Two findings from the reviewer's latest pass:
- config_validators.py:329: comment in the LOGIN_FLOW validation block
still referenced `_sync_derived_flags` (removed in commit 5; derivation
now lives in `Settings.__post_init__`). Updated the comment to point at
the correct location so a future reader grepping for the function name
doesn't come up empty.
- tests/unit/test_config_validators.py: added
`test_oauth_single_audience_migration_hint` next to the existing
`test_invalid_deployment_mode_raises_error`. The new test pins the
ADR-022 rename-hint branch in `detect_auth_mode` by setting
`MCP_DEPLOYMENT_MODE=oauth_single_audience` and asserting the
ValueError mentions both the old and new mode names plus "ADR-022".
Without this, a future refactor could drop the hint without any test
catching it (the prior `invalid_mode` test only asserts the generic
"Valid values:" prefix).
No functional changes; 1010 unit tests now pass (+1 from the new hint
test).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>