-f3b91026815b` | `019d4e73-6440-7523-b60c-bfab1ad4a30d` |
|
||||||
|
| Rows | 1,871,739 | 3,862,658 |
|
||||||
|
| Institutions | 4,946 | 3,065 |
|
||||||
|
| Time periods | 2009/10–2022/23 | 2016/17–2022/23 |
|
||||||
|
|
||||||
|
**Destination categories (KS4).** School sixth form · Sixth form college ·
|
||||||
|
Further education · Other education destination · Sustained apprenticeships (with
|
||||||
|
level breakdown) · Sustained employment destination · Not recorded as a sustained
|
||||||
|
destination · Activity not captured. Plus the aggregates `Sustained education
|
||||||
|
destination` and `Sustained education, employment & apprenticeships`.
|
||||||
|
|
||||||
|
**16-18 adds** UK higher education institution and FE split by level, which is
|
||||||
|
what makes the post-16 section worth having.
|
||||||
|
|
||||||
|
**Breakdowns.** `Disadvantage Status` gives Disadvantaged / Not known to be
|
||||||
|
disadvantaged / Total — exactly the three-way switch. Sex, ethnicity, FSM status,
|
||||||
|
prior attainment and SEN provision also travel in the same table; we ingest none
|
||||||
|
of them.
|
||||||
|
|
||||||
|
**Indicators.** Both counts and percentages, plus the cohort size. Bar widths use
|
||||||
|
the counts — the published percentages do not sum to 100.
|
||||||
|
|
||||||
|
### Coverage, and what degrades
|
||||||
|
|
||||||
|
Random 400-school sample, 2022/23, mainstream secondaries (n=262):
|
||||||
|
|
||||||
|
| View | As published by DfE | After R1–R3 masking | Consequence |
|
||||||
|
|---|---|---|---|
|
||||||
|
| All pupils, all categories | 100% | **94%** | Bar works nearly everywhere |
|
||||||
|
| Disadvantaged, headline rate | 95% | 95% | Gap panel works |
|
||||||
|
| Disadvantaged, three grouped cards | 68% | 68% | Degrades card by card |
|
||||||
|
| Disadvantaged, all six categories | 20% | **20%** | Bar unusable for this group |
|
||||||
|
|
||||||
|
The middle column is what the site actually serves. Masking costs the
|
||||||
|
all-pupils bar on 6% of mainstream secondaries — those are schools where a
|
||||||
|
category was suppressed in exactly one pupil group and no non-zero companion
|
||||||
|
existed below the all-pupils row.
|
||||||
|
|
||||||
|
Special schools and alternative provision are far worse: 13% and 41% respectively
|
||||||
|
have the whole cohort suppressed even for all pupils. The empty state is
|
||||||
|
load-bearing, not defensive.
|
||||||
|
|
||||||
|
## The display
|
||||||
|
|
||||||
|
Question-led. Three cards over one bar, with the cards acting as a lens on the
|
||||||
|
bar rather than a summary beside it — hovering a card dims the bar, table and
|
||||||
|
England reference to the categories that card is built from. The full mockup is
|
||||||
|
linked above; what matters for implementation:
|
||||||
|
|
||||||
|
**The headline is not the sustained rate.** That figure sits between 92% and 97%
|
||||||
|
for nearly every school in England. The mix is what varies, so the mix leads.
|
||||||
|
|
||||||
|
**The grouping is ours, not DfE's.** "Academic route" = school sixth form +
|
||||||
|
sixth-form college; "College" = FE and other colleges; "Work" = apprenticeship +
|
||||||
|
employment. This is the most arguable thing on the page, so it lives in one place
|
||||||
|
in `lib/destinations.ts`, is explained in a tooltip, and is reversible in one
|
||||||
|
edit.
|
||||||
|
|
||||||
|
**The absence is hatched neutral, never a colour.** "Activity not captured" means
|
||||||
|
no record in the sources DfE holds — it includes independent schools, moving
|
||||||
|
abroad and private training. Colouring it as a bad outcome would be a factual
|
||||||
|
error rendered in CSS. The hatch also fixes a real contrast problem: neutral
|
||||||
|
against the employment blue failed CVD separation at ΔE 7.6, and texture is the
|
||||||
|
secondary encoding that rescues it. Every other adjacent pair clears ΔE 10.9
|
||||||
|
under protanopia.
|
||||||
|
|
||||||
|
**Colour tokens.** Education is one hue in three steps (school-like to
|
||||||
|
college-like); apprenticeship and employment are separate hues. Six new tokens in
|
||||||
|
`globals.css`, defined in both themes, per the existing token discipline.
|
||||||
|
|
||||||
|
**The disadvantage split rides the same control.** One visualisation serving
|
||||||
|
three cohorts, with the England reference repointing to the matching national
|
||||||
|
group. The gap statement stays visible below the bar whatever is selected,
|
||||||
|
because a gap nobody clicks on is a gap nobody sees.
|
||||||
|
|
||||||
|
## Data model
|
||||||
|
|
||||||
|
### Extraction
|
||||||
|
|
||||||
|
A new `tap-uk-ees-destinations` extractor, separate from `tap-uk-ees`. The
|
||||||
|
existing tap downloads a release ZIP and reads a CSV inside it; the destinations
|
||||||
|
files are far larger than we need and the query API filters server-side, so this
|
||||||
|
one POSTs to `/v1/data-sets/{id}/query` and pages through results.
|
||||||
|
|
||||||
|
With every dimension pinned — destination measures, disadvantage status, sex
|
||||||
|
Total, characteristic topic Total — one year returns **252,610 rows** across all
|
||||||
|
geographic levels. Three school-level years is comfortably tractable.
|
||||||
|
|
||||||
|
Pinning is mandatory, not an optimisation: leaving the characteristic dimensions
|
||||||
|
unconstrained returned 45 rows where 9 were wanted, because every breakdown
|
||||||
|
shares one table.
|
||||||
|
|
||||||
|
The tap emits the raw value as text. **It does not coerce `c`.**
|
||||||
|
|
||||||
|
### Staging
|
||||||
|
|
||||||
|
`stg_ees_ks4_destinations` / `stg_ees_ks5_destinations`. Each raw value becomes
|
||||||
|
two columns:
|
||||||
|
|
||||||
|
```sql
|
||||||
|
case when raw ~ '^-?[0-9]+(\.[0-9]+)?$' then raw::numeric end as pupils,
|
||||||
|
case
|
||||||
|
when raw ~ '^-?[0-9]+(\.[0-9]+)?$' then 'published'
|
||||||
|
when lower(trim(raw)) = 'c' then 'suppressed'
|
||||||
|
else 'not_applicable'
|
||||||
|
end as status
|
||||||
|
```
|
||||||
|
|
||||||
|
### Marts
|
||||||
|
|
||||||
|
`fact_ks4_destinations` and `fact_ks5_destinations`, **long format**:
|
||||||
|
|
||||||
|
```
|
||||||
|
urn, year, pupil_group, destination_category, cohort_pupils, pupils, percentage, status
|
||||||
|
```
|
||||||
|
|
||||||
|
This departs from the wide house pattern (`fact_ks4_performance` and friends) on
|
||||||
|
purpose. `pupil_group` is a genuine third dimension; going wide would need three
|
||||||
|
sets of every column, and R2 is far easier to test on rows than on columns.
|
||||||
|
|
||||||
|
Roughly 8 categories × 3 groups × 4,946 schools × 3 years ≈ 356k rows.
|
||||||
|
|
||||||
|
`fact_destination_national` carries the same grain for England, so the page's
|
||||||
|
England reference repoints with the switch.
|
||||||
|
|
||||||
|
### dbt tests
|
||||||
|
|
||||||
|
- `assert_destinations_no_derived_remainder` — for every (urn, year,
|
||||||
|
pupil_group) with exactly one suppressed category, assert no aggregate row
|
||||||
|
exists that would let the residual be recovered. **This is the R1 guard.**
|
||||||
|
- `assert_destinations_group_masking` — for every (urn, year, category), if the
|
||||||
|
disadvantaged group carries `suppressed`, so does the other-pupils group.
|
||||||
|
**This is the R3 guard**, applied in the mart so no consumer can reach an
|
||||||
|
unmasked combination.
|
||||||
|
- `assert_destination_status_null_agreement` — `pupils is null` wherever
|
||||||
|
`status != 'published'`, and never null where it is.
|
||||||
|
- `assert_destinations_join_dim_school` — no orphaned URNs, matching the
|
||||||
|
existing `assert_no_orphaned_facts` pattern.
|
||||||
|
|
||||||
|
## API
|
||||||
|
|
||||||
|
`GET /api/schools/{urn}` gains a `destinations` block:
|
||||||
|
|
||||||
|
```json
|
||||||
|
{
|
||||||
|
"ks4": {
|
||||||
|
"cohort_year": "2022/23",
|
||||||
|
"published": "2026-04",
|
||||||
|
"groups": {
|
||||||
|
"all": { "cohort": 180, "categories": [ … ], "aggregates": { … } },
|
||||||
|
"disadvantaged": { … },
|
||||||
|
"other": { … }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"ks5": { … }
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Each category carries `pupils`, `percentage` and `status`. **The serialiser never
|
||||||
|
emits a computed remainder**, and a backend test asserts that a group containing a
|
||||||
|
suppressed category serialises no total that closes the gap.
|
||||||
|
|
||||||
|
`null` for the whole block where nothing is published — the frontend renders the
|
||||||
|
empty state from its absence, not from a sentinel.
|
||||||
|
|
||||||
|
## Frontend
|
||||||
|
|
||||||
|
| File | Kind | Job |
|
||||||
|
|---|---|---|
|
||||||
|
| `lib/destinations.ts` | pure | Category list, the academic/college/work grouping, `canAggregate()` enforcing R2, percentage derivation from counts |
|
||||||
|
| `components/school/DestinationsSection.tsx` | server | Section shell, renders **all pupils** into the HTML |
|
||||||
|
| `components/school/DestinationsView.tsx` | client | Cohort switch, card↔bar linkage |
|
||||||
|
| `components/school/Post16DestinationsSection.tsx` | server | Year 13 section, sixth-form schools only |
|
||||||
|
| `app/globals.css` | tokens | Six destination colours, both themes |
|
||||||
|
|
||||||
|
Server-first matches the directory's existing discipline — every component in
|
||||||
|
`components/school/` is a server component except `AdmissionsViewToggle`, which
|
||||||
|
is the precedent this follows. All-pupils figures are in the HTML for crawlers
|
||||||
|
and for no-JS; only the switch and the hover linkage need the client.
|
||||||
|
|
||||||
|
`lib/schoolSections.ts` gains `hasKs4Destinations` / `hasKs5Destinations` flags
|
||||||
|
and the nav items, following the existing `computeSchoolFlags` pattern.
|
||||||
|
|
||||||
|
**Placement** on the secondary template: GCSE results → After Year 11 → After the
|
||||||
|
sixth form → admissions. Destinations follow attainment because they answer "and
|
||||||
|
then what happened".
|
||||||
|
|
||||||
|
**Dating.** The latest destination year is 2022/23, published April 2026, while
|
||||||
|
the site's newest KS4 year is 2024/25. The section header states its own cohort
|
||||||
|
year, or it reads as stale data next to the GCSE section above it.
|
||||||
|
|
||||||
|
## Edge states
|
||||||
|
|
||||||
|
| State | Frequency | Behaviour |
|
||||||
|
|---|---|---|
|
||||||
|
| Whole cohort suppressed | 13% of special, 41% of AP | Section renders the explanation, no chart |
|
||||||
|
| Some categories withheld | 80% of disadvantaged views | Cards degrade individually; **no bar**; table marks withheld rows |
|
||||||
|
| Disadvantaged group suppressed entirely | 5% | Switch drops to two options, gap panel not rendered |
|
||||||
|
| No sixth form | — | Post-16 section not rendered at all — absence is correct, a "no data" placeholder would imply something is missing |
|
||||||
|
| School too new | — | "First figures expected in 2026", not a bare no |
|
||||||
|
|
||||||
|
## Testing
|
||||||
|
|
||||||
|
Per CLAUDE.md, user-facing behaviour extends `e2e/` in the same PR.
|
||||||
|
|
||||||
|
**Unit** — `lib/destinations.ts` is where R1 and R2 live, so it carries the
|
||||||
|
heaviest tests: `canAggregate()` refuses a group containing one suppressed cell,
|
||||||
|
allows one spanning two, and the bar builder refuses to emit segments for any
|
||||||
|
group with suppression. These are the tests that must fail loudly if someone
|
||||||
|
later "fixes" a gap in the chart.
|
||||||
|
|
||||||
|
**dbt** — the three tests above.
|
||||||
|
|
||||||
|
**Backend** — the serialiser emits no closing total for a partially suppressed
|
||||||
|
group.
|
||||||
|
|
||||||
|
**E2E** — a school with full data renders three cards and a bar; a school with a
|
||||||
|
partially suppressed disadvantaged group renders the withheld state and **no bar
|
||||||
|
element**; a suppressed school renders the explanation; a school with no sixth
|
||||||
|
form renders no post-16 section.
|
||||||
|
|
||||||
|
Note the staging caveat: mart changes are inert until the Airflow pipeline runs,
|
||||||
|
and the staging E2E gate runs post-merge.
|
||||||
|
|
||||||
|
## Out of scope
|
||||||
|
|
||||||
|
- **Compare view and rankings.** The long mart shape supports both; neither is
|
||||||
|
built here. Flagged because "% to a school sixth form" is a plausible rankings
|
||||||
|
metric and the mart shape should not have to change to allow it.
|
||||||
|
- **Ethnicity, sex, SEN and prior-attainment breakdowns.** Available in the same
|
||||||
|
file, ingested deliberately not at all — each is a separate editorial decision
|
||||||
|
about what a school page should assert.
|
||||||
|
- **Longer term destinations** (3 and 5 years out) and **Progression to higher
|
||||||
|
education** — separate publications, worth a later look for sixth forms.
|
||||||
|
- **Primary schools.** No KS2 destination measures publication exists; DfE
|
||||||
|
tracking starts at KS4. Naming the secondaries a primary's leavers go to needs
|
||||||
|
the National Pupil Database, which is not publishable at that grain.
|
||||||
|
|
||||||
|
## Risks
|
||||||
|
|
||||||
|
**A later change reintroduces the disclosure.** The likeliest routes are
|
||||||
|
applying `safe_numeric` to a destination column for consistency, adding a
|
||||||
|
`coalesce` in a mart, or — as happened in review — enforcing a disclosure rule
|
||||||
|
at the rendering layer instead of the publishing layer. Mitigation is the dbt
|
||||||
|
tests plus `backend/tests/test_destinations_api.py`, which reconstructs the
|
||||||
|
residual the way an attacker would and asserts it no longer resolves.
|
||||||
|
|
||||||
|
**The two-year lag reads as staleness.** Mitigated by dating the cohort in the
|
||||||
|
section header rather than only in a tooltip.
|
||||||
|
|
||||||
|
**Sixth-form retention will be misread.** "41% went to a school sixth form" says
|
||||||
|
nothing about *which* school. The published file reports destination type, never
|
||||||
|
destination institution. Copy must never imply "stayed on here", and the tooltip
|
||||||
|
should say so.
|
||||||
|
|
||||||
|
**Section length.** The secondary template is already long and this adds two
|
||||||
|
sections. If it becomes a problem the post-16 section is the one to collapse
|
||||||
|
behind a disclosure, not the Year 11 one.
|
||||||
|
|
||||||
|
## Open questions
|
||||||
|
|
||||||
|
1. Is the disadvantage split its own section or a sub-block inside the
|
||||||
|
destinations section? Modelled as a sub-block; it is the most differentiating
|
||||||
|
figure on the page and the most easily misread on a small cohort.
|
||||||
|
2. Do we ingest the apprenticeship level breakdown (intermediate / advanced /
|
||||||
|
higher) now, or collapse to one apprenticeship figure and revisit? Collapsed
|
||||||
|
in this design.
|
||||||
@@ -0,0 +1,368 @@
|
|||||||
|
# Giving schoolcompare a human author: an About page and a blog
|
||||||
|
|
||||||
|
**Date:** 2026-09-02
|
||||||
|
**Status:** Design — awaiting review
|
||||||
|
**Scope:** A named author for the site, an `/about` page, and a Payload-CMS-backed
|
||||||
|
blog at `/blog`.
|
||||||
|
|
||||||
|
## Why
|
||||||
|
|
||||||
|
The site reads as synthetic. Not because of its tone, but because of three
|
||||||
|
specific absences:
|
||||||
|
|
||||||
|
1. **Nobody is accountable for the numbers.** There is no author, no statement
|
||||||
|
of why the site exists, and no one who can be wrong. The only human trace on
|
||||||
|
the entire site is `contact@schoolcompare.co.uk` in the footer.
|
||||||
|
2. **No visible judgement.** Every figure is presented as though it fell out of
|
||||||
|
a machine. Hundreds of editorial decisions went into this codebase — which
|
||||||
|
metrics to show, when a benchmark is invalid, what to suppress — and not one
|
||||||
|
of them is visible to a reader. `isSpecialSchool()` silently drops the
|
||||||
|
England comparison for special schools and PRUs because that comparison is
|
||||||
|
meaningless; nowhere does the site *say* so.
|
||||||
|
3. **The voice is institutional third person.** "schoolcompare brings it all
|
||||||
|
into one place." "Built for parents, governors, journalists." That is
|
||||||
|
brochure register, and it is precisely the register that machine-generated
|
||||||
|
content defaults to.
|
||||||
|
|
||||||
|
There is a second, independent reason. The SEO programme
|
||||||
|
(`2026-08-20-seo-programme-design.md`) defines eight workstreams and none of
|
||||||
|
them address E-E-A-T or authorship. School performance data is YMYL territory;
|
||||||
|
an anonymous site republishing DfE figures has no authorship signal at all. This
|
||||||
|
work fills that hole, and the blog gives W6 (explainer content) somewhere to
|
||||||
|
live.
|
||||||
|
|
||||||
|
### The failure mode to avoid
|
||||||
|
|
||||||
|
The standard fix — a stock photo and "Hi, I'm Tudor, and I'm passionate about
|
||||||
|
education!" — reads as *more* synthetic than the current coldness. Manufactured
|
||||||
|
warmth is a stronger machine-tell than plain institutional voice. Everything
|
||||||
|
here has to be specific, occasionally awkward, and willing to be unflattering,
|
||||||
|
or it makes the problem worse.
|
||||||
|
|
||||||
|
## Positioning
|
||||||
|
|
||||||
|
The author is **Tudor**: first name only, real photograph, no surname, no
|
||||||
|
employer named.
|
||||||
|
|
||||||
|
The credibility claim is deliberately **not** educational expertise. The About
|
||||||
|
page states plainly: *"I'm not an education expert."* Authority comes from two
|
||||||
|
things that are actually true:
|
||||||
|
|
||||||
|
- **Experience.** A parent going through primary admissions in south-west London
|
||||||
|
right now. Google's E-E-A-T leads with Experience, and lived experience of the
|
||||||
|
thing is exactly what the DfE's own service lacks.
|
||||||
|
- **Method.** Every number's provenance is stated, so a reader can check the
|
||||||
|
site rather than trust it.
|
||||||
|
|
||||||
|
This is more durable than borrowed expertise: it cannot be undermined by someone
|
||||||
|
noticing the author has no teaching qualification.
|
||||||
|
|
||||||
|
**Consequence for the design.** A `Person` entity with no surname is a weak
|
||||||
|
search signal and cannot be corroborated off-site. The credibility load
|
||||||
|
therefore shifts onto the methodology being visibly rigorous. That is a design
|
||||||
|
constraint, not a caveat — it is why the About page carries a substantial
|
||||||
|
"how this is built and where it can be wrong" section rather than a short bio.
|
||||||
|
|
||||||
|
### Voice rules
|
||||||
|
|
||||||
|
Applied to About and every post. Recorded here so the voice does not drift.
|
||||||
|
|
||||||
|
- First person singular. "I built", not "we provide".
|
||||||
|
- Concrete over general. "when we were looking at schools in Wandsworth" beats
|
||||||
|
any amount of stated warmth.
|
||||||
|
- State limits before someone else finds them. Every post that presents a
|
||||||
|
metric says what it does not show.
|
||||||
|
- No mission statements, no "passionate about", no invented team.
|
||||||
|
- No em dashes. One of the clearest tells of machine-written prose, which is
|
||||||
|
the exact problem this work exists to fix.
|
||||||
|
- Short sentences. The existing code comments in this repo are already written
|
||||||
|
this way; the prose should match.
|
||||||
|
|
||||||
|
## Scope
|
||||||
|
|
||||||
|
**In:**
|
||||||
|
|
||||||
|
- `/about` — a coded page (not CMS-managed).
|
||||||
|
- `/blog` and `/blog/[slug]` — Payload-backed, with an index and post pages.
|
||||||
|
- Payload CMS installed into the existing Next application.
|
||||||
|
- Footer and navigation links to both.
|
||||||
|
- `Person`, `Organization`, `BlogPosting`, `BreadcrumbList` JSON-LD.
|
||||||
|
- RSS feed and sitemap integration.
|
||||||
|
- One first post, so the blog does not launch empty.
|
||||||
|
|
||||||
|
**Out (deliberately):**
|
||||||
|
|
||||||
|
- Rewriting existing homepage/how-it-works copy into first person. Worth doing,
|
||||||
|
but it would double the review surface of this PR. Separate change.
|
||||||
|
- In-product signed notes on school pages (the "distributed humanity" idea).
|
||||||
|
Revisit once About and the blog exist.
|
||||||
|
- Comments, newsletter, author accounts beyond one.
|
||||||
|
- A team page. There is no team.
|
||||||
|
|
||||||
|
## Architecture
|
||||||
|
|
||||||
|
### Topology
|
||||||
|
|
||||||
|
Payload 3 installs **into the existing Next application** and serves `/admin`
|
||||||
|
from the same container. One image, one deploy, no new service. This is
|
||||||
|
Payload 3's native model and it makes on-demand revalidation trivial, because
|
||||||
|
the CMS hooks run in the same process as the Next cache.
|
||||||
|
|
||||||
|
Accepted costs: the public site's image now carries Payload, so a CMS security
|
||||||
|
patch redeploys the whole site; and the image grows substantially.
|
||||||
|
|
||||||
|
### Two collisions that must be handled
|
||||||
|
|
||||||
|
**1. `/api` is already taken.** `app/api/[...path]/route.ts` is a catch-all that
|
||||||
|
proxies `/api/*` to FastAPI at runtime. Payload's default API route is also
|
||||||
|
`/api`. Left alone, these fight, and the failure is not clean — the catch-all
|
||||||
|
would swallow Payload's admin API calls and forward them to FastAPI.
|
||||||
|
|
||||||
|
Payload's API route is therefore remapped:
|
||||||
|
|
||||||
|
```ts
|
||||||
|
routes: { api: '/cms-api', admin: '/admin' }
|
||||||
|
```
|
||||||
|
|
||||||
|
with its route group at `app/(payload)/cms-api/[...slug]/route.ts`. The
|
||||||
|
`/cms-api` prefix must also be added to the FastAPI proxy's excluded-paths list
|
||||||
|
as a defensive second line.
|
||||||
|
|
||||||
|
**2. `next.config.js` is CommonJS.** Payload's `withPayload()` wrapper is ESM
|
||||||
|
only. The config must become `next.config.mjs`, converting `module.exports` to
|
||||||
|
`export default` and wrapping the export. All existing content — the standalone
|
||||||
|
output, `outputFileTracingIncludes`, the staging `X-Robots-Tag` header block,
|
||||||
|
the CSP — carries over unchanged. This is mechanical but it touches the file
|
||||||
|
that controls staging's noindex, so it needs care and an explicit test.
|
||||||
|
|
||||||
|
### Database
|
||||||
|
|
||||||
|
Payload uses the existing `sc_database` Postgres instance, in its **own
|
||||||
|
`payload` schema**:
|
||||||
|
|
||||||
|
```ts
|
||||||
|
db: postgresAdapter({
|
||||||
|
pool: { connectionString: process.env.DATABASE_URL },
|
||||||
|
schemaName: 'payload',
|
||||||
|
})
|
||||||
|
```
|
||||||
|
|
||||||
|
The frontend container is already on the `backend` Docker network, so it can
|
||||||
|
reach `sc_database:5432` with no networking change. It needs a new
|
||||||
|
`DATABASE_URL` environment variable.
|
||||||
|
|
||||||
|
Schema isolation is not cosmetic. `public` currently holds the application
|
||||||
|
tables and Airflow's metadata, and `scripts/migrate_csv_to_db.py --drop` exists
|
||||||
|
to drop and reimport. Blog content living in its own schema means no data
|
||||||
|
pipeline operation can destroy it.
|
||||||
|
|
||||||
|
**Verified 2026-09-02** (this was an open question when the spec was written).
|
||||||
|
`--drop` calls `run_full_migration()` in `backend/migration.py`, which drops
|
||||||
|
exactly two tables by name:
|
||||||
|
|
||||||
|
```python
|
||||||
|
ks2_tables = ["school_results", "schools"]
|
||||||
|
for tname in ks2_tables:
|
||||||
|
if tname in existing:
|
||||||
|
Base.metadata.tables[tname].drop(bind=engine)
|
||||||
|
```
|
||||||
|
|
||||||
|
There is no `Base.metadata.drop_all()` anywhere in `backend/`, and no
|
||||||
|
`DROP SCHEMA`. The only other drop is `_apply_schema_drops()`, a single
|
||||||
|
schema-qualified `DROP TABLE IF EXISTS marts.fact_parent_view CASCADE`.
|
||||||
|
Nothing sets `search_path`, so the SQLAlchemy metadata resolves to `public`,
|
||||||
|
and `inspector.get_table_names()` does not even enumerate other schemas.
|
||||||
|
|
||||||
|
So the guarantee is stronger than schema isolation alone: `--drop` targets two
|
||||||
|
named tables that Payload does not have, and would not reach `posts`, `media`
|
||||||
|
or `users` even if they shared a schema. The `payload` schema remains the right
|
||||||
|
choice — it protects against a *future* broadening of that script rather than
|
||||||
|
today's behaviour — but the safety claim rests on verified code, not on
|
||||||
|
assumption.
|
||||||
|
|
||||||
|
Putting CMS tables in this instance is consistent with existing practice —
|
||||||
|
Airflow already stores its metadata there.
|
||||||
|
|
||||||
|
### Migrations
|
||||||
|
|
||||||
|
Payload's Postgres adapter auto-pushes schema in development and requires
|
||||||
|
explicit migrations in production. Use `prodMigrations`, which runs pending
|
||||||
|
migrations during server initialisation:
|
||||||
|
|
||||||
|
```ts
|
||||||
|
db: postgresAdapter({ /* ... */, prodMigrations: migrations })
|
||||||
|
```
|
||||||
|
|
||||||
|
This is preferred over a one-shot init container (the `airflow-init` pattern)
|
||||||
|
because the app is a single long-running process and there is no ordering
|
||||||
|
problem to solve. Migration files are generated with `payload migrate:create`
|
||||||
|
and committed, so schema changes travel through the same PR and staging gate as
|
||||||
|
code.
|
||||||
|
|
||||||
|
### Media
|
||||||
|
|
||||||
|
Uploads go to a Docker named volume, consistent with `postgres_data`,
|
||||||
|
`typesense_data` and `airflow_logs`.
|
||||||
|
|
||||||
|
- `staticDir` must be an **absolute** path in Payload 3: `/app/media`.
|
||||||
|
- The container runs as `nextjs` (uid 1001). The Dockerfile must
|
||||||
|
`mkdir -p /app/media && chown nextjs:nodejs /app/media` **before** the volume
|
||||||
|
is mounted, or Docker will create the mountpoint root-owned and every upload
|
||||||
|
will fail with EACCES.
|
||||||
|
- `sharp` moves from `devDependencies` to `dependencies` — Payload needs it at
|
||||||
|
runtime to generate `imageSizes`.
|
||||||
|
- The volume must be added to the backup routine alongside Postgres. A blog
|
||||||
|
post's images are not reproducible from the pipeline.
|
||||||
|
|
||||||
|
### Rendering
|
||||||
|
|
||||||
|
**Constraint:** CI builds the image with no database reachable. Blog pages
|
||||||
|
therefore cannot use build-time `generateStaticParams` — that would either fail
|
||||||
|
the build or bake in an empty post list.
|
||||||
|
|
||||||
|
Instead: ISR. Post and index pages declare a `revalidate` window and render on
|
||||||
|
first request, with Payload `afterChange` / `afterDelete` hooks calling
|
||||||
|
`revalidatePath('/blog')` and `revalidatePath('/blog/' + slug)` for immediate
|
||||||
|
publication. Because Payload runs in the same process, the hook calls
|
||||||
|
`revalidatePath` from `next/cache` directly — no webhook, no shared secret.
|
||||||
|
|
||||||
|
The ISR cache lives on container disk and is cleared by a redeploy. For a
|
||||||
|
single container serving a handful of posts this is fine.
|
||||||
|
|
||||||
|
### Collections
|
||||||
|
|
||||||
|
- **`posts`** — `title`, `slug`, `publishedAt`, `excerpt`, `heroImage`
|
||||||
|
(relation to `media`), `content` (Lexical rich text), `seo` group
|
||||||
|
(`metaTitle`, `metaDescription`), `_status` (drafts enabled).
|
||||||
|
- **`media`** — upload collection, `alt` required, `imageSizes` for thumbnail
|
||||||
|
and hero widths, public read access.
|
||||||
|
- **`users`** — Payload's auth collection. One account. Public creation
|
||||||
|
disabled.
|
||||||
|
|
||||||
|
Drafts are enabled so posts can be written over several sittings and previewed
|
||||||
|
before publication.
|
||||||
|
|
||||||
|
**Payload Blocks** are how posts embed live product components — a real trend
|
||||||
|
chart or comparison table inside a post, rendered from live data rather than
|
||||||
|
screenshotted. This is the main thing the CMS has to earn back against
|
||||||
|
file-based MDX, and it directly serves the goal: showing judgement in context.
|
||||||
|
Ship with one block (a callout/aside for "what this number doesn't tell you");
|
||||||
|
add a live-chart block once a post needs it.
|
||||||
|
|
||||||
|
### Security
|
||||||
|
|
||||||
|
`/admin` is the first authenticated surface on this site. Public, hardened:
|
||||||
|
|
||||||
|
- `PAYLOAD_SECRET` — long, random, set in the Portainer stack environment, never
|
||||||
|
committed. The same variable must exist in staging with a *different* value.
|
||||||
|
- Strong unique password on the single admin account.
|
||||||
|
- Login rate limiting via Payload's `maxLoginAttempts` / `lockTime`.
|
||||||
|
- `X-Robots-Tag: noindex, nofollow` on `/admin/*` and `/cms-api/*`, and a
|
||||||
|
`robots.ts` disallow. The admin panel must never be indexed.
|
||||||
|
- Public user creation disabled; no open registration.
|
||||||
|
- Verify the existing CSP `frame-ancestors` directive does not break the admin
|
||||||
|
panel.
|
||||||
|
|
||||||
|
Residual risk, accepted: a future Payload authentication CVE is live against the
|
||||||
|
public internet. Mitigation is prompt patching, which the staging→prod pipeline
|
||||||
|
already supports. If this becomes uncomfortable, restricting `/admin` at the
|
||||||
|
proxy to LAN/VPN is a one-line change later.
|
||||||
|
|
||||||
|
Staging note: staging runs the same image on `stx.`, so it gets its own admin
|
||||||
|
panel and its own database. It must have its own `PAYLOAD_SECRET` and its own
|
||||||
|
credentials — never production's.
|
||||||
|
|
||||||
|
## Deployment changes
|
||||||
|
|
||||||
|
- `nextjs-app/Dockerfile` — create and chown `/app/media`; ensure Payload's
|
||||||
|
admin bundle and `sharp` survive standalone output file tracing.
|
||||||
|
- `docker-compose.portainer.yml` and the staging equivalent — add
|
||||||
|
`DATABASE_URL` and `PAYLOAD_SECRET` to the `frontend` service, add a
|
||||||
|
`payload_media` volume mounted at `/app/media`, and add
|
||||||
|
`depends_on: sc_database`.
|
||||||
|
- Document both new environment variables in the compose header comment block,
|
||||||
|
which is where this stack records its configuration.
|
||||||
|
|
||||||
|
## SEO
|
||||||
|
|
||||||
|
- `Person` (Tudor, with photo) and `Organization` JSON-LD on `/about`.
|
||||||
|
- `BlogPosting` + `BreadcrumbList` on post pages, with `author` referencing the
|
||||||
|
same `Person`.
|
||||||
|
- Canonical URLs on `/blog` and every post.
|
||||||
|
- Posts and `/about` added to the existing sitemap (`app/sitemap.xml/route.ts`
|
||||||
|
and `app/sitemaps/[...parts]`). Post URLs come from Payload at request time.
|
||||||
|
- RSS feed at `/blog/rss.xml`.
|
||||||
|
- Footer links to both pages, under a new "About" column.
|
||||||
|
|
||||||
|
**Navigation is deliberately left alone.** `Navigation.tsx` renders a bottom tab
|
||||||
|
bar on mobile that already carries four items (Search, Compare, Rankings,
|
||||||
|
Admissions). A fifth tab makes each one cramped at 320px, and About and Blog are
|
||||||
|
both lower-intent than any of the four. Both live in the footer; About
|
||||||
|
additionally gets a byline link from every post, which is where a reader who
|
||||||
|
cares actually asks the question. Revisit only if analytics show people hunting
|
||||||
|
for it.
|
||||||
|
|
||||||
|
## Testing
|
||||||
|
|
||||||
|
Unit (Jest):
|
||||||
|
|
||||||
|
- Post rendering, including a post with no hero image and one with no excerpt.
|
||||||
|
- Slug generation and collision handling.
|
||||||
|
- JSON-LD shape for `BlogPosting` and `Person`.
|
||||||
|
- The `next.config.mjs` conversion preserves the staging `X-Robots-Tag` rule —
|
||||||
|
this guards the riskiest mechanical change in the plan.
|
||||||
|
|
||||||
|
E2E (Playwright, `e2e/`, required by CLAUDE.md for user-facing change):
|
||||||
|
|
||||||
|
- `/about` renders, shows the author name and photo, and is reachable from the
|
||||||
|
footer and nav.
|
||||||
|
- `/blog` lists at least one post; clicking through reaches the post.
|
||||||
|
- A post page renders title, date, body and byline.
|
||||||
|
- `/admin` responds with `noindex` and does not leak a stack trace when
|
||||||
|
unauthenticated.
|
||||||
|
|
||||||
|
Note the known constraint: new journeys cannot be proven in PR checks, because
|
||||||
|
the staging E2E gate runs post-merge.
|
||||||
|
|
||||||
|
## Risks
|
||||||
|
|
||||||
|
| Risk | Mitigation |
|
||||||
|
|---|---|
|
||||||
|
| `next.config.mjs` conversion silently drops the staging noindex header, making staging a crawlable duplicate | Unit test asserting the header rule; verify on staging before promotion |
|
||||||
|
| Payload API route collides with the FastAPI `/api` proxy | Remap to `/cms-api`; add to the proxy's exclusion list |
|
||||||
|
| Media volume mounts root-owned; all uploads fail with EACCES | `mkdir`+`chown` in the Dockerfile before the mount; test an upload on staging |
|
||||||
|
| Build fails or bakes empty content because CI has no DB | No build-time DB access; ISR only |
|
||||||
|
| A pipeline `--drop` destroys blog content | Separate `payload` schema; verify `--drop` blast radius before building |
|
||||||
|
| Media volume not backed up; images unrecoverable | Add `payload_media` to the backup routine |
|
||||||
|
| Payload auth CVE exposed publicly | Prompt patching; proxy restriction available as a fallback |
|
||||||
|
| Blog launches empty or goes stale | Ship with one post; cadence is explicitly "a few times a year", so no cadence is promised anywhere on the page — no dates implying a schedule |
|
||||||
|
|
||||||
|
## Sequence
|
||||||
|
|
||||||
|
Each step is independently reviewable and mergeable.
|
||||||
|
|
||||||
|
1. **Payload foundation** — install, `next.config.mjs` conversion, `payload`
|
||||||
|
schema, `/cms-api` remap, `users` collection, `/admin` hardening, compose and
|
||||||
|
Dockerfile changes. No public-facing change yet. Verify on staging that the
|
||||||
|
site is unchanged and `/admin` works.
|
||||||
|
2. **`/about`** — coded page, photo, `Person`/`Organization` JSON-LD, footer and
|
||||||
|
nav links, e2e journey. Independently valuable and does not depend on the
|
||||||
|
blog.
|
||||||
|
3. **Blog** — `posts` and `media` collections, `/blog` index and post pages, ISR
|
||||||
|
plus revalidation hooks, RSS, sitemap, structured data, e2e journeys.
|
||||||
|
4. **First post** — written in the admin panel, published through the normal
|
||||||
|
flow, proving the whole path end to end.
|
||||||
|
|
||||||
|
Step 1 carries all the infrastructure risk and none of the visible benefit, so
|
||||||
|
it should be verified on staging carefully before step 2 starts.
|
||||||
|
|
||||||
|
## Dependencies on Tudor
|
||||||
|
|
||||||
|
- **A photograph.** Blocks step 2. Nothing else in the plan is blocked by it.
|
||||||
|
- **The first post's subject.** Blocks step 4 only. Suggested: what school
|
||||||
|
performance data cannot tell you — it demonstrates judgement, is genuinely
|
||||||
|
useful, and is the kind of thing an anonymous or machine-written site will not
|
||||||
|
publish.
|
||||||
|
- ~~Confirmation that `scripts/migrate_csv_to_db.py --drop` is schema-scoped.~~
|
||||||
|
**Resolved 2026-09-02** — verified in `backend/migration.py`; see the
|
||||||
|
Database section. No action needed.
|
||||||
+628
-5
@@ -1304,6 +1304,52 @@ test('with the distance feature off, the section is absent rather than empty', a
|
|||||||
.toHaveCount(0);
|
.toHaveCount(0);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A secondary school carrying an EES admissions row, which is what makes its
|
||||||
|
* Admissions section render while the distance feature is dark.
|
||||||
|
*/
|
||||||
|
async function secondarySchoolWithAdmissions(page: Page) {
|
||||||
|
const list = await page.request.get('/api/schools?phase=secondary&page_size=40');
|
||||||
|
if (!list.ok()) return null;
|
||||||
|
const body = await list.json();
|
||||||
|
for (const s of (body?.schools ?? []).slice(0, 25)) {
|
||||||
|
const res = await page.request.get(`/api/schools/${s.urn}`);
|
||||||
|
if (!res.ok()) continue;
|
||||||
|
const detail = await res.json();
|
||||||
|
if (detail?.admissions == null) continue;
|
||||||
|
return { urn: s.urn as number };
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
test('with the distance feature off, a secondary page makes no claim about publication', async ({ page }) => {
|
||||||
|
/*
|
||||||
|
* Shipping dark must not put words in the council's mouth. The secondary
|
||||||
|
* template is the only one that words the absence, and "X has not published
|
||||||
|
* a cut-off distance for this school" is false wherever X does publish and
|
||||||
|
* we are simply withholding it.
|
||||||
|
*
|
||||||
|
* This is why the API omits the key rather than sending null: absent means
|
||||||
|
* "cut-offs are not published at all", null means "this school has none".
|
||||||
|
* Only the second is a fact about the school, and only the second is sayable.
|
||||||
|
*/
|
||||||
|
test.skip(await distanceFeatureIsOn(page),
|
||||||
|
'the admission_distance flag is on in this environment');
|
||||||
|
|
||||||
|
const found = await secondarySchoolWithAdmissions(page);
|
||||||
|
test.skip(found === null, 'no secondary school in the sample has an admissions row');
|
||||||
|
|
||||||
|
await page.goto(`/school/${found!.urn}`);
|
||||||
|
await expect(page.locator('h1').first()).toBeVisible({ timeout: 15_000 });
|
||||||
|
|
||||||
|
// The Admissions section is still there — this is not a test that the whole
|
||||||
|
// section vanished, which would pass for the wrong reason.
|
||||||
|
await expect(page.locator('#admissions')).toHaveCount(1);
|
||||||
|
|
||||||
|
await expect(page.getByText(/has not published a cut-off distance/)).toHaveCount(0);
|
||||||
|
await expect(page.getByText(/Contact the admissions authority/)).toHaveCount(0);
|
||||||
|
});
|
||||||
|
|
||||||
test('/api/flags is not reachable from the public internet', async ({ page }) => {
|
test('/api/flags is not reachable from the public internet', async ({ page }) => {
|
||||||
// It names every unreleased feature and whether it is on. Next reads it
|
// It names every unreleased feature and whether it is on. Next reads it
|
||||||
// server-side over the Docker network; the public proxy must deny it.
|
// server-side over the Docker network; the public proxy must deny it.
|
||||||
@@ -1889,6 +1935,63 @@ async function firstPlaceOfKind(page: Page, kind: string) {
|
|||||||
return hit as { kind: string; slug: string; name: string; count: number };
|
return hit as { kind: string; slug: string; name: string; count: number };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The round trip. Place pages always linked down to school pages; school
|
||||||
|
* pages linked nowhere on the site, so the ~27k of them that carry most of
|
||||||
|
* the inbound authority stranded it — their only anchor pointed at the
|
||||||
|
* school's own website.
|
||||||
|
*
|
||||||
|
* Asserting both directions is the point. A one-way link is what already
|
||||||
|
* existed and is not what this journey is for.
|
||||||
|
*/
|
||||||
|
test('a school page links back into the location layer, and the place page links down', async ({ page }) => {
|
||||||
|
const town = await firstPlaceOfKind(page, 'town');
|
||||||
|
|
||||||
|
// Start from the place page and take its first school, so the pair is
|
||||||
|
// guaranteed to be genuinely related rather than a hardcoded guess.
|
||||||
|
await page.goto(`/schools/${town.slug}`);
|
||||||
|
const schoolHref = await page.locator('a[href^="/school/"]').first()
|
||||||
|
.getAttribute('href');
|
||||||
|
expect(schoolHref, 'the town page listed no school to follow').toBeTruthy();
|
||||||
|
|
||||||
|
await page.goto(schoolHref!);
|
||||||
|
|
||||||
|
// Down: the school page must offer a link back to the town it sits in.
|
||||||
|
const backToTown = page.locator(`a[href="/schools/${town.slug}"]`);
|
||||||
|
await expect(backToTown).toHaveCount(1);
|
||||||
|
await expect(backToTown).toBeVisible();
|
||||||
|
|
||||||
|
// The anchor says what it leads to, which is worth more than "see more".
|
||||||
|
await expect(backToTown).toContainText(town.name, { ignoreCase: true });
|
||||||
|
await expect(backToTown).toContainText(/\d+ schools?/);
|
||||||
|
|
||||||
|
// And the breadcrumb resolves the school into a real hierarchy.
|
||||||
|
const blocks = await page.locator('script[type="application/ld+json"]')
|
||||||
|
.allTextContents();
|
||||||
|
const graph = blocks.join(' ');
|
||||||
|
expect(graph).toContain('"BreadcrumbList"');
|
||||||
|
// The narrower type, not the EducationalOrganization parent it used to be.
|
||||||
|
expect(graph).toContain('"School"');
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The phase variants are the pages this most needs to reach: ~950 of them
|
||||||
|
* were once reachable by nothing at all, absent from every sitemap and
|
||||||
|
* unlinked from the place page. Conditional because not every school sits
|
||||||
|
* in a town that publishes one.
|
||||||
|
*/
|
||||||
|
const phaseLink = page.locator(`a[href^="/schools/${town.slug}/"]`).first();
|
||||||
|
if (await phaseLink.count()) {
|
||||||
|
const phaseHref = await phaseLink.getAttribute('href');
|
||||||
|
expect((await page.request.get(phaseHref!)).status()).toBe(200);
|
||||||
|
await expect(phaseLink).toContainText(/primary|secondary/);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Following it lands on a real page, not a 404.
|
||||||
|
await backToTown.click();
|
||||||
|
await page.waitForURL(new RegExp(`/schools/${town.slug}$`));
|
||||||
|
await expect(page.locator('h1')).toContainText(town.name, { ignoreCase: true });
|
||||||
|
});
|
||||||
|
|
||||||
for (const [kind, prefix, article] of [
|
for (const [kind, prefix, article] of [
|
||||||
['town', '/schools/', 'a'],
|
['town', '/schools/', 'a'],
|
||||||
['authority', '/schools/authority/', 'an'],
|
['authority', '/schools/authority/', 'an'],
|
||||||
@@ -1978,6 +2081,59 @@ test('a place page links its phase variants, and they resolve', async ({ page })
|
|||||||
await expect(page.locator('h1')).toContainText(new RegExp(`${phase} schools in`, 'i'));
|
await expect(page.locator('h1')).toContainText(new RegExp(`${phase} schools in`, 'i'));
|
||||||
});
|
});
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The table shipped with one column of scores. A parent shortlisting from a
|
||||||
|
* town page needs to know whether a school takes their child's age, whether
|
||||||
|
* it is a faith school, and — for a primary — whether it has a nursery,
|
||||||
|
* before a percentage means anything.
|
||||||
|
*
|
||||||
|
* These assert the column headings rather than the values: nursery_provision
|
||||||
|
* and parliamentary_constituency are optional mart columns, and on an
|
||||||
|
* environment whose pipeline has not rebuilt them the API degrades them to
|
||||||
|
* absent. A value assertion would then fail for a data reason, not a code one.
|
||||||
|
*/
|
||||||
|
async function phasedPlace(page: Page, phase: 'primary' | 'secondary') {
|
||||||
|
const place = await firstPlaceOfKind(page, 'town');
|
||||||
|
const detail = await (await page.request.get(`/api/places/town/${place.slug}`)).json();
|
||||||
|
test.skip(!(detail.place.phases ?? []).includes(phase),
|
||||||
|
`no ${phase} page clears the threshold here`);
|
||||||
|
return place;
|
||||||
|
}
|
||||||
|
|
||||||
|
test('a primary place page names each school as well as scoring it', async ({ page }) => {
|
||||||
|
const place = await phasedPlace(page, 'primary');
|
||||||
|
await page.goto(`/schools/${place.slug}/primary`);
|
||||||
|
for (const heading of ['Ages', 'Religious character', 'Nursery', 'Constituency']) {
|
||||||
|
await expect(page.getByRole('columnheader', { name: heading, exact: true }))
|
||||||
|
.toBeVisible();
|
||||||
|
}
|
||||||
|
// age_range rides in on SCHOOL_COLUMNS and predates the optional columns,
|
||||||
|
// so it is the one attribute safe to assert a value for anywhere.
|
||||||
|
await expect(page.locator('table tbody td').filter({ hasText: /^\d+–\d+$/ }).first())
|
||||||
|
.toBeVisible();
|
||||||
|
});
|
||||||
|
|
||||||
|
test('a secondary place page does not ask about nurseries', async ({ page }) => {
|
||||||
|
const place = await phasedPlace(page, 'secondary');
|
||||||
|
await page.goto(`/schools/${place.slug}/secondary`);
|
||||||
|
await expect(page.getByRole('columnheader', { name: 'Ages', exact: true }))
|
||||||
|
.toBeVisible();
|
||||||
|
await expect(page.getByRole('columnheader', { name: 'Nursery', exact: true }))
|
||||||
|
.toHaveCount(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the measure stays beside the school name, not behind a swipe', async ({ page }) => {
|
||||||
|
// Six columns overflow a phone; .tableWrap turns that into a horizontal
|
||||||
|
// scroll. With the measure last, the number the page exists for is the one
|
||||||
|
// off the screen.
|
||||||
|
const place = await phasedPlace(page, 'primary');
|
||||||
|
await page.setViewportSize({ width: 390, height: 844 });
|
||||||
|
await page.goto(`/schools/${place.slug}/primary`);
|
||||||
|
const second = page.locator('table thead th').nth(1);
|
||||||
|
await expect(second).toContainText(/reading, writing/i);
|
||||||
|
await expect(second).toBeInViewport();
|
||||||
|
});
|
||||||
|
|
||||||
test('phase variants are submitted in the places sitemap', async ({ page }) => {
|
test('phase variants are submitted in the places sitemap', async ({ page }) => {
|
||||||
const xml = await (await page.request.get('/sitemaps/places-1.xml')).text();
|
const xml = await (await page.request.get('/sitemaps/places-1.xml')).text();
|
||||||
expect(xml).toMatch(/\/schools\/[a-z0-9-]+\/primary</);
|
expect(xml).toMatch(/\/schools\/[a-z0-9-]+\/primary</);
|
||||||
@@ -2094,12 +2250,32 @@ test('a place page lists its schools alphabetically', async ({ page }) => {
|
|||||||
expect(town).toBeTruthy();
|
expect(town).toBeTruthy();
|
||||||
|
|
||||||
await page.goto(`/schools/${town.slug}`);
|
await page.goto(`/schools/${town.slug}`);
|
||||||
const names = await page.locator('a[href^="/school/"]').allTextContents();
|
|
||||||
expect(names.length).toBeGreaterThan(1);
|
|
||||||
|
|
||||||
const sorted = [...names].sort((a, b) =>
|
/*
|
||||||
a.toLowerCase().localeCompare(b.toLowerCase()));
|
* Per table, not per page.
|
||||||
expect(names).toEqual(sorted);
|
*
|
||||||
|
* An unphased place page renders one table per phase, and an all-through
|
||||||
|
* school legitimately appears in both — so the page's school links are not
|
||||||
|
* one alphabetical run and never were. This assertion used to collect them
|
||||||
|
* all together and only passed because no town it picked happened to hold an
|
||||||
|
* all-through school; when the data gave Abbots Langley one, Breakspeare
|
||||||
|
* School showed up in the primary table and again in the secondary, and the
|
||||||
|
* test failed on correct behaviour.
|
||||||
|
*/
|
||||||
|
const tables = page.locator('table');
|
||||||
|
const tableCount = await tables.count();
|
||||||
|
expect(tableCount).toBeGreaterThan(0);
|
||||||
|
|
||||||
|
let checked = 0;
|
||||||
|
for (let i = 0; i < tableCount; i++) {
|
||||||
|
const names = await tables.nth(i).locator('a[href^="/school/"]').allTextContents();
|
||||||
|
if (names.length < 2) continue; // a one-row table says nothing about order
|
||||||
|
const sorted = [...names].sort((a, b) =>
|
||||||
|
a.toLowerCase().localeCompare(b.toLowerCase()));
|
||||||
|
expect(names, `table ${i + 1} is not alphabetical`).toEqual(sorted);
|
||||||
|
checked++;
|
||||||
|
}
|
||||||
|
expect(checked, 'no table had enough rows to check the ordering').toBeGreaterThan(0);
|
||||||
});
|
});
|
||||||
|
|
||||||
test('the rankings page still orders by score, not name', async ({ page }) => {
|
test('the rankings page still orders by score, not name', async ({ page }) => {
|
||||||
@@ -2111,3 +2287,450 @@ test('the rankings page still orders by score, not name', async ({ page }) => {
|
|||||||
.filter((v: number | null) => v != null);
|
.filter((v: number | null) => v != null);
|
||||||
expect(scores).toEqual([...scores].sort((a: number, b: number) => b - a));
|
expect(scores).toEqual([...scores].sort((a: number, b: number) => b - a));
|
||||||
});
|
});
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Analytics on the location layer.
|
||||||
|
*
|
||||||
|
* Umami counts a pageview for every one of these URLs already. What it cannot
|
||||||
|
* say is which *kind* of location page earns engagement, because all four
|
||||||
|
* families share the /schools/ prefix — and that is the question that decides
|
||||||
|
* whether to keep investing in them.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/** Capture Umami events, with the real script blocked so it cannot clobber
|
||||||
|
* the stub. Must be called before the first navigation. */
|
||||||
|
async function captureEvents(page: Page) {
|
||||||
|
const events: Array<{ name: string; data: Record<string, unknown> }> = [];
|
||||||
|
await page.route('**/analytics.schoolcompare.co.uk/**', (route) => route.abort());
|
||||||
|
await page.exposeFunction('__capture',
|
||||||
|
(name: string, data: Record<string, unknown>) => { events.push({ name, data }); });
|
||||||
|
await page.addInitScript(() => {
|
||||||
|
(window as unknown as { umami: unknown }).umami = {
|
||||||
|
track: (name: string, data: unknown) =>
|
||||||
|
(window as unknown as { __capture: (n: string, d: unknown) => void })
|
||||||
|
.__capture(name, data),
|
||||||
|
};
|
||||||
|
});
|
||||||
|
return events;
|
||||||
|
}
|
||||||
|
|
||||||
|
test('a location page reports which kind of place it is', async ({ page }) => {
|
||||||
|
const events = await captureEvents(page);
|
||||||
|
const place = await firstPlaceOfKind(page, 'authority');
|
||||||
|
|
||||||
|
await page.goto(`/schools/authority/${place.slug}`);
|
||||||
|
await expect.poll(() => events.find((e) => e.name === 'place_viewed'),
|
||||||
|
{ timeout: 10_000 }).toBeTruthy();
|
||||||
|
|
||||||
|
const event = events.find((e) => e.name === 'place_viewed')!;
|
||||||
|
expect(event.data.kind).toBe('authority');
|
||||||
|
expect(event.data.slug).toBe(place.slug);
|
||||||
|
expect(event.data.phase).toBe('all');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('a school reached from a location page is attributed to it, not to direct', async ({ page }) => {
|
||||||
|
/*
|
||||||
|
* The defect this was written for. getNavigationSource had no case for
|
||||||
|
* /schools/, so every school view that came through the location layer was
|
||||||
|
* filed as 'direct' — the bucket you read as "typed the URL". The one
|
||||||
|
* measurement that says whether ~3,900 SEO pages work was reporting the
|
||||||
|
* wrong answer, confidently.
|
||||||
|
*/
|
||||||
|
const events = await captureEvents(page);
|
||||||
|
const place = await firstPlaceOfKind(page, 'town');
|
||||||
|
|
||||||
|
await page.goto(`/schools/${place.slug}`);
|
||||||
|
await page.locator('a[href^="/school/"]').first().click();
|
||||||
|
await page.waitForURL(/\/school\//);
|
||||||
|
|
||||||
|
await expect.poll(() => events.find((e) => e.name === 'school_viewed'),
|
||||||
|
{ timeout: 10_000 }).toBeTruthy();
|
||||||
|
expect(events.find((e) => e.name === 'school_viewed')!.data.from).toBe('place');
|
||||||
|
});
|
||||||
|
|
||||||
|
/*
|
||||||
|
* School autosuggest (spec 2026-08-26).
|
||||||
|
*/
|
||||||
|
async function autosuggestIsOn(page: Page): Promise<boolean> {
|
||||||
|
await page.goto('/');
|
||||||
|
return (await page.getByRole('combobox').count()) > 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
test('the suggest endpoint answers from Typesense', async ({ page }) => {
|
||||||
|
// Not flagged — the endpoint is live even while the UI is dark, so it can
|
||||||
|
// be smoke-tested before the feature is switched on.
|
||||||
|
const res = await page.request.get('/api/suggest?q=brecknock');
|
||||||
|
expect(res.ok()).toBeTruthy();
|
||||||
|
const { suggestions } = await res.json();
|
||||||
|
expect(Array.isArray(suggestions)).toBeTruthy();
|
||||||
|
if (suggestions.length) {
|
||||||
|
// Local authority is what tells two "St Mary's" apart.
|
||||||
|
expect(suggestions[0]).toHaveProperty('school_name');
|
||||||
|
expect(suggestions[0]).toHaveProperty('local_authority');
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test('a one-character query is answered, not rejected', async ({ page }) => {
|
||||||
|
// The keystroke path never errors on ordinary input.
|
||||||
|
const res = await page.request.get('/api/suggest?q=b');
|
||||||
|
expect(res.status()).toBe(200);
|
||||||
|
expect((await res.json()).suggestions).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the suggest response is cacheable', async ({ page }) => {
|
||||||
|
const res = await page.request.get('/api/suggest?q=brecknock');
|
||||||
|
expect(res.headers()['cache-control'] ?? '').toContain('s-maxage');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('typing a school name suggests it, and choosing it opens that school', async ({ page }) => {
|
||||||
|
test.skip(!(await autosuggestIsOn(page)),
|
||||||
|
'the school_autosuggest flag is off in this environment');
|
||||||
|
|
||||||
|
// A school certain to exist in any environment with data.
|
||||||
|
const { schools } = await (await page.request.get('/api/schools?page_size=1')).json();
|
||||||
|
test.skip(!schools?.length, 'no schools in this environment');
|
||||||
|
const name = schools[0].school_name as string;
|
||||||
|
|
||||||
|
await page.goto('/');
|
||||||
|
await page.getByRole('combobox').first().fill(name.slice(0, 12));
|
||||||
|
const option = page.getByRole('option').first();
|
||||||
|
await expect(option).toBeVisible();
|
||||||
|
await option.click();
|
||||||
|
await expect(page).toHaveURL(/\/school\/\d+/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the whole dropdown is reachable, not clipped by the hero', async ({ page }) => {
|
||||||
|
/*
|
||||||
|
* The hero panel had overflow: hidden to clip its artwork to the rounded
|
||||||
|
* corners, and it clipped the dropdown too — 320px of list against 145px of
|
||||||
|
* panel below the input, so roughly half was cut off with nothing to say so.
|
||||||
|
*
|
||||||
|
* toBeVisible() does not catch this: it checks the box is non-empty and not
|
||||||
|
* visibility:hidden, and an ancestor's overflow clips neither. The invariant
|
||||||
|
* that does catch it is that the LAST option is the thing actually painted
|
||||||
|
* at its own coordinates — which fails for clipping and for occlusion alike.
|
||||||
|
*/
|
||||||
|
test.skip(!(await autosuggestIsOn(page)),
|
||||||
|
'the school_autosuggest flag is off in this environment');
|
||||||
|
|
||||||
|
const { schools } = await (await page.request.get('/api/schools?page_size=1')).json();
|
||||||
|
test.skip(!schools?.length, 'no schools in this environment');
|
||||||
|
|
||||||
|
await page.goto('/');
|
||||||
|
await page.getByRole('combobox').first().fill(
|
||||||
|
(schools[0].school_name as string).slice(0, 6));
|
||||||
|
|
||||||
|
const options = page.getByRole('option');
|
||||||
|
await expect(options.first()).toBeVisible();
|
||||||
|
const count = await options.count();
|
||||||
|
|
||||||
|
const painted = await options.nth(count - 1).evaluate((el) => {
|
||||||
|
const r = el.getBoundingClientRect();
|
||||||
|
const hit = document.elementFromPoint(r.left + r.width / 2, r.top + r.height / 2);
|
||||||
|
return { inside: el.contains(hit) || el === hit, bottom: Math.round(r.bottom) };
|
||||||
|
});
|
||||||
|
expect(painted.inside,
|
||||||
|
`the last option is not painted at its own coordinates (bottom ${painted.bottom}) `
|
||||||
|
+ '— an ancestor is clipping or covering the dropdown').toBeTruthy();
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the dropdown does not survive into the results it produced', async ({ page }) => {
|
||||||
|
/*
|
||||||
|
* The bug that took the staging gate down, and it was not a test problem:
|
||||||
|
* after a search the results-page bar still holds the term, so the dropdown
|
||||||
|
* reopened on top of the results and swallowed the click on the first one.
|
||||||
|
* Playwright reported it as "<li role=option> intercepts pointer events"; a
|
||||||
|
* reader would simply have found their first result unclickable.
|
||||||
|
*/
|
||||||
|
test.skip(!(await autosuggestIsOn(page)),
|
||||||
|
'the school_autosuggest flag is off in this environment');
|
||||||
|
|
||||||
|
await page.goto('/');
|
||||||
|
await page.getByRole('combobox').first().fill('school');
|
||||||
|
await expect(page.getByRole('option').first()).toBeVisible();
|
||||||
|
|
||||||
|
await page.getByRole('button', { name: /Search/i }).first().click();
|
||||||
|
await page.waitForURL(/search=school/);
|
||||||
|
|
||||||
|
await expect(page.getByRole('listbox')).toHaveCount(0);
|
||||||
|
// And the results underneath are actually reachable, which is the point.
|
||||||
|
await page.locator('a[href^="/school/"]').first().click({ timeout: 15_000 });
|
||||||
|
await expect(page).toHaveURL(/\/school\//);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('with autosuggest off, the search box is a plain input', async ({ page }) => {
|
||||||
|
test.skip(await autosuggestIsOn(page),
|
||||||
|
'the school_autosuggest flag is on in this environment');
|
||||||
|
|
||||||
|
await page.goto('/');
|
||||||
|
await expect(page.getByRole('combobox')).toHaveCount(0);
|
||||||
|
// And the box still works: the existing search must be untouched.
|
||||||
|
await page.getByPlaceholder(/School name or postcode/i).first().fill('abbey');
|
||||||
|
await page.getByRole('button', { name: /Search/i }).first().click();
|
||||||
|
await expect(page).toHaveURL(/search=abbey/);
|
||||||
|
});
|
||||||
|
|
||||||
|
// ── Destination measures ───────────────────────────────────────────────────
|
||||||
|
//
|
||||||
|
// Two failure modes have to be told apart here, and conflating them is how
|
||||||
|
// this suite would either hide a regression or block the promotion pipeline:
|
||||||
|
//
|
||||||
|
// * the backend does not serve the `destinations` field at all — a code
|
||||||
|
// regression, or a deploy that did not land. FAILS.
|
||||||
|
// * the field is served but every school is empty — the annual EES DAG has
|
||||||
|
// not run on this environment yet. SKIPS, loudly.
|
||||||
|
//
|
||||||
|
// The second is a data-load precondition, not a defect, and it is true for
|
||||||
|
// every commit between this merging and the DAG being triggered. Failing on it
|
||||||
|
// would redden the staging gate for unrelated work. This is not the quiet skip
|
||||||
|
// 4f01fbd removed from the distance journeys: that one hid a broken feature
|
||||||
|
// behind a flag check, whereas the assertion that the code is deployed and
|
||||||
|
// correctly shaped still runs here on every commit.
|
||||||
|
|
||||||
|
async function secondaryWithDestinations(page: Page): Promise<{
|
||||||
|
urn: string; destinations: any;
|
||||||
|
}> {
|
||||||
|
const res = await page.request.get('/api/schools?search=school&per_page=100');
|
||||||
|
expect(res.ok()).toBeTruthy();
|
||||||
|
const body = await res.json();
|
||||||
|
const urns: string[] = (body.schools ?? [])
|
||||||
|
.filter((s: { phase?: string; attainment_8_score?: number | null }) =>
|
||||||
|
s.phase === 'Secondary' && s.attainment_8_score != null)
|
||||||
|
.map((s: { urn: number }) => String(s.urn));
|
||||||
|
expect(urns.length).toBeGreaterThan(0);
|
||||||
|
|
||||||
|
let served = false;
|
||||||
|
for (const urn of urns.slice(0, 25)) {
|
||||||
|
const detail = await page.request.get(`/api/schools/${urn}`);
|
||||||
|
if (!detail.ok()) continue;
|
||||||
|
const data = await detail.json();
|
||||||
|
// The key must exist, even as null. Its absence means the backend in front
|
||||||
|
// of us does not know about destinations at all.
|
||||||
|
if ('destinations' in data) served = true;
|
||||||
|
if (data.destinations?.ks4) return { urn, destinations: data.destinations };
|
||||||
|
}
|
||||||
|
|
||||||
|
expect(served,
|
||||||
|
'GET /api/schools/{urn} served no `destinations` key at all — the backend '
|
||||||
|
+ 'is missing this feature, not merely missing its data').toBeTruthy();
|
||||||
|
|
||||||
|
test.skip(true,
|
||||||
|
'No school has destination data yet: the annual EES DAG has not run on '
|
||||||
|
+ 'this environment. The API shape is correct, so this is a data-load '
|
||||||
|
+ 'precondition rather than a regression.');
|
||||||
|
throw new Error('unreachable');
|
||||||
|
}
|
||||||
|
|
||||||
|
test('a secondary school page says where its Year 11 leavers went', async ({ page }) => {
|
||||||
|
const { urn } = await secondaryWithDestinations(page);
|
||||||
|
await page.goto(`/school/${urn}`);
|
||||||
|
|
||||||
|
const section = page.locator('#destinations');
|
||||||
|
await expect(section).toBeVisible({ timeout: 15_000 });
|
||||||
|
await expect(section.getByRole('heading', { name: 'After Year 11' })).toBeVisible();
|
||||||
|
// The section must date its own cohort: destinations run about two GCSE
|
||||||
|
// years behind the results above them, and an undated figure reads as stale.
|
||||||
|
await expect(section).toContainText(/20\d{2}\/\d{2}/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the destinations bar is absent entirely whenever a figure is withheld', async ({ page }) => {
|
||||||
|
const { urn, destinations } = await secondaryWithDestinations(page);
|
||||||
|
await page.goto(`/school/${urn}`);
|
||||||
|
const section = page.locator('#destinations');
|
||||||
|
await expect(section).toBeVisible({ timeout: 15_000 });
|
||||||
|
|
||||||
|
const allGroup = destinations.ks4.groups.all;
|
||||||
|
const suppressed = (allGroup?.categories ?? [])
|
||||||
|
.filter((c: { status: string }) => c.status === 'suppressed');
|
||||||
|
|
||||||
|
if (suppressed.length > 0) {
|
||||||
|
// R1: a bar drawn from the published segments leaves a gap whose width is
|
||||||
|
// the withheld figure, readable straight off the axis.
|
||||||
|
await expect(section.locator('[data-destination-segment]')).toHaveCount(0);
|
||||||
|
await expect(section.getByText(/withheld/i).first()).toBeVisible();
|
||||||
|
} else {
|
||||||
|
const published = (allGroup?.categories ?? [])
|
||||||
|
.filter((c: { status: string }) => c.status === 'published');
|
||||||
|
await expect(section.locator('[data-destination-segment]'))
|
||||||
|
.toHaveCount(published.length);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test('switching to disadvantaged pupils never reveals a withheld figure', async ({ page }) => {
|
||||||
|
const { urn, destinations } = await secondaryWithDestinations(page);
|
||||||
|
const disadvantaged = destinations.ks4.groups.disadvantaged;
|
||||||
|
test.skip(!disadvantaged, 'this school publishes no disadvantaged breakdown');
|
||||||
|
|
||||||
|
await page.goto(`/school/${urn}`);
|
||||||
|
const section = page.locator('#destinations');
|
||||||
|
await expect(section).toBeVisible({ timeout: 15_000 });
|
||||||
|
|
||||||
|
const radio = section.getByRole('radio', { name: /disadvantaged/i });
|
||||||
|
await expect(radio).toBeVisible();
|
||||||
|
await radio.click();
|
||||||
|
|
||||||
|
const suppressed = (disadvantaged.categories ?? [])
|
||||||
|
.filter((c: { status: string }) => c.status === 'suppressed');
|
||||||
|
if (suppressed.length > 0) {
|
||||||
|
await expect(section.locator('[data-destination-segment]')).toHaveCount(0);
|
||||||
|
|
||||||
|
// The residual must appear nowhere on the page — it is the withheld figure.
|
||||||
|
const cohort: number = disadvantaged.cohort;
|
||||||
|
const publishedTotal = (disadvantaged.categories ?? [])
|
||||||
|
.filter((c: { status: string }) => c.status === 'published')
|
||||||
|
.reduce((sum: number, c: { pupils: number }) => sum + c.pupils, 0);
|
||||||
|
const residual = cohort - publishedTotal;
|
||||||
|
const text = (await section.textContent()) ?? '';
|
||||||
|
expect(text).not.toMatch(new RegExp(`\\b${residual}\\b`));
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test('a school with no sixth form has no post-16 destinations section', async ({ page }) => {
|
||||||
|
const res = await page.request.get('/api/schools?search=school&per_page=100');
|
||||||
|
const body = await res.json();
|
||||||
|
const noSixthForm = (body.schools ?? [])
|
||||||
|
.filter((s: { phase?: string; has_sixth_form?: boolean }) =>
|
||||||
|
s.phase === 'Secondary' && s.has_sixth_form === false)
|
||||||
|
.map((s: { urn: number }) => String(s.urn));
|
||||||
|
test.skip(noSixthForm.length === 0, 'no sixth-form-less secondary in this dataset');
|
||||||
|
|
||||||
|
await page.goto(`/school/${noSixthForm[0]}`);
|
||||||
|
await expect(page.locator('h1').first()).toBeVisible({ timeout: 15_000 });
|
||||||
|
// Absence is the correct statement, so there must be no placeholder either.
|
||||||
|
await expect(page.locator('#post16-destinations')).toHaveCount(0);
|
||||||
|
await expect(page.getByText(/destination data coming soon/i)).toHaveCount(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the destinations section never claims a pupil stayed at this school', async ({ page }) => {
|
||||||
|
const { urn } = await secondaryWithDestinations(page);
|
||||||
|
await page.goto(`/school/${urn}`);
|
||||||
|
const section = page.locator('#destinations');
|
||||||
|
await expect(section).toBeVisible({ timeout: 15_000 });
|
||||||
|
// The published file records the TYPE of place a leaver went to, never which
|
||||||
|
// one, so the page can never say a pupil stayed on here.
|
||||||
|
const text = (await section.textContent()) ?? '';
|
||||||
|
expect(text).not.toMatch(/stayed on (here|at this school)/i);
|
||||||
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The About page and the blog exist to give the site a named human author.
|
||||||
|
* These journeys assert the load-bearing parts of that — a name, a face, the
|
||||||
|
* honesty claim, and a resolvable Person entity — rather than exact copy,
|
||||||
|
* which will be edited.
|
||||||
|
*
|
||||||
|
* Both are behind flags (about_page, blog), so each has a lit journey and a
|
||||||
|
* dark one. Flag state is read from the observable effect rather than from
|
||||||
|
* /api/flags, which the public proxy denies on purpose — the same approach
|
||||||
|
* distanceFeatureIsOn() takes above.
|
||||||
|
*/
|
||||||
|
async function aboutPageIsOn(page: Page): Promise<boolean> {
|
||||||
|
return (await page.request.get('/about')).ok();
|
||||||
|
}
|
||||||
|
|
||||||
|
async function blogIsOn(page: Page): Promise<boolean> {
|
||||||
|
return (await page.request.get('/blog')).ok();
|
||||||
|
}
|
||||||
|
|
||||||
|
test('with the about page off, it is absent rather than empty', async ({ page }) => {
|
||||||
|
test.skip(await aboutPageIsOn(page), 'the about_page flag is on in this environment');
|
||||||
|
|
||||||
|
// Dark means the URL does not exist, not that it renders empty: a 404 is
|
||||||
|
// what stops a crawler keeping the page in its index.
|
||||||
|
expect((await page.request.get('/about')).status()).toBe(404);
|
||||||
|
|
||||||
|
// A footer link into a 404 is the failure this flag has to avoid.
|
||||||
|
await page.goto('/');
|
||||||
|
await expect(page.locator('footer a[href="/about"]')).toHaveCount(0);
|
||||||
|
|
||||||
|
// And a sitemap must never advertise a URL that 404s.
|
||||||
|
const sitemap = await page.request.get('/content-sitemap.xml');
|
||||||
|
expect(await sitemap.text()).not.toContain('/about');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('with the blog off, it is absent rather than empty', async ({ page }) => {
|
||||||
|
test.skip(await blogIsOn(page), 'the blog flag is on in this environment');
|
||||||
|
|
||||||
|
expect((await page.request.get('/blog')).status()).toBe(404);
|
||||||
|
expect((await page.request.get('/blog/rss.xml')).status()).toBe(404);
|
||||||
|
|
||||||
|
await page.goto('/');
|
||||||
|
await expect(page.locator('footer a[href="/blog"]')).toHaveCount(0);
|
||||||
|
|
||||||
|
const sitemap = await page.request.get('/content-sitemap.xml');
|
||||||
|
expect(await sitemap.text()).not.toContain('/blog');
|
||||||
|
|
||||||
|
// The admin panel is deliberately NOT flagged: posts have to be writable
|
||||||
|
// before the blog is readable, or there is nothing to turn on.
|
||||||
|
expect((await page.request.get('/admin')).status()).not.toBe(404);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the about page names a human author and is reachable from the footer', async ({ page }) => {
|
||||||
|
test.skip(!(await aboutPageIsOn(page)), 'the about_page flag is off in this environment');
|
||||||
|
|
||||||
|
await page.goto('/');
|
||||||
|
const aboutLink = page.locator('footer a[href="/about"]');
|
||||||
|
await expect(aboutLink).toBeVisible();
|
||||||
|
await aboutLink.click();
|
||||||
|
await page.waitForURL(/\/about$/);
|
||||||
|
|
||||||
|
await expect(page.getByRole('heading', { level: 1 })).toContainText('Tudor');
|
||||||
|
await expect(page.locator('img[alt*="Tudor"]')).toBeVisible();
|
||||||
|
|
||||||
|
// The credibility claim is lived experience plus stated provenance, not
|
||||||
|
// expertise. If this sentence ever disappears the positioning has drifted.
|
||||||
|
await expect(page.getByText(/not an education expert/i)).toBeVisible();
|
||||||
|
|
||||||
|
const jsonLd = await page
|
||||||
|
.locator('script[type="application/ld+json"]')
|
||||||
|
.first()
|
||||||
|
.textContent();
|
||||||
|
expect(jsonLd).toContain('"Person"');
|
||||||
|
// First name only — a surname here would be the one place it leaks.
|
||||||
|
expect(jsonLd).not.toMatch(/familyName/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the blog lists posts and each one renders with a byline', async ({ page }) => {
|
||||||
|
test.skip(!(await blogIsOn(page)), 'the blog flag is off in this environment');
|
||||||
|
|
||||||
|
await page.goto('/blog');
|
||||||
|
await expect(page.getByRole('heading', { level: 1 })).toBeVisible();
|
||||||
|
|
||||||
|
const postLinks = page.locator('a[href^="/blog/"]');
|
||||||
|
// Data invariant: staging must carry at least one published post. If this
|
||||||
|
// fails, the environment has no content rather than the code being broken.
|
||||||
|
expect(await postLinks.count()).toBeGreaterThan(0);
|
||||||
|
|
||||||
|
await postLinks.first().click();
|
||||||
|
await page.waitForURL(/\/blog\/.+/);
|
||||||
|
await expect(page.getByRole('heading', { level: 1 })).toBeVisible();
|
||||||
|
await expect(page.getByText(/^By Tudor/)).toBeVisible();
|
||||||
|
|
||||||
|
const jsonLd = await page
|
||||||
|
.locator('script[type="application/ld+json"]')
|
||||||
|
.first()
|
||||||
|
.textContent();
|
||||||
|
expect(jsonLd).toContain('"BlogPosting"');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the admin panel is not indexable', async ({ page }) => {
|
||||||
|
const response = await page.request.get('/admin');
|
||||||
|
expect(response.headers()['x-robots-tag']).toContain('noindex');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the content sitemap lists the about page and is advertised in robots', async ({ page }) => {
|
||||||
|
const sitemap = await page.request.get('/content-sitemap.xml');
|
||||||
|
// Served whatever the flags say: robots.txt names it unconditionally, and
|
||||||
|
// with both dark it is a valid empty urlset rather than a 404.
|
||||||
|
expect(sitemap.ok()).toBeTruthy();
|
||||||
|
|
||||||
|
if (await aboutPageIsOn(page)) {
|
||||||
|
expect(await sitemap.text()).toContain('/about');
|
||||||
|
}
|
||||||
|
|
||||||
|
// The school corpus sitemap is proxied from FastAPI; this one is Next's.
|
||||||
|
// robots.txt must advertise both or the blog never gets discovered.
|
||||||
|
const robots = await page.request.get('/robots.txt');
|
||||||
|
const body = await robots.text();
|
||||||
|
expect(body).toContain('/sitemap.xml');
|
||||||
|
expect(body).toContain('/content-sitemap.xml');
|
||||||
|
});
|
||||||
+12
-4
@@ -1,8 +1,16 @@
|
|||||||
# API Configuration
|
# Browser requests use the same-origin Next.js proxy.
|
||||||
NEXT_PUBLIC_API_URL=http://localhost:8000/api
|
NEXT_PUBLIC_API_URL=/api
|
||||||
|
|
||||||
# Production API URL (for deployment)
|
# Absolute URL for server-side fetching and the proxy; include /api.
|
||||||
# NEXT_PUBLIC_API_URL=https://api.schoolcompare.co.uk/api
|
# In the managed container network this is http://backend:80/api (staging differs).
|
||||||
|
FASTAPI_URL=http://localhost:8000/api
|
||||||
|
|
||||||
|
# Payload CMS runtime configuration. Use the managed environment's database;
|
||||||
|
# Payload owns the payload schema, independently of the school marts.
|
||||||
|
DATABASE_URL=postgresql://schoolcompare:CHANGE_THIS_PASSWORD@localhost:5432/schoolcompare
|
||||||
|
# Generate a secret: python -c "import secrets; print(secrets.token_urlsafe(32))"
|
||||||
|
# Use distinct secrets for staging and production.
|
||||||
|
PAYLOAD_SECRET=CHANGE_THIS_TO_A_SECURE_RANDOM_SECRET
|
||||||
|
|
||||||
# Node Environment
|
# Node Environment
|
||||||
NODE_ENV=development
|
NODE_ENV=development
|
||||||
@@ -39,3 +39,4 @@ yarn-error.log*
|
|||||||
# typescript
|
# typescript
|
||||||
*.tsbuildinfo
|
*.tsbuildinfo
|
||||||
next-env.d.ts
|
next-env.d.ts
|
||||||
|
|
||||||
+12
-288
@@ -1,291 +1,15 @@
|
|||||||
# Deployment Guide
|
# Frontend deployment
|
||||||
|
|
||||||
This guide covers deployment options for the SchoolCompare Next.js application.
|
Next.js and Payload run in the same frontend container. The maintained deployment
|
||||||
|
procedure is [docs/DEPLOY.md](../docs/DEPLOY.md), with the production and staging
|
||||||
|
Portainer compose files at the repository root.
|
||||||
|
|
||||||
## Deployment Options
|
The frontend Dockerfile builds a standalone Next.js image. Runtime configuration
|
||||||
|
supplies `FASTAPI_URL`, `DATABASE_URL` and `PAYLOAD_SECRET`; uploaded CMS media is
|
||||||
|
persisted in a volume. Promote the built image through the repository's Gitea
|
||||||
|
workflow after human staging approval.
|
||||||
|
|
||||||
### Option 1: Vercel (Recommended for Next.js)
|
Earlier Vercel and standalone deployment recipes have been retired from this file
|
||||||
|
because they do not describe the current CMS, persistence and promotion setup.
|
||||||
Vercel is the easiest and most optimized platform for Next.js applications.
|
See [development](../docs/DEVELOPMENT.md) for checks and
|
||||||
|
[publishing](docs/PUBLISHING.md) for CMS operations.
|
||||||
#### Steps:
|
|
||||||
|
|
||||||
1. **Install Vercel CLI**:
|
|
||||||
```bash
|
|
||||||
npm install -g vercel
|
|
||||||
```
|
|
||||||
|
|
||||||
2. **Login to Vercel**:
|
|
||||||
```bash
|
|
||||||
vercel login
|
|
||||||
```
|
|
||||||
|
|
||||||
3. **Deploy**:
|
|
||||||
```bash
|
|
||||||
vercel --prod
|
|
||||||
```
|
|
||||||
|
|
||||||
4. **Configure Environment Variables** in Vercel dashboard:
|
|
||||||
- `NEXT_PUBLIC_API_URL`: Your FastAPI endpoint (e.g., `https://api.schoolcompare.co.uk/api`)
|
|
||||||
- `FASTAPI_URL`: Same as above for server-side requests
|
|
||||||
|
|
||||||
#### Benefits:
|
|
||||||
- Automatic HTTPS
|
|
||||||
- Global CDN
|
|
||||||
- Zero-config deployment
|
|
||||||
- Automatic preview deployments
|
|
||||||
- Built-in analytics
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### Option 2: Docker (Self-hosted)
|
|
||||||
|
|
||||||
Deploy using Docker containers for full control.
|
|
||||||
|
|
||||||
#### Prerequisites:
|
|
||||||
- Docker 20+
|
|
||||||
- Docker Compose 2+
|
|
||||||
|
|
||||||
#### Steps:
|
|
||||||
|
|
||||||
1. **Build Docker Image**:
|
|
||||||
```bash
|
|
||||||
docker build -t schoolcompare-nextjs:latest .
|
|
||||||
```
|
|
||||||
|
|
||||||
2. **Run with Docker Compose**:
|
|
||||||
```bash
|
|
||||||
# Create .env file with production variables
|
|
||||||
echo "NEXT_PUBLIC_API_URL=https://api.schoolcompare.co.uk/api" > .env
|
|
||||||
echo "FASTAPI_URL=http://backend:8000/api" >> .env
|
|
||||||
|
|
||||||
# Start services
|
|
||||||
docker-compose up -d
|
|
||||||
```
|
|
||||||
|
|
||||||
3. **Verify Deployment**:
|
|
||||||
```bash
|
|
||||||
curl http://localhost:3000
|
|
||||||
```
|
|
||||||
|
|
||||||
#### Environment Variables:
|
|
||||||
- `NEXT_PUBLIC_API_URL`: Public API endpoint (client-side)
|
|
||||||
- `FASTAPI_URL`: Internal API endpoint (server-side)
|
|
||||||
- `NODE_ENV`: `production`
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### Option 3: PM2 (Node.js Process Manager)
|
|
||||||
|
|
||||||
Deploy directly on a Node.js server using PM2.
|
|
||||||
|
|
||||||
#### Prerequisites:
|
|
||||||
- Node.js 24+
|
|
||||||
- PM2 (`npm install -g pm2`)
|
|
||||||
|
|
||||||
#### Steps:
|
|
||||||
|
|
||||||
1. **Build Application**:
|
|
||||||
```bash
|
|
||||||
npm run build
|
|
||||||
```
|
|
||||||
|
|
||||||
2. **Create PM2 Ecosystem File** (`ecosystem.config.js`):
|
|
||||||
```javascript
|
|
||||||
module.exports = {
|
|
||||||
apps: [{
|
|
||||||
name: 'schoolcompare-nextjs',
|
|
||||||
script: 'npm',
|
|
||||||
args: 'start',
|
|
||||||
cwd: '/path/to/nextjs-app',
|
|
||||||
instances: 'max',
|
|
||||||
exec_mode: 'cluster',
|
|
||||||
env: {
|
|
||||||
NODE_ENV: 'production',
|
|
||||||
PORT: 3000,
|
|
||||||
NEXT_PUBLIC_API_URL: 'https://api.schoolcompare.co.uk/api',
|
|
||||||
FASTAPI_URL: 'http://localhost:8000/api',
|
|
||||||
},
|
|
||||||
}],
|
|
||||||
};
|
|
||||||
```
|
|
||||||
|
|
||||||
3. **Start with PM2**:
|
|
||||||
```bash
|
|
||||||
pm2 start ecosystem.config.js
|
|
||||||
pm2 save
|
|
||||||
pm2 startup
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### Option 4: Nginx Reverse Proxy
|
|
||||||
|
|
||||||
Use Nginx as a reverse proxy in front of Next.js.
|
|
||||||
|
|
||||||
#### Nginx Configuration:
|
|
||||||
|
|
||||||
```nginx
|
|
||||||
server {
|
|
||||||
listen 80;
|
|
||||||
server_name schoolcompare.co.uk;
|
|
||||||
|
|
||||||
# Redirect to HTTPS
|
|
||||||
return 301 https://$server_name$request_uri;
|
|
||||||
}
|
|
||||||
|
|
||||||
server {
|
|
||||||
listen 443 ssl http2;
|
|
||||||
server_name schoolcompare.co.uk;
|
|
||||||
|
|
||||||
# SSL Configuration
|
|
||||||
ssl_certificate /etc/ssl/certs/schoolcompare.crt;
|
|
||||||
ssl_certificate_key /etc/ssl/private/schoolcompare.key;
|
|
||||||
|
|
||||||
# Security Headers
|
|
||||||
# frame-ancestors replaces X-Frame-Options so the analytics subdomain
|
|
||||||
# (Umami heatmap/recorder) can embed the site in an iframe.
|
|
||||||
add_header Content-Security-Policy "frame-ancestors 'self' https://analytics.schoolcompare.co.uk" always;
|
|
||||||
add_header X-Content-Type-Options "nosniff" always;
|
|
||||||
add_header X-XSS-Protection "1; mode=block" always;
|
|
||||||
|
|
||||||
# Proxy to Next.js
|
|
||||||
location / {
|
|
||||||
proxy_pass http://localhost:3000;
|
|
||||||
proxy_http_version 1.1;
|
|
||||||
proxy_set_header Upgrade $http_upgrade;
|
|
||||||
proxy_set_header Connection 'upgrade';
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_cache_bypass $http_upgrade;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
}
|
|
||||||
|
|
||||||
# Proxy to FastAPI
|
|
||||||
location /api/ {
|
|
||||||
proxy_pass http://localhost:8000;
|
|
||||||
proxy_http_version 1.1;
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
}
|
|
||||||
|
|
||||||
# Cache static files
|
|
||||||
location /_next/static/ {
|
|
||||||
proxy_pass http://localhost:3000;
|
|
||||||
add_header Cache-Control "public, max-age=31536000, immutable";
|
|
||||||
}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Pre-Deployment Checklist
|
|
||||||
|
|
||||||
- [ ] Run `npm run build` successfully
|
|
||||||
- [ ] Run `npm test` - all tests pass
|
|
||||||
- [ ] Environment variables configured
|
|
||||||
- [ ] FastAPI backend accessible
|
|
||||||
- [ ] Database migrations applied
|
|
||||||
- [ ] SSL certificates configured (production)
|
|
||||||
- [ ] Domain DNS configured
|
|
||||||
- [ ] Monitoring/logging set up
|
|
||||||
- [ ] Backup strategy in place
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Post-Deployment Verification
|
|
||||||
|
|
||||||
1. **Health Check**:
|
|
||||||
```bash
|
|
||||||
curl https://schoolcompare.co.uk
|
|
||||||
```
|
|
||||||
|
|
||||||
2. **Test Routes**:
|
|
||||||
- Home: `https://schoolcompare.co.uk/`
|
|
||||||
- School Page: `https://schoolcompare.co.uk/school/100001`
|
|
||||||
- Compare: `https://schoolcompare.co.uk/compare`
|
|
||||||
- Rankings: `https://schoolcompare.co.uk/rankings`
|
|
||||||
|
|
||||||
3. **Check SEO**:
|
|
||||||
- Sitemap: `https://schoolcompare.co.uk/sitemap.xml`
|
|
||||||
- Robots: `https://schoolcompare.co.uk/robots.txt`
|
|
||||||
|
|
||||||
4. **Performance Audit**:
|
|
||||||
- Run Lighthouse in Chrome DevTools
|
|
||||||
- Target scores: 90+ for Performance, Accessibility, Best Practices, SEO
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Monitoring
|
|
||||||
|
|
||||||
### Recommended Tools:
|
|
||||||
- **Vercel Analytics** (if using Vercel)
|
|
||||||
- **Sentry** for error tracking
|
|
||||||
- **Google Analytics** for user analytics
|
|
||||||
- **Uptime Robot** for uptime monitoring
|
|
||||||
|
|
||||||
### Health Check Endpoint:
|
|
||||||
The application automatically serves health data at the root route.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Rollback Procedure
|
|
||||||
|
|
||||||
### Vercel:
|
|
||||||
```bash
|
|
||||||
vercel rollback
|
|
||||||
```
|
|
||||||
|
|
||||||
### Docker:
|
|
||||||
```bash
|
|
||||||
docker-compose down
|
|
||||||
docker-compose up -d --force-recreate
|
|
||||||
```
|
|
||||||
|
|
||||||
### PM2:
|
|
||||||
```bash
|
|
||||||
pm2 stop schoolcompare-nextjs
|
|
||||||
# Restore previous build
|
|
||||||
pm2 start schoolcompare-nextjs
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Troubleshooting
|
|
||||||
|
|
||||||
### Issue: API requests failing
|
|
||||||
- **Solution**: Check `NEXT_PUBLIC_API_URL` and `FASTAPI_URL` environment variables
|
|
||||||
- **Verify**: FastAPI backend is accessible from Next.js container/server
|
|
||||||
|
|
||||||
### Issue: Build fails
|
|
||||||
- **Solution**: Check Node.js version (requires 24+)
|
|
||||||
- **Clear cache**: `rm -rf .next node_modules && npm install && npm run build`
|
|
||||||
|
|
||||||
### Issue: Slow page loads
|
|
||||||
- **Solution**: Enable caching in API calls
|
|
||||||
- **Check**: Network latency to FastAPI backend
|
|
||||||
- **Verify**: CDN is serving static assets
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Security Considerations
|
|
||||||
|
|
||||||
- ✅ HTTPS enabled
|
|
||||||
- ✅ Security headers configured (X-Frame-Options, CSP, etc.)
|
|
||||||
- ✅ API keys in environment variables (never in code)
|
|
||||||
- ✅ CORS properly configured
|
|
||||||
- ✅ Rate limiting on API endpoints
|
|
||||||
- ✅ Regular security updates
|
|
||||||
- ✅ Dependency vulnerability scanning
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Support
|
|
||||||
|
|
||||||
For deployment issues, contact the DevOps team or refer to:
|
|
||||||
- [Next.js Deployment Docs](https://nextjs.org/docs/deployment)
|
|
||||||
- [Vercel Documentation](https://vercel.com/docs)
|
|
||||||
- [Docker Documentation](https://docs.docker.com/)
|
|
||||||
@@ -53,6 +53,13 @@ COPY --from=builder /app/.next/static ./.next/static
|
|||||||
# a miss here is a silent 500 on /opengraph-image, not a build failure.
|
# a miss here is a silent 500 on /opengraph-image, not a build failure.
|
||||||
COPY --from=builder /app/assets ./assets
|
COPY --from=builder /app/assets ./assets
|
||||||
|
|
||||||
|
# Payload writes uploads here, and the compose file mounts a named volume over
|
||||||
|
# it. The directory must exist and be owned by the runtime user BEFORE the
|
||||||
|
# mount: Docker seeds a fresh named volume from the image path, so a missing or
|
||||||
|
# root-owned directory here makes every upload fail with EACCES at runtime,
|
||||||
|
# long after the build passed. The chown below covers it.
|
||||||
|
RUN mkdir -p /app/media
|
||||||
|
|
||||||
# Set correct permissions
|
# Set correct permissions
|
||||||
RUN chown -R nextjs:nodejs /app
|
RUN chown -R nextjs:nodejs /app
|
||||||
|
|
||||||
|
|||||||
+43
-141
@@ -1,156 +1,58 @@
|
|||||||
# SchoolCompare Next.js Application
|
# SchoolCompare frontend and CMS
|
||||||
|
|
||||||
Modern Next.js application for comparing primary school KS2 performance across England.
|
Next.js App Router with React, TypeScript, CSS Modules, Chart.js, Leaflet and
|
||||||
|
Payload CMS. It serves school search, comparisons, rankings, school/place detail
|
||||||
|
pages and editorial content across England.
|
||||||
|
|
||||||
## Features
|
Start with the [repository overview](../README.md),
|
||||||
|
[architecture](../docs/ARCHITECTURE.md) and [development checks](../docs/DEVELOPMENT.md).
|
||||||
|
|
||||||
- **Server-Side Rendering (SSR)**: Fast initial page loads with pre-rendered content
|
## Source map
|
||||||
- **Individual School Pages**: Dedicated pages for each school with full SEO optimization
|
|
||||||
- **Side-by-Side Comparison**: Compare up to 5 schools simultaneously
|
|
||||||
- **School Rankings**: Top-performing schools by various metrics
|
|
||||||
- **Interactive Maps**: Leaflet integration for geographic visualization
|
|
||||||
- **Performance Charts**: Chart.js visualizations for historical data
|
|
||||||
- **Responsive Design**: Mobile-first approach with full responsive support
|
|
||||||
- **SEO Optimized**: Dynamic sitemaps, meta tags, and structured data
|
|
||||||
|
|
||||||
## Tech Stack
|
| Path | Purpose |
|
||||||
|
|---|---|
|
||||||
|
| `app/(frontend)/` | Public root layout, server pages and FastAPI proxy |
|
||||||
|
| `app/(payload)/` | Payload root layout, `/admin` and `/cms-api` |
|
||||||
|
| `app/robots.ts`, `app/opengraph-image.tsx`, root icons | Site-wide metadata endpoints |
|
||||||
|
| `components/` | Client views and reusable display components |
|
||||||
|
| `components/school/` | School detail sections |
|
||||||
|
| `lib/api.ts`, `lib/types.ts` | Fetch wrappers and manual school API types |
|
||||||
|
| `lib/schoolSections.ts`, `lib/compareLogic.ts` | Presentation decisions and data preparation |
|
||||||
|
| `context/`, `hooks/` | Comparison state, suggestion state and responsive behaviour |
|
||||||
|
| `collections/`, `blocks/`, `migrations/` | CMS schema and production migrations |
|
||||||
|
| `__tests__/` | Jest and React Testing Library tests |
|
||||||
|
|
||||||
- **Framework**: Next.js 16 (App Router)
|
Do not introduce a shared `app/layout.tsx`: public pages and Payload have separate
|
||||||
- **Language**: TypeScript 5
|
root layouts. Keep root metadata files outside the route groups.
|
||||||
- **Styling**: CSS Modules + CSS Variables
|
|
||||||
- **State Management**: React Context API + URL state
|
|
||||||
- **Data Fetching**: SWR (client-side) + Next.js fetch (server-side)
|
|
||||||
- **Charts**: Chart.js + react-chartjs-2
|
|
||||||
- **Maps**: Leaflet + react-leaflet
|
|
||||||
- **Testing**: Jest + React Testing Library
|
|
||||||
- **Validation**: Zod
|
|
||||||
|
|
||||||
## Getting Started
|
## Data and state
|
||||||
|
|
||||||
### Prerequisites
|
Server pages fetch initial data directly from `FASTAPI_URL`. Browser fetches use
|
||||||
|
`/api` by default, forwarded by `app/(frontend)/api/[...path]/route.ts`.
|
||||||
|
`FASTAPI_URL` must include `/api`. See `.env.example` for CMS and API settings.
|
||||||
|
|
||||||
- Node.js 24+ (using nvm recommended)
|
State uses React hooks/context, URL search parameters and localStorage for the
|
||||||
- FastAPI backend running on port 8000
|
comparison basket. SWR is not installed. Maps use dynamic Leaflet wrappers.
|
||||||
|
Revalidation intervals are configured in fetch wrappers and pages; they vary by
|
||||||
|
resource. Backend reloads do not automatically invalidate every Next.js cache.
|
||||||
|
|
||||||
### Installation
|
## Commands
|
||||||
|
|
||||||
```bash
|
```sh
|
||||||
# Install dependencies
|
npm ci
|
||||||
npm install
|
npm run typecheck
|
||||||
|
npm test -- --runInBand
|
||||||
# Copy environment variables
|
|
||||||
cp .env.example .env.local
|
|
||||||
|
|
||||||
# Update .env.local with your configuration
|
|
||||||
```
|
|
||||||
|
|
||||||
### Development
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Start development server
|
|
||||||
npm run dev
|
|
||||||
|
|
||||||
# Open http://localhost:3000
|
|
||||||
```
|
|
||||||
|
|
||||||
### Building
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Build for production
|
|
||||||
npm run build
|
npm run build
|
||||||
|
|
||||||
# Start production server
|
|
||||||
npm start
|
|
||||||
```
|
```
|
||||||
|
|
||||||
### Testing
|
`test:watch` and `test:coverage` are also available. There is no `lint` script.
|
||||||
|
A running application needs the backend/data environment described in the
|
||||||
|
[development guide](../docs/DEVELOPMENT.md).
|
||||||
|
|
||||||
```bash
|
After CMS field or editor changes, run `npm run generate:importmap`. Keep
|
||||||
# Run tests
|
`payload-types.ts` generated from the CMS schema rather than editing it by hand.
|
||||||
npm test
|
The build must work without a database connection; avoid module-scope CMS queries
|
||||||
|
and DB-backed `generateStaticParams` functions.
|
||||||
|
|
||||||
# Run tests in watch mode
|
See [publishing](docs/PUBLISHING.md) for CMS operations and
|
||||||
npm run test:watch
|
[deployment](../docs/DEPLOY.md) for staging and production promotion.
|
||||||
|
|
||||||
# Run tests with coverage
|
|
||||||
npm run test:coverage
|
|
||||||
```
|
|
||||||
|
|
||||||
### Linting
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Run ESLint
|
|
||||||
npm run lint
|
|
||||||
```
|
|
||||||
|
|
||||||
## Project Structure
|
|
||||||
|
|
||||||
```
|
|
||||||
nextjs-app/
|
|
||||||
├── app/ # App Router pages
|
|
||||||
│ ├── layout.tsx # Root layout
|
|
||||||
│ ├── page.tsx # Home page
|
|
||||||
│ ├── compare/ # Compare page
|
|
||||||
│ ├── rankings/ # Rankings page
|
|
||||||
│ ├── school/[urn]/ # Individual school pages
|
|
||||||
│ ├── sitemap.ts # Dynamic sitemap
|
|
||||||
│ └── robots.ts # Robots.txt
|
|
||||||
├── components/ # React components
|
|
||||||
│ ├── SchoolCard.tsx # School card component
|
|
||||||
│ ├── FilterBar.tsx # Search/filter controls
|
|
||||||
│ ├── ComparisonView.tsx # Comparison interface
|
|
||||||
│ ├── RankingsView.tsx # Rankings table
|
|
||||||
│ └── ...
|
|
||||||
├── lib/ # Utility libraries
|
|
||||||
│ ├── api.ts # API client
|
|
||||||
│ ├── types.ts # TypeScript types
|
|
||||||
│ └── utils.ts # Helper functions
|
|
||||||
├── hooks/ # Custom React hooks
|
|
||||||
├── context/ # React Context providers
|
|
||||||
├── styles/ # Global styles
|
|
||||||
├── public/ # Static assets
|
|
||||||
└── __tests__/ # Test files
|
|
||||||
```
|
|
||||||
|
|
||||||
## Environment Variables
|
|
||||||
|
|
||||||
| Variable | Description | Default |
|
|
||||||
|----------|-------------|---------|
|
|
||||||
| `NEXT_PUBLIC_API_URL` | Public API endpoint (client-side) | `http://localhost:8000/api` |
|
|
||||||
| `FASTAPI_URL` | Server-side API endpoint | `http://localhost:8000/api` |
|
|
||||||
| `NODE_ENV` | Environment mode | `development` |
|
|
||||||
|
|
||||||
## Performance Optimizations
|
|
||||||
|
|
||||||
- **Server-Side Rendering**: Initial HTML rendered on server
|
|
||||||
- **Static Generation**: Where possible, pages are pre-generated
|
|
||||||
- **Image Optimization**: Next.js Image component with AVIF/WebP support
|
|
||||||
- **Code Splitting**: Automatic route-based code splitting
|
|
||||||
- **Dynamic Imports**: Heavy components loaded on demand
|
|
||||||
- **API Caching**: Configurable revalidation for data fetching
|
|
||||||
- **Bundle Optimization**: Tree shaking and minification
|
|
||||||
- **Compression**: Gzip compression enabled
|
|
||||||
|
|
||||||
## SEO Features
|
|
||||||
|
|
||||||
- **Dynamic Meta Tags**: Generated per page with Next.js Metadata API
|
|
||||||
- **Open Graph**: Social media optimization
|
|
||||||
- **JSON-LD**: Structured data for search engines
|
|
||||||
- **Sitemap**: Auto-generated from database
|
|
||||||
- **Robots.txt**: Search engine crawling rules
|
|
||||||
- **Canonical URLs**: Duplicate content prevention
|
|
||||||
|
|
||||||
## Browser Support
|
|
||||||
|
|
||||||
- Chrome (latest)
|
|
||||||
- Firefox (latest)
|
|
||||||
- Safari (latest)
|
|
||||||
- Edge (latest)
|
|
||||||
|
|
||||||
## License
|
|
||||||
|
|
||||||
Proprietary - SchoolCompare
|
|
||||||
|
|
||||||
## Support
|
|
||||||
|
|
||||||
For issues and questions, please contact the development team.
|
|
||||||
@@ -8,7 +8,7 @@
|
|||||||
// environment provides — under jsdom this suite fails on import, not on an
|
// environment provides — under jsdom this suite fails on import, not on an
|
||||||
// assertion.
|
// assertion.
|
||||||
import { NextRequest } from 'next/server';
|
import { NextRequest } from 'next/server';
|
||||||
import { GET } from '@/app/api/[...path]/route';
|
import { GET } from '@/app/(frontend)/api/[...path]/route';
|
||||||
|
|
||||||
function request(path: string) {
|
function request(path: string) {
|
||||||
return new NextRequest(`http://localhost:3000/api/${path}`);
|
return new NextRequest(`http://localhost:3000/api/${path}`);
|
||||||
|
|||||||
@@ -0,0 +1,34 @@
|
|||||||
|
import { metadata } from '@/app/(frontend)/about/page';
|
||||||
|
import { personJsonLd, organizationJsonLd } from '@/lib/jsonld';
|
||||||
|
|
||||||
|
describe('/about metadata', () => {
|
||||||
|
it('canonicalises to the bare path', () => {
|
||||||
|
expect(metadata.alternates?.canonical)
|
||||||
|
.toBe('https://www.schoolcompare.co.uk/about');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('author structured data', () => {
|
||||||
|
it('describes a Person with a first name and a photo', () => {
|
||||||
|
const person = personJsonLd();
|
||||||
|
expect(person['@type']).toBe('Person');
|
||||||
|
expect(person.name).toBe('Tudor');
|
||||||
|
expect(person.image).toBe('https://www.schoolcompare.co.uk/brand/tudor.jpg');
|
||||||
|
expect(person.url).toBe('https://www.schoolcompare.co.uk/about');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('never publishes a surname or an employer', () => {
|
||||||
|
// Author identity constraint: first name only. A surname here would be
|
||||||
|
// the one place it leaks, since JSON-LD is machine-read and archived.
|
||||||
|
const serialised = JSON.stringify(personJsonLd());
|
||||||
|
expect(serialised).not.toMatch(/familyName|Sitaru/i);
|
||||||
|
expect(serialised).not.toMatch(/worksFor|affiliation/i);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('describes the site as an Organization the Person authors for', () => {
|
||||||
|
const org = organizationJsonLd();
|
||||||
|
expect(org['@type']).toBe('Organization');
|
||||||
|
expect(org.name).toBe('schoolcompare');
|
||||||
|
expect(org.url).toBe('https://www.schoolcompare.co.uk');
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,66 @@
|
|||||||
|
/**
|
||||||
|
* The blog index imports getCachedPayload, which pulls in Payload — ESM-only,
|
||||||
|
* and next/jest will not transform node_modules. Mocking that one module keeps
|
||||||
|
* the page's metadata testable without loading the CMS; the mock is never
|
||||||
|
* called, because `metadata` is a static export evaluated at import time.
|
||||||
|
*/
|
||||||
|
jest.mock('@/lib/payload', () => ({ getCachedPayload: jest.fn() }));
|
||||||
|
|
||||||
|
import { metadata } from '@/app/(frontend)/blog/page';
|
||||||
|
import { blogPostingJsonLd, breadcrumbJsonLd } from '@/lib/jsonld';
|
||||||
|
|
||||||
|
const post = {
|
||||||
|
title: 'What the data cannot tell you',
|
||||||
|
slug: 'what-the-data-cannot-tell-you',
|
||||||
|
excerpt: 'Results describe one year group on a handful of days.',
|
||||||
|
publishedAt: '2026-09-15T00:00:00.000Z',
|
||||||
|
};
|
||||||
|
|
||||||
|
describe('/blog metadata', () => {
|
||||||
|
it('canonicalises to the bare path', () => {
|
||||||
|
expect(metadata.alternates?.canonical)
|
||||||
|
.toBe('https://www.schoolcompare.co.uk/blog');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('BlogPosting structured data', () => {
|
||||||
|
it('names the same Person entity the about page declares', () => {
|
||||||
|
// By @id, not by repeating the person: search engines must resolve every
|
||||||
|
// post and the about page to one author entity, or the site has several.
|
||||||
|
const ld = blogPostingJsonLd(post, { namedAuthor: true });
|
||||||
|
expect(ld['@type']).toBe('BlogPosting');
|
||||||
|
expect(ld.author['@id']).toBe('https://www.schoolcompare.co.uk/about#tudor');
|
||||||
|
expect(ld.publisher['@id']).toBe('https://www.schoolcompare.co.uk#organization');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('attributes to the organization when the about page is dark', () => {
|
||||||
|
/*
|
||||||
|
* The two flags are independent, so blog-on-about-off is a reachable
|
||||||
|
* state. The Person entity lives at /about#tudor and that URL 404s while
|
||||||
|
* the flag is dark, so claiming it would declare an author that resolves
|
||||||
|
* to nothing — worse for the blog's credibility than having no named
|
||||||
|
* author at all. Attribute to the publisher instead.
|
||||||
|
*/
|
||||||
|
const ld = blogPostingJsonLd(post, { namedAuthor: false });
|
||||||
|
expect(ld.author['@id']).toBe('https://www.schoolcompare.co.uk#organization');
|
||||||
|
expect(JSON.stringify(ld)).not.toContain('/about');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('carries a self-referencing canonical url and the publish date', () => {
|
||||||
|
const ld = blogPostingJsonLd(post, { namedAuthor: true });
|
||||||
|
expect(ld.url).toBe(
|
||||||
|
'https://www.schoolcompare.co.uk/blog/what-the-data-cannot-tell-you',
|
||||||
|
);
|
||||||
|
expect(ld.datePublished).toBe('2026-09-15T00:00:00.000Z');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('breadcrumbs', () => {
|
||||||
|
it('places the post under the blog index', () => {
|
||||||
|
const ld = breadcrumbJsonLd(post);
|
||||||
|
expect(ld.itemListElement[0].item).toBe('https://www.schoolcompare.co.uk/blog');
|
||||||
|
expect(ld.itemListElement[1].item).toBe(
|
||||||
|
'https://www.schoolcompare.co.uk/blog/what-the-data-cannot-tell-you',
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -1,7 +1,8 @@
|
|||||||
import { metadata as homeMetadata } from '@/app/page';
|
import { metadata as homeMetadata } from '@/app/(frontend)/page';
|
||||||
import { metadata as rankingsMetadata } from '@/app/rankings/page';
|
import { metadata as rankingsMetadata } from '@/app/(frontend)/rankings/page';
|
||||||
import { metadata as admissionsMetadata } from '@/app/admissions/page';
|
import { metadata as admissionsMetadata } from '@/app/(frontend)/admissions/page';
|
||||||
import { generateMetadata as compareMetadata } from '@/app/compare/page';
|
import { generateMetadata as compareMetadata } from '@/app/(frontend)/compare/page';
|
||||||
|
import { metadata as rootMetadata } from '@/app/(frontend)/layout';
|
||||||
|
|
||||||
describe('canonical URLs', () => {
|
describe('canonical URLs', () => {
|
||||||
it('the homepage canonicalises to the bare root', () => {
|
it('the homepage canonicalises to the bare root', () => {
|
||||||
@@ -128,3 +129,41 @@ describe('C1 snippet copy', () => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The share card must be declared, not inherited.
|
||||||
|
*
|
||||||
|
* `app/opengraph-image.tsx` is a metadata file convention, and it does attach
|
||||||
|
* to routes in the app root segment — `_not-found` gets an og:image from it.
|
||||||
|
* It does NOT attach to the site's pages, which live in the `(frontend)`
|
||||||
|
* route group whose own layout is a root layout. Staging served og:title,
|
||||||
|
* og:description, og:url, og:site_name and og:type and no og:image at all,
|
||||||
|
* so every link pasted into a chat rendered bare.
|
||||||
|
*
|
||||||
|
* The file stays at the app root, because /robots.txt and /icon.png depend on
|
||||||
|
* it being there. The site's root layout points at the route it generates.
|
||||||
|
*/
|
||||||
|
describe('the share card', () => {
|
||||||
|
it('declares an opengraph image on the site root layout', () => {
|
||||||
|
// No og:image means every link pasted into a chat renders bare.
|
||||||
|
const images = rootMetadata.openGraph?.images;
|
||||||
|
expect(images).toBeTruthy();
|
||||||
|
expect(JSON.stringify(images)).toContain('/opengraph-image');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('declares a twitter image too', () => {
|
||||||
|
// twitter.card is summary_large_image. Claiming a large-image card and
|
||||||
|
// supplying no image is worse than claiming a summary card.
|
||||||
|
// Metadata['twitter'] is a union and `card` is not on every member, so
|
||||||
|
// this reads the serialised shape rather than narrowing the type.
|
||||||
|
const twitter = JSON.stringify(rootMetadata.twitter);
|
||||||
|
expect(twitter).toContain('summary_large_image');
|
||||||
|
expect(twitter).toContain('/opengraph-image');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('resolves the card to an absolute url via metadataBase', () => {
|
||||||
|
// The e2e journey does `new URL(ogUrl)`, which throws on a relative path.
|
||||||
|
expect(rootMetadata.metadataBase?.toString())
|
||||||
|
.toBe('https://www.schoolcompare.co.uk/');
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,66 @@
|
|||||||
|
/**
|
||||||
|
* next.config.mjs carries the staging noindex rule. Breaking it turns
|
||||||
|
* stx.schoolcompare.co.uk into a fully crawlable duplicate of production,
|
||||||
|
* and nothing else in the suite would notice.
|
||||||
|
*
|
||||||
|
* The non-null assertions are deliberate: every key asserted here is optional
|
||||||
|
* on NextConfig, and a missing one is precisely the regression under test, so
|
||||||
|
* the assertion below should fail the test rather than the compile.
|
||||||
|
*/
|
||||||
|
import nextConfig from '@/next.config.mjs';
|
||||||
|
|
||||||
|
async function headerRules() {
|
||||||
|
return nextConfig.headers!();
|
||||||
|
}
|
||||||
|
|
||||||
|
describe('next.config.mjs', () => {
|
||||||
|
it('keeps the staging host out of the index', async () => {
|
||||||
|
const headers = await headerRules();
|
||||||
|
const stagingRule = headers.find((rule) =>
|
||||||
|
rule.has?.some(
|
||||||
|
(cond) => cond.type === 'host' && cond.value === 'stx.schoolcompare.co.uk',
|
||||||
|
),
|
||||||
|
);
|
||||||
|
expect(stagingRule).toBeDefined();
|
||||||
|
expect(stagingRule!.headers).toContainEqual({
|
||||||
|
key: 'X-Robots-Tag',
|
||||||
|
value: 'noindex, nofollow',
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it('still emits standalone output for the Docker runner', () => {
|
||||||
|
expect(nextConfig.output).toBe('standalone');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('still traces the share-card fonts into the standalone bundle', () => {
|
||||||
|
expect(nextConfig.outputFileTracingIncludes!['/opengraph-image']).toEqual([
|
||||||
|
'./assets/**',
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('still allows the analytics subdomain to frame the site', async () => {
|
||||||
|
const headers = await headerRules();
|
||||||
|
const csp = headers
|
||||||
|
.flatMap((rule) => rule.headers)
|
||||||
|
.find((header) => header.key === 'Content-Security-Policy');
|
||||||
|
expect(csp).toBeDefined();
|
||||||
|
expect(csp!.value).toContain('https://analytics.schoolcompare.co.uk');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('admin surface', () => {
|
||||||
|
it('serves noindex on the admin panel and the CMS API', async () => {
|
||||||
|
// robots.txt disallows these too, but a Disallow only blocks crawling — a
|
||||||
|
// URL found from an external link can still be indexed without ever being
|
||||||
|
// fetched. This header is what actually keeps them out.
|
||||||
|
const headers = await headerRules();
|
||||||
|
for (const source of ['/admin/:path*', '/cms-api/:path*']) {
|
||||||
|
const rule = headers.find((entry) => entry.source === source);
|
||||||
|
expect(rule).toBeDefined();
|
||||||
|
expect(rule!.headers).toContainEqual({
|
||||||
|
key: 'X-Robots-Tag',
|
||||||
|
value: 'noindex, nofollow',
|
||||||
|
});
|
||||||
|
}
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
import { generateMetadata as placeMeta } from '@/app/schools/[place]/page';
|
import { generateMetadata as placeMeta } from '@/app/(frontend)/schools/[place]/page';
|
||||||
|
|
||||||
jest.mock('@/lib/places', () => ({
|
jest.mock('@/lib/places', () => ({
|
||||||
...jest.requireActual('@/lib/places'),
|
...jest.requireActual('@/lib/places'),
|
||||||
|
|||||||
@@ -0,0 +1,20 @@
|
|||||||
|
import robots from '@/app/robots';
|
||||||
|
|
||||||
|
describe('robots.txt', () => {
|
||||||
|
it('disallows the admin panel and the CMS API', () => {
|
||||||
|
const rules = robots().rules;
|
||||||
|
const rule = Array.isArray(rules) ? rules[0] : rules;
|
||||||
|
expect(rule.disallow).toEqual(
|
||||||
|
expect.arrayContaining(['/api/', '/_next/', '/admin/', '/cms-api/']),
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('sitemap discovery', () => {
|
||||||
|
it('lists both the proxied school sitemap and the Next-owned content sitemap', () => {
|
||||||
|
expect(robots().sitemap).toEqual([
|
||||||
|
'https://www.schoolcompare.co.uk/sitemap.xml',
|
||||||
|
'https://www.schoolcompare.co.uk/content-sitemap.xml',
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,149 @@
|
|||||||
|
import { render, screen } from '@testing-library/react';
|
||||||
|
import { DestinationsSection } from '@/components/school/DestinationsSection';
|
||||||
|
import type { DestinationPhase } from '@/lib/types';
|
||||||
|
import type { DestinationCategory, DestinationStatus } from '@/lib/destinations';
|
||||||
|
|
||||||
|
const cell = (
|
||||||
|
category: DestinationCategory,
|
||||||
|
pupils: number | null,
|
||||||
|
status: DestinationStatus = 'published',
|
||||||
|
) => ({
|
||||||
|
category, pupils,
|
||||||
|
percentage: pupils === null ? null : (pupils / 180) * 100,
|
||||||
|
status,
|
||||||
|
});
|
||||||
|
|
||||||
|
const ALL_PUBLISHED = [
|
||||||
|
cell('school_sixth_form', 75), cell('sixth_form_college', 21),
|
||||||
|
cell('further_education', 55), cell('other_education', 6),
|
||||||
|
cell('apprenticeship', 8), cell('employment', 6),
|
||||||
|
cell('not_sustained', 5), cell('not_captured', 4),
|
||||||
|
];
|
||||||
|
|
||||||
|
const fullPhase: DestinationPhase = {
|
||||||
|
cohort_year: '2022/23',
|
||||||
|
groups: { all: { cohort: 180, categories: ALL_PUBLISHED } },
|
||||||
|
};
|
||||||
|
|
||||||
|
const suppressedPhase: DestinationPhase = {
|
||||||
|
cohort_year: '2022/23',
|
||||||
|
groups: {
|
||||||
|
all: {
|
||||||
|
cohort: 180,
|
||||||
|
categories: [
|
||||||
|
cell('school_sixth_form', 75), cell('sixth_form_college', null, 'suppressed'),
|
||||||
|
cell('further_education', 55), cell('other_education', 6),
|
||||||
|
cell('apprenticeship', 8), cell('employment', 6),
|
||||||
|
cell('not_sustained', 5), cell('not_captured', 4),
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
describe('DestinationsSection', () => {
|
||||||
|
it('dates its own cohort so it is not read as stale next to the GCSE section', () => {
|
||||||
|
render(<DestinationsSection destinations={fullPhase} />);
|
||||||
|
expect(screen.getByText(/2022\/23/)).toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('renders one bar segment per published category', () => {
|
||||||
|
const { container } = render(<DestinationsSection destinations={fullPhase} />);
|
||||||
|
expect(container.querySelectorAll('[data-destination-segment]')).toHaveLength(8);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('renders NO bar at all when a category is withheld', () => {
|
||||||
|
const { container } = render(<DestinationsSection destinations={suppressedPhase} />);
|
||||||
|
// R1: a bar with a gap in it publishes the withheld figure by its width.
|
||||||
|
expect(container.querySelectorAll('[data-destination-segment]')).toHaveLength(0);
|
||||||
|
expect(screen.getAllByText(/withheld/i).length).toBeGreaterThan(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('never states the remainder for a partially suppressed group', () => {
|
||||||
|
const { container } = render(<DestinationsSection destinations={suppressedPhase} />);
|
||||||
|
// 180 cohort - 159 published = 21, the withheld figure. It must appear nowhere.
|
||||||
|
expect(container.textContent).not.toMatch(/\b21\b/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('shows a card value for a group whose components are all published', () => {
|
||||||
|
render(<DestinationsSection destinations={fullPhase} />);
|
||||||
|
// academic route = 75 + 21 = 96 of 180 = 53%
|
||||||
|
expect(screen.getByText('53%')).toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('refuses a card value when one of its components is withheld', () => {
|
||||||
|
render(<DestinationsSection destinations={suppressedPhase} />);
|
||||||
|
// academic route needs sixth_form_college, which is suppressed.
|
||||||
|
expect(screen.getByText(/not published/i)).toBeInTheDocument();
|
||||||
|
expect(screen.queryByText('53%')).not.toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('never claims a pupil stayed at this school', () => {
|
||||||
|
const { container } = render(<DestinationsSection destinations={fullPhase} />);
|
||||||
|
// The published file reports destination TYPE, never destination institution.
|
||||||
|
expect(container.textContent).not.toMatch(/stayed on (here|at this school)/i);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('renders nothing when no group carries categories', () => {
|
||||||
|
const empty: DestinationPhase = { cohort_year: '2022/23', groups: {} };
|
||||||
|
const { container } = render(<DestinationsSection destinations={empty} />);
|
||||||
|
expect(container.firstChild).toBeNull();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('the detail table keeps the three statuses apart', () => {
|
||||||
|
// 'suppressed' and 'not_applicable' are different claims, and the mart, the
|
||||||
|
// SQLAlchemy model and the serialiser all preserve the difference. The table
|
||||||
|
// used to key its Share column off `percentage === null`, which is true for
|
||||||
|
// both, so a category that simply does not apply was labelled "withheld" —
|
||||||
|
// while the Pupils column beside it rendered blank.
|
||||||
|
const mixedPhase: DestinationPhase = {
|
||||||
|
cohort_year: '2022/23',
|
||||||
|
groups: {
|
||||||
|
all: {
|
||||||
|
cohort: 180,
|
||||||
|
categories: [
|
||||||
|
cell('school_sixth_form', 75),
|
||||||
|
cell('sixth_form_college', null, 'suppressed'),
|
||||||
|
cell('further_education', null, 'suppressed'),
|
||||||
|
cell('apprenticeship', null, 'not_applicable'),
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
const rowFor = (container: HTMLElement, category: string) =>
|
||||||
|
Array.from(container.querySelectorAll('tbody tr'))
|
||||||
|
.find(tr => tr.textContent?.includes(category));
|
||||||
|
|
||||||
|
it('never labels a not-applicable category as withheld', () => {
|
||||||
|
const { container } = render(<DestinationsSection destinations={mixedPhase} />);
|
||||||
|
const row = rowFor(container, 'Apprenticeship');
|
||||||
|
expect(row).toBeTruthy();
|
||||||
|
expect(row!.textContent).not.toMatch(/withheld/i);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('labels a genuinely suppressed category as withheld in both columns', () => {
|
||||||
|
const { container } = render(<DestinationsSection destinations={mixedPhase} />);
|
||||||
|
const row = rowFor(container, 'Sixth-form college');
|
||||||
|
expect(row).toBeTruthy();
|
||||||
|
expect(row!.querySelectorAll('td')).toHaveLength(2);
|
||||||
|
Array.from(row!.querySelectorAll('td')).forEach(td =>
|
||||||
|
expect(td.textContent).toMatch(/withheld/i));
|
||||||
|
});
|
||||||
|
|
||||||
|
it('the two columns of a row never disagree about what the row is', () => {
|
||||||
|
const { container } = render(<DestinationsSection destinations={mixedPhase} />);
|
||||||
|
Array.from(container.querySelectorAll('tbody tr')).forEach(tr => {
|
||||||
|
const cells = Array.from(tr.querySelectorAll('td'))
|
||||||
|
.map(td => /withheld/i.test(td.textContent ?? ''));
|
||||||
|
expect(new Set(cells).size).toBe(1);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it('shows a published category its real figures', () => {
|
||||||
|
const { container } = render(<DestinationsSection destinations={mixedPhase} />);
|
||||||
|
const row = rowFor(container, 'State-funded school sixth form');
|
||||||
|
expect(row!.textContent).toMatch(/75/);
|
||||||
|
expect(row!.textContent).toMatch(/42%/);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,110 @@
|
|||||||
|
import { render, screen, fireEvent, waitFor } from '@testing-library/react';
|
||||||
|
import userEvent from '@testing-library/user-event';
|
||||||
|
import { FilterBar } from '@/components/FilterBar';
|
||||||
|
|
||||||
|
const push = jest.fn();
|
||||||
|
let searchParams = new URLSearchParams();
|
||||||
|
jest.mock('next/navigation', () => ({
|
||||||
|
useRouter: () => ({ push, replace: jest.fn(), prefetch: jest.fn() }),
|
||||||
|
usePathname: () => '/',
|
||||||
|
useSearchParams: () => searchParams,
|
||||||
|
}));
|
||||||
|
|
||||||
|
const FILTERS = {
|
||||||
|
local_authorities: [], school_types: [], years: [], phases: [],
|
||||||
|
genders: [], admissions_policies: [],
|
||||||
|
};
|
||||||
|
|
||||||
|
const realFetch = global.fetch;
|
||||||
|
beforeEach(() => {
|
||||||
|
global.fetch = jest.fn(async () => ({
|
||||||
|
ok: true,
|
||||||
|
json: async () => ({ suggestions: [{
|
||||||
|
urn: 100010, school_name: 'Brecknock Primary School',
|
||||||
|
local_authority: 'Camden', postcode: 'NW1 1AA',
|
||||||
|
phase: 'Primary', school_type: 'Community school' }] }),
|
||||||
|
})) as unknown as typeof fetch;
|
||||||
|
push.mockClear();
|
||||||
|
searchParams = new URLSearchParams();
|
||||||
|
});
|
||||||
|
afterEach(() => { global.fetch = realFetch; });
|
||||||
|
|
||||||
|
describe('FilterBar autosuggest', () => {
|
||||||
|
it('is a combobox only when the flag is on', () => {
|
||||||
|
const { rerender } = render(<FilterBar filters={FILTERS} autosuggest={false} />);
|
||||||
|
expect(screen.queryByRole('combobox')).not.toBeInTheDocument();
|
||||||
|
rerender(<FilterBar filters={FILTERS} autosuggest />);
|
||||||
|
expect(screen.getByRole('combobox')).toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('makes no request while the flag is off', async () => {
|
||||||
|
// Off means off: no listener, no fetch, no markup.
|
||||||
|
render(<FilterBar filters={FILTERS} autosuggest={false} />);
|
||||||
|
await userEvent.type(screen.getByPlaceholderText(/School name or postcode/i),
|
||||||
|
'brecknock');
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('shows suggestions and navigates when one is chosen', async () => {
|
||||||
|
render(<FilterBar filters={FILTERS} autosuggest />);
|
||||||
|
await userEvent.type(screen.getByRole('combobox'), 'brecknock');
|
||||||
|
const option = await screen.findByRole('option', { name: /Brecknock/ });
|
||||||
|
await userEvent.click(option);
|
||||||
|
expect(push).toHaveBeenCalledWith(
|
||||||
|
expect.stringContaining('/school/100010'));
|
||||||
|
});
|
||||||
|
|
||||||
|
it('suppresses suggestions once the value is a postcode', async () => {
|
||||||
|
// The box takes a name OR a postcode; suggestions must get out of the way.
|
||||||
|
//
|
||||||
|
// fireEvent.change, not userEvent.type: typing sets "N", "NW", "NW1"... and
|
||||||
|
// "NW1" is not a postcode, so a request for it is correct behaviour. Only
|
||||||
|
// the settled value is the assertion, so set it in one go.
|
||||||
|
render(<FilterBar filters={FILTERS} autosuggest />);
|
||||||
|
fireEvent.change(screen.getByRole('combobox'), { target: { value: 'NW1 1AA' } });
|
||||||
|
await new Promise((r) => setTimeout(r, 300)); // past the 200ms debounce
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('Enter with no active option still submits the free-text search', async () => {
|
||||||
|
// The existing behaviour is preserved, not replaced.
|
||||||
|
render(<FilterBar filters={FILTERS} autosuggest />);
|
||||||
|
const input = screen.getByRole('combobox');
|
||||||
|
await userEvent.type(input, 'brecknock{Enter}');
|
||||||
|
// updateURL pushes inside startTransition, so the call is not synchronous.
|
||||||
|
await waitFor(() => expect(push).toHaveBeenCalledWith(
|
||||||
|
expect.stringContaining('search=brecknock')));
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('FilterBar autosuggest does not reopen over results', () => {
|
||||||
|
it('stays shut when the input arrives pre-filled from the URL', async () => {
|
||||||
|
/*
|
||||||
|
* The results-page bar renders with the search term already in the input.
|
||||||
|
* Opening on that would drop the dropdown on top of the results the search
|
||||||
|
* just produced — which is exactly what happened: the first result became
|
||||||
|
* unclickable, because the list sat over it and swallowed the pointer.
|
||||||
|
*
|
||||||
|
* Suggestions answer typing, not the presence of a value.
|
||||||
|
*/
|
||||||
|
searchParams = new URLSearchParams('search=brecknock');
|
||||||
|
render(<FilterBar filters={FILTERS} autosuggest />);
|
||||||
|
|
||||||
|
expect(screen.getByRole('combobox')).toHaveValue('brecknock');
|
||||||
|
await new Promise((r) => setTimeout(r, 300)); // past the 200ms debounce
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
expect(screen.queryByRole('listbox')).not.toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('closes the dropdown when the search is submitted', async () => {
|
||||||
|
render(<FilterBar filters={FILTERS} autosuggest />);
|
||||||
|
const input = screen.getByRole('combobox');
|
||||||
|
|
||||||
|
await userEvent.type(input, 'brecknock');
|
||||||
|
expect(await screen.findByRole('listbox')).toBeInTheDocument();
|
||||||
|
|
||||||
|
await userEvent.type(input, '{Enter}');
|
||||||
|
await waitFor(() =>
|
||||||
|
expect(screen.queryByRole('listbox')).not.toBeInTheDocument());
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
/**
|
||||||
|
* The footer is the only navigational route to /about and /blog, so it is
|
||||||
|
* where a dark flag would otherwise leave a link into a 404.
|
||||||
|
*
|
||||||
|
* Both props default to false. A caller that forgets to pass them hides the
|
||||||
|
* links, which is the direction that cannot break a page — the same reasoning
|
||||||
|
* as backend/flags.py's "every flag defaults to False".
|
||||||
|
*/
|
||||||
|
import { render, screen } from '@testing-library/react';
|
||||||
|
import { Footer } from '@/components/Footer';
|
||||||
|
|
||||||
|
describe('footer feature links', () => {
|
||||||
|
it('links to both when both flags are on', () => {
|
||||||
|
render(<Footer aboutEnabled blogEnabled />);
|
||||||
|
expect(screen.getByRole('link', { name: /who's behind this/i }))
|
||||||
|
.toHaveAttribute('href', '/about');
|
||||||
|
expect(screen.getByRole('link', { name: /^blog$/i }))
|
||||||
|
.toHaveAttribute('href', '/blog');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('omits the about link when that flag is dark', () => {
|
||||||
|
render(<Footer blogEnabled />);
|
||||||
|
expect(screen.queryByRole('link', { name: /who's behind this/i })).toBeNull();
|
||||||
|
expect(screen.getByRole('link', { name: /^blog$/i })).toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('omits the blog link when that flag is dark', () => {
|
||||||
|
render(<Footer aboutEnabled />);
|
||||||
|
expect(screen.queryByRole('link', { name: /^blog$/i })).toBeNull();
|
||||||
|
expect(screen.getByRole('link', { name: /who's behind this/i }))
|
||||||
|
.toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('drops the whole section when both are dark, not an empty heading', () => {
|
||||||
|
// Shipping dark means the footer renders as it did before the feature
|
||||||
|
// existed, not as a section with its contents removed.
|
||||||
|
render(<Footer />);
|
||||||
|
expect(screen.queryByRole('heading', { name: /^about$/i })).toBeNull();
|
||||||
|
expect(screen.queryByRole('link', { name: /who's behind this/i })).toBeNull();
|
||||||
|
expect(screen.queryByRole('link', { name: /^blog$/i })).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('defaults to dark when a caller passes nothing', () => {
|
||||||
|
render(<Footer />);
|
||||||
|
expect(screen.queryByRole('link', { name: /who's behind this/i })).toBeNull();
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,92 @@
|
|||||||
|
/**
|
||||||
|
* The module that ends the stranding: before it, a school page's only anchor
|
||||||
|
* pointed at the school's own website, so ~27k pages sent authority off-site
|
||||||
|
* and none of it reached the location layer.
|
||||||
|
*/
|
||||||
|
import { render, screen } from '@testing-library/react';
|
||||||
|
import { NearbyPlaces } from '@/components/school/NearbyPlaces';
|
||||||
|
|
||||||
|
const essex = { kind: 'authority', slug: 'essex', name: 'Essex', count: 480, url: '/schools/authority/essex', phases: [] };
|
||||||
|
const brentwood = { kind: 'town', slug: 'brentwood', name: 'Brentwood', count: 37, url: '/schools/brentwood', phases: [] };
|
||||||
|
const cm15 = { kind: 'outcode', slug: 'cm15', name: 'CM15', count: 12, url: '/schools/near/cm15', phases: [] };
|
||||||
|
|
||||||
|
describe('NearbyPlaces', () => {
|
||||||
|
it('links to every place the school belongs to', () => {
|
||||||
|
render(<NearbyPlaces places={[essex, brentwood, cm15]} />);
|
||||||
|
|
||||||
|
expect(screen.getByRole('link', { name: /Brentwood/ }))
|
||||||
|
.toHaveAttribute('href', '/schools/brentwood');
|
||||||
|
expect(screen.getByRole('link', { name: /Essex/ }))
|
||||||
|
.toHaveAttribute('href', '/schools/authority/essex');
|
||||||
|
expect(screen.getByRole('link', { name: /CM15/ }))
|
||||||
|
.toHaveAttribute('href', '/schools/near/cm15');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('says how many schools each link leads to', () => {
|
||||||
|
// An anchor that states its destination's size is worth more to a reader
|
||||||
|
// and to a crawler than "see more".
|
||||||
|
render(<NearbyPlaces places={[brentwood]} />);
|
||||||
|
expect(screen.getByRole('link', { name: /37 schools in Brentwood/ }))
|
||||||
|
.toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('renders nothing at all when the school has no published places', () => {
|
||||||
|
// Not an empty heading. A school whose town and authority both fall below
|
||||||
|
// the threshold has nowhere to point, and the page should look as it did
|
||||||
|
// before the module existed.
|
||||||
|
const { container } = render(<NearbyPlaces places={[]} />);
|
||||||
|
expect(container).toBeEmptyDOMElement();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('puts the narrowest place first, which is the most useful link', () => {
|
||||||
|
// The API orders widest-first for the breadcrumb; a reader on a school
|
||||||
|
// page wants its town before its county.
|
||||||
|
render(<NearbyPlaces places={[essex, brentwood, cm15]} />);
|
||||||
|
const hrefs = screen.getAllByRole('link').map((a) => a.getAttribute('href'));
|
||||||
|
expect(hrefs.indexOf('/schools/brentwood'))
|
||||||
|
.toBeLessThan(hrefs.indexOf('/schools/authority/essex'));
|
||||||
|
});
|
||||||
|
|
||||||
|
it('handles a singular count without saying "1 schools"', () => {
|
||||||
|
render(<NearbyPlaces places={[{ ...brentwood, count: 1 }]} />);
|
||||||
|
expect(screen.getByRole('link', { name: /1 school in Brentwood/ }))
|
||||||
|
.toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('links the phase page the school appears on', () => {
|
||||||
|
// "primary schools in brentwood" is the query these pages exist for.
|
||||||
|
render(<NearbyPlaces places={[{
|
||||||
|
...brentwood,
|
||||||
|
phases: [{ phase: 'primary', count: 22, url: '/schools/brentwood/primary' }],
|
||||||
|
}]} />);
|
||||||
|
|
||||||
|
expect(screen.getByRole('link', { name: /22 primary schools in Brentwood/ }))
|
||||||
|
.toHaveAttribute('href', '/schools/brentwood/primary');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('links both phase pages for an all-through school', () => {
|
||||||
|
render(<NearbyPlaces places={[{
|
||||||
|
...brentwood,
|
||||||
|
phases: [
|
||||||
|
{ phase: 'primary', count: 22, url: '/schools/brentwood/primary' },
|
||||||
|
{ phase: 'secondary', count: 9, url: '/schools/brentwood/secondary' },
|
||||||
|
],
|
||||||
|
}]} />);
|
||||||
|
|
||||||
|
expect(screen.getByRole('link', { name: /22 primary schools/ })).toBeInTheDocument();
|
||||||
|
expect(screen.getByRole('link', { name: /9 secondary schools/ })).toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('keeps a phase link next to the place it belongs to', () => {
|
||||||
|
// Grouping matters: "22 primary schools in Brentwood" directly after
|
||||||
|
// "37 schools in Brentwood" reads as one place, not two unrelated links.
|
||||||
|
render(<NearbyPlaces places={[essex, {
|
||||||
|
...brentwood,
|
||||||
|
phases: [{ phase: 'primary', count: 22, url: '/schools/brentwood/primary' }],
|
||||||
|
}]} />);
|
||||||
|
|
||||||
|
const hrefs = screen.getAllByRole('link').map((a) => a.getAttribute('href'));
|
||||||
|
expect(hrefs.indexOf('/schools/brentwood/primary'))
|
||||||
|
.toBe(hrefs.indexOf('/schools/brentwood') + 1);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -346,3 +346,134 @@ describe('PlaceView unlinkable authorities', () => {
|
|||||||
.toContain('Isles Of Scilly');
|
.toContain('Isles Of Scilly');
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
describe('PlaceView school attributes', () => {
|
||||||
|
/*
|
||||||
|
* The table shipped with one column of scores, which answers "how did they
|
||||||
|
* do" and nothing about whether the school is one a family could use. Age
|
||||||
|
* range, faith, nursery and constituency are the four facts a parent
|
||||||
|
* filters on before they look at a number at all.
|
||||||
|
*/
|
||||||
|
const withAttributes: PlaceDetail = {
|
||||||
|
place: { kind: 'town', slug: 'chelmsford', name: 'Chelmsford', count: 3,
|
||||||
|
parent_authority: 'Essex', phases: ['primary', 'secondary'] },
|
||||||
|
schools: [
|
||||||
|
{ urn: 1, school_name: 'Alpha Primary', phase: 'Primary',
|
||||||
|
rwm_expected_pct: 82, attainment_8_score: null,
|
||||||
|
age_range: '4-11', religious_denomination: 'Church of England',
|
||||||
|
nursery_provision: true,
|
||||||
|
parliamentary_constituency: 'Chelmsford' } as never,
|
||||||
|
{ urn: 2, school_name: 'Beta High', phase: 'Secondary',
|
||||||
|
rwm_expected_pct: null, attainment_8_score: 47,
|
||||||
|
age_range: '11-16', religious_denomination: 'Does not apply',
|
||||||
|
nursery_provision: false,
|
||||||
|
parliamentary_constituency: 'Witham' } as never,
|
||||||
|
],
|
||||||
|
averages: { rwm_expected_pct: 63, attainment_8_score: 45 },
|
||||||
|
};
|
||||||
|
|
||||||
|
function headings(container: HTMLElement, table = 0): string[] {
|
||||||
|
return Array.from(container.querySelectorAll('table')[table]
|
||||||
|
.querySelectorAll('thead th')).map((th) => th.textContent ?? '');
|
||||||
|
}
|
||||||
|
|
||||||
|
it('heads a primary table with all four attributes', () => {
|
||||||
|
const { container } = render(<PlaceView detail={withAttributes}
|
||||||
|
englandAverage={61} neighbours={[]} />);
|
||||||
|
expect(headings(container)).toEqual([
|
||||||
|
'School', 'Reading, writing & maths',
|
||||||
|
'Ages', 'Religious character', 'Nursery', 'Constituency',
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('omits nursery from a secondary table, where it does not apply', () => {
|
||||||
|
const { container } = render(<PlaceView detail={withAttributes}
|
||||||
|
englandAverage={61} neighbours={[]} />);
|
||||||
|
expect(headings(container, 1)).toEqual([
|
||||||
|
'School', 'Attainment 8', 'Ages', 'Religious character', 'Constituency',
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('keeps the measure beside the school name, where a phone can see it', () => {
|
||||||
|
// Six columns overflow a phone and .tableWrap turns that into a swipe.
|
||||||
|
// With the measure last, the one number the page exists for is the one
|
||||||
|
// scrolled off the screen.
|
||||||
|
const { container } = render(<PlaceView detail={withAttributes}
|
||||||
|
phase="primary" englandAverage={61} neighbours={[]} />);
|
||||||
|
expect(headings(container)[1]).toBe('Reading, writing & maths');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('shows the age range without repeating the column heading', () => {
|
||||||
|
render(<PlaceView detail={withAttributes} englandAverage={61}
|
||||||
|
neighbours={[]} />);
|
||||||
|
expect(screen.getByText('4–11')).toBeInTheDocument();
|
||||||
|
expect(screen.queryByText('Ages 4–11')).not.toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('names the faith of a faith school', () => {
|
||||||
|
render(<PlaceView detail={withAttributes} englandAverage={61}
|
||||||
|
neighbours={[]} />);
|
||||||
|
expect(screen.getByText('Church of England')).toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('reads "Does not apply" as no religious character, not as a value', () => {
|
||||||
|
// GIAS spells the absence of a faith as "Does not apply", which is a
|
||||||
|
// database answer rather than an English one. The school page already
|
||||||
|
// suppresses it; the two must not disagree about the same school.
|
||||||
|
const { container } = render(<PlaceView detail={withAttributes}
|
||||||
|
englandAverage={61} neighbours={[]} />);
|
||||||
|
const secondary = container.querySelectorAll('table')[1]
|
||||||
|
.querySelectorAll('tbody td');
|
||||||
|
expect(secondary[3].textContent).toBe('—');
|
||||||
|
expect(screen.queryByText(/Does not apply/)).not.toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('marks a nursery as such and a school without one as not', () => {
|
||||||
|
const { container } = render(<PlaceView detail={withAttributes}
|
||||||
|
englandAverage={61} neighbours={[]} />);
|
||||||
|
const cells = container.querySelectorAll('table')[0]
|
||||||
|
.querySelectorAll('tbody td');
|
||||||
|
expect(cells[4].textContent).toBe('Yes');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('names the constituency of each school', () => {
|
||||||
|
render(<PlaceView detail={withAttributes} englandAverage={61}
|
||||||
|
neighbours={[]} />);
|
||||||
|
expect(screen.getByText('Chelmsford', { selector: 'td' })).toBeInTheDocument();
|
||||||
|
expect(screen.getByText('Witham', { selector: 'td' })).toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('dashes an attribute the data does not carry', () => {
|
||||||
|
// nursery_provision and parliamentary_constituency are absent from marts
|
||||||
|
// the pipeline has not rebuilt, and the API degrades them to null rather
|
||||||
|
// than failing. A row must survive that.
|
||||||
|
const bare: PlaceDetail = {
|
||||||
|
...withAttributes,
|
||||||
|
schools: [{ urn: 3, school_name: 'Gamma Primary', phase: 'Primary',
|
||||||
|
rwm_expected_pct: 70 } as never],
|
||||||
|
};
|
||||||
|
const { container } = render(<PlaceView detail={bare} phase="primary"
|
||||||
|
englandAverage={61} neighbours={[]} />);
|
||||||
|
const cells = Array.from(container.querySelectorAll('tbody td'))
|
||||||
|
.map((td) => td.textContent);
|
||||||
|
expect(cells.slice(2)).toEqual(['—', '—', '—', '—']);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('gives an all-through school its nursery under primary only', () => {
|
||||||
|
// All-through schools render in both groups. Nursery belongs to the
|
||||||
|
// primary reading of the same school, not the secondary one.
|
||||||
|
const allThrough: PlaceDetail = {
|
||||||
|
...withAttributes,
|
||||||
|
schools: [{ urn: 4, school_name: 'Delta Academy', phase: 'All-through',
|
||||||
|
rwm_expected_pct: 66, attainment_8_score: 51,
|
||||||
|
age_range: '4-18', religious_denomination: 'None',
|
||||||
|
nursery_provision: true,
|
||||||
|
parliamentary_constituency: 'Chelmsford' } as never],
|
||||||
|
};
|
||||||
|
const { container } = render(<PlaceView detail={allThrough}
|
||||||
|
englandAverage={61} neighbours={[]} />);
|
||||||
|
const tables = container.querySelectorAll('table');
|
||||||
|
expect(tables[0].textContent).toContain('Yes');
|
||||||
|
expect(tables[1].textContent).not.toContain('Yes');
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
import { render, screen } from '@testing-library/react';
|
||||||
|
import { Post16DestinationsSection } from '@/components/school/Post16DestinationsSection';
|
||||||
|
import type { DestinationPhase } from '@/lib/types';
|
||||||
|
|
||||||
|
const phase: DestinationPhase = {
|
||||||
|
cohort_year: '2022/23',
|
||||||
|
groups: {
|
||||||
|
all: {
|
||||||
|
cohort: 96,
|
||||||
|
categories: [
|
||||||
|
{ category: 'higher_education', pupils: 56, percentage: 58.3, status: 'published' },
|
||||||
|
{ category: 'further_education', pupils: 12, percentage: 12.5, status: 'published' },
|
||||||
|
{ category: 'apprenticeship', pupils: 9, percentage: 9.4, status: 'published' },
|
||||||
|
{ category: 'employment', pupils: 13, percentage: 13.5, status: 'published' },
|
||||||
|
{ category: 'not_sustained', pupils: 6, percentage: 6.3, status: 'published' },
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
describe('Post16DestinationsSection', () => {
|
||||||
|
it('names the Year 13 cohort, not Year 11', () => {
|
||||||
|
const { container } = render(<Post16DestinationsSection destinations={phase} />);
|
||||||
|
expect(container.textContent).toMatch(/Year 13/);
|
||||||
|
expect(container.textContent).not.toMatch(/Year 11/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('reports higher education destinations', () => {
|
||||||
|
render(<Post16DestinationsSection destinations={phase} />);
|
||||||
|
expect(screen.getByText(/UK higher education/i)).toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('uses its own anchor so the nav does not collide with After Year 11', () => {
|
||||||
|
const { container } = render(<Post16DestinationsSection destinations={phase} />);
|
||||||
|
expect(container.querySelector('#post16-destinations')).toBeTruthy();
|
||||||
|
expect(container.querySelector('#destinations')).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('renders nothing when no group carries categories', () => {
|
||||||
|
const empty: DestinationPhase = { cohort_year: '2022/23', groups: {} };
|
||||||
|
const { container } = render(<Post16DestinationsSection destinations={empty} />);
|
||||||
|
expect(container.firstChild).toBeNull();
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
/**
|
||||||
|
* The trail has to be written by something, and it has to be written on every
|
||||||
|
* route — not only the ones that happen to track an event.
|
||||||
|
*/
|
||||||
|
import { render } from '@testing-library/react';
|
||||||
|
|
||||||
|
const recordVisitedPath = jest.fn();
|
||||||
|
let pathname = '/schools/brentwood';
|
||||||
|
|
||||||
|
jest.mock('next/navigation', () => ({ usePathname: () => pathname }));
|
||||||
|
jest.mock('@/lib/analytics', () => ({
|
||||||
|
recordVisitedPath: (p: string) => recordVisitedPath(p),
|
||||||
|
}));
|
||||||
|
|
||||||
|
// eslint-disable-next-line @typescript-eslint/no-var-requires
|
||||||
|
const { RouteTrail } = require('@/components/RouteTrail');
|
||||||
|
|
||||||
|
describe('RouteTrail', () => {
|
||||||
|
beforeEach(() => recordVisitedPath.mockClear());
|
||||||
|
|
||||||
|
it('records the page it is mounted on', () => {
|
||||||
|
render(<RouteTrail />);
|
||||||
|
expect(recordVisitedPath).toHaveBeenCalledWith('/schools/brentwood');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('records each new route as the user moves through the app', () => {
|
||||||
|
const { rerender } = render(<RouteTrail />);
|
||||||
|
pathname = '/school/115429-brentwood-school';
|
||||||
|
rerender(<RouteTrail />);
|
||||||
|
expect(recordVisitedPath).toHaveBeenLastCalledWith(
|
||||||
|
'/school/115429-brentwood-school');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('renders nothing, so it can sit anywhere in the layout', () => {
|
||||||
|
const { container } = render(<RouteTrail />);
|
||||||
|
expect(container).toBeEmptyDOMElement();
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
import { render, screen } from '@testing-library/react';
|
||||||
|
import { SuggestList, suggestOptionId } from '@/components/SuggestList';
|
||||||
|
|
||||||
|
const ROWS = [
|
||||||
|
{ urn: 1, school_name: "St Mary's Primary", local_authority: 'Camden',
|
||||||
|
postcode: 'NW1 1AA', phase: 'Primary', school_type: 'Voluntary aided school' },
|
||||||
|
{ urn: 2, school_name: "St Mary's Primary", local_authority: 'Barnet',
|
||||||
|
postcode: 'EN5 2AA', phase: 'Primary', school_type: 'Community school' },
|
||||||
|
];
|
||||||
|
|
||||||
|
describe('SuggestList', () => {
|
||||||
|
it('is a listbox of options', () => {
|
||||||
|
render(<SuggestList id="s" suggestions={ROWS} activeIndex={-1}
|
||||||
|
onPick={() => {}} onHover={() => {}} />);
|
||||||
|
expect(screen.getByRole('listbox')).toBeInTheDocument();
|
||||||
|
expect(screen.getAllByRole('option')).toHaveLength(2);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('shows the local authority, which is what tells two schools apart', () => {
|
||||||
|
// Both rows are "St Mary's Primary". Without the authority the list is
|
||||||
|
// unusable for exactly the query autosuggest exists to serve.
|
||||||
|
render(<SuggestList id="s" suggestions={ROWS} activeIndex={-1}
|
||||||
|
onPick={() => {}} onHover={() => {}} />);
|
||||||
|
expect(screen.getByText('Camden')).toBeInTheDocument();
|
||||||
|
expect(screen.getByText('Barnet')).toBeInTheDocument();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('marks only the active option selected', () => {
|
||||||
|
render(<SuggestList id="s" suggestions={ROWS} activeIndex={1}
|
||||||
|
onPick={() => {}} onHover={() => {}} />);
|
||||||
|
const options = screen.getAllByRole('option');
|
||||||
|
expect(options[0]).toHaveAttribute('aria-selected', 'false');
|
||||||
|
expect(options[1]).toHaveAttribute('aria-selected', 'true');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('gives each option the id the input will point at', () => {
|
||||||
|
// aria-activedescendant on the input has to name a real element id, or
|
||||||
|
// a screen reader announces nothing as the user arrows through.
|
||||||
|
render(<SuggestList id="s" suggestions={ROWS} activeIndex={0}
|
||||||
|
onPick={() => {}} onHover={() => {}} />);
|
||||||
|
expect(screen.getAllByRole('option')[0]).toHaveAttribute(
|
||||||
|
'id', suggestOptionId('s', 0));
|
||||||
|
});
|
||||||
|
|
||||||
|
it('renders nothing when there is nothing to suggest', () => {
|
||||||
|
const { container } = render(<SuggestList id="s" suggestions={[]}
|
||||||
|
activeIndex={-1} onPick={() => {}} onHover={() => {}} />);
|
||||||
|
expect(container).toBeEmptyDOMElement();
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
import { render } from '@testing-library/react';
|
||||||
|
import { TrackPlaceView } from '@/components/places/TrackPlaceView';
|
||||||
|
|
||||||
|
const trackMock = jest.fn();
|
||||||
|
jest.mock('@/lib/analytics', () => ({
|
||||||
|
track: (...args: unknown[]) => trackMock(...args),
|
||||||
|
getNavigationSource: () => 'search',
|
||||||
|
}));
|
||||||
|
|
||||||
|
describe('TrackPlaceView', () => {
|
||||||
|
beforeEach(() => trackMock.mockClear());
|
||||||
|
|
||||||
|
it('reports which kind of location page was viewed', () => {
|
||||||
|
/*
|
||||||
|
* `kind` is the reason this event exists. Whether to keep investing in the
|
||||||
|
* location layer turns on which *sort* of page earns engagement — towns,
|
||||||
|
* authorities or postcode districts — and a bare pageview cannot say,
|
||||||
|
* because all four families share the /schools/ prefix.
|
||||||
|
*/
|
||||||
|
render(<TrackPlaceView kind="authority" slug="kent" count={412} />);
|
||||||
|
expect(trackMock).toHaveBeenCalledWith('place_viewed', {
|
||||||
|
kind: 'authority', slug: 'kent', phase: 'all',
|
||||||
|
school_count: 412, from: 'search',
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it('names the phase when the page is a phase variant', () => {
|
||||||
|
render(<TrackPlaceView kind="town" slug="brentwood" count={29} phase="primary" />);
|
||||||
|
expect(trackMock).toHaveBeenCalledWith('place_viewed',
|
||||||
|
expect.objectContaining({ phase: 'primary' }));
|
||||||
|
});
|
||||||
|
|
||||||
|
it('fires once, not once per render', () => {
|
||||||
|
const { rerender } = render(
|
||||||
|
<TrackPlaceView kind="town" slug="brentwood" count={29} />);
|
||||||
|
rerender(<TrackPlaceView kind="town" slug="brentwood" count={29} />);
|
||||||
|
expect(trackMock).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('renders nothing', () => {
|
||||||
|
const { container } = render(
|
||||||
|
<TrackPlaceView kind="town" slug="brentwood" count={29} />);
|
||||||
|
expect(container).toBeEmptyDOMElement();
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,192 @@
|
|||||||
|
import fs from 'fs';
|
||||||
|
import path from 'path';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Guards against light-theme-only CSS.
|
||||||
|
*
|
||||||
|
* The site themes entirely through tokens redefined under
|
||||||
|
* `@media (prefers-color-scheme: dark)`. A hardcoded colour therefore does not
|
||||||
|
* fail loudly — it renders perfectly in the theme it was written for and
|
||||||
|
* quietly wrongly in the other, which nobody sees unless they happen to be in
|
||||||
|
* dark mode when they look.
|
||||||
|
*
|
||||||
|
* Both rules below are drawn from real defects in SchoolHeroMap.module.css,
|
||||||
|
* found by eye rather than by any test:
|
||||||
|
*
|
||||||
|
* - the map's fade to the header ramped through hardcoded white and landed on
|
||||||
|
* `var(--bg-card)`. Invisible in light; a bright band across the full width
|
||||||
|
* of a near-black card in dark.
|
||||||
|
* - the controls floating over the map paired a hardcoded white background
|
||||||
|
* with `color: var(--text-primary)`, which resolves to #E9EEF0 in dark —
|
||||||
|
* near-white text on a near-white button.
|
||||||
|
*/
|
||||||
|
|
||||||
|
const COMPONENTS = path.join(__dirname, '..', '..', 'components');
|
||||||
|
|
||||||
|
function stylesheets(dir: string): string[] {
|
||||||
|
return fs.readdirSync(dir, { withFileTypes: true }).flatMap((entry) => {
|
||||||
|
const full = path.join(dir, entry.name);
|
||||||
|
if (entry.isDirectory()) return stylesheets(full);
|
||||||
|
return entry.name.endsWith('.module.css') ? [full] : [];
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Innermost `selector { body }` pairs. Nested at-rules never match as rules,
|
||||||
|
* because their body contains braces.
|
||||||
|
*
|
||||||
|
* Comments are stripped before matching rather than after, so that the whole
|
||||||
|
* selector survives. Taking only its last line — which is what stripping a
|
||||||
|
* leading comment used to require — silently discarded every selector in a
|
||||||
|
* grouped rule but the final one, and a safety guard that cannot see half its
|
||||||
|
* input fails open. */
|
||||||
|
function rules(css: string): Array<{ selector: string; body: string }> {
|
||||||
|
const bare = css.replace(/\/\*[\s\S]*?\*\//g, '');
|
||||||
|
return Array.from(bare.matchAll(/([^{}]+)\{([^{}]*)\}/g), (m) => ({
|
||||||
|
selector: m[1].trim().replace(/\s*\n\s*/g, ' '),
|
||||||
|
body: m[2],
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
const HARDCODED_WHITE_BG = /background[^;]*(?:255,\s*255,\s*255|#fff\b|#ffffff\b)/i;
|
||||||
|
const THEMED_COLOR = /(?:^|[^-])color:\s*var\(--/;
|
||||||
|
|
||||||
|
const files = stylesheets(COMPONENTS);
|
||||||
|
|
||||||
|
/** Component sources, for the third-party-surface rule below. */
|
||||||
|
function sources(dir: string): string[] {
|
||||||
|
return fs.readdirSync(dir, { withFileTypes: true }).flatMap((entry) => {
|
||||||
|
const full = path.join(dir, entry.name);
|
||||||
|
if (entry.isDirectory()) return sources(full);
|
||||||
|
return entry.name.endsWith('.tsx') ? [full] : [];
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
describe('dark-theme safety', () => {
|
||||||
|
it('finds stylesheets to check', () => {
|
||||||
|
expect(files.length).toBeGreaterThan(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('never pairs a hardcoded white background with a themed text colour', () => {
|
||||||
|
const offenders = files.flatMap((file) =>
|
||||||
|
rules(fs.readFileSync(file, 'utf8'))
|
||||||
|
.filter((r) => HARDCODED_WHITE_BG.test(r.body) && THEMED_COLOR.test(r.body))
|
||||||
|
.map((r) => `${path.relative(COMPONENTS, file)} ${r.selector}`));
|
||||||
|
|
||||||
|
// Either the surface follows the theme and so should the text, or it does
|
||||||
|
// not and the text must be literal too. Mixing them is how near-white text
|
||||||
|
// ends up on a near-white button.
|
||||||
|
expect(offenders).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('never fades to a themed colour through a hardcoded one', () => {
|
||||||
|
const offenders = files.flatMap((file) =>
|
||||||
|
rules(fs.readFileSync(file, 'utf8'))
|
||||||
|
.filter((r) => /linear-gradient/.test(r.body)
|
||||||
|
&& /var\(--bg-(card|primary|secondary)\)/.test(r.body)
|
||||||
|
&& /255,\s*255,\s*255|#fff\b/i.test(r.body))
|
||||||
|
.map((r) => `${path.relative(COMPONENTS, file)} ${r.selector}`));
|
||||||
|
|
||||||
|
// A gradient that lands on a token has to be made of that token, or the
|
||||||
|
// ramp and its destination disagree in one theme. Use the matching
|
||||||
|
// `--*-rgb` token for the transparent stops.
|
||||||
|
expect(offenders).toEqual([]);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The same defect one stylesheet further out.
|
||||||
|
*
|
||||||
|
* The rules above scan our own CSS modules. They cannot see a surface painted
|
||||||
|
* by a third-party sheet: leaflet.css hardcodes `background: white` on
|
||||||
|
* `.leaflet-popup-content-wrapper` and `.leaflet-popup-tip`, and
|
||||||
|
* LeafletMapInner builds its popup as an HTML string with inline
|
||||||
|
* `color: var(--text-primary)`. Neither half lives in a .module.css, so the
|
||||||
|
* module scan passed while dark mode rendered #E9EEF0 on #FFFFFF — 1.17:1,
|
||||||
|
* with the school name and the headline figure effectively invisible.
|
||||||
|
*
|
||||||
|
* globals.css already pulls the rest of Leaflet's chrome onto the tokens (the
|
||||||
|
* attribution bar, the zoom controls) for exactly this reason. The popup was
|
||||||
|
* simply missed.
|
||||||
|
*/
|
||||||
|
describe('third-party surfaces under themed text', () => {
|
||||||
|
const GLOBALS = path.join(__dirname, '..', '..', 'app', '(frontend)', 'globals.css');
|
||||||
|
|
||||||
|
/** Leaflet surfaces our own code writes token-coloured text onto. */
|
||||||
|
const LEAFLET_POPUP_SURFACES = [
|
||||||
|
'.leaflet-popup-content-wrapper',
|
||||||
|
'.leaflet-popup-tip',
|
||||||
|
];
|
||||||
|
|
||||||
|
it('still finds a component painting themed text into a Leaflet popup', () => {
|
||||||
|
// Guards the rule below against passing vacuously if the popups are ever
|
||||||
|
// rewritten as React components rather than HTML strings.
|
||||||
|
const themed = sources(COMPONENTS).filter((file) => {
|
||||||
|
const src = fs.readFileSync(file, 'utf8');
|
||||||
|
return /bindPopup\(/.test(src) && /color:var\(--|color: var\(--/.test(src);
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(themed.length).toBeGreaterThan(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('themes the Leaflet popup surface, because the text on it is themed', () => {
|
||||||
|
const globals = rules(fs.readFileSync(GLOBALS, 'utf8'));
|
||||||
|
|
||||||
|
const unthemed = LEAFLET_POPUP_SURFACES.filter((surface) => {
|
||||||
|
const rule = globals.find((r) => r.selector.includes(surface));
|
||||||
|
return !rule || !/background[^;]*var\(--/.test(rule.body);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Leaflet's white is not a colour this site owns. Either the surface
|
||||||
|
// follows the theme or the text on it must be literal — and the text is
|
||||||
|
// already themed.
|
||||||
|
expect(unthemed).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('never puts a literal white label on a themed fill', () => {
|
||||||
|
/*
|
||||||
|
* The mirror image of the module-CSS rule above, and the half of the popup
|
||||||
|
* that theming the card does not reach. "View Details" is
|
||||||
|
* `background:var(--status-above);color:white`; --status-above is #36743F
|
||||||
|
* in light but #7FCB8A in dark, so the label went from 5.63:1 to 1.94:1.
|
||||||
|
*
|
||||||
|
* --text-inverse is the token for ink on a saturated fill — #FFFFFF in
|
||||||
|
* light, #111A20 in dark — and the popup's Ofsted badge already uses it.
|
||||||
|
*/
|
||||||
|
const offenders = sources(COMPONENTS).flatMap((file) => {
|
||||||
|
const src = fs.readFileSync(file, 'utf8');
|
||||||
|
return Array.from(
|
||||||
|
src.matchAll(/background:\s*var\(--[^;"']*;[^"']*?color:\s*(white|#fff\b|#ffffff\b)/gi),
|
||||||
|
() => path.relative(COMPONENTS, file));
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(offenders).toEqual([]);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Destination measures add the first new colour family since the palette was
|
||||||
|
* set. The tokens have to exist in both blocks or the section renders one
|
||||||
|
* theme's fills on the other theme's ground — the exact failure the suite
|
||||||
|
* above exists to catch, but for tokens rather than literals.
|
||||||
|
*/
|
||||||
|
describe('destination tokens', () => {
|
||||||
|
const css = fs.readFileSync(
|
||||||
|
path.join(__dirname, '..', '..', 'app', '(frontend)', 'globals.css'), 'utf8');
|
||||||
|
|
||||||
|
const TOKENS = [
|
||||||
|
'--dest-sixthform', '--dest-sfcollege', '--dest-fecollege',
|
||||||
|
'--dest-apprentice', '--dest-employment', '--dest-none', '--dest-none-hatch',
|
||||||
|
];
|
||||||
|
|
||||||
|
const DARK_AT = css.indexOf('@media (prefers-color-scheme: dark)');
|
||||||
|
|
||||||
|
it('defines every destination token in the light palette', () => {
|
||||||
|
const light = css.slice(0, DARK_AT);
|
||||||
|
expect(TOKENS.filter((t) => !light.includes(`${t}:`))).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('redefines every destination token for dark', () => {
|
||||||
|
const dark = css.slice(DARK_AT);
|
||||||
|
expect(TOKENS.filter((t) => !dark.includes(`${t}:`))).toEqual([]);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,108 @@
|
|||||||
|
import fs from 'fs';
|
||||||
|
import path from 'path';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The hero search and the results filter bar are the same component in two
|
||||||
|
* costumes. `.filterBar` is the card — background, border, shadow, padding —
|
||||||
|
* and `.heroMode` strips all of it so the search sits directly on the hero
|
||||||
|
* panel.
|
||||||
|
*
|
||||||
|
* Both selectors have specificity (0,1,0), so **source order decides**, and
|
||||||
|
* `.heroMode` only wins because it is declared immediately after. Any later
|
||||||
|
* bare `.filterBar` rule — which in practice means one inside a media query —
|
||||||
|
* silently wins instead, and the hero grows a card's padding back.
|
||||||
|
*
|
||||||
|
* That is exactly what happened: `@media (max-width: 768px) { .filterBar {
|
||||||
|
* padding: 0.875rem } }` re-added 14px in hero mode, indenting the search box,
|
||||||
|
* the hint and the location link 14px past the headline above them and costing
|
||||||
|
* the search field 28px of width on a 390px screen. The two rules directly
|
||||||
|
* below it in the same block were correctly written as
|
||||||
|
* `.filterBar:not(.heroMode)`; this one was missed, and nothing caught it
|
||||||
|
* because the result is a plausible-looking layout rather than a broken one.
|
||||||
|
*/
|
||||||
|
|
||||||
|
const CSS = path.join(__dirname, '..', '..', 'components', 'FilterBar.module.css');
|
||||||
|
|
||||||
|
/** Properties `.heroMode` resets. A later bare `.filterBar` rule setting any
|
||||||
|
* of these puts the card back on the hero. */
|
||||||
|
const RESET_BY_HERO_MODE = [
|
||||||
|
'background', 'border', 'border-radius', 'box-shadow', 'padding',
|
||||||
|
];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Comments are stripped before anything is parsed.
|
||||||
|
*
|
||||||
|
* A `{` or `}` inside a comment would otherwise desynchronise the brace walk
|
||||||
|
* below and the rule regex alike, and the selector text captured for each rule
|
||||||
|
* would carry the preceding comment along with it.
|
||||||
|
*/
|
||||||
|
function withoutComments(css: string): string {
|
||||||
|
return css.replace(/\/\*[\s\S]*?\*\//g, '');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The individual selectors in a rule's prelude.
|
||||||
|
*
|
||||||
|
* Split on commas, because a selector list is a list: `.filterBar, .other { }`
|
||||||
|
* applies to `.filterBar` just as surely as `.filterBar { }` does, and an
|
||||||
|
* earlier version of this guard compared the whole prelude against the literal
|
||||||
|
* string '.filterBar' — so writing the regression as a comma list, or across
|
||||||
|
* two lines, would have walked straight past it.
|
||||||
|
*/
|
||||||
|
function selectorsOf(prelude: string): string[] {
|
||||||
|
return prelude.split(',').map((sel) => sel.trim().replace(/\s+/g, ' '))
|
||||||
|
.filter(Boolean);
|
||||||
|
}
|
||||||
|
|
||||||
|
function mediaQueryBodies(css: string): string[] {
|
||||||
|
const bodies: string[] = [];
|
||||||
|
const re = /@media[^{]*\{/g;
|
||||||
|
let m: RegExpExecArray | null;
|
||||||
|
while ((m = re.exec(css)) !== null) {
|
||||||
|
// Walk braces from the opening one to find this at-rule's whole body.
|
||||||
|
let depth = 1;
|
||||||
|
let i = m.index + m[0].length;
|
||||||
|
const start = i;
|
||||||
|
while (i < css.length && depth > 0) {
|
||||||
|
if (css[i] === '{') depth++;
|
||||||
|
else if (css[i] === '}') depth--;
|
||||||
|
i++;
|
||||||
|
}
|
||||||
|
bodies.push(css.slice(start, i - 1));
|
||||||
|
}
|
||||||
|
return bodies;
|
||||||
|
}
|
||||||
|
|
||||||
|
describe('FilterBar hero-mode scoping', () => {
|
||||||
|
const css = withoutComments(fs.readFileSync(CSS, 'utf8'));
|
||||||
|
|
||||||
|
it('confirms heroMode still resets the card, which is what makes this matter', () => {
|
||||||
|
const hero = css.match(/\.heroMode\s*\{([^}]*)\}/);
|
||||||
|
expect(hero).not.toBeNull();
|
||||||
|
expect(hero![1]).toMatch(/padding:\s*0/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('never re-applies card styling to the hero from inside a media query', () => {
|
||||||
|
const offenders: string[] = [];
|
||||||
|
|
||||||
|
for (const body of mediaQueryBodies(css)) {
|
||||||
|
for (const rule of body.matchAll(/([^{}]+)\{([^{}]*)\}/g)) {
|
||||||
|
// Only a *bare* .filterBar is dangerous, and it is dangerous wherever
|
||||||
|
// it appears in a selector list. Scoped variants
|
||||||
|
// (`.filterBar:not(.heroMode)`) and descendants are fine.
|
||||||
|
const selectors = selectorsOf(rule[1]);
|
||||||
|
if (!selectors.includes('.filterBar')) continue;
|
||||||
|
|
||||||
|
for (const prop of RESET_BY_HERO_MODE) {
|
||||||
|
if (new RegExp(`(^|[;\\s])${prop}\\s*:`).test(rule[2])) {
|
||||||
|
offenders.push(`${rule[1].trim()} sets ${prop}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Fix by scoping the rule as `.filterBar:not(.heroMode)`, the way the
|
||||||
|
// neighbouring rules in the same block already are.
|
||||||
|
expect(offenders).toEqual([]);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -98,6 +98,17 @@ describe('secondary detail page', () => {
|
|||||||
|
|
||||||
expect(screen.getByText(/has not published a cut-off distance/)).toBeInTheDocument();
|
expect(screen.getByText(/has not published a cut-off distance/)).toBeInTheDocument();
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it('makes no claim about publication when the feature is switched off', () => {
|
||||||
|
// Absent, not null. The API omits the key entirely while the
|
||||||
|
// admission_distance flag is off, and "Islington has not published a
|
||||||
|
// cut-off distance" is then a statement about us, not about Islington —
|
||||||
|
// false wherever the authority does publish one.
|
||||||
|
renderSecondarySchoolDetail({ ...secondaryFixture, admissionDistance: undefined });
|
||||||
|
|
||||||
|
expect(screen.queryByText(/has not published a cut-off distance/)).not.toBeInTheDocument();
|
||||||
|
expect(screen.queryByText(/Contact the admissions authority/)).not.toBeInTheDocument();
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
// ── The Distance section ───────────────────────────────────────────────
|
// ── The Distance section ───────────────────────────────────────────────
|
||||||
|
|||||||
@@ -0,0 +1,73 @@
|
|||||||
|
import { renderHook, act, waitFor } from '@testing-library/react';
|
||||||
|
import { useSchoolSuggest } from '@/hooks/useSchoolSuggest';
|
||||||
|
|
||||||
|
const realFetch = global.fetch;
|
||||||
|
|
||||||
|
function mockFetch(rows: unknown[], delayMs = 0) {
|
||||||
|
global.fetch = jest.fn(async (_url: unknown, init?: { signal?: AbortSignal }) => {
|
||||||
|
if (delayMs) {
|
||||||
|
await new Promise((resolve, reject) => {
|
||||||
|
const t = setTimeout(resolve, delayMs);
|
||||||
|
init?.signal?.addEventListener('abort', () => {
|
||||||
|
clearTimeout(t);
|
||||||
|
reject(Object.assign(new Error('aborted'), { name: 'AbortError' }));
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
return { ok: true, json: async () => ({ suggestions: rows }) };
|
||||||
|
}) as unknown as typeof fetch;
|
||||||
|
}
|
||||||
|
|
||||||
|
const ROW = {
|
||||||
|
urn: 1, school_name: 'Brecknock Primary School', local_authority: 'Camden',
|
||||||
|
postcode: 'NW1 1AA', phase: 'Primary', school_type: 'Community school',
|
||||||
|
};
|
||||||
|
|
||||||
|
describe('useSchoolSuggest', () => {
|
||||||
|
beforeEach(() => { jest.useFakeTimers(); });
|
||||||
|
afterEach(() => { jest.useRealTimers(); global.fetch = realFetch; });
|
||||||
|
|
||||||
|
it('does not fetch below the minimum query length', () => {
|
||||||
|
mockFetch([ROW]);
|
||||||
|
renderHook(() => useSchoolSuggest('b', true));
|
||||||
|
act(() => { jest.advanceTimersByTime(500); });
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('does not fetch at all when disabled', () => {
|
||||||
|
// The flag being off must mean no request, not a hidden dropdown.
|
||||||
|
mockFetch([ROW]);
|
||||||
|
renderHook(() => useSchoolSuggest('brecknock', false));
|
||||||
|
act(() => { jest.advanceTimersByTime(500); });
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('debounces rather than firing per keystroke', () => {
|
||||||
|
mockFetch([ROW]);
|
||||||
|
const { rerender } = renderHook(
|
||||||
|
({ q }) => useSchoolSuggest(q, true), { initialProps: { q: 'br' } });
|
||||||
|
rerender({ q: 'bre' });
|
||||||
|
rerender({ q: 'brec' });
|
||||||
|
act(() => { jest.advanceTimersByTime(199); });
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
act(() => { jest.advanceTimersByTime(2); });
|
||||||
|
expect(global.fetch).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('opens with results once they arrive', async () => {
|
||||||
|
mockFetch([ROW]);
|
||||||
|
const { result } = renderHook(() => useSchoolSuggest('brecknock', true));
|
||||||
|
act(() => { jest.advanceTimersByTime(200); });
|
||||||
|
await waitFor(() => expect(result.current.suggestions).toHaveLength(1));
|
||||||
|
expect(result.current.open).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('close() hides the list without clearing the query', async () => {
|
||||||
|
mockFetch([ROW]);
|
||||||
|
const { result } = renderHook(() => useSchoolSuggest('brecknock', true));
|
||||||
|
act(() => { jest.advanceTimersByTime(200); });
|
||||||
|
await waitFor(() => expect(result.current.open).toBe(true));
|
||||||
|
act(() => { result.current.close(); });
|
||||||
|
expect(result.current.open).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,158 @@
|
|||||||
|
import { getNavigationSource } from '@/lib/analytics';
|
||||||
|
|
||||||
|
/** jsdom's document.referrer is read-only; redefining it is the way in. */
|
||||||
|
function referrer(url: string) {
|
||||||
|
Object.defineProperty(document, 'referrer', { value: url, configurable: true });
|
||||||
|
}
|
||||||
|
|
||||||
|
const ORIGIN = 'http://localhost';
|
||||||
|
|
||||||
|
describe('getNavigationSource', () => {
|
||||||
|
afterEach(() => referrer(''));
|
||||||
|
|
||||||
|
it('attributes a visit from a location page to the place layer', () => {
|
||||||
|
/*
|
||||||
|
* The one this was added for.
|
||||||
|
*
|
||||||
|
* W2 published ~3,900 location pages whose entire purpose is to funnel
|
||||||
|
* search traffic onto school pages. Before this case existed they fell
|
||||||
|
* through to 'direct' — so the location layer's contribution was not
|
||||||
|
* merely missing from the funnel, it was being counted in the bucket you
|
||||||
|
* read as "typed the URL". The measurement that decides whether W2 worked
|
||||||
|
* was confidently reporting the wrong answer.
|
||||||
|
*/
|
||||||
|
referrer(`${ORIGIN}/schools/barnet`);
|
||||||
|
expect(getNavigationSource()).toBe('place');
|
||||||
|
});
|
||||||
|
|
||||||
|
it.each([
|
||||||
|
['/schools/authority/kent', 'authority'],
|
||||||
|
['/schools/near/sw11', 'outcode'],
|
||||||
|
['/schools/brentwood/primary', 'phase variant'],
|
||||||
|
])('covers %s (%s)', (path) => {
|
||||||
|
referrer(`${ORIGIN}${path}`);
|
||||||
|
expect(getNavigationSource()).toBe('place');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('still calls a school page "detail", one character away', () => {
|
||||||
|
// /school/ and /schools/ differ by one letter and mean different things.
|
||||||
|
// A prefix test written in the wrong order silently merges them.
|
||||||
|
referrer(`${ORIGIN}/school/100010-brecknock-primary-school`);
|
||||||
|
expect(getNavigationSource()).toBe('detail');
|
||||||
|
});
|
||||||
|
|
||||||
|
it.each([
|
||||||
|
['/', 'search'],
|
||||||
|
['/rankings', 'rankings'],
|
||||||
|
['/compare?urns=1,2', 'compare'],
|
||||||
|
])('leaves %s attributed as %s', (path, expected) => {
|
||||||
|
referrer(`${ORIGIN}${path}`);
|
||||||
|
expect(getNavigationSource()).toBe(expected);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('treats an external referrer as direct', () => {
|
||||||
|
// Umami records the real referrer on the pageview; this field is only
|
||||||
|
// about internal navigation.
|
||||||
|
referrer('https://www.google.com/search?q=schools+in+barnet');
|
||||||
|
expect(getNavigationSource()).toBe('direct');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('treats no referrer as direct', () => {
|
||||||
|
referrer('');
|
||||||
|
expect(getNavigationSource()).toBe('direct');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The defect the existing suite could not see.
|
||||||
|
*
|
||||||
|
* Every test above sets document.referrer, which the browser writes only when
|
||||||
|
* a *document* loads. Every internal navigation in this app is an App Router
|
||||||
|
* soft navigation — history.pushState, no new document — so document.referrer
|
||||||
|
* keeps naming whatever opened the tab for the whole session. Verified on
|
||||||
|
* staging: /schools/brentwood → click a school → URL changes to /school/…
|
||||||
|
* and document.referrer is still "".
|
||||||
|
*
|
||||||
|
* So `from` reported 'direct' for essentially every in-app journey, and the
|
||||||
|
* suite passed because it only ever exercised the full-page-load path.
|
||||||
|
*/
|
||||||
|
function freshAnalytics() {
|
||||||
|
let mod!: typeof import('@/lib/analytics');
|
||||||
|
jest.isolateModules(() => {
|
||||||
|
mod = require('@/lib/analytics');
|
||||||
|
});
|
||||||
|
return mod;
|
||||||
|
}
|
||||||
|
|
||||||
|
function at(path: string) {
|
||||||
|
window.history.pushState({}, '', path);
|
||||||
|
}
|
||||||
|
|
||||||
|
describe('getNavigationSource across a soft navigation', () => {
|
||||||
|
afterEach(() => {
|
||||||
|
referrer('');
|
||||||
|
at('/');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('attributes a school view to the place page the user actually came from', () => {
|
||||||
|
const { recordVisitedPath, getNavigationSource: source } = freshAnalytics();
|
||||||
|
at('/schools/brentwood');
|
||||||
|
recordVisitedPath('/schools/brentwood');
|
||||||
|
|
||||||
|
at('/school/115429-brentwood-school');
|
||||||
|
recordVisitedPath('/school/115429-brentwood-school');
|
||||||
|
|
||||||
|
expect(source()).toBe('place');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('does not depend on whether the new path was recorded first', () => {
|
||||||
|
// The trail is written by a layout-level effect and read by a page-level
|
||||||
|
// one. React orders those by tree position, which is not a contract worth
|
||||||
|
// resting a measurement on, so the answer must be the same either way.
|
||||||
|
const { recordVisitedPath, getNavigationSource: source } = freshAnalytics();
|
||||||
|
recordVisitedPath('/rankings');
|
||||||
|
at('/school/115429-brentwood-school');
|
||||||
|
|
||||||
|
expect(source()).toBe('rankings');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('names the previous page, not the current one, when both are schools', () => {
|
||||||
|
const { recordVisitedPath, getNavigationSource: source } = freshAnalytics();
|
||||||
|
at('/school/100010-brecknock-primary-school');
|
||||||
|
recordVisitedPath('/school/100010-brecknock-primary-school');
|
||||||
|
|
||||||
|
at('/school/115429-brentwood-school');
|
||||||
|
recordVisitedPath('/school/115429-brentwood-school');
|
||||||
|
|
||||||
|
expect(source()).toBe('detail');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('looks past a return visit to the page the user came back from', () => {
|
||||||
|
const { recordVisitedPath, getNavigationSource: source } = freshAnalytics();
|
||||||
|
for (const p of ['/schools/brentwood', '/school/115429-brentwood-school',
|
||||||
|
'/schools/brentwood']) {
|
||||||
|
at(p);
|
||||||
|
recordVisitedPath(p);
|
||||||
|
}
|
||||||
|
expect(source()).toBe('detail');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('falls back to the referrer on a real document load, where it is true', () => {
|
||||||
|
// A fresh module is a fresh document: nothing has been recorded, and
|
||||||
|
// document.referrer is meaningful again.
|
||||||
|
const { getNavigationSource: source } = freshAnalytics();
|
||||||
|
at('/school/115429-brentwood-school');
|
||||||
|
referrer(`${ORIGIN}/schools/barnet`);
|
||||||
|
|
||||||
|
expect(source()).toBe('place');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('still reads an arrival from outside as direct', () => {
|
||||||
|
const { recordVisitedPath, getNavigationSource: source } = freshAnalytics();
|
||||||
|
at('/schools/brentwood');
|
||||||
|
recordVisitedPath('/schools/brentwood');
|
||||||
|
referrer('https://www.google.com/search?q=schools+in+brentwood');
|
||||||
|
|
||||||
|
expect(source()).toBe('direct');
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,87 @@
|
|||||||
|
import {
|
||||||
|
canAggregate, aggregateCells,
|
||||||
|
canRenderBar, toBarSegments, CARD_GROUPS,
|
||||||
|
type DestinationCell, type DestinationGroup, type DestinationCategory,
|
||||||
|
} from '@/lib/destinations';
|
||||||
|
|
||||||
|
const pub = (category: DestinationCategory, pupils: number, cohort: number): DestinationCell => ({
|
||||||
|
category, pupils, percentage: (pupils / cohort) * 100, status: 'published',
|
||||||
|
});
|
||||||
|
const sup = (category: DestinationCategory): DestinationCell => ({
|
||||||
|
category, pupils: null, percentage: null, status: 'suppressed',
|
||||||
|
});
|
||||||
|
|
||||||
|
const fullGroup = (): DestinationGroup => ({
|
||||||
|
cohort: 180,
|
||||||
|
cells: [
|
||||||
|
pub('school_sixth_form', 75, 180), pub('sixth_form_college', 21, 180),
|
||||||
|
pub('further_education', 55, 180), pub('other_education', 6, 180),
|
||||||
|
pub('apprenticeship', 8, 180), pub('employment', 6, 180),
|
||||||
|
pub('not_sustained', 5, 180), pub('not_captured', 4, 180),
|
||||||
|
],
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('canAggregate — R2, computing from components', () => {
|
||||||
|
it('allows a sum when every component is published', () => {
|
||||||
|
expect(canAggregate([pub('apprenticeship', 8, 180), pub('employment', 6, 180)])).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('refuses a sum when any component is suppressed', () => {
|
||||||
|
expect(canAggregate([pub('apprenticeship', 8, 180), sup('employment')])).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('refuses a sum when every component is suppressed', () => {
|
||||||
|
expect(canAggregate([sup('apprenticeship'), sup('employment')])).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('aggregateCells', () => {
|
||||||
|
it('sums published cells and derives a percentage from the cohort', () => {
|
||||||
|
expect(aggregateCells([pub('apprenticeship', 8, 180), pub('employment', 6, 180)], 180))
|
||||||
|
.toEqual({ pupils: 14, percentage: (14 / 180) * 100 });
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns null rather than a partial sum when a component is suppressed', () => {
|
||||||
|
expect(aggregateCells([pub('apprenticeship', 8, 180), sup('employment')], 180)).toBeNull();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('canRenderBar — R1', () => {
|
||||||
|
it('allows a bar when the whole group is published', () => {
|
||||||
|
expect(canRenderBar(fullGroup())).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('refuses a bar when a single category is suppressed', () => {
|
||||||
|
const g = fullGroup();
|
||||||
|
g.cells[1] = sup('sixth_form_college');
|
||||||
|
expect(canRenderBar(g)).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('toBarSegments', () => {
|
||||||
|
it('derives widths from counts, not from rounded percentages', () => {
|
||||||
|
const segs = toBarSegments(fullGroup());
|
||||||
|
expect(segs).toHaveLength(8);
|
||||||
|
expect(segs[0].widthPct).toBeCloseTo((75 / 180) * 100, 10);
|
||||||
|
expect(segs.reduce((a, s) => a + s.widthPct, 0)).toBeCloseTo(100, 6);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('throws rather than silently leaving a gap when the group is suppressed', () => {
|
||||||
|
const g = fullGroup();
|
||||||
|
g.cells[1] = sup('sixth_form_college');
|
||||||
|
expect(() => toBarSegments(g)).toThrow(/suppressed/i);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('CARD_GROUPS', () => {
|
||||||
|
it('partitions every destination category exactly once, plus the absence', () => {
|
||||||
|
const grouped = Object.values(CARD_GROUPS).flat();
|
||||||
|
expect(new Set(grouped).size).toBe(grouped.length);
|
||||||
|
expect(grouped).toEqual(expect.arrayContaining([
|
||||||
|
'school_sixth_form', 'sixth_form_college', 'further_education',
|
||||||
|
'other_education', 'apprenticeship', 'employment',
|
||||||
|
]));
|
||||||
|
expect(grouped).not.toContain('not_sustained');
|
||||||
|
expect(grouped).not.toContain('not_captured');
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
import { getFlags } from '@/lib/flags';
|
import { getFlags, FLAGS_REVALIDATE } from '@/lib/flags';
|
||||||
|
|
||||||
// jsdom provides no global fetch, so there is nothing for jest.spyOn to attach
|
// jsdom provides no global fetch, so there is nothing for jest.spyOn to attach
|
||||||
// to — assign it and restore the original afterwards. This is the first test
|
// to — assign it and restore the original afterwards. This is the first test
|
||||||
@@ -31,4 +31,28 @@ describe('getFlags', () => {
|
|||||||
mockFetch(async () => ({ ok: false, status: 503 }));
|
mockFetch(async () => ({ ok: false, status: 503 }));
|
||||||
await expect(getFlags()).resolves.toEqual({});
|
await expect(getFlags()).resolves.toEqual({});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Reading a flag pins the calling route's ISR floor: Next uses the LOWEST
|
||||||
|
* revalidate among a route's fetches for the whole route. That is why the
|
||||||
|
* revalidate is an argument rather than the constant.
|
||||||
|
*
|
||||||
|
* Every SEO route here declares `revalidate = 604800`. A gate that read
|
||||||
|
* flags at the 300s default would drop the whole school and place corpus
|
||||||
|
* from a weekly cache to a 5-minute one, which is a large origin-load
|
||||||
|
* regression to pay for a feature flag.
|
||||||
|
*/
|
||||||
|
it('reads at the 300s floor by default', async () => {
|
||||||
|
mockFetch(async () => ({ ok: true, json: async () => ({}) }));
|
||||||
|
await getFlags();
|
||||||
|
expect((global.fetch as jest.Mock).mock.calls[0][1])
|
||||||
|
.toEqual({ next: { revalidate: FLAGS_REVALIDATE } });
|
||||||
|
});
|
||||||
|
|
||||||
|
it('lets a caller pass its own route floor instead', async () => {
|
||||||
|
mockFetch(async () => ({ ok: true, json: async () => ({}) }));
|
||||||
|
await getFlags(604800);
|
||||||
|
expect((global.fetch as jest.Mock).mock.calls[0][1])
|
||||||
|
.toEqual({ next: { revalidate: 604800 } });
|
||||||
|
});
|
||||||
});
|
});
|
||||||
@@ -0,0 +1,68 @@
|
|||||||
|
/**
|
||||||
|
* School pages had no BreadcrumbList and no links into the location layer.
|
||||||
|
* Both are fixed by the same data — the `places` array the API now returns —
|
||||||
|
* so they are tested together.
|
||||||
|
*/
|
||||||
|
import { schoolBreadcrumbJsonLd } from '@/lib/jsonld';
|
||||||
|
|
||||||
|
const essex = { kind: 'authority', slug: 'essex', name: 'Essex', count: 480, url: '/schools/authority/essex', phases: [] };
|
||||||
|
const brentwood = { kind: 'town', slug: 'brentwood', name: 'Brentwood', count: 37, url: '/schools/brentwood', phases: [] };
|
||||||
|
const outcode = { kind: 'outcode', slug: 'cm15', name: 'CM15', count: 12, url: '/schools/near/cm15', phases: [] };
|
||||||
|
|
||||||
|
describe('school breadcrumbs', () => {
|
||||||
|
it('reads home to authority to town to school', () => {
|
||||||
|
const ld = schoolBreadcrumbJsonLd({
|
||||||
|
name: 'Brentwood School', url: '/school/100000-brentwood-school',
|
||||||
|
places: [essex, brentwood],
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(ld['@type']).toBe('BreadcrumbList');
|
||||||
|
expect(ld.itemListElement.map((i) => i.name))
|
||||||
|
.toEqual(['schoolcompare', 'Essex', 'Brentwood', 'Brentwood School']);
|
||||||
|
expect(ld.itemListElement.map((i) => i.position)).toEqual([1, 2, 3, 4]);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('skips a level the school has no published place for', () => {
|
||||||
|
// A school whose town falls below the publish threshold has no town page.
|
||||||
|
// The trail closes over the gap rather than linking to a 404.
|
||||||
|
const ld = schoolBreadcrumbJsonLd({
|
||||||
|
name: 'Lone School', url: '/school/1-lone-school', places: [essex],
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(ld.itemListElement.map((i) => i.name))
|
||||||
|
.toEqual(['schoolcompare', 'Essex', 'Lone School']);
|
||||||
|
expect(ld.itemListElement.map((i) => i.position)).toEqual([1, 2, 3]);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('omits outcodes, which are not a place a breadcrumb reads through', () => {
|
||||||
|
// CM15 is a useful link in the module but nonsense in a trail: nobody
|
||||||
|
// navigates Essex → CM15 → school.
|
||||||
|
const ld = schoolBreadcrumbJsonLd({
|
||||||
|
name: 'Brentwood School', url: '/school/100000-brentwood-school',
|
||||||
|
places: [essex, brentwood, outcode],
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(JSON.stringify(ld)).not.toContain('cm15');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('still produces a valid trail when the school has no places at all', () => {
|
||||||
|
const ld = schoolBreadcrumbJsonLd({
|
||||||
|
name: 'Orphan School', url: '/school/2-orphan-school', places: [],
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(ld.itemListElement.map((i) => i.name)).toEqual(['schoolcompare', 'Orphan School']);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('uses absolute urls, as every other entity on the site does', () => {
|
||||||
|
const ld = schoolBreadcrumbJsonLd({
|
||||||
|
name: 'Brentwood School', url: '/school/100000-brentwood-school',
|
||||||
|
places: [essex, brentwood],
|
||||||
|
});
|
||||||
|
|
||||||
|
for (const item of ld.itemListElement) {
|
||||||
|
expect(item.item).toMatch(/^https:\/\/www\.schoolcompare\.co\.uk\//);
|
||||||
|
}
|
||||||
|
// The root is the homepage: there is no /schools index page to link to.
|
||||||
|
expect(ld.itemListElement[0].item).toBe('https://www.schoolcompare.co.uk/');
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
import { computeSecondaryFlags, buildSecondaryNavItems } from '@/lib/schoolSections';
|
||||||
|
import type { School, SchoolDestinations } from '@/lib/types';
|
||||||
|
|
||||||
|
const schoolInfo = {
|
||||||
|
urn: 137083, school_name: 'Northbrook Academy', phase: 'Secondary',
|
||||||
|
has_sixth_form: true,
|
||||||
|
} as unknown as School;
|
||||||
|
|
||||||
|
const base = { schoolInfo, yearlyData: [], deprivation: null, finance: null };
|
||||||
|
|
||||||
|
const phase = (categories = 1) => ({
|
||||||
|
cohort_year: '2022/23',
|
||||||
|
groups: {
|
||||||
|
all: {
|
||||||
|
cohort: 180,
|
||||||
|
categories: Array.from({ length: categories }, () => ({
|
||||||
|
category: 'school_sixth_form' as const,
|
||||||
|
pupils: 75, percentage: 41.7, status: 'published' as const,
|
||||||
|
})),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
const ks4Only: SchoolDestinations = { ks4: phase(), ks5: null };
|
||||||
|
const both: SchoolDestinations = { ks4: phase(), ks5: phase() };
|
||||||
|
|
||||||
|
describe('computeSecondaryFlags — destinations', () => {
|
||||||
|
it('flags KS4 destinations when the block carries categories', () => {
|
||||||
|
const flags = computeSecondaryFlags({ ...base, destinations: ks4Only });
|
||||||
|
expect(flags.hasKs4Destinations).toBe(true);
|
||||||
|
expect(flags.hasKs5Destinations).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('flags both phases when both are present', () => {
|
||||||
|
const flags = computeSecondaryFlags({ ...base, destinations: both });
|
||||||
|
expect(flags.hasKs4Destinations).toBe(true);
|
||||||
|
expect(flags.hasKs5Destinations).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('flags neither when the block is absent', () => {
|
||||||
|
const flags = computeSecondaryFlags({ ...base, destinations: null });
|
||||||
|
expect(flags.hasKs4Destinations).toBe(false);
|
||||||
|
expect(flags.hasKs5Destinations).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('does not flag a phase whose groups carry no categories', () => {
|
||||||
|
const empty: SchoolDestinations = {
|
||||||
|
ks4: { cohort_year: '2022/23', groups: {} }, ks5: null,
|
||||||
|
};
|
||||||
|
expect(computeSecondaryFlags({ ...base, destinations: empty }).hasKs4Destinations)
|
||||||
|
.toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('does not flag a phase whose only group has an empty category list', () => {
|
||||||
|
const empty: SchoolDestinations = { ks4: phase(0), ks5: null };
|
||||||
|
expect(computeSecondaryFlags({ ...base, destinations: empty }).hasKs4Destinations)
|
||||||
|
.toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('buildSecondaryNavItems — destinations', () => {
|
||||||
|
const navInput = {
|
||||||
|
ofsted: null, admissions: null, admissionDistance: null,
|
||||||
|
hasLocation: false, yearlyDataLength: 0,
|
||||||
|
};
|
||||||
|
|
||||||
|
it('adds both entries, after GCSEs', () => {
|
||||||
|
const flags = computeSecondaryFlags({ ...base, destinations: both });
|
||||||
|
const ids = buildSecondaryNavItems({ ...flags, hasResults: true }, navInput)
|
||||||
|
.map(i => i.id);
|
||||||
|
expect(ids).toContain('destinations');
|
||||||
|
expect(ids).toContain('post16-destinations');
|
||||||
|
expect(ids.indexOf('destinations')).toBeGreaterThan(ids.indexOf('gcse'));
|
||||||
|
expect(ids.indexOf('post16-destinations')).toBe(ids.indexOf('destinations') + 1);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('adds no entry for a phase that will not render — the nav must not link to a missing anchor', () => {
|
||||||
|
const flags = computeSecondaryFlags({ ...base, destinations: null });
|
||||||
|
const ids = buildSecondaryNavItems(flags, navInput).map(i => i.id);
|
||||||
|
expect(ids).not.toContain('destinations');
|
||||||
|
expect(ids).not.toContain('post16-destinations');
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -13,6 +13,8 @@ import {
|
|||||||
metricKind,
|
metricKind,
|
||||||
shortName,
|
shortName,
|
||||||
computeYBounds,
|
computeYBounds,
|
||||||
|
formatAgeRange,
|
||||||
|
formatAgeSpan,
|
||||||
} from '@/lib/utils';
|
} from '@/lib/utils';
|
||||||
|
|
||||||
describe('formatPercentage', () => {
|
describe('formatPercentage', () => {
|
||||||
@@ -320,3 +322,27 @@ describe('shortName', () => {
|
|||||||
expect(shortName('A'.repeat(30), 10)).toBe('AAAAAAAAA…');
|
expect(shortName('A'.repeat(30), 10)).toBe('AAAAAAAAA…');
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
describe('formatAgeSpan', () => {
|
||||||
|
it('normalises a hyphenated range to an en dash, without a label', () => {
|
||||||
|
// The place table carries "Ages" in the column heading, so repeating it
|
||||||
|
// in every cell is noise. formatAgeRange keeps the label for the contexts
|
||||||
|
// that have no heading to hang it on.
|
||||||
|
expect(formatAgeSpan('4-11')).toBe('4–11');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('leaves a range it does not recognise alone rather than mangling it', () => {
|
||||||
|
expect(formatAgeSpan('3-19 (SEN)')).toBe('3-19 (SEN)');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns an empty string for a missing range', () => {
|
||||||
|
expect(formatAgeSpan(null)).toBe('');
|
||||||
|
expect(formatAgeSpan(undefined)).toBe('');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('formatAgeRange', () => {
|
||||||
|
it('keeps its label, so the two helpers stay distinguishable', () => {
|
||||||
|
expect(formatAgeRange('4-11')).toBe('Ages 4–11');
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,70 @@
|
|||||||
|
/**
|
||||||
|
* Payload is ESM-only and next/jest will not transform it, so the collections
|
||||||
|
* cannot be imported and their sanitised config inspected here (see
|
||||||
|
* lib/payloadRoutes.ts for the full reasoning). These assert the source of the
|
||||||
|
* collection definitions instead — enough to catch the settings whose loss is
|
||||||
|
* silent, and cheap. Behaviour is proved by the e2e journeys against staging.
|
||||||
|
*/
|
||||||
|
import fs from 'fs';
|
||||||
|
import path from 'path';
|
||||||
|
|
||||||
|
const read = (file: string) =>
|
||||||
|
fs.readFileSync(path.join(__dirname, '..', '..', 'collections', file), 'utf8');
|
||||||
|
|
||||||
|
const POSTS = read('Posts.ts');
|
||||||
|
const MEDIA = read('Media.ts');
|
||||||
|
const CONFIG = fs.readFileSync(
|
||||||
|
path.join(__dirname, '..', '..', 'payload.config.ts'),
|
||||||
|
'utf8',
|
||||||
|
);
|
||||||
|
|
||||||
|
describe('posts collection', () => {
|
||||||
|
it('supports drafts, so saving is not publishing', () => {
|
||||||
|
expect(POSTS).toMatch(/drafts:\s*true/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('has a unique, indexed slug for stable URLs', () => {
|
||||||
|
const slugField = POSTS.slice(POSTS.indexOf("name: 'slug'"));
|
||||||
|
expect(slugField).toMatch(/unique:\s*true/);
|
||||||
|
expect(slugField).toMatch(/index:\s*true/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('hides drafts from anonymous readers at the access layer', () => {
|
||||||
|
// Payload's docs are explicit: "The `draft` argument alone does not
|
||||||
|
// restrict documents with _status: 'draft' from being returned by the
|
||||||
|
// API." The blog pages' where-clause is not enforcement — a direct GET
|
||||||
|
// /cms-api/posts would return unpublished drafts to anyone. Access
|
||||||
|
// control returning a query constraint is the only thing that stops it.
|
||||||
|
expect(POSTS).toMatch(/_status:\s*\{\s*equals:\s*'published'\s*\}/);
|
||||||
|
expect(POSTS).toMatch(/if\s*\(req\.user\)\s*return true/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('revalidates the post page when a post changes or is deleted', () => {
|
||||||
|
// /blog/[slug] is ISR — generated on first request and cached — so an edit
|
||||||
|
// to an already-published post would otherwise not appear until the
|
||||||
|
// revalidate window expired, up to an hour of a writer concluding that
|
||||||
|
// saving is broken. The index and feeds are force-dynamic and need no hook.
|
||||||
|
expect(POSTS).toContain('afterChange');
|
||||||
|
expect(POSTS).toContain('afterDelete');
|
||||||
|
expect(POSTS).toMatch(/revalidatePath\(`\/blog\/\$\{[^}]+\}`\)/);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('media collection', () => {
|
||||||
|
it('writes uploads to the mounted volume, by absolute path', () => {
|
||||||
|
// Must match the payload_media mount in docker-compose.portainer.yml.
|
||||||
|
// Payload 3 requires staticDir to be absolute.
|
||||||
|
expect(MEDIA).toMatch(/staticDir:\s*'\/app\/media'/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('requires alt text on every upload', () => {
|
||||||
|
const altField = MEDIA.slice(MEDIA.indexOf("name: 'alt'"));
|
||||||
|
expect(altField).toMatch(/required:\s*true/);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('payload config', () => {
|
||||||
|
it('registers every collection', () => {
|
||||||
|
expect(CONFIG).toMatch(/collections:\s*\[Users,\s*Posts,\s*Media\]/);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,67 @@
|
|||||||
|
/**
|
||||||
|
* The admin panel does not import field components directly. Payload sends the
|
||||||
|
* client a *path* for each one — a richText field's is
|
||||||
|
* `@payloadcms/richtext-lexical/rsc#RscEntryLexicalField` — and resolves it
|
||||||
|
* through this generated map. An entry that is missing from the map is not an
|
||||||
|
* error the panel reports: the field simply does not render.
|
||||||
|
*
|
||||||
|
* That failure is quietly awful, because `required: true` is enforced on the
|
||||||
|
* server regardless. A writer gets a new-post form with no Content editor and
|
||||||
|
* a save that refuses on a field they were never shown.
|
||||||
|
*
|
||||||
|
* The map is generated by `npx payload generate:importmap`, so it drifts every
|
||||||
|
* time a field or a lexical feature is added and nobody re-runs it. These
|
||||||
|
* assert the entries the current config needs.
|
||||||
|
*/
|
||||||
|
import fs from 'fs';
|
||||||
|
import path from 'path';
|
||||||
|
|
||||||
|
const MAP = fs.readFileSync(
|
||||||
|
path.join(__dirname, '..', '..', 'app', '(payload)', 'admin', 'importMap.js'),
|
||||||
|
'utf8',
|
||||||
|
);
|
||||||
|
const POSTS = fs.readFileSync(
|
||||||
|
path.join(__dirname, '..', '..', 'collections', 'Posts.ts'),
|
||||||
|
'utf8',
|
||||||
|
);
|
||||||
|
|
||||||
|
describe('admin import map', () => {
|
||||||
|
it('resolves the richText field, so Content renders in the editor', () => {
|
||||||
|
// Guarded because Posts.content is required: without this entry the field
|
||||||
|
// is invisible and the post is unsaveable.
|
||||||
|
expect(POSTS).toMatch(/type:\s*'richText'/);
|
||||||
|
expect(MAP).toContain('@payloadcms/richtext-lexical/rsc#RscEntryLexicalField');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('resolves the richText cell, so the list view can render the column', () => {
|
||||||
|
expect(MAP).toContain('@payloadcms/richtext-lexical/rsc#RscEntryLexicalCell');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('resolves the diff component, which the drafts UI needs', () => {
|
||||||
|
// versions.drafts is on, so the panel offers version comparison.
|
||||||
|
expect(POSTS).toMatch(/drafts:\s*true/);
|
||||||
|
expect(MAP).toContain('@payloadcms/richtext-lexical/rsc#LexicalDiffComponent');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('resolves BlocksFeature, so the Callout block is insertable', () => {
|
||||||
|
expect(POSTS).toContain('BlocksFeature');
|
||||||
|
expect(MAP).toContain('@payloadcms/richtext-lexical/client#BlocksFeatureClient');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('resolves the default toolbar features the editor is built with', () => {
|
||||||
|
// defaultFeatures is spread into the editor config; each one contributes a
|
||||||
|
// client component the toolbar cannot render without.
|
||||||
|
for (const feature of [
|
||||||
|
'BoldFeatureClient',
|
||||||
|
'ItalicFeatureClient',
|
||||||
|
'HeadingFeatureClient',
|
||||||
|
'LinkFeatureClient',
|
||||||
|
'UploadFeatureClient',
|
||||||
|
'UnorderedListFeatureClient',
|
||||||
|
'OrderedListFeatureClient',
|
||||||
|
'InlineToolbarFeatureClient',
|
||||||
|
]) {
|
||||||
|
expect(MAP).toContain(`@payloadcms/richtext-lexical/client#${feature}`);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
/**
|
||||||
|
* The generated migration is schema-qualified to "payload" throughout but does
|
||||||
|
* not create that schema — `schemaName` says where tables go, it does not
|
||||||
|
* create anything. On staging and production, which have never run it, the
|
||||||
|
* whole migration fails with `schema "payload" does not exist`.
|
||||||
|
*
|
||||||
|
* The CREATE SCHEMA is therefore hand-added, which makes it exactly the kind
|
||||||
|
* of edit a regeneration silently discards. This is the guard.
|
||||||
|
*/
|
||||||
|
import fs from 'fs';
|
||||||
|
import path from 'path';
|
||||||
|
|
||||||
|
const DIR = path.join(__dirname, '..', '..', 'migrations');
|
||||||
|
|
||||||
|
function migrationFiles() {
|
||||||
|
return fs
|
||||||
|
.readdirSync(DIR)
|
||||||
|
.filter((f) => f.endsWith('.ts') && f !== 'index.ts');
|
||||||
|
}
|
||||||
|
|
||||||
|
describe('payload migrations', () => {
|
||||||
|
it('ships at least one migration, so a container has tables to find', () => {
|
||||||
|
expect(migrationFiles().length).toBeGreaterThan(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('creates the payload schema before creating anything in it', () => {
|
||||||
|
const initial = migrationFiles().find((f) => f.includes('initial'))!;
|
||||||
|
const sql = fs.readFileSync(path.join(DIR, initial), 'utf8');
|
||||||
|
|
||||||
|
expect(sql).toMatch(/CREATE SCHEMA IF NOT EXISTS "payload"/);
|
||||||
|
|
||||||
|
// Ordering matters: the schema must be created before the first object
|
||||||
|
// that lives in it, or the migration fails on its first statement.
|
||||||
|
expect(sql.indexOf('CREATE SCHEMA IF NOT EXISTS "payload"'))
|
||||||
|
.toBeLessThan(sql.indexOf('CREATE TABLE "payload"'));
|
||||||
|
});
|
||||||
|
|
||||||
|
it('creates the tables the app queries on boot', () => {
|
||||||
|
const initial = migrationFiles().find((f) => f.includes('initial'))!;
|
||||||
|
const sql = fs.readFileSync(path.join(DIR, initial), 'utf8');
|
||||||
|
for (const table of ['users', 'posts', '_posts_v', 'media', 'payload_migrations']) {
|
||||||
|
expect(sql).toContain(`CREATE TABLE "payload"."${table}"`);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it('is wired into the adapter, so it runs on server init', () => {
|
||||||
|
const config = fs.readFileSync(
|
||||||
|
path.join(__dirname, '..', '..', 'payload.config.ts'), 'utf8',
|
||||||
|
);
|
||||||
|
expect(config).toMatch(/prodMigrations:\s*migrations/);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
/**
|
||||||
|
* Guards the one thing about Payload's mounting that fails silently.
|
||||||
|
*
|
||||||
|
* payload.config.ts itself cannot be imported here — Payload is ESM-only and
|
||||||
|
* next/jest will not transform it — so this asserts the shared constants and
|
||||||
|
* that the config actually wires them in, by reading its source. The live
|
||||||
|
* proof that /api still reaches FastAPI is the e2e journeys, which call
|
||||||
|
* /api/schools against the running app.
|
||||||
|
*/
|
||||||
|
import fs from 'fs';
|
||||||
|
import path from 'path';
|
||||||
|
import { PAYLOAD_API_ROUTE, PAYLOAD_ADMIN_ROUTE } from '@/lib/payloadRoutes';
|
||||||
|
|
||||||
|
const CONFIG = fs.readFileSync(
|
||||||
|
path.join(__dirname, '..', '..', 'payload.config.ts'),
|
||||||
|
'utf8',
|
||||||
|
);
|
||||||
|
|
||||||
|
describe('payload mount points', () => {
|
||||||
|
it('serves the CMS API from /cms-api, never /api', () => {
|
||||||
|
// /api is the FastAPI proxy's catch-all. Payload's default would be
|
||||||
|
// swallowed by it and forwarded to the backend, silently.
|
||||||
|
expect(PAYLOAD_API_ROUTE).toBe('/cms-api');
|
||||||
|
expect(PAYLOAD_API_ROUTE).not.toBe('/api');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('serves the admin panel from /admin', () => {
|
||||||
|
expect(PAYLOAD_ADMIN_ROUTE).toBe('/admin');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('wires both constants into the Payload config', () => {
|
||||||
|
expect(CONFIG).toContain('PAYLOAD_API_ROUTE');
|
||||||
|
expect(CONFIG).toContain('PAYLOAD_ADMIN_ROUTE');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('never hardcodes a routes block that could drift from the constants', () => {
|
||||||
|
expect(CONFIG).not.toMatch(/routes:\s*\{[^}]*api:\s*['"]/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('isolates CMS tables in their own postgres schema', () => {
|
||||||
|
// Blog content must stay separate from school marts and Airflow metadata.
|
||||||
|
expect(CONFIG).toMatch(/schemaName:\s*['"]payload['"]/);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -21,7 +21,7 @@ import {
|
|||||||
import { nationalAveragesFixture } from './schoolFixtures';
|
import { nationalAveragesFixture } from './schoolFixtures';
|
||||||
|
|
||||||
// The shell calls useComparison(), which throws outside the provider. In the
|
// The shell calls useComparison(), which throws outside the provider. In the
|
||||||
// app this wrapper comes from app/layout.tsx.
|
// app this wrapper comes from app/(frontend)/layout.tsx.
|
||||||
function withProviders(ui: ReactNode) {
|
function withProviders(ui: ReactNode) {
|
||||||
return <ComparisonProvider>{ui}</ComparisonProvider>;
|
return <ComparisonProvider>{ui}</ComparisonProvider>;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,82 @@
|
|||||||
|
.page {
|
||||||
|
max-width: 42rem;
|
||||||
|
margin: 0 auto;
|
||||||
|
padding: 2.5rem 1.25rem 4rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.header {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 1.25rem;
|
||||||
|
margin-bottom: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.portrait {
|
||||||
|
border-radius: 50%;
|
||||||
|
border: 2px solid var(--border);
|
||||||
|
object-fit: cover;
|
||||||
|
flex-shrink: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.kicker {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
font-size: 0.75rem;
|
||||||
|
font-weight: 600;
|
||||||
|
text-transform: uppercase;
|
||||||
|
letter-spacing: 0.06em;
|
||||||
|
color: var(--brand);
|
||||||
|
margin: 0 0 0.35rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.heading {
|
||||||
|
font-family: var(--font-display);
|
||||||
|
font-size: clamp(1.5rem, 4vw, 2rem);
|
||||||
|
font-weight: 700;
|
||||||
|
line-height: 1.2;
|
||||||
|
color: var(--text-primary);
|
||||||
|
margin: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.subheading {
|
||||||
|
font-family: var(--font-display);
|
||||||
|
font-size: 1.15rem;
|
||||||
|
font-weight: 600;
|
||||||
|
color: var(--text-primary);
|
||||||
|
margin: 2.25rem 0 0.75rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.prose p {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
font-size: 1rem;
|
||||||
|
line-height: 1.7;
|
||||||
|
color: var(--text-secondary);
|
||||||
|
margin: 0 0 1.1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* The opening paragraph carries the page. Larger, and in the primary ink
|
||||||
|
rather than the secondary, so it reads as a voice rather than as body copy.
|
||||||
|
|
||||||
|
Must stay in the descendant form: `.prose p` scores (0,1,1) and would beat a
|
||||||
|
bare `.lede` at (0,1,0), so simplifying this selector silently reverts the
|
||||||
|
lede to ordinary body copy. */
|
||||||
|
.prose .lede {
|
||||||
|
font-size: 1.125rem;
|
||||||
|
color: var(--text-primary);
|
||||||
|
}
|
||||||
|
|
||||||
|
.link {
|
||||||
|
color: var(--brand);
|
||||||
|
font-weight: 600;
|
||||||
|
}
|
||||||
|
|
||||||
|
.link:hover {
|
||||||
|
color: var(--brand-strong);
|
||||||
|
}
|
||||||
|
|
||||||
|
@media (max-width: 480px) {
|
||||||
|
.header {
|
||||||
|
flex-direction: column;
|
||||||
|
align-items: flex-start;
|
||||||
|
gap: 1rem;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,143 @@
|
|||||||
|
import type { Metadata } from 'next';
|
||||||
|
import Image from 'next/image';
|
||||||
|
import { notFound } from 'next/navigation';
|
||||||
|
import { absoluteUrl } from '@/lib/site';
|
||||||
|
import { getFlags } from '@/lib/flags';
|
||||||
|
import { personJsonLd, organizationJsonLd } from '@/lib/jsonld';
|
||||||
|
import styles from './About.module.css';
|
||||||
|
|
||||||
|
export const metadata: Metadata = {
|
||||||
|
title: 'About',
|
||||||
|
description:
|
||||||
|
'Who builds schoolcompare, why it exists, and where its numbers come from.',
|
||||||
|
alternates: { canonical: absoluteUrl('/about') },
|
||||||
|
};
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Gated on about_page. The default 300s read is the right floor here: this
|
||||||
|
* page declares no revalidate of its own, so nothing is lost by it, and a flip
|
||||||
|
* lands within five minutes.
|
||||||
|
*
|
||||||
|
* notFound(), not a redirect: while the flag is dark this URL does not exist,
|
||||||
|
* and a 404 is what tells a crawler not to keep it.
|
||||||
|
*/
|
||||||
|
export default async function AboutPage() {
|
||||||
|
const flags = await getFlags();
|
||||||
|
if (flags.about_page !== true) notFound();
|
||||||
|
|
||||||
|
const jsonLd = {
|
||||||
|
'@context': 'https://schema.org',
|
||||||
|
'@graph': [personJsonLd(), organizationJsonLd()],
|
||||||
|
};
|
||||||
|
|
||||||
|
return (
|
||||||
|
<div className={styles.page}>
|
||||||
|
<script
|
||||||
|
type="application/ld+json"
|
||||||
|
dangerouslySetInnerHTML={{ __html: JSON.stringify(jsonLd) }}
|
||||||
|
/>
|
||||||
|
|
||||||
|
<header className={styles.header}>
|
||||||
|
<Image
|
||||||
|
src="/brand/tudor.jpg"
|
||||||
|
alt="Tudor, who builds schoolcompare"
|
||||||
|
width={96}
|
||||||
|
height={96}
|
||||||
|
className={styles.portrait}
|
||||||
|
priority
|
||||||
|
/>
|
||||||
|
<div>
|
||||||
|
<p className={styles.kicker}>Who's behind this</p>
|
||||||
|
<h1 className={styles.heading}>I'm Tudor. I built this site.</h1>
|
||||||
|
</div>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
<div className={styles.prose}>
|
||||||
|
<p className={styles.lede}>
|
||||||
|
I'm a parent in south-west London. When we started looking at
|
||||||
|
primary schools, I found the information I needed was all published,
|
||||||
|
and almost impossible to hold in one place.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
SATs results were in one government table. Ofsted judgements were in a
|
||||||
|
separate service, in a format that had just changed. Admissions
|
||||||
|
distances were buried in council PDFs, a different one per borough,
|
||||||
|
each with its own layout. I ended up building a spreadsheet, and then
|
||||||
|
I got tired of the spreadsheet.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
So I built this instead. It pulls the official figures into one place
|
||||||
|
and puts them side by side, which is what I wanted and could not find.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<h2 className={styles.subheading}>I'm not an education expert</h2>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
I want to be straightforward about that. I'm not a teacher, a
|
||||||
|
governor, or an education researcher. I have no qualification that
|
||||||
|
makes my opinion about a school worth more than yours.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
What I do have is the problem itself. I'm going through primary
|
||||||
|
admissions right now, and I work with data for a living. That
|
||||||
|
combination is enough to take published figures and present them
|
||||||
|
honestly. It is not enough to tell you which school is right for your
|
||||||
|
child, and this site never tries to.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<h2 className={styles.subheading}>Where the numbers come from</h2>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
Everything here is official published data: Key Stage 2 and Key Stage
|
||||||
|
4 results and school characteristics from the Department for
|
||||||
|
Education, inspection outcomes from Ofsted, and admissions data from
|
||||||
|
local authorities. Nothing is estimated, modelled or filled in. Where
|
||||||
|
a figure is missing, the page says so rather than showing a guess.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
This is an independent site. It is not affiliated with the Department
|
||||||
|
for Education or with Ofsted, and nobody pays to appear on it or to
|
||||||
|
rank higher.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<h2 className={styles.subheading}>What the data can't tell you</h2>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
A school is not its results. The figures here describe one year group,
|
||||||
|
on a handful of days, measured in a way that suits national statistics
|
||||||
|
rather than your child. A small cohort makes percentages swing wildly.
|
||||||
|
In a class of thirty, one pupil is worth more than three points.
|
||||||
|
Results say nothing at all about whether a child will be happy
|
||||||
|
somewhere.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
I try to build that honesty into the site rather than just say it
|
||||||
|
here. Special schools and pupil referral units are never compared
|
||||||
|
against a mainstream national average, because that comparison is
|
||||||
|
meaningless and makes good schools look like failing ones. Where a
|
||||||
|
number is unreliable, the aim is for the page to tell you before you
|
||||||
|
draw a conclusion from it.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<h2 className={styles.subheading}>If something's wrong</h2>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
Tell me and I'll fix it. If a figure looks wrong, or a page gives
|
||||||
|
a misleading impression of a school, I genuinely want to know.
|
||||||
|
It's the fastest way this gets better.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
<a href="mailto:contact@schoolcompare.co.uk" className={styles.link}>
|
||||||
|
contact@schoolcompare.co.uk
|
||||||
|
</a>
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
}
|
||||||
File renamed without changes.
File renamed without changes.
@@ -0,0 +1,76 @@
|
|||||||
|
.page {
|
||||||
|
max-width: 42rem;
|
||||||
|
margin: 0 auto;
|
||||||
|
padding: 2.5rem 1.25rem 4rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.header { margin-bottom: 2.5rem; }
|
||||||
|
|
||||||
|
.kicker {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
font-size: 0.75rem;
|
||||||
|
font-weight: 600;
|
||||||
|
text-transform: uppercase;
|
||||||
|
letter-spacing: 0.06em;
|
||||||
|
color: var(--brand);
|
||||||
|
margin: 0 0 0.35rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.heading {
|
||||||
|
font-family: var(--font-display);
|
||||||
|
font-size: clamp(1.5rem, 4vw, 2rem);
|
||||||
|
font-weight: 700;
|
||||||
|
line-height: 1.2;
|
||||||
|
color: var(--text-primary);
|
||||||
|
margin: 0 0 0.75rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.standfirst {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
font-size: 1.05rem;
|
||||||
|
line-height: 1.65;
|
||||||
|
color: var(--text-secondary);
|
||||||
|
margin: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.list { list-style: none; padding: 0; margin: 0; }
|
||||||
|
|
||||||
|
.item {
|
||||||
|
padding: 1.5rem 0;
|
||||||
|
border-top: 1px solid var(--border);
|
||||||
|
}
|
||||||
|
|
||||||
|
.date {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
font-size: 0.8rem;
|
||||||
|
color: var(--text-muted);
|
||||||
|
/* Inter's tabular numerals keep a column of dates aligned. */
|
||||||
|
font-variant-numeric: tabular-nums;
|
||||||
|
}
|
||||||
|
|
||||||
|
.itemTitle {
|
||||||
|
font-family: var(--font-display);
|
||||||
|
font-size: 1.25rem;
|
||||||
|
font-weight: 600;
|
||||||
|
line-height: 1.3;
|
||||||
|
margin: 0.35rem 0 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.itemLink { color: var(--text-primary); text-decoration: none; }
|
||||||
|
.itemLink:hover { color: var(--brand); }
|
||||||
|
|
||||||
|
.excerpt {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
font-size: 0.95rem;
|
||||||
|
line-height: 1.65;
|
||||||
|
color: var(--text-secondary);
|
||||||
|
margin: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.empty {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
color: var(--text-muted);
|
||||||
|
}
|
||||||
|
|
||||||
|
.link { color: var(--brand); font-weight: 600; }
|
||||||
|
.link:hover { color: var(--brand-strong); }
|
||||||
@@ -0,0 +1,87 @@
|
|||||||
|
.page {
|
||||||
|
max-width: 42rem;
|
||||||
|
margin: 0 auto;
|
||||||
|
padding: 2.5rem 1.25rem 4rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.crumb {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
font-size: 0.85rem;
|
||||||
|
margin-bottom: 1.25rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.heading {
|
||||||
|
font-family: var(--font-display);
|
||||||
|
font-size: clamp(1.6rem, 5vw, 2.25rem);
|
||||||
|
font-weight: 700;
|
||||||
|
line-height: 1.2;
|
||||||
|
color: var(--text-primary);
|
||||||
|
margin: 0 0 0.75rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.byline {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
font-size: 0.9rem;
|
||||||
|
color: var(--text-muted);
|
||||||
|
margin: 0 0 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.hero {
|
||||||
|
width: 100%;
|
||||||
|
height: auto;
|
||||||
|
border-radius: 10px;
|
||||||
|
border: 1px solid var(--border);
|
||||||
|
margin-bottom: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Rich-text output: the editor emits plain elements, so these are styled by
|
||||||
|
descendant selector rather than by class. */
|
||||||
|
.prose p {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
font-size: 1rem;
|
||||||
|
line-height: 1.7;
|
||||||
|
color: var(--text-secondary);
|
||||||
|
margin: 0 0 1.1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.prose h2 {
|
||||||
|
font-family: var(--font-display);
|
||||||
|
font-size: 1.25rem;
|
||||||
|
font-weight: 600;
|
||||||
|
color: var(--text-primary);
|
||||||
|
margin: 2.25rem 0 0.75rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.prose h3 {
|
||||||
|
font-family: var(--font-display);
|
||||||
|
font-size: 1.05rem;
|
||||||
|
font-weight: 600;
|
||||||
|
color: var(--text-primary);
|
||||||
|
margin: 1.75rem 0 0.6rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.prose ul,
|
||||||
|
.prose ol {
|
||||||
|
font-family: var(--font-ui);
|
||||||
|
font-size: 1rem;
|
||||||
|
line-height: 1.7;
|
||||||
|
color: var(--text-secondary);
|
||||||
|
padding-left: 1.35rem;
|
||||||
|
margin: 0 0 1.1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.prose li { margin-bottom: 0.4rem; }
|
||||||
|
|
||||||
|
.prose a { color: var(--brand); font-weight: 500; }
|
||||||
|
.prose a:hover { color: var(--brand-strong); }
|
||||||
|
|
||||||
|
.prose blockquote {
|
||||||
|
border-left: 3px solid var(--border-strong);
|
||||||
|
padding-left: 1rem;
|
||||||
|
margin: 1.5rem 0;
|
||||||
|
color: var(--text-muted);
|
||||||
|
font-style: italic;
|
||||||
|
}
|
||||||
|
|
||||||
|
.link { color: var(--brand); font-weight: 600; }
|
||||||
|
.link:hover { color: var(--brand-strong); }
|
||||||
@@ -0,0 +1,194 @@
|
|||||||
|
import { cache } from 'react';
|
||||||
|
import type { Metadata } from 'next';
|
||||||
|
import Link from 'next/link';
|
||||||
|
import { notFound } from 'next/navigation';
|
||||||
|
import { RichText } from '@payloadcms/richtext-lexical/react';
|
||||||
|
import type { JSXConvertersFunction } from '@payloadcms/richtext-lexical/react';
|
||||||
|
import { getCachedPayload } from '@/lib/payload';
|
||||||
|
import type { Post, Media } from '@/payload-types';
|
||||||
|
import { absoluteUrl } from '@/lib/site';
|
||||||
|
import { getFlags } from '@/lib/flags';
|
||||||
|
import {
|
||||||
|
blogPostingJsonLd,
|
||||||
|
breadcrumbJsonLd,
|
||||||
|
personJsonLd,
|
||||||
|
organizationJsonLd,
|
||||||
|
} from '@/lib/jsonld';
|
||||||
|
import { CalloutBlock } from '@/components/blog/CalloutBlock';
|
||||||
|
import styles from './Post.module.css';
|
||||||
|
|
||||||
|
/*
|
||||||
|
* ISR. Unlike the index, this route has a dynamic param and no
|
||||||
|
* generateStaticParams, so there is nothing for the build to prerender: each
|
||||||
|
* post is generated on first request and cached until the collection's
|
||||||
|
* afterChange hook revalidates it. That hook is what makes an edit to an
|
||||||
|
* already-published post appear immediately.
|
||||||
|
*/
|
||||||
|
export const revalidate = 3600;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* heroImage is `number | Media | null`: an id when the query is shallow, the
|
||||||
|
* populated document at depth 1. Both pages query at depth 1, but narrowing
|
||||||
|
* rather than asserting keeps it correct if that ever changes.
|
||||||
|
*/
|
||||||
|
function heroOf(post: Post): Media | null {
|
||||||
|
return typeof post.heroImage === 'object' && post.heroImage !== null
|
||||||
|
? post.heroImage
|
||||||
|
: null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Spreads the default converters and adds the one custom block.
|
||||||
|
*
|
||||||
|
* Without the spread, every default node type — paragraphs, headings, links —
|
||||||
|
* loses its renderer and the post body comes out empty.
|
||||||
|
*/
|
||||||
|
const calloutConverters: JSXConvertersFunction = ({ defaultConverters }) => ({
|
||||||
|
...defaultConverters,
|
||||||
|
blocks: {
|
||||||
|
// Annotated because the generic block converter cannot infer a custom
|
||||||
|
// block's field shape; String() guards the values regardless.
|
||||||
|
callout: ({ node }: { node: { fields: Record<string, unknown> } }) => (
|
||||||
|
<CalloutBlock
|
||||||
|
tone={String(node.fields.tone ?? 'caveat')}
|
||||||
|
body={String(node.fields.body ?? '')}
|
||||||
|
/>
|
||||||
|
),
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Wrapped in React's cache() because Next calls generateMetadata and the page
|
||||||
|
* component separately for the same request — without it, every post view runs
|
||||||
|
* this query against Postgres twice. cache() dedupes within a single request
|
||||||
|
* only, so it never serves one visitor's request from another's.
|
||||||
|
*/
|
||||||
|
const findPost = cache(async (slug: string) => {
|
||||||
|
const payload = await getCachedPayload();
|
||||||
|
const { docs } = await payload.find({
|
||||||
|
collection: 'posts',
|
||||||
|
where: { slug: { equals: slug }, _status: { equals: 'published' } },
|
||||||
|
limit: 1,
|
||||||
|
depth: 1,
|
||||||
|
});
|
||||||
|
return docs[0] ?? null;
|
||||||
|
});
|
||||||
|
|
||||||
|
function summarise(post: Post) {
|
||||||
|
return {
|
||||||
|
title: post.title,
|
||||||
|
slug: post.slug,
|
||||||
|
excerpt: post.excerpt,
|
||||||
|
publishedAt: post.publishedAt,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function generateMetadata(
|
||||||
|
{ params }: { params: Promise<{ slug: string }> },
|
||||||
|
): Promise<Metadata> {
|
||||||
|
const { slug } = await params;
|
||||||
|
const post = await findPost(slug);
|
||||||
|
if (!post) return { title: 'Not found' };
|
||||||
|
|
||||||
|
const hero = heroOf(post);
|
||||||
|
|
||||||
|
return {
|
||||||
|
title: post.title,
|
||||||
|
description: post.excerpt,
|
||||||
|
alternates: { canonical: absoluteUrl(`/blog/${post.slug}`) },
|
||||||
|
openGraph: {
|
||||||
|
type: 'article',
|
||||||
|
title: post.title,
|
||||||
|
description: post.excerpt,
|
||||||
|
url: absoluteUrl(`/blog/${post.slug}`),
|
||||||
|
publishedTime: post.publishedAt,
|
||||||
|
// A post with a hero image shares that; one without falls through to the
|
||||||
|
// generated share card at app/opengraph-image.tsx.
|
||||||
|
...(hero?.url ? { images: [{ url: hero.url }] } : {}),
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
export default async function PostPage(
|
||||||
|
{ params }: { params: Promise<{ slug: string }> },
|
||||||
|
) {
|
||||||
|
const { slug } = await params;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Flags read at this route's own declared floor, so gating costs it nothing.
|
||||||
|
* Checked before the post is fetched: a dark blog should not query Payload.
|
||||||
|
*/
|
||||||
|
const flags = await getFlags(3600);
|
||||||
|
if (flags.blog !== true) notFound();
|
||||||
|
const namedAuthor = flags.about_page === true;
|
||||||
|
|
||||||
|
const post = await findPost(slug);
|
||||||
|
if (!post) notFound();
|
||||||
|
|
||||||
|
const summary = summarise(post);
|
||||||
|
const hero = heroOf(post);
|
||||||
|
|
||||||
|
const jsonLd = {
|
||||||
|
'@context': 'https://schema.org',
|
||||||
|
/*
|
||||||
|
* The Person entity is anchored at /about#tudor, so it is declared only
|
||||||
|
* when that page exists. Claiming an author whose URL 404s is a worse
|
||||||
|
* signal than attributing the post to the publisher.
|
||||||
|
*/
|
||||||
|
'@graph': [
|
||||||
|
blogPostingJsonLd(summary, { namedAuthor }),
|
||||||
|
breadcrumbJsonLd(summary),
|
||||||
|
...(namedAuthor ? [personJsonLd()] : []),
|
||||||
|
organizationJsonLd(),
|
||||||
|
],
|
||||||
|
};
|
||||||
|
|
||||||
|
return (
|
||||||
|
<article className={styles.page}>
|
||||||
|
<script
|
||||||
|
type="application/ld+json"
|
||||||
|
dangerouslySetInnerHTML={{ __html: JSON.stringify(jsonLd) }}
|
||||||
|
/>
|
||||||
|
|
||||||
|
<nav className={styles.crumb}>
|
||||||
|
<Link href="/blog" className={styles.link}>Blog</Link>
|
||||||
|
</nav>
|
||||||
|
|
||||||
|
<h1 className={styles.heading}>{summary.title}</h1>
|
||||||
|
|
||||||
|
<p className={styles.byline}>
|
||||||
|
{/* Unlinked while about_page is dark; the flags are independent. */}
|
||||||
|
By {namedAuthor
|
||||||
|
? <Link href="/about" className={styles.link}>Tudor</Link>
|
||||||
|
: 'Tudor'}
|
||||||
|
{' · '}
|
||||||
|
<time dateTime={summary.publishedAt}>
|
||||||
|
{new Date(summary.publishedAt).toLocaleDateString('en-GB', {
|
||||||
|
day: 'numeric',
|
||||||
|
month: 'long',
|
||||||
|
year: 'numeric',
|
||||||
|
})}
|
||||||
|
</time>
|
||||||
|
</p>
|
||||||
|
|
||||||
|
{/*
|
||||||
|
A plain <img>, not next/image: Payload already generated the sized
|
||||||
|
derivatives on upload (Media's imageSizes), so routing it through the
|
||||||
|
optimizer would resize an image that is already the right size.
|
||||||
|
*/}
|
||||||
|
{hero?.url && (
|
||||||
|
<img
|
||||||
|
className={styles.hero}
|
||||||
|
src={hero.url}
|
||||||
|
alt={hero.alt ?? ''}
|
||||||
|
width={hero.width ?? undefined}
|
||||||
|
height={hero.height ?? undefined}
|
||||||
|
/>
|
||||||
|
)}
|
||||||
|
|
||||||
|
<div className={styles.prose}>
|
||||||
|
<RichText data={post.content} converters={calloutConverters} />
|
||||||
|
</div>
|
||||||
|
</article>
|
||||||
|
);
|
||||||
|
}
|
||||||
@@ -0,0 +1,85 @@
|
|||||||
|
import type { Metadata } from 'next';
|
||||||
|
import Link from 'next/link';
|
||||||
|
import { notFound } from 'next/navigation';
|
||||||
|
import { getCachedPayload } from '@/lib/payload';
|
||||||
|
import { absoluteUrl } from '@/lib/site';
|
||||||
|
import { getFlags } from '@/lib/flags';
|
||||||
|
import styles from './Blog.module.css';
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Dynamic, not ISR.
|
||||||
|
*
|
||||||
|
* This route has no dynamic params, so Next prerenders it at build time — and
|
||||||
|
* CI builds the image with no database reachable, which fails the build. It is
|
||||||
|
* a single indexed query against Postgres on the same Docker network, so
|
||||||
|
* rendering per request is cheap, and it means a newly published post appears
|
||||||
|
* here immediately rather than waiting on a revalidation.
|
||||||
|
*/
|
||||||
|
export const dynamic = 'force-dynamic';
|
||||||
|
|
||||||
|
export const metadata: Metadata = {
|
||||||
|
title: 'Blog',
|
||||||
|
description:
|
||||||
|
'Notes on what school performance data shows, and what it does not.',
|
||||||
|
alternates: { canonical: absoluteUrl('/blog') },
|
||||||
|
};
|
||||||
|
|
||||||
|
function formatDate(value: string) {
|
||||||
|
return new Date(value).toLocaleDateString('en-GB', {
|
||||||
|
day: 'numeric',
|
||||||
|
month: 'long',
|
||||||
|
year: 'numeric',
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
export default async function BlogIndexPage() {
|
||||||
|
const flags = await getFlags();
|
||||||
|
if (flags.blog !== true) notFound();
|
||||||
|
|
||||||
|
const payload = await getCachedPayload();
|
||||||
|
const { docs } = await payload.find({
|
||||||
|
collection: 'posts',
|
||||||
|
where: { _status: { equals: 'published' } },
|
||||||
|
sort: '-publishedAt',
|
||||||
|
limit: 50,
|
||||||
|
depth: 0,
|
||||||
|
});
|
||||||
|
|
||||||
|
return (
|
||||||
|
<div className={styles.page}>
|
||||||
|
<header className={styles.header}>
|
||||||
|
<p className={styles.kicker}>Blog</p>
|
||||||
|
<h1 className={styles.heading}>Notes on the numbers</h1>
|
||||||
|
<p className={styles.standfirst}>
|
||||||
|
What school performance data shows, what it doesn't, and how to
|
||||||
|
read it without being misled. Written by{' '}
|
||||||
|
{/* Plain text when about_page is dark: the two flags are
|
||||||
|
independent, so this link would otherwise point at a 404. */}
|
||||||
|
{flags.about_page === true
|
||||||
|
? <Link href="/about" className={styles.link}>Tudor</Link>
|
||||||
|
: 'Tudor'}.
|
||||||
|
</p>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
{docs.length === 0 ? (
|
||||||
|
<p className={styles.empty}>No posts yet.</p>
|
||||||
|
) : (
|
||||||
|
<ul className={styles.list}>
|
||||||
|
{docs.map((post) => (
|
||||||
|
<li key={post.id} className={styles.item}>
|
||||||
|
<time className={styles.date} dateTime={String(post.publishedAt)}>
|
||||||
|
{formatDate(String(post.publishedAt))}
|
||||||
|
</time>
|
||||||
|
<h2 className={styles.itemTitle}>
|
||||||
|
<Link href={`/blog/${post.slug}`} className={styles.itemLink}>
|
||||||
|
{post.title}
|
||||||
|
</Link>
|
||||||
|
</h2>
|
||||||
|
<p className={styles.excerpt}>{post.excerpt}</p>
|
||||||
|
</li>
|
||||||
|
))}
|
||||||
|
</ul>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
}
|
||||||
@@ -0,0 +1,58 @@
|
|||||||
|
import { getCachedPayload } from '@/lib/payload';
|
||||||
|
import { absoluteUrl } from '@/lib/site';
|
||||||
|
import { getFlags } from '@/lib/flags';
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Dynamic, not ISR.
|
||||||
|
*
|
||||||
|
* This route has no dynamic params, so Next prerenders it at build time — and
|
||||||
|
* CI builds the image with no database reachable, which fails the build. It is
|
||||||
|
* a single indexed query against Postgres on the same Docker network, so
|
||||||
|
* rendering per request is cheap, and it means a newly published post appears
|
||||||
|
* here immediately rather than waiting on a revalidation.
|
||||||
|
*/
|
||||||
|
export const dynamic = 'force-dynamic';
|
||||||
|
|
||||||
|
function escapeXml(value: string): string {
|
||||||
|
return value.replace(/[<>&'"]/g, (char) =>
|
||||||
|
({ '<': '<', '>': '>', '&': '&', "'": ''', '"': '"' }[char]!));
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function GET() {
|
||||||
|
// A dark blog has no feed. 404 rather than an empty channel: an empty feed
|
||||||
|
// is a live feed with nothing in it, which a reader would keep polling.
|
||||||
|
const flags = await getFlags();
|
||||||
|
if (flags.blog !== true) return new Response('Not found', { status: 404 });
|
||||||
|
|
||||||
|
const payload = await getCachedPayload();
|
||||||
|
const { docs } = await payload.find({
|
||||||
|
collection: 'posts',
|
||||||
|
where: { _status: { equals: 'published' } },
|
||||||
|
sort: '-publishedAt',
|
||||||
|
limit: 50,
|
||||||
|
depth: 0,
|
||||||
|
});
|
||||||
|
|
||||||
|
const items = docs.map((post) => `
|
||||||
|
<item>
|
||||||
|
<title>${escapeXml(String(post.title))}</title>
|
||||||
|
<link>${absoluteUrl(`/blog/${post.slug}`)}</link>
|
||||||
|
<guid isPermaLink="true">${absoluteUrl(`/blog/${post.slug}`)}</guid>
|
||||||
|
<description>${escapeXml(String(post.excerpt))}</description>
|
||||||
|
<pubDate>${new Date(String(post.publishedAt)).toUTCString()}</pubDate>
|
||||||
|
</item>`).join('');
|
||||||
|
|
||||||
|
const xml = `<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
<rss version="2.0">
|
||||||
|
<channel>
|
||||||
|
<title>schoolcompare blog</title>
|
||||||
|
<link>${absoluteUrl('/blog')}</link>
|
||||||
|
<description>What school performance data shows, and what it does not.</description>
|
||||||
|
<language>en-GB</language>${items}
|
||||||
|
</channel>
|
||||||
|
</rss>`;
|
||||||
|
|
||||||
|
return new Response(xml, {
|
||||||
|
headers: { 'Content-Type': 'application/rss+xml; charset=utf-8' },
|
||||||
|
});
|
||||||
|
}
|
||||||
File renamed without changes.
@@ -0,0 +1,68 @@
|
|||||||
|
/*
|
||||||
|
* A second sitemap for the URLs Next owns.
|
||||||
|
*
|
||||||
|
* /sitemap.xml is proxied from FastAPI (app/(frontend)/sitemap.xml), which
|
||||||
|
* knows nothing about Payload — the backend and frontend ship as separate
|
||||||
|
* images. Rather than teach it, the Next-owned URLs get their own sitemap and
|
||||||
|
* robots.txt lists both.
|
||||||
|
*/
|
||||||
|
import { getCachedPayload } from '@/lib/payload';
|
||||||
|
import { absoluteUrl } from '@/lib/site';
|
||||||
|
import { getFlags } from '@/lib/flags';
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Dynamic, not ISR.
|
||||||
|
*
|
||||||
|
* This route has no dynamic params, so Next prerenders it at build time — and
|
||||||
|
* CI builds the image with no database reachable, which fails the build. It is
|
||||||
|
* a single indexed query against Postgres on the same Docker network, so
|
||||||
|
* rendering per request is cheap, and it means a newly published post appears
|
||||||
|
* here immediately rather than waiting on a revalidation.
|
||||||
|
*/
|
||||||
|
export const dynamic = 'force-dynamic';
|
||||||
|
|
||||||
|
export async function GET() {
|
||||||
|
/*
|
||||||
|
* A dark page must not be advertised. Submitting a URL that 404s is the one
|
||||||
|
* thing a sitemap is not allowed to do, so each entry is gated on the same
|
||||||
|
* flag that gates the page itself.
|
||||||
|
*
|
||||||
|
* With both flags dark this emits a valid, empty <urlset> rather than a 404:
|
||||||
|
* robots.txt names this sitemap unconditionally, and an empty sitemap is a
|
||||||
|
* well-formed statement that there is nothing here yet.
|
||||||
|
*/
|
||||||
|
const flags = await getFlags();
|
||||||
|
const aboutEnabled = flags.about_page === true;
|
||||||
|
const blogEnabled = flags.blog === true;
|
||||||
|
|
||||||
|
// Only query Payload when the blog is actually being advertised.
|
||||||
|
const docs = blogEnabled
|
||||||
|
? (await (await getCachedPayload()).find({
|
||||||
|
collection: 'posts',
|
||||||
|
where: { _status: { equals: 'published' } },
|
||||||
|
sort: '-publishedAt',
|
||||||
|
limit: 500,
|
||||||
|
depth: 0,
|
||||||
|
})).docs
|
||||||
|
: [];
|
||||||
|
|
||||||
|
const urls: Array<{ loc: string; lastmod: string | null }> = [
|
||||||
|
...(aboutEnabled ? [{ loc: absoluteUrl('/about'), lastmod: null }] : []),
|
||||||
|
...(blogEnabled ? [{ loc: absoluteUrl('/blog'), lastmod: null }] : []),
|
||||||
|
...docs.map((post) => ({
|
||||||
|
loc: absoluteUrl(`/blog/${post.slug}`),
|
||||||
|
lastmod: new Date(String(post.updatedAt ?? post.publishedAt)).toISOString(),
|
||||||
|
})),
|
||||||
|
];
|
||||||
|
|
||||||
|
const xml = `<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
|
||||||
|
${urls.map(({ loc, lastmod }) =>
|
||||||
|
` <url><loc>${loc}</loc>${lastmod ? `<lastmod>${lastmod}</lastmod>` : ''}</url>`,
|
||||||
|
).join('\n')}
|
||||||
|
</urlset>`;
|
||||||
|
|
||||||
|
return new Response(xml, {
|
||||||
|
headers: { 'Content-Type': 'application/xml; charset=utf-8' },
|
||||||
|
});
|
||||||
|
}
|
||||||
@@ -28,6 +28,9 @@
|
|||||||
--bg-primary: #FAFAF8; /* Warm White */
|
--bg-primary: #FAFAF8; /* Warm White */
|
||||||
--bg-secondary: #F5EFE6; /* Sand — hero panels, sunken rows */
|
--bg-secondary: #F5EFE6; /* Sand — hero panels, sunken rows */
|
||||||
--bg-card: #FFFFFF;
|
--bg-card: #FFFFFF;
|
||||||
|
/* For gradients that have to fade to the card colour. A hardcoded white
|
||||||
|
ramp reads as a bright band against a dark card. */
|
||||||
|
--bg-card-rgb: 255, 255, 255;
|
||||||
--surface-inverse: #0F766E;
|
--surface-inverse: #0F766E;
|
||||||
|
|
||||||
/* ── Ink ────────────────────────────────────────────────────────── */
|
/* ── Ink ────────────────────────────────────────────────────────── */
|
||||||
@@ -102,6 +105,23 @@
|
|||||||
--series-7: #0E7A86;
|
--series-7: #0E7A86;
|
||||||
--series-8: #8A4A6B;
|
--series-8: #8A4A6B;
|
||||||
|
|
||||||
|
/* ── Destination measures ───────────────────────────────────────────
|
||||||
|
Education is one hue in three steps (school-like -> college-like) so the
|
||||||
|
education destinations read as one family; apprenticeship and employment
|
||||||
|
are separate hues. The absence is neutral and HATCHED, never a colour:
|
||||||
|
"activity not captured" covers independent schools, moving abroad and
|
||||||
|
training DfE holds no data on, so rendering it as a bad outcome would be
|
||||||
|
a factual error. The hatch is also the secondary encoding that rescues
|
||||||
|
the neutral/blue pair, which separates at only dE 7.6 as flat fills.
|
||||||
|
Every other adjacent pair clears dE 10.9 under protanopia. */
|
||||||
|
--dest-sixthform: #0F766E;
|
||||||
|
--dest-sfcollege: #4A9E96;
|
||||||
|
--dest-fecollege: #7CBFB8;
|
||||||
|
--dest-apprentice: #806200;
|
||||||
|
--dest-employment: #2F6F8F;
|
||||||
|
--dest-none: #6B7580;
|
||||||
|
--dest-none-hatch: rgba(107, 117, 128, 0.34);
|
||||||
|
|
||||||
/* ── Phase: category, desaturated so it stays under the status hues ── */
|
/* ── Phase: category, desaturated so it stays under the status hues ── */
|
||||||
--phase-primary: #0F766E;
|
--phase-primary: #0F766E;
|
||||||
--phase-primary-bg: rgba(167, 215, 197, 0.40);
|
--phase-primary-bg: rgba(167, 215, 197, 0.40);
|
||||||
@@ -234,6 +254,7 @@
|
|||||||
--bg-primary: #111A20;
|
--bg-primary: #111A20;
|
||||||
--bg-secondary: #16222A;
|
--bg-secondary: #16222A;
|
||||||
--bg-card: #18242C;
|
--bg-card: #18242C;
|
||||||
|
--bg-card-rgb: 24, 36, 44;
|
||||||
--surface-inverse: #E9EEF0;
|
--surface-inverse: #E9EEF0;
|
||||||
|
|
||||||
--text-primary: #E9EEF0;
|
--text-primary: #E9EEF0;
|
||||||
@@ -289,6 +310,17 @@
|
|||||||
--series-7: #6FD0DC;
|
--series-7: #6FD0DC;
|
||||||
--series-8: #D99BB8;
|
--series-8: #D99BB8;
|
||||||
|
|
||||||
|
/* Destinations. Not a naive inversion: the education ramp reverses
|
||||||
|
direction so its darkest step stays the one furthest from the
|
||||||
|
school, and each step is re-checked against the dark card. */
|
||||||
|
--dest-sixthform: #5FC7BB;
|
||||||
|
--dest-sfcollege: #3E9B92;
|
||||||
|
--dest-fecollege: #2A716B;
|
||||||
|
--dest-apprentice: #EFC658;
|
||||||
|
--dest-employment: #8FB4D9;
|
||||||
|
--dest-none: #8B9AA1;
|
||||||
|
--dest-none-hatch: rgba(139, 154, 161, 0.34);
|
||||||
|
|
||||||
--phase-primary: #5FC7BB;
|
--phase-primary: #5FC7BB;
|
||||||
--phase-primary-bg: rgba(95, 199, 187, 0.16);
|
--phase-primary-bg: rgba(95, 199, 187, 0.16);
|
||||||
--phase-primary-text: #8ADACF;
|
--phase-primary-text: #8ADACF;
|
||||||
@@ -584,6 +616,35 @@ html .leaflet-bar a:hover {
|
|||||||
color: var(--text-primary);
|
color: var(--text-primary);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The popup, which leaflet.css paints `background: white; color: #333` on both
|
||||||
|
* the card and its tip. The content LeafletMapInner binds into it is themed —
|
||||||
|
* the school name and the headline figure are `var(--text-primary)` — so in
|
||||||
|
* dark mode that was #E9EEF0 on #FFFFFF, a contrast ratio of 1.17:1. The name
|
||||||
|
* and the number were the two least readable things on the page.
|
||||||
|
*
|
||||||
|
* Moving the surface onto --bg-card fixes every foreground at once rather than
|
||||||
|
* one at a time: the muted phase line goes 2.90:1 -> 5.45:1, the vs-national
|
||||||
|
* delta 1.94:1 -> 8.14:1, the Ofsted badge 1.74:1 -> 9.11:1. In light mode
|
||||||
|
* --bg-card is #FFFFFF, so the popup looks as it always did.
|
||||||
|
*/
|
||||||
|
html .leaflet-popup-content-wrapper,
|
||||||
|
html .leaflet-popup-tip {
|
||||||
|
background: var(--bg-card);
|
||||||
|
color: var(--text-primary);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Leaflet's own selector is `.leaflet-container a.leaflet-popup-close-button`
|
||||||
|
at 0,2,1 — an `html` prefix alone would lose to it. */
|
||||||
|
html .leaflet-container a.leaflet-popup-close-button {
|
||||||
|
color: var(--text-muted);
|
||||||
|
}
|
||||||
|
|
||||||
|
html .leaflet-container a.leaflet-popup-close-button:hover,
|
||||||
|
html .leaflet-container a.leaflet-popup-close-button:focus {
|
||||||
|
color: var(--text-primary);
|
||||||
|
}
|
||||||
|
|
||||||
/* Main content column */
|
/* Main content column */
|
||||||
.main {
|
.main {
|
||||||
max-width: 1400px;
|
max-width: 1400px;
|
||||||
@@ -4,8 +4,10 @@ import Script from 'next/script';
|
|||||||
import { Navigation } from '@/components/Navigation';
|
import { Navigation } from '@/components/Navigation';
|
||||||
import { Footer } from '@/components/Footer';
|
import { Footer } from '@/components/Footer';
|
||||||
import { ComparisonToast } from '@/components/ComparisonToast';
|
import { ComparisonToast } from '@/components/ComparisonToast';
|
||||||
|
import { RouteTrail } from '@/components/RouteTrail';
|
||||||
import { ComparisonProvider } from '@/context/ComparisonProvider';
|
import { ComparisonProvider } from '@/context/ComparisonProvider';
|
||||||
import { SITE_URL } from '@/lib/site';
|
import { SITE_URL } from '@/lib/site';
|
||||||
|
import { getFlags } from '@/lib/flags';
|
||||||
import './globals.css';
|
import './globals.css';
|
||||||
|
|
||||||
// Manrope carries headings and key messaging — the guideline's "friendly,
|
// Manrope carries headings and key messaging — the guideline's "friendly,
|
||||||
@@ -57,14 +59,32 @@ export const metadata: Metadata = {
|
|||||||
authors: [{ name: 'schoolcompare' }],
|
authors: [{ name: 'schoolcompare' }],
|
||||||
manifest: '/manifest.json',
|
manifest: '/manifest.json',
|
||||||
// No `icons` key on purpose: setting it here would override the file
|
// No `icons` key on purpose: setting it here would override the file
|
||||||
// conventions. app/icon.svg and app/apple-icon.tsx are the source, and
|
// conventions. app/icon.png and app/apple-icon.png are the source.
|
||||||
// app/opengraph-image.tsx supplies og:image and twitter:image.
|
//
|
||||||
|
// og:image and twitter:image are NOT inherited from
|
||||||
|
// app/opengraph-image.tsx — see the note on openGraph.images below. The
|
||||||
|
// icon conventions do reach these pages; the opengraph-image one does not.
|
||||||
metadataBase: new URL(SITE_URL),
|
metadataBase: new URL(SITE_URL),
|
||||||
openGraph: {
|
openGraph: {
|
||||||
type: 'website',
|
type: 'website',
|
||||||
title: 'Compare Schools Side by Side | schoolcompare',
|
title: 'Compare Schools Side by Side | schoolcompare',
|
||||||
description:
|
description:
|
||||||
'Put five English schools on one screen — SATs, GCSE results, Ofsted grades, and how close you had to live to get a place.',
|
'Put five English schools on one screen — SATs, GCSE results, Ofsted grades, and how close you had to live to get a place.',
|
||||||
|
/*
|
||||||
|
* Declared, not inherited.
|
||||||
|
*
|
||||||
|
* app/opengraph-image.tsx is a metadata file convention, and it does
|
||||||
|
* attach to routes in the app root segment — _not-found gets an og:image
|
||||||
|
* from it. It does not reach the site's pages, which live in the
|
||||||
|
* (frontend) route group whose own layout.tsx is a root layout. Staging
|
||||||
|
* served og:title, og:description, og:url, og:site_name and og:type with
|
||||||
|
* no og:image at all, so every link pasted into a chat rendered bare.
|
||||||
|
*
|
||||||
|
* The file stays at the app root: /robots.txt and /icon.png depend on it
|
||||||
|
* being there, and moving it is what broke those before. This points at
|
||||||
|
* the route it generates instead. metadataBase makes it absolute.
|
||||||
|
*/
|
||||||
|
images: ['/opengraph-image'],
|
||||||
url: SITE_URL,
|
url: SITE_URL,
|
||||||
siteName: 'schoolcompare',
|
siteName: 'schoolcompare',
|
||||||
},
|
},
|
||||||
@@ -74,14 +94,34 @@ export const metadata: Metadata = {
|
|||||||
title: 'Compare Schools Side by Side | schoolcompare',
|
title: 'Compare Schools Side by Side | schoolcompare',
|
||||||
description:
|
description:
|
||||||
'Put five English schools on one screen — SATs, GCSE results, Ofsted grades, and how close you had to live to get a place.',
|
'Put five English schools on one screen — SATs, GCSE results, Ofsted grades, and how close you had to live to get a place.',
|
||||||
|
// The card is summary_large_image; claiming that and supplying no image
|
||||||
|
// is worse than claiming a summary card.
|
||||||
|
images: ['/opengraph-image'],
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
export default function RootLayout({
|
/*
|
||||||
|
* The footer's About and Blog links are flagged, which makes this the one
|
||||||
|
* place on the site that reads a flag on every route.
|
||||||
|
*
|
||||||
|
* 604800 is deliberate and load-bearing: it is the revalidate every SEO route
|
||||||
|
* here already declares. Next pins a route to the LOWEST revalidate among its
|
||||||
|
* fetches, so reading flags at the 300s default would drop the whole school
|
||||||
|
* and place corpus from a weekly cache to a 5-minute one — a large origin-load
|
||||||
|
* regression to hide two footer links.
|
||||||
|
*
|
||||||
|
* The cost is latency in one direction only. The pages themselves read the
|
||||||
|
* same flags at their own floors and flip within minutes; the footer links
|
||||||
|
* follow within a week. Turning a feature on early therefore shows the page
|
||||||
|
* before its footer link, which is harmless. Turning one off leaves a link to
|
||||||
|
* a 404 until the cache turns over, so a rollback that matters wants a purge.
|
||||||
|
*/
|
||||||
|
export default async function RootLayout({
|
||||||
children,
|
children,
|
||||||
}: Readonly<{
|
}: Readonly<{
|
||||||
children: React.ReactNode;
|
children: React.ReactNode;
|
||||||
}>) {
|
}>) {
|
||||||
|
const flags = await getFlags(604800);
|
||||||
return (
|
return (
|
||||||
// The font variable classes must sit on <html>, not <body>. globals.css
|
// The font variable classes must sit on <html>, not <body>. globals.css
|
||||||
// declares --font-display on :root as var(--font-manrope) and --font-ui as
|
// declares --font-display on :root as var(--font-manrope) and --font-ui as
|
||||||
@@ -114,6 +154,10 @@ export default function RootLayout({
|
|||||||
/>
|
/>
|
||||||
</head>
|
</head>
|
||||||
<body>
|
<body>
|
||||||
|
{/* Records every route so funnel attribution has a previous page to
|
||||||
|
name. document.referrer cannot: a soft navigation creates no
|
||||||
|
document, so the browser never updates it. */}
|
||||||
|
<RouteTrail />
|
||||||
<ComparisonProvider>
|
<ComparisonProvider>
|
||||||
<a href="#main-content" className="skip-link">Skip to main content</a>
|
<a href="#main-content" className="skip-link">Skip to main content</a>
|
||||||
<Navigation />
|
<Navigation />
|
||||||
@@ -121,7 +165,10 @@ export default function RootLayout({
|
|||||||
{children}
|
{children}
|
||||||
</main>
|
</main>
|
||||||
<ComparisonToast />
|
<ComparisonToast />
|
||||||
<Footer />
|
<Footer
|
||||||
|
aboutEnabled={flags.about_page === true}
|
||||||
|
blogEnabled={flags.blog === true}
|
||||||
|
/>
|
||||||
</ComparisonProvider>
|
</ComparisonProvider>
|
||||||
</body>
|
</body>
|
||||||
</html>
|
</html>
|
||||||
@@ -8,6 +8,7 @@ import type { Metadata } from 'next';
|
|||||||
import { fetchSchools, fetchFilters, fetchDataInfo } from '@/lib/api';
|
import { fetchSchools, fetchFilters, fetchDataInfo } from '@/lib/api';
|
||||||
import { formatAcademicYear } from '@/lib/utils';
|
import { formatAcademicYear } from '@/lib/utils';
|
||||||
import { HomeView } from '@/components/HomeView';
|
import { HomeView } from '@/components/HomeView';
|
||||||
|
import { getFlags } from '@/lib/flags';
|
||||||
import { HowItWorksSection } from '@/components/HowItWorksSection';
|
import { HowItWorksSection } from '@/components/HowItWorksSection';
|
||||||
import { EditorialSection } from '@/components/EditorialSection';
|
import { EditorialSection } from '@/components/EditorialSection';
|
||||||
|
|
||||||
@@ -63,6 +64,11 @@ export default async function HomePage({ searchParams }: HomePageProps) {
|
|||||||
// Await search params (Next.js 15 requirement)
|
// Await search params (Next.js 15 requirement)
|
||||||
const params = await searchParams;
|
const params = await searchParams;
|
||||||
|
|
||||||
|
// Server-read: no flag value reaches the browser bundle. Threaded down to
|
||||||
|
// both FilterBar instances via HomeView.
|
||||||
|
const flags = await getFlags();
|
||||||
|
const autosuggest = flags.school_autosuggest === true;
|
||||||
|
|
||||||
// Parse search params
|
// Parse search params
|
||||||
const page = parseInt(params.page || '1');
|
const page = parseInt(params.page || '1');
|
||||||
const radius = params.radius ? parseFloat(params.radius) : undefined;
|
const radius = params.radius ? parseFloat(params.radius) : undefined;
|
||||||
@@ -111,6 +117,7 @@ export default async function HomePage({ searchParams }: HomePageProps) {
|
|||||||
const years = dataInfo?.years_available ?? [];
|
const years = dataInfo?.years_available ?? [];
|
||||||
return (
|
return (
|
||||||
<HomeView
|
<HomeView
|
||||||
|
autosuggest={autosuggest}
|
||||||
initialSchools={schoolsData}
|
initialSchools={schoolsData}
|
||||||
filters={resolvedFilters}
|
filters={resolvedFilters}
|
||||||
totalSchools={total}
|
totalSchools={total}
|
||||||
@@ -131,6 +138,7 @@ export default async function HomePage({ searchParams }: HomePageProps) {
|
|||||||
const emptyFilters = { local_authorities: [], school_types: [], years: [], phases: [], genders: [], admissions_policies: [] };
|
const emptyFilters = { local_authorities: [], school_types: [], years: [], phases: [], genders: [], admissions_policies: [] };
|
||||||
return (
|
return (
|
||||||
<HomeView
|
<HomeView
|
||||||
|
autosuggest={autosuggest}
|
||||||
initialSchools={{ schools: [], page: 1, page_size: 50, total: 0, total_pages: 0 }}
|
initialSchools={{ schools: [], page: 1, page_size: 50, total: 0, total_pages: 0 }}
|
||||||
filters={emptyFilters}
|
filters={emptyFilters}
|
||||||
totalSchools={null}
|
totalSchools={null}
|
||||||
File renamed without changes.
+31
-4
@@ -7,6 +7,8 @@
|
|||||||
import { fetchSchoolDetails, fetchSchools, fetchNationalAverages } from '@/lib/api';
|
import { fetchSchoolDetails, fetchSchools, fetchNationalAverages } from '@/lib/api';
|
||||||
import { notFound, redirect } from 'next/navigation';
|
import { notFound, redirect } from 'next/navigation';
|
||||||
import { SchoolDetailShell } from '@/components/school/SchoolDetailShell';
|
import { SchoolDetailShell } from '@/components/school/SchoolDetailShell';
|
||||||
|
import { NearbyPlaces } from '@/components/school/NearbyPlaces';
|
||||||
|
import { schoolBreadcrumbJsonLd, type SchoolPlace } from '@/lib/jsonld';
|
||||||
import { PrimarySchoolSections } from '@/components/school/PrimarySchoolSections';
|
import { PrimarySchoolSections } from '@/components/school/PrimarySchoolSections';
|
||||||
import { SecondarySchoolSections } from '@/components/school/SecondarySchoolSections';
|
import { SecondarySchoolSections } from '@/components/school/SecondarySchoolSections';
|
||||||
import {
|
import {
|
||||||
@@ -148,7 +150,11 @@ export default async function SchoolPage({ params }: SchoolPageProps) {
|
|||||||
notFound();
|
notFound();
|
||||||
}
|
}
|
||||||
|
|
||||||
const { school_info, yearly_data, absence_data, ofsted, census, admissions, admissions_history, admission_distance, deprivation, finance } = data;
|
const { school_info, yearly_data, absence_data, ofsted, census, admissions, admissions_history, admission_distance, deprivation, finance, destinations } = data;
|
||||||
|
// Absent on an older API build; the module and the trail both degrade to
|
||||||
|
// nothing rather than throwing, which is how this shipped without a
|
||||||
|
// lockstep deploy of the two images.
|
||||||
|
const places: SchoolPlace[] = data.places ?? [];
|
||||||
|
|
||||||
// Redirect bare URN to canonical slug URL
|
// Redirect bare URN to canonical slug URL
|
||||||
const canonicalSlug = schoolUrl(urn, school_info.school_name).replace('/school/', '');
|
const canonicalSlug = schoolUrl(urn, school_info.school_name).replace('/school/', '');
|
||||||
@@ -171,6 +177,7 @@ export default async function SchoolPage({ params }: SchoolPageProps) {
|
|||||||
schoolInfo: school_info, yearlyData: yearly_data,
|
schoolInfo: school_info, yearlyData: yearly_data,
|
||||||
absenceData: absence_data, census: census ?? null,
|
absenceData: absence_data, census: census ?? null,
|
||||||
deprivation: deprivation ?? null, finance: finance ?? null,
|
deprivation: deprivation ?? null, finance: finance ?? null,
|
||||||
|
destinations: destinations ?? null,
|
||||||
};
|
};
|
||||||
const primaryFlags = computeSchoolFlags(sectionInput);
|
const primaryFlags = computeSchoolFlags(sectionInput);
|
||||||
const secondaryFlags = computeSecondaryFlags(sectionInput);
|
const secondaryFlags = computeSecondaryFlags(sectionInput);
|
||||||
@@ -184,10 +191,19 @@ export default async function SchoolPage({ params }: SchoolPageProps) {
|
|||||||
const primaryNavItems = buildNavItems(primaryFlags, navInput);
|
const primaryNavItems = buildNavItems(primaryFlags, navInput);
|
||||||
const secondaryNavItems = buildSecondaryNavItems(secondaryFlags, navInput);
|
const secondaryNavItems = buildSecondaryNavItems(secondaryFlags, navInput);
|
||||||
|
|
||||||
// Generate JSON-LD structured data for SEO
|
/*
|
||||||
|
* `School`, not `EducationalOrganization`.
|
||||||
|
*
|
||||||
|
* Both are valid, but EducationalOrganization is the parent type covering
|
||||||
|
* universities, training providers and nurseries alike. School is the
|
||||||
|
* specific one, and a type that says what the page is about is the whole
|
||||||
|
* point of declaring it. Google's own guidance treats the narrower type as
|
||||||
|
* the correct choice where it applies.
|
||||||
|
*/
|
||||||
const structuredData = {
|
const structuredData = {
|
||||||
'@context': 'https://schema.org',
|
'@context': 'https://schema.org',
|
||||||
'@type': 'EducationalOrganization',
|
'@graph': [{
|
||||||
|
'@type': 'School',
|
||||||
name: school_info.school_name,
|
name: school_info.school_name,
|
||||||
identifier: school_info.urn.toString(),
|
identifier: school_info.urn.toString(),
|
||||||
...(school_info.address && {
|
...(school_info.address && {
|
||||||
@@ -209,6 +225,15 @@ export default async function SchoolPage({ params }: SchoolPageProps) {
|
|||||||
...(school_info.school_type && {
|
...(school_info.school_type && {
|
||||||
additionalType: school_info.school_type,
|
additionalType: school_info.school_type,
|
||||||
}),
|
}),
|
||||||
|
},
|
||||||
|
// The trail the page sits at the end of. School pages carried no
|
||||||
|
// breadcrumb at all, while every place page already emitted one.
|
||||||
|
schoolBreadcrumbJsonLd({
|
||||||
|
name: school_info.school_name,
|
||||||
|
url: `/school/${slug}`,
|
||||||
|
places,
|
||||||
|
}),
|
||||||
|
],
|
||||||
};
|
};
|
||||||
|
|
||||||
return (
|
return (
|
||||||
@@ -232,10 +257,11 @@ export default async function SchoolPage({ params }: SchoolPageProps) {
|
|||||||
census={census ?? null}
|
census={census ?? null}
|
||||||
admissions={admissions ?? null}
|
admissions={admissions ?? null}
|
||||||
admissionsHistory={admissions_history ?? []}
|
admissionsHistory={admissions_history ?? []}
|
||||||
admissionDistance={admission_distance ?? null}
|
admissionDistance={admission_distance}
|
||||||
deprivation={deprivation ?? null}
|
deprivation={deprivation ?? null}
|
||||||
finance={finance ?? null}
|
finance={finance ?? null}
|
||||||
nationalAvg={nationalAvg}
|
nationalAvg={nationalAvg}
|
||||||
|
destinations={destinations ?? null}
|
||||||
flags={secondaryFlags}
|
flags={secondaryFlags}
|
||||||
/>
|
/>
|
||||||
</SchoolDetailShell>
|
</SchoolDetailShell>
|
||||||
@@ -262,6 +288,7 @@ export default async function SchoolPage({ params }: SchoolPageProps) {
|
|||||||
/>
|
/>
|
||||||
</SchoolDetailShell>
|
</SchoolDetailShell>
|
||||||
)}
|
)}
|
||||||
|
<NearbyPlaces places={places} />
|
||||||
</>
|
</>
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
@@ -0,0 +1,16 @@
|
|||||||
|
import type { Metadata } from 'next';
|
||||||
|
import config from '@payload-config';
|
||||||
|
import { NotFoundPage, generatePageMetadata } from '@payloadcms/next/views';
|
||||||
|
import { importMap } from '../importMap.js';
|
||||||
|
|
||||||
|
type Args = {
|
||||||
|
params: Promise<{ segments: string[] }>;
|
||||||
|
searchParams: Promise<{ [key: string]: string | string[] }>;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const generateMetadata = ({ params, searchParams }: Args): Promise<Metadata> =>
|
||||||
|
generatePageMetadata({ config, params, searchParams });
|
||||||
|
|
||||||
|
export default function NotFound({ params, searchParams }: Args) {
|
||||||
|
return NotFoundPage({ config, importMap, params, searchParams });
|
||||||
|
}
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
import type { Metadata } from 'next';
|
||||||
|
import config from '@payload-config';
|
||||||
|
import { RootPage, generatePageMetadata } from '@payloadcms/next/views';
|
||||||
|
import { importMap } from '../importMap.js';
|
||||||
|
|
||||||
|
type Args = {
|
||||||
|
params: Promise<{ segments: string[] }>;
|
||||||
|
searchParams: Promise<{ [key: string]: string | string[] }>;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const generateMetadata = ({ params, searchParams }: Args): Promise<Metadata> =>
|
||||||
|
generatePageMetadata({ config, params, searchParams });
|
||||||
|
|
||||||
|
export default function Page({ params, searchParams }: Args) {
|
||||||
|
return RootPage({ config, importMap, params, searchParams });
|
||||||
|
}
|
||||||
@@ -0,0 +1,54 @@
|
|||||||
|
import { RscEntryLexicalCell as RscEntryLexicalCell_44fe37237e0ebf4470c9990d8cb7b07e } from '@payloadcms/richtext-lexical/rsc'
|
||||||
|
import { RscEntryLexicalField as RscEntryLexicalField_44fe37237e0ebf4470c9990d8cb7b07e } from '@payloadcms/richtext-lexical/rsc'
|
||||||
|
import { LexicalDiffComponent as LexicalDiffComponent_44fe37237e0ebf4470c9990d8cb7b07e } from '@payloadcms/richtext-lexical/rsc'
|
||||||
|
import { BlocksFeatureClient as BlocksFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { BoldFeatureClient as BoldFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { ItalicFeatureClient as ItalicFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { UnderlineFeatureClient as UnderlineFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { StrikethroughFeatureClient as StrikethroughFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { SubscriptFeatureClient as SubscriptFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { SuperscriptFeatureClient as SuperscriptFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { InlineCodeFeatureClient as InlineCodeFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { ParagraphFeatureClient as ParagraphFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { HeadingFeatureClient as HeadingFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { AlignFeatureClient as AlignFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { IndentFeatureClient as IndentFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { UnorderedListFeatureClient as UnorderedListFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { OrderedListFeatureClient as OrderedListFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { ChecklistFeatureClient as ChecklistFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { LinkFeatureClient as LinkFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { RelationshipFeatureClient as RelationshipFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { BlockquoteFeatureClient as BlockquoteFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { UploadFeatureClient as UploadFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { HorizontalRuleFeatureClient as HorizontalRuleFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { InlineToolbarFeatureClient as InlineToolbarFeatureClient_e70f5e05f09f93e00b997edb1ef0c864 } from '@payloadcms/richtext-lexical/client'
|
||||||
|
import { CollectionCards as CollectionCards_f9c02e79a4aed9a3924487c0cd4cafb1 } from '@payloadcms/next/rsc'
|
||||||
|
|
||||||
|
/** @type import('payload').ImportMap */
|
||||||
|
export const importMap = {
|
||||||
|
"@payloadcms/richtext-lexical/rsc#RscEntryLexicalCell": RscEntryLexicalCell_44fe37237e0ebf4470c9990d8cb7b07e,
|
||||||
|
"@payloadcms/richtext-lexical/rsc#RscEntryLexicalField": RscEntryLexicalField_44fe37237e0ebf4470c9990d8cb7b07e,
|
||||||
|
"@payloadcms/richtext-lexical/rsc#LexicalDiffComponent": LexicalDiffComponent_44fe37237e0ebf4470c9990d8cb7b07e,
|
||||||
|
"@payloadcms/richtext-lexical/client#BlocksFeatureClient": BlocksFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#BoldFeatureClient": BoldFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#ItalicFeatureClient": ItalicFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#UnderlineFeatureClient": UnderlineFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#StrikethroughFeatureClient": StrikethroughFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#SubscriptFeatureClient": SubscriptFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#SuperscriptFeatureClient": SuperscriptFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#InlineCodeFeatureClient": InlineCodeFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#ParagraphFeatureClient": ParagraphFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#HeadingFeatureClient": HeadingFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#AlignFeatureClient": AlignFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#IndentFeatureClient": IndentFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#UnorderedListFeatureClient": UnorderedListFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#OrderedListFeatureClient": OrderedListFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#ChecklistFeatureClient": ChecklistFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#LinkFeatureClient": LinkFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#RelationshipFeatureClient": RelationshipFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#BlockquoteFeatureClient": BlockquoteFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#UploadFeatureClient": UploadFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#HorizontalRuleFeatureClient": HorizontalRuleFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/richtext-lexical/client#InlineToolbarFeatureClient": InlineToolbarFeatureClient_e70f5e05f09f93e00b997edb1ef0c864,
|
||||||
|
"@payloadcms/next/rsc#CollectionCards": CollectionCards_f9c02e79a4aed9a3924487c0cd4cafb1
|
||||||
|
}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
/*
|
||||||
|
* Payload's REST API, mounted at /cms-api rather than /api.
|
||||||
|
* See lib/payloadRoutes.ts — /api is the FastAPI proxy's catch-all.
|
||||||
|
*/
|
||||||
|
import config from '@payload-config';
|
||||||
|
import {
|
||||||
|
REST_DELETE,
|
||||||
|
REST_GET,
|
||||||
|
REST_OPTIONS,
|
||||||
|
REST_PATCH,
|
||||||
|
REST_POST,
|
||||||
|
REST_PUT,
|
||||||
|
} from '@payloadcms/next/routes';
|
||||||
|
|
||||||
|
export const GET = REST_GET(config);
|
||||||
|
export const POST = REST_POST(config);
|
||||||
|
export const DELETE = REST_DELETE(config);
|
||||||
|
export const PATCH = REST_PATCH(config);
|
||||||
|
export const PUT = REST_PUT(config);
|
||||||
|
export const OPTIONS = REST_OPTIONS(config);
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
import config from '@payload-config';
|
||||||
|
import { GRAPHQL_PLAYGROUND_GET } from '@payloadcms/next/routes';
|
||||||
|
|
||||||
|
export const GET = GRAPHQL_PLAYGROUND_GET(config);
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
import config from '@payload-config';
|
||||||
|
import { GRAPHQL_POST, REST_OPTIONS } from '@payloadcms/next/routes';
|
||||||
|
|
||||||
|
export const POST = GRAPHQL_POST(config);
|
||||||
|
export const OPTIONS = REST_OPTIONS(config);
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
/**
|
||||||
|
* Root layout for the Payload admin panel.
|
||||||
|
*
|
||||||
|
* This is a SECOND root layout: it renders its own <html>/<body>, as does
|
||||||
|
* app/(frontend)/layout.tsx. Next permits that only while no app/layout.tsx
|
||||||
|
* exists — which is why the site's routes were moved into (frontend). Adding
|
||||||
|
* an app/layout.tsx would nest the admin panel inside the site's nav, footer
|
||||||
|
* and providers and emit nested <html>.
|
||||||
|
*/
|
||||||
|
import type { ServerFunctionClient } from 'payload';
|
||||||
|
import config from '@payload-config';
|
||||||
|
import { RootLayout, handleServerFunctions } from '@payloadcms/next/layouts';
|
||||||
|
import { importMap } from './admin/importMap.js';
|
||||||
|
import '@payloadcms/next/css';
|
||||||
|
|
||||||
|
const serverFunction: ServerFunctionClient = async function (args) {
|
||||||
|
'use server';
|
||||||
|
return handleServerFunctions({ ...args, config, importMap });
|
||||||
|
};
|
||||||
|
|
||||||
|
export default function PayloadLayout({ children }: { children: React.ReactNode }) {
|
||||||
|
return (
|
||||||
|
<RootLayout config={config} importMap={importMap} serverFunction={serverFunction}>
|
||||||
|
{children}
|
||||||
|
</RootLayout>
|
||||||
|
);
|
||||||
|
}
|
||||||
Loaded 100 of 185 files, more files were not shown because too many files have changed in this diff.
Show more
Reference in new issue
Block a user