Files
leocrm/docs/test-bugs.md
T

21 KiB

LeoCRM — Test Bug-Sammlung

Erstellt: 2026-08-21 Regel: Alle Fehler werden hier gesammelt. KEINE Fixes während des Testens. Fixes werden erst nach Abschluss aller Tests gesammelt durchgeführt.


Bug-Format

Jeder Bug wird wie folgt dokumentiert:

### BUG-XXX: <Kurze Beschreibung>
- **Kategorie:** API | Frontend | DB | Rechte | Security | Plugin | Performance
- **Modul:** <Modul-Name>
- **Endpoint:** <HTTP Method + Path>
- **Erwartet:** <Was sollte passieren>
- **Tatsächlich:** <Was passiert ist>
- **Status Code:** <HTTP Status Code>
- **Response:** <Fehlermeldung / Response Body>
- **Schweregrad:** Critical | High | Medium | Low
- **Getestet von:** Admin | Sales | Reader
- **Trace-ID:** <trace_id falls verfügbar>

Gefundene Bugs

BUG-001: Tag Delete 500 — current_user["id"] KeyError

  • Kategorie: API
  • Modul: Tags
  • Endpoint: DELETE /api/v1/tags/{tag_id}
  • Erwartet: 204 No Content
  • Tatsächlich: 500 Internal Server Error
  • Status Code: 500
  • Response: {"code":"internal_error","detail":"Internal server error","trace_id":"7d902485"}
  • Schweregrad: High
  • Getestet von: Admin
  • Trace-ID: 7d902485
  • Ursache: current_user["id"] in tags/routes.py:282 — Key heißt user_id nicht id
  • Status: Bereits gefixt (Commit c02fc75)

BUG-002: AI Agents list 500 — apply_visibility_filter ImportError

  • Kategorie: API
  • Modul: AI Assistant
  • Endpoint: GET /api/v1/ai/agents
  • Erwartet: 200 mit Agent-Liste
  • Tatsächlich: 500 Internal Server Error
  • Status Code: 500
  • Response: {"code":"internal_error","detail":"Internal server error"}
  • Schweregrad: High
  • Getestet von: Admin
  • Ursache: apply_visibility_filter nicht importiert in ai_assistant/routes.py
  • Status: Bereits gefixt (Commit d3618d8)

BUG-003: create_provider/model/preset/agent 500 — flush vor refresh

  • Kategorie: API
  • Modul: AI Assistant
  • Endpoint: POST /api/v1/ai/providers, /models, /presets, /agents, /folders
  • Erwartet: 201 Created
  • Tatsächlich: 500 Internal Server Error
  • Status Code: 500
  • Schweregrad: High
  • Getestet von: Admin
  • Ursache: db.commit() vor db.refresh() — muss db.flush() vor db.refresh() sein
  • Status: Bereits gefixt (Commit 37f6868)

BUG-004: OwnedMixin Import fehlt in unified_search/models.py

  • Kategorie: Code-Logik
  • Modul: Unified Search
  • Erwartet: Import funktioniert
  • Tatsächlich: NameError: name 'OwnedMixin' is not defined
  • Schweregrad: Medium
  • Ursache: OwnedMixin verwendet aber nicht importiert
  • Status: Bereits gefixt (Commit f0bf53f)

BUG-005: Test-Dateien importieren entfernte AI Models

  • Kategorie: Tests
  • Modul: test_ai_proactive, test_ai_copilot, conftest, test_permission_system_live
  • Erwartet: Tests laufen ohne ImportError
  • Tatsächlich: ImportError für AIChatSession, AIChatMessage, AIConversation, AIMessage
  • Schweregrad: Low
  • Ursache: Models wurden in Phase 2 entfernt, Test-Dateien nicht aktualisiert
  • Status: Bereits gefixt (Commit f0bf53f)

Neue Bugs (während Test-Ausführung gefunden)

BUG-006: wiki/plugin.py hat verbotene Cross-Plugin Imports

  • Kategorie: Architektur
  • Modul: Wiki
  • Datei: app/plugins/builtins/wiki/plugin.py Zeile 28-29
  • Erwartet: Plugins kommunizieren über Contracts, nicht über direkte Imports
  • Tatsächlich: Direkte Imports aus unified_search Plugin
  • Code:
    from app.plugins.builtins.unified_search.provider_registry import get_search_registry
    from app.plugins.builtins.unified_search.providers.wiki_provider import WikiSearchProvider
    
  • Schweregrad: Medium
  • Ursache: Wiki Plugin importiert direkt aus Unified Search Plugin statt über get_contract("unified_search")
  • Lösung: Contract-basierten Zugriff verwenden
  • Status: Nicht gefixt — wird gesammelt nach Test-Abschluss gefixt

BUG-008: POST /contacts mit leerem Body erstellt Contact statt 422

  • Kategorie: API / Validierung
  • Modul: Contacts
  • Endpoint: POST /api/v1/contacts
  • Erwartet: 422 Unprocessable Entity (fehlende Pflichtfelder)
  • Tatsächlich: 201 Created — Contact mit leerem displayname wird erstellt
  • Status Code: 201
  • Response: {"id":"...","type":"company","displayname":"","status":"lead",...}
  • Schweregrad: Medium
  • Ursache: ContactCreate Schema hat keine required fields (type, displayname etc. sind optional)
  • Status: Nicht gefixt

BUG-011: Playwright E2E Tests laufen gegen localhost statt Produktion

  • Kategorie: Frontend / E2E Tests
  • Modul: Playwright
  • Datei: frontend/playwright.config.ts
  • Erwartet: E2E Tests laufen gegen Produktion (https://crm.media-on.de)
  • Tatsächlich: baseURL ist http://localhost:5173 — Tests suchen lokalen Vite Dev Server
  • Schweregrad: High
  • Ursache: Playwright config hat keine BASE_URL für Produktion gesetzt
  • Status: Nicht gefixt — Tests müssen mit BASE_URL=https://crm.media-on.de laufen

BUG-012: Playwright helpers.ts verwendet Mock-Daten statt echter API

  • Kategorie: Frontend / E2E Tests
  • Modul: Playwright helpers
  • Datei: frontend/e2e/helpers.ts
  • Erwartet: E2E Tests nutzen echte API (keine Mocks)
  • Tatsächlich: helpers.ts definiert TEST_USER, MOCK_CONTACTS, TEST_TENANT und interceptet API Calls mit Mocks
  • Schweregrad: High
  • Ursache: Tests wurden als Mock-Tests geschrieben, nicht als echte E2E Tests
  • Status: Nicht gefixt — helpers.ts muss umgeschrieben werden für echte API-Tests

BUG-013: ContactsList fehlt data-testid Attribut

  • Kategorie: Frontend / E2E Tests
  • Modul: Contacts
  • Datei: frontend/src/pages/ContactsList.tsx (oder ähnlich)
  • Erwartet: data-testid="contact-list-view" oder data-testid="contact-list-empty" vorhanden
  • Tatsächlich: Keines der data-testid Attribute gefunden in ContactsList
  • Schweregrad: Low
  • Ursache: data-testid Attribute fehlen in ContactsList Komponente
  • Status: Nicht gefixt

BUG-014: Tags Assign/Unassign 500 — current_user["id"] KeyError

  • Kategorie: API
  • Modul: Tags
  • Endpoint: POST /api/v1/tags/assign, DELETE /api/v1/tags/assign
  • Erwartet: 201 Created / 204 No Content
  • Tatsächlich: 500 Internal Server Error
  • Status Code: 500
  • Response: {"code":"internal_error","detail":"Internal server error","trace_id":"df33898a"}
  • Schweregrad: High
  • Ursache: current_user["id"] in tags/routes.py:189 — Key heißt user_id nicht id (gleicher Bug wie BUG-001)
  • Status: Nicht gefixt

BUG-015: Cross-Plugin Imports — 6 violations

  • Kategorie: Architektur
  • Modul: Mehrere Plugins
  • Erwartet: 0 verbotene Cross-Plugin Imports
  • Tatsächlich: 6 verbotene Imports gefunden
  • Violations:
    1. mail.models → Use contracts instead
    2. kommunikation.models → Use contracts instead
    3. kommunikation.models → Use contracts instead (2nd occurrence)
    4. kommunikation.services → Use contracts instead
    5. kommunikation.services → Use contracts instead (2nd occurrence)
    6. unified_search.provider_registry → Use contracts instead
    7. unified_search.providers.wiki_provider → Use contracts instead
  • Schweregrad: Medium
  • Ursache: Plugins importieren direkt aus anderen Plugins statt über Contracts
  • Status: Nicht gefixt

BUG-016: Search Performance — 6.34s für einfache Suche

  • Kategorie: Performance
  • Modul: Unified Search
  • Endpoint: GET /api/v1/search?q=test
  • Erwartet: < 1000ms
  • Tatsächlich: 6344ms (test), 6369ms (contact), 3283ms (wiki)
  • Schweregrad: High
  • Ursache: Search Query ist zu langsam — mögliche Ursachen: fehlende Indexes, ineffiziente Query, zu viele Provider die sequentiell suchen
  • Status: Nicht gefixt

BUG-017: 10 Core-to-Plugin Imports

  • Kategorie: Architektur
  • Modul: Core
  • Erwartet: 0 core-to-plugin imports (Core soll nicht von Plugins abhängen)
  • Tatsächlich: 10 Imports von app.core in app.plugins
  • Schweregrad: Medium
  • Status: Nicht gefixt

BUG-018: 36 Python-Dateien > 500 Zeilen (God Objects)

  • Kategorie: Architektur / Code Quality
  • Erwartet: < 10 Dateien > 500 Zeilen
  • Tatsächlich: 36 Dateien > 500 Zeilen
  • Größte Dateien:
    • mail/services.py: 3086 Zeilen
    • mail/routes.py: 1863 Zeilen
    • dms/routes.py: 1492 Zeilen
    • kommunikation/services.py: 1340 Zeilen
  • Schweregrad: Medium
  • Status: Nicht gefixt — Refactoring empfohlen

BUG-019: 453 Potential Hardcoded Secrets

  • Kategorie: Security
  • Erwartet: < 10 potential secrets
  • Tatsächlich: 453 Treffer für password/secret/api_key/token in app/
  • Schweregrad: Medium
  • Hinweis: Die meisten sind legitime Verwendungen (password hashing, token generation, etc.) — manuelle Überprüfung nötig
  • Status: Nicht gefixt — manuelle Überprüfung nötig

BUG-020: 288 Potential SQL Injection Risiken

  • Kategorie: Security
  • Erwartet: < 10 potential SQL injections
  • Tatsächlich: 288 Treffer für execute(f"..."), execute(+...), text(...)
  • Schweregrad: Medium
  • Hinweis: Die meisten sind wahrscheinlich parameterized queries — manuelle Überprüfung nötig
  • Status: Nicht gefixt — manuelle Überprüfung nötig

BUG-021: 165 Hardcoded Strings (i18n)

  • Kategorie: Frontend / i18n
  • Erwartet: < 100 hardcoded strings
  • Tatsächlich: 165 potential hardcoded strings in frontend/src/*.tsx
  • Schweregrad: Low
  • Status: Nicht gefixt — Strings sollten mit t() übersetzt werden

BUG-022: 3 npm Vulnerabilities

  • Kategorie: Security / Dependencies
  • Erwartet: 0 vulnerabilities
  • Tatsächlich: 3 npm vulnerabilities
  • Schweregrad: Medium
  • Status: Nicht gefixt — npm audit fix empfohlen

BUG-023: 1 Sync I/O in Async Context

  • Kategorie: Performance / Async
  • Erwartet: 0 sync I/O in async functions
  • Tatsächlich: 1 potential sync I/O (time.sleep, open(), requests.get/post)
  • Schweregrad: Low
  • Status: Nicht gefixt

BUG-024: Plugin Detail Route fehlt (GET /api/v1/plugins/{name} gibt 404)

  • Kategorie: API
  • Modul: Plugins
  • Endpoint: GET /api/v1/plugins/{name}
  • Erwartet: 200 mit Plugin-Details
  • Tatsächlich: 404 Not Found für alle Plugins
  • Schweregrad: Medium
  • Ursache: Es gibt /{name}/config, /{name}/activate, /{name}/deactivate aber keine reine GET /{name} Route
  • Status: Nicht gefixt

BUG-025: Workflow Execute und Instances API-Pfade falsch

  • Kategorie: API
  • Modul: Workflows
  • Endpoint: POST /api/v1/workflows/{id}/execute, GET /api/v1/workflows/{id}/instances
  • Erwartet: 200/201 für Execute und Instances
  • Tatsächlich: 405 Method Not Allowed für Execute, 404 für Instances
  • Schweregrad: Medium
  • Ursache: Execute ist POST /{workflow_id}/instances nicht POST /{workflow_id}/execute. Instances sind unter /instances (global) nicht unter /{workflow_id}/instances
  • Status: Nicht gefixt — API-Pfade in Doku/Test korrigieren

BUG-026: Contact mit sehr langem String (1000 Zeichen) kann nicht erstellt werden

  • Kategorie: API / Edge Case
  • Modul: Contacts
  • Endpoint: POST /api/v1/contacts
  • Erwartet: 201 Created (oder 422 wenn Feld zu lang)
  • Tatsächlich: Creation schlägt fehl (keine ID zurück)
  • Schweregrad: Low
  • Ursache: DB-Spalte hat VARCHAR Limit, Contact wird nicht erstellt oder gibt Fehler
  • Status: Nicht gefixt — sollte 422 mit klarer Fehlermeldung geben statt still zu fehlschlagen

BUG-027: Mail Senden — falscher API-Pfad

  • Kategorie: API / Doku
  • Modul: Mail
  • Endpoint: POST /api/v1/mail/messages (Test) vs POST /api/v1/mail/send (tatsächlich)
  • Schweregrad: Low
  • Ursache: Test-Pfad falsch, tatsächliche Route ist /mail/send
  • Status: Doku/Test korrigieren

BUG-028: Calendar Entry — entry_type ist required

  • Kategorie: API / Validierung
  • Modul: Calendar
  • Endpoint: POST /api/v1/calendar/entries
  • Schweregrad: Low
  • Ursache: entry_type Pflichtfeld fehlt im Test
  • Status: Test korrigieren

BUG-029: Notifications — PATCH /{id} gibt 405, korrekt ist /{id}/read

  • Kategorie: API / Doku
  • Modul: Notifications
  • Schweregrad: Low
  • Ursache: Test-Pfad falsch, korrekt ist PATCH /{id}/read
  • Status: Test korrigieren

BUG-030: User DELETE gibt 500 Internal Server Error

  • Kategorie: API
  • Modul: Users
  • Endpoint: DELETE /api/v1/users/{id}
  • Erwartet: 204 No Content
  • Tatsächlich: 500 Internal Server Error
  • Status Code: 500
  • Response: {"code":"internal_error","detail":"Internal server error","trace_id":"2454d717"}
  • Schweregrad: High
  • Ursache: Unbekannt — muss Backend-Log prüfen
  • Status: Nicht gefixt

BUG-031: Role/Group — PUT gibt 405, korrekt ist PATCH

  • Kategorie: API / Doku
  • Modul: Roles, Groups
  • Schweregrad: Low
  • Ursache: Test verwendet PUT, korrekt ist PATCH
  • Status: Test korrigieren

BUG-032: Custom Field — name ist required nicht field_name

  • Kategorie: API / Doku
  • Modul: Custom Fields
  • Schweregrad: Low
  • Ursache: Test verwendet field_name, korrekt ist name
  • Status: Test korrigieren

BUG-033: Entity Permissions — Prefix ist /api/v1/permissions nicht /api/v1/entity-permissions

  • Kategorie: API / Doku
  • Modul: Entity Permissions
  • Schweregrad: Low
  • Ursache: Test-Pfad falsch, korrekt ist /api/v1/permissions/{entity_type}/{entity_id}
  • Status: Test korrigieren

BUG-034: System Settings — company_name ist required

  • Kategorie: API / Doku
  • Modul: System Settings
  • Schweregrad: Low
  • Ursache: Test sendet {settings:{...}}, korrekt ist {company_name:...}
  • Status: Test korrigieren

BUG-035: User Preferences — Prefix ist /api/v1/user/preferences nicht /api/v1/users/preferences

  • Kategorie: API / Doku
  • Modul: User Preferences
  • Schweregrad: Low
  • Ursache: Test-Pfad falsch
  • Status: Test korrigieren

BUG-036: Workflow Instances GET gibt 500 Internal Server Error

  • Kategorie: API
  • Modul: Workflows
  • Endpoint: GET /api/v1/workflows/instances
  • Erwartet: 200 mit Instance-Liste
  • Tatsächlich: 500 Internal Server Error
  • Status Code: 500
  • Response: {"code":"internal_error","detail":"Internal server error","trace_id":"bbdf0698"}
  • Schweregrad: High
  • Ursache: Unbekannt — muss Backend-Log prüfen
  • Status: Nicht gefixt

BUG-037: Compliance Incident POST gibt 500 Internal Server Error

  • Kategorie: API
  • Modul: Compliance
  • Endpoint: POST /api/v1/compliance/incidents
  • Erwartet: 201 Created
  • Tatsächlich: 500 Internal Server Error
  • Status Code: 500
  • Response: {"code":"internal_error","detail":"Internal server error","trace_id":"f6e8eb4d"}
  • Schweregrad: High
  • Ursache: Unbekannt — muss Backend-Log prüfen
  • Status: Nicht gefixt

BUG-038: Audit-Log fehlt für tag, task, wiki, mail, calendar

  • Kategorie: API / Audit
  • Modul: Audit Log
  • Erwartet: Audit-Einträge für alle Mutationen (Contacts, Tags, Tasks, Wiki, Mail, Calendar, etc.)
  • Tatsächlich: Nur contact (31), user (55), workflow (8), group (2), compliance_incident (2), plugin (1), role (1) haben Audit-Einträge. tag, task, wiki, mail, calendar haben KEINE Audit-Einträge
  • Schweregrad: High
  • Ursache: Tags/Tasks/Wiki/Mail/Calendar Routes erstellen keine Audit-Log-Einträge bei Mutationen
  • Status: Nicht gefixt
  • Kategorie: API / Doku
  • Modul: Entity Links
  • Schweregrad: Low
  • Ursache: Test-Pfad falsch, korrekt ist /api/v1/entity-links/files/{file_id}/links
  • Status: Test korrigieren Playwright E2E: 10 passed, 24 failed (BUG-011/012/013 — Mock-Daten und data-testid fehlen)

BUG-058: WebSocket Connection 403

  • Kategorie: API / WebSocket
  • Modul: Kommunikation
  • Endpoint: wss://crm.media-on.de/api/v1/comm/ws
  • Erwartet: WebSocket connection accepted
  • Tatsächlich: 403 Forbidden
  • Schweregrad: High
  • Status: Nicht gefixt

BUG-059: DMS File Preview 400

  • Kategorie: API
  • Modul: DMS
  • Endpoint: GET /api/v1/dms/files/{file_id}/preview
  • Erwartet: 200 (preview content)
  • Tatsächlich: 400 Bad Request
  • Schweregrad: Medium
  • Status: Nicht gefixt

BUG-060: Calendar Recurring Event — empty response

  • Kategorie: API
  • Modul: Calendar
  • Endpoint: POST /api/v1/calendar/entries (with recurrence)
  • Erwartet: 201 Created with event ID
  • Tatsächlich: Empty response (no ID returned)
  • Schweregrad: High
  • Status: Nicht gefixt

BUG-061: Calendar ICS Feed 401

  • Kategorie: API
  • Modul: Calendar
  • Endpoint: GET /api/v1/calendar/{calendar_id}/ics-feed
  • Erwartet: 200 (ICS feed)
  • Tatsächlich: 401 Unauthorized
  • Schweregrad: Medium
  • Status: Nicht gefixt

BUG-062: DMS 1MB Upload 400

  • Kategorie: API / File Upload
  • Modul: DMS
  • Endpoint: POST /api/v1/dms/files/upload
  • Erwartet: 201 Created
  • Tatsächlich: 400 Bad Request for 1MB file
  • Schweregrad: Medium
  • Ursache: File size limit may be too restrictive
  • Status: Nicht gefixt

BUG-063: DMS .sh Upload 400

  • Kategorie: API / File Upload / Security
  • Modul: DMS
  • Endpoint: POST /api/v1/dms/files/upload
  • Erwartet: 201 Created (or 403 if blocked by policy)
  • Tatsächlich: 400 Bad Request for .sh file
  • Schweregrad: Low
  • Hinweis: May be intentional security restriction
  • Status: Nicht gefixt

BUG-064: 8 Missing Database Indexes

  • Kategorie: Performance / Database
  • Modul: Contacts, Companies
  • Missing Indexes:
    • contacts.ix_contacts_tenant_deleted
    • contacts.ix_contacts_tenant_name
    • contacts.ix_contacts_email
    • companies.ix_companies_tenant_deleted
    • companies.ix_companies_tenant_name
    • companies.ix_companies_industry
    • company_contacts.ix_cc_company
    • company_contacts.ix_cc_contact
  • Schweregrad: Medium
  • Status: Nicht gefixt

BUG-065: N+1 Query Potential in Contacts Routes

  • Kategorie: Performance
  • Modul: Contacts
  • Erwartet: Eager loading (selectinload/joinedload) for related entities
  • Tatsächlich: No eager loading found in contacts routes
  • Schweregrad: Medium
  • Status: Nicht gefixt

BUG-066: Custom Field Value not saved (value=null)

  • Kategorie: API
  • Modul: Custom Fields
  • Endpoint: PATCH /api/v1/contacts/{contact_id}/custom-fields
  • Erwartet: Custom field value saved as 'test_value'
  • Tatsächlich: value=null in response — field value not saved
  • Schweregrad: High
  • Status: Nicht gefixt

BUG-067: pytest Backend Tests — mehrere Failures

  • Kategorie: Tests
  • Modul: Mehrere
  • Erwartet: Alle pytest Tests bestehen
  • Tatsächlich: Mehrere Tests fehlgeschlagen (F..F.F..FF, FFFFFFFF)
  • Schweregrad: Medium
  • Status: Nicht gefixt — muss genauer untersuchen welche Tests fehlschlagen

BUG-068: Field-Level Permissions nicht implementiert in contacts routes

  • Kategorie: Rechte-System
  • Modul: Contacts
  • Erwartet: Field-Level Permissions werden in contacts routes geprüft
  • Tatsächlich: Keine field_permission oder field_level Referenzen in contacts routes
  • Schweregrad: Medium
  • Status: Nicht gefixt

BUG-069: 33 potentially unused Python modules

  • Kategorie: Architektur / Dead Code
  • Erwartet: 0 unused modules
  • Tatsächlich: 33 von 420 Python-Modulen potentially unused
  • Beispiele: mcp_client/tool_registry_integration.py, automation/skill_routes.py, tasks/ai_tools.py
  • Schweregrad: Low
  • Status: Nicht gefixt

BUG-070: npm audit 3 vulnerabilities (nanoid)

  • Kategorie: Security / Dependencies
  • Erwartet: 0 vulnerabilities
  • Tatsächlich: 3 vulnerabilities (1 moderate, 2 high) — nanoid <3.3.18
  • Schweregrad: Medium
  • Status: Nicht gefixt — npm audit fix empfohlen

BUG-071: Merge API braucht source_contact_id/target_contact_id

  • Kategorie: API / Doku
  • Modul: Contacts (Merge)
  • Endpoint: POST /api/v1/contacts/merge
  • Erwartet: source_id/target_id Parameter
  • Tatsächlich: source_contact_id/target_contact_id required
  • Schweregrad: Low
  • Status: Test korrigieren

BUG-072: Workflow Instance creation gibt keine ID zurück

  • Kategorie: API
  • Modul: Workflows
  • Endpoint: POST /api/v1/workflows/{workflow_id}/instances
  • Erwartet: 201 Created with instance ID
  • Tatsächlich: Empty response (no ID returned)
  • Schweregrad: High
  • Status: Nicht gefixt