Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 1 | //! Every response the REST routes give, run through the converter the API |
| 2 | //! sends them with, checked for `camelCase` that would leak out. | |
| 3 | //! | |
| 4 | //! The samples are the reference's example responses, put back into the | |
| 5 | //! `camelCase` the services send (as serde's `rename_all` writes it) and, | |
| 6 | //! where an operation returns a contract type, decoded into that type and | |
| 7 | //! encoded again, so that every field the type has is sent, not only the | |
| 8 | //! ones an example shows. | |
| 9 | ||
| Merge checks: statuses and check runs on every commit | 10 | use g1t_contracts::{access, actions, checks, codeowners, integrations, repos, rules, search, teams, webhooks, work}; |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 11 | use g1t_kit::wire::{self, USER_KEYED}; |
| 12 | use serde::Serialize; | |
| 13 | use serde::de::DeserializeOwned; | |
| 14 | use serde_json::{Map, Value, json}; | |
| 15 | ||
| 16 | use crate::openapi::document; | |
| 17 | use crate::operations::Op; | |
| Merge checks: statuses and check runs on every commit | 18 | use crate::checks::ChecksOp; |
| Merge rulesets: branch and tag rules, agent-first, enforced on push and merge | 19 | use crate::rules::RulesOp; |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 20 | |
| 21 | /// A key as `#[serde(rename_all = "camelCase")]` writes it. | |
| 22 | fn camel_key(key: &str) -> String { | |
| 23 | let mut out = String::with_capacity(key.len()); | |
| 24 | let mut upper = false; | |
| 25 | for c in key.chars() { | |
| 26 | if c == '_' { | |
| 27 | upper = true; | |
| 28 | } else if upper { | |
| 29 | out.extend(c.to_uppercase()); | |
| 30 | upper = false; | |
| 31 | } else { | |
| 32 | out.push(c); | |
| 33 | } | |
| 34 | } | |
| 35 | out | |
| 36 | } | |
| 37 | ||
| 38 | /// A response as the services send it: `camelCase`, but for the maps the | |
| 39 | /// converter passes through, which are data. | |
| 40 | fn as_services_send(value: &Value) -> Value { | |
| 41 | match value { | |
| 42 | Value::Object(fields) => { | |
| 43 | let mut out = Map::new(); | |
| 44 | for (key, value) in fields { | |
| 45 | let user_keyed = value.is_object() | |
| 46 | && (USER_KEYED.contains(&key.as_str()) || key.starts_with("by_")); | |
| 47 | let value = if user_keyed { value.clone() } else { as_services_send(value) }; | |
| 48 | // A `by_…` map keeps its name in the converter's spelling. | |
| 49 | let key = if key.starts_with("by_") { key.clone() } else { camel_key(key) }; | |
| 50 | out.insert(key, value); | |
| 51 | } | |
| 52 | Value::Object(out) | |
| 53 | } | |
| 54 | Value::Array(items) => Value::Array(items.iter().map(as_services_send).collect()), | |
| 55 | other => other.clone(), | |
| 56 | } | |
| 57 | } | |
| 58 | ||
| 59 | /// `value` decoded as `T` and encoded again, as the service would send it. | |
| 60 | fn through<T: DeserializeOwned + Serialize>(op: Op, value: Value) -> Value { | |
| 61 | let decoded: T = serde_json::from_value(value) | |
| 62 | .unwrap_or_else(|error| panic!("{}: the example is not a {}: {error}", op.name(), std::any::type_name::<T>())); | |
| 63 | serde_json::to_value(decoded).unwrap() | |
| 64 | } | |
| 65 | ||
| 66 | /// What the service behind an operation sends, from its example. | |
| 67 | fn sample(op: Op, example: &Value) -> Value { | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 68 | // Types serde already writes in `snake_case`: a person, and who has |
| 69 | // access. Sent as they are. | |
| 70 | let as_is = example.clone(); | |
| 71 | match op { | |
| 72 | Op::Whoami => return through::<g1t_contracts::User>(op, as_is), | |
| 73 | Op::ListCollaborators => return through::<access::RepoAccess>(op, as_is), | |
| 74 | Op::AddCollaborator => return through::<access::Added>(op, as_is), | |
| 75 | Op::UpdateCollaborator => return through::<access::Collaborator>(op, as_is), | |
| 76 | Op::GetCollaboratorPermission => return through::<access::PermissionInfo>(op, as_is), | |
| 77 | Op::ListRepoInvitations | Op::ListMyRepoInvitations => { | |
| 78 | return through::<Vec<access::RepoInvitation>>(op, as_is); | |
| 79 | } | |
| 80 | Op::RevokeRepoInvitation | Op::AcceptRepoInvitation | Op::DeclineRepoInvitation => { | |
| 81 | return through::<access::RepoInvitation>(op, as_is); | |
| 82 | } | |
| 83 | Op::ListOutsideCollaborators => return through::<Vec<access::OutsideCollaborator>>(op, as_is), | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 84 | // Teams and code owners, also `snake_case`. |
| 85 | Op::ListTeams | Op::ListChildTeams | Op::ListUserTeams => return through::<Vec<teams::Team>>(op, as_is), | |
| 86 | Op::GetTeam | Op::CreateTeam | Op::UpdateTeam | Op::SetTeamReviewAssignment => { | |
| 87 | return through::<teams::Team>(op, as_is); | |
| 88 | } | |
| 89 | Op::ListTeamMembers => return through::<Vec<teams::TeamMember>>(op, as_is), | |
| 90 | Op::SetTeamMember => return through::<teams::TeamMember>(op, as_is), | |
| 91 | Op::ListTeamRepos => return through::<Vec<teams::TeamRepo>>(op, as_is), | |
| 92 | Op::SetTeamRepo => return through::<teams::TeamRepo>(op, as_is), | |
| 93 | Op::DeleteTeam | Op::RemoveTeamMember | Op::RemoveTeamRepo => return through::<bool>(op, as_is), | |
| 94 | Op::GetCodeownersErrors => return through::<codeowners::CodeOwnersReport>(op, as_is), | |
| Merge rulesets: branch and tag rules, agent-first, enforced on push and merge | 95 | // Rulesets travel in `snake_case` between services too. |
| 96 | Op::Rules(RulesOp::ListRepoRulesets | RulesOp::ListWorkspaceRulesets) => { | |
| 97 | return through::<Vec<rules::Ruleset>>(op, as_is); | |
| 98 | } | |
| 99 | Op::Rules( | |
| 100 | RulesOp::GetRepoRuleset | |
| 101 | | RulesOp::CreateRepoRuleset | |
| 102 | | RulesOp::UpdateRepoRuleset | |
| 103 | | RulesOp::GetWorkspaceRuleset | |
| 104 | | RulesOp::CreateWorkspaceRuleset | |
| 105 | | RulesOp::UpdateWorkspaceRuleset, | |
| 106 | ) => return through::<rules::Ruleset>(op, as_is), | |
| 107 | Op::Rules(RulesOp::GetBranchRules) => return through::<rules::EffectiveRules>(op, as_is), | |
| 108 | Op::Rules(RulesOp::ListRuleEvaluations | RulesOp::ListWorkspaceRuleEvaluations) => { | |
| 109 | return through::<rules::EvaluationPage>(op, as_is); | |
| 110 | } | |
| 111 | // Built by the API itself. | |
| 112 | Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset) => return as_is, | |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 113 | // Deployments travel in `snake_case` between services too. |
| 114 | Op::Deployments(_) => return as_is, | |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 115 | // Built by the API itself, in `snake_case`. |
| 116 | Op::ListSecurityAlerts => return through::<Vec<crate::alerts::SecurityAlert>>(op, as_is), | |
| 117 | Op::DismissSecurityAlert | Op::ReopenSecurityAlert => { | |
| 118 | return through::<crate::alerts::SecurityAlert>(op, as_is); | |
| 119 | } | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 120 | _ => {} |
| 121 | } | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 122 | let mut sent = as_services_send(example); |
| 123 | // A pull request's code owners are `snake_case` inside it. | |
| 124 | if op == Op::GetPullRequest | |
| 125 | && let Some(code_owners) = example.get("code_owners") | |
| 126 | { | |
| 127 | sent["codeOwners"] = code_owners.clone(); | |
| 128 | } | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 129 | match op { |
| Merge branch 'worktree-agent-ad7c6d88d93adc817' | 130 | Op::GetWorkspace | Op::CreateWorkspace | Op::UpdateWorkspace => through::<g1t_contracts::identity::Workspace>(op, sent), |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 131 | Op::ListRepos => through::<Vec<repos::Repo>>(op, sent), |
| Search across all of g1t, Explore, and a command palette | 132 | Op::Search => through::<search::SearchResults>(op, sent), |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 133 | Op::GetRepo |
| 134 | | Op::CreateRepo | |
| 135 | | Op::UpdateRepo | |
| 136 | | Op::TransferRepo | |
| 137 | | Op::RenameRepo | |
| 138 | | Op::RenameBranch | |
| 139 | | Op::ArchiveRepo | |
| 140 | | Op::UnarchiveRepo | |
| 141 | | Op::SetRepoVisibility | |
| 142 | | Op::RestoreRepo => through::<repos::Repo>(op, sent), | |
| 143 | Op::DeleteRepo => through::<repos::DeletedRepo>(op, sent), | |
| 144 | Op::ListDeletedRepos => through::<Vec<repos::DeletedRepo>>(op, sent), | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 145 | Op::GetRepoSettings | Op::UpdateRepoSettings => through::<work::RepoSettings>(op, sent), |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 146 | Op::ListCheckNames => through::<Vec<work::SeenCheck>>(op, sent), |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 147 | Op::GetMergeQueue => through::<work::QueueView>(op, sent), |
| 148 | Op::ListIssues => through::<Vec<work::Issue>>(op, sent), | |
| 149 | Op::CreateIssue | Op::UpdateIssue | Op::CloseIssue | Op::ReopenIssue => { | |
| 150 | through::<work::Issue>(op, sent) | |
| 151 | } | |
| 152 | Op::GetIssue => through::<work::IssueDetail>(op, sent), | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 153 | Op::Delegate => through::<work::Delegated>(op, sent), |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 154 | Op::ListPullRequests => through::<Vec<work::Pull>>(op, sent), |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 155 | Op::UpdatePullRequest => through::<work::Pull>(op, sent), |
| 156 | Op::ListLabels | Op::AddDefaultLabels | Op::ListIssueLabels => through::<Vec<work::Label>>(op, sent), | |
| 157 | Op::CreateLabel | Op::UpdateLabel => through::<work::Label>(op, sent), | |
| 158 | Op::ListMilestones => through::<Vec<work::Milestone>>(op, sent), | |
| 159 | Op::CreateMilestone | Op::UpdateMilestone => through::<work::Milestone>(op, sent), | |
| 160 | Op::GetMilestone => through::<work::MilestoneDetail>(op, sent), | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 161 | Op::GetPullRequest => through::<work::PullDetail>(op, sent), |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 162 | Op::MarkPullRequestReady |
| 163 | | Op::ClosePullRequest | |
| 164 | | Op::MergePullRequest | |
| 165 | | Op::AssignIssue | |
| 166 | | Op::RequestReviewers | |
| 167 | | Op::RemoveRequestedReviewers => { | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 168 | through::<work::Pull>(op, sent) |
| 169 | } | |
| 170 | Op::ListWorkflows => through::<Vec<actions::Workflow>>(op, sent), | |
| 171 | Op::ListWorkflowRuns => through::<Vec<actions::WorkflowRun>>(op, sent), | |
| 172 | Op::GetWorkflowRun => through::<actions::RunDetail>(op, sent), | |
| 173 | Op::GetJobLogs => through::<actions::JobLog>(op, sent), | |
| 174 | Op::DispatchWorkflow | Op::CancelWorkflowRun | Op::RerunWorkflowRun => { | |
| 175 | through::<actions::WorkflowRun>(op, sent) | |
| 176 | } | |
| 177 | Op::ListActionsSecrets | Op::ListActionsVariables => through::<Vec<actions::Setting>>(op, sent), | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 178 | Op::ListRunners => through::<Vec<g1t_contracts::runners::Runner>>(op, sent), |
| 179 | Op::ListRunnerGroups => through::<Vec<g1t_contracts::runners::RunnerGroup>>(op, sent), | |
| 180 | Op::CreateRunnerGroup | Op::UpdateRunnerGroup => through::<g1t_contracts::runners::RunnerGroup>(op, sent), | |
| 181 | Op::GetRunnerSettings | Op::UpdateRunnerSettings => through::<g1t_contracts::runners::RunnerSettings>(op, sent), | |
| 182 | Op::CreateRunnerRegistrationToken => through::<g1t_contracts::runners::RegistrationToken>(op, sent), | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 183 | Op::ListWebhooks => through::<Vec<webhooks::Hook>>(op, sent), |
| 184 | Op::ListIntegrations => through::<Vec<integrations::Connection>>(op, sent), | |
| 185 | Op::GetModelRoutes | Op::SetModelRoutes => through::<Vec<integrations::ModelRoute>>(op, sent), | |
| 186 | Op::ListEvents => through::<Vec<g1t_contracts::events::Event>>(op, sent), | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 187 | Op::ListEmails | Op::AddEmail | Op::RemoveEmail | Op::UpdateEmailSettings => { |
| 188 | through::<g1t_contracts::accounts::AccountEmails>(op, sent) | |
| 189 | } | |
| 190 | Op::ListInvites => through::<g1t_contracts::identity::InvitesOverview>(op, sent), | |
| 191 | Op::CreateInvite | Op::RevokeInvite | Op::InviteMember | Op::RevokeWorkspaceInvite => { | |
| 192 | through::<g1t_contracts::identity::Invite>(op, sent) | |
| 193 | } | |
| 194 | Op::ListWorkspaceInvites => through::<Vec<g1t_contracts::identity::Invite>>(op, sent), | |
| API: notifications over REST and MCP, with notifications scopes | 195 | Op::ListNotifications => through::<g1t_contracts::inbox::InboxPage>(op, sent), |
| 196 | Op::GetNotificationThread | Op::MarkThreadRead | Op::MarkThreadDone | Op::SaveThread | Op::SnoozeThread => { | |
| 197 | through::<g1t_contracts::inbox::InboxThread>(op, sent) | |
| 198 | } | |
| 199 | Op::GetThreadSubscription | Op::SetThreadSubscription | Op::DeleteThreadSubscription => { | |
| 200 | through::<g1t_contracts::inbox::ThreadSubscription>(op, sent) | |
| 201 | } | |
| Merge checks: statuses and check runs on every commit | 202 | Op::Checks(ChecksOp::CreateCommitStatus) => through::<work::CommitStatus>(op, sent), |
| 203 | Op::Checks(ChecksOp::ListCommitStatuses) => through::<Vec<work::CommitStatus>>(op, sent), | |
| 204 | Op::Checks(ChecksOp::GetCombinedStatus) => through::<checks::CombinedStatus>(op, sent), | |
| 205 | Op::Checks(ChecksOp::CreateCheckRun | ChecksOp::UpdateCheckRun | ChecksOp::GetCheckRun) => { | |
| 206 | through::<checks::CommitCheckRun>(op, sent) | |
| 207 | } | |
| 208 | Op::Checks(ChecksOp::ListCheckRunAnnotations) => through::<Vec<checks::CheckAnnotation>>(op, sent), | |
| 209 | Op::Checks(ChecksOp::ListCheckRunsForRef) => through::<checks::CheckRunList>(op, sent), | |
| 210 | Op::Checks(ChecksOp::ListCheckSuitesForRef) => through::<checks::CheckSuiteList>(op, sent), | |
| 211 | Op::Checks(ChecksOp::GetCheckSuite) => through::<checks::CommitCheckSuite>(op, sent), | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 212 | _ => sent, |
| 213 | } | |
| 214 | } | |
| 215 | ||
| 216 | /// Every key of `example`, as paths, outside the maps passed through. | |
| 217 | fn paths(value: &Value, path: &str, out: &mut Vec<String>) { | |
| 218 | match value { | |
| 219 | Value::Object(fields) => { | |
| 220 | for (key, value) in fields { | |
| 221 | let here = format!("{path}.{key}"); | |
| 222 | out.push(here.clone()); | |
| 223 | let user_keyed = value.is_object() | |
| 224 | && (USER_KEYED.contains(&key.as_str()) || key.starts_with("by_")); | |
| 225 | if !user_keyed { | |
| 226 | paths(value, &here, out); | |
| 227 | } | |
| 228 | } | |
| 229 | } | |
| 230 | Value::Array(items) => { | |
| 231 | for item in items { | |
| 232 | paths(item, &format!("{path}[]"), out); | |
| 233 | } | |
| 234 | } | |
| 235 | _ => {} | |
| 236 | } | |
| 237 | } | |
| 238 | ||
| 239 | #[test] | |
| 240 | fn no_route_answers_with_camel_case() { | |
| 241 | let document = document(); | |
| 242 | let (mut checked, mut converted) = (0, 0); | |
| 243 | for (path, methods) in document["paths"].as_object().unwrap() { | |
| 244 | for (method, operation) in methods.as_object().unwrap() { | |
| 245 | let example = &operation["responses"]["200"]["content"]["application/json"]["example"]; | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 246 | let tool = operation["x-operation"].as_str().unwrap_or_default(); |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 247 | let Some(op) = Op::by_name(tool) else { |
| 248 | // Device sign-in, which is written in `snake_case` by hand. | |
| 249 | assert!(wire::camel_case_keys(example).is_empty(), "{method} {path}"); | |
| 250 | continue; | |
| 251 | }; | |
| 252 | let sample = sample(op, example); | |
| 253 | converted += wire::camel_case_keys(&sample).len(); | |
| 254 | let sent = wire::snake_case(sample); | |
| 255 | let leaked = wire::camel_case_keys(&sent); | |
| 256 | assert!(leaked.is_empty(), "{method} {path} sends {leaked:?}"); | |
| 257 | // The reference shows what is sent: each of its names is one. | |
| 258 | let (mut shown, mut real) = (Vec::new(), Vec::new()); | |
| 259 | paths(example, "", &mut shown); | |
| 260 | paths(&sent, "", &mut real); | |
| 261 | for name in shown { | |
| 262 | assert!(real.contains(&name), "{method} {path}: the reference shows {name}, which is not sent"); | |
| 263 | } | |
| 264 | checked += 1; | |
| 265 | } | |
| 266 | } | |
| 267 | assert!(checked >= Op::ALL.len()); | |
| 268 | // The samples are in the services' spelling, so there was something to | |
| 269 | // convert. | |
| 270 | assert!(converted > 100, "{converted}"); | |
| 271 | } | |
| 272 | ||
| 273 | #[test] | |
| 274 | fn every_route_has_a_sample() { | |
| 275 | let document = document(); | |
| 276 | for route in crate::rest::ROUTES { | |
| 277 | let path = route | |
| 278 | .path | |
| 279 | .split('/') | |
| 280 | .map(|segment| match segment.strip_prefix(':') { | |
| 281 | Some(name) => format!("{{{name}}}"), | |
| 282 | None => segment.to_owned(), | |
| 283 | }) | |
| 284 | .collect::<Vec<_>>() | |
| 285 | .join("/"); | |
| 286 | let example = &document["paths"][&path][route.method.to_lowercase()]["responses"]["200"] | |
| 287 | ["content"]["application/json"]["example"]; | |
| 288 | assert!(!example.is_null(), "{} {path}", route.method); | |
| 289 | } | |
| 290 | } | |
| 291 | ||
| 292 | #[test] | |
| 293 | fn errors_and_reports_are_snake_case() { | |
| 294 | let failure = g1t_contracts::Failure { | |
| 295 | code: g1t_contracts::FailureCode::NotFound, | |
| 296 | message: "No such endpoint.".to_owned(), | |
| 297 | }; | |
| 298 | assert!(wire::camel_case_keys(&wire::snake_case(json!({ "error": failure }))).is_empty()); | |
| 299 | } | |
| 300 | ||
| 301 | #[test] | |
| 302 | fn a_job_spec_keeps_github_s_spelling() { | |
| 303 | let spec = json!({ | |
| 304 | "job": "job_1", | |
| 305 | "spec": { "runs-on": "ubuntu-latest", "timeoutMinutes": 5 }, | |
| 306 | "workflow": { "env": { "nodeEnv": "x" } }, | |
| 307 | "github": { "eventName": "push", "headRef": "" }, | |
| 308 | "event": { "pull_request": { "headSha": "x" } }, | |
| 309 | "contexts": { "inputs": { "dryRun": true }, "matrix": { "nodeVersion": 20 } }, | |
| 310 | "checkout": { "ref": "main" }, | |
| 311 | "timeoutMinutes": 30, | |
| 312 | "masks": [], | |
| 313 | }); | |
| 314 | let sent = wire::snake_case_keeping(spec.clone(), crate::JOB_SPEC_AS_GIVEN); | |
| 315 | assert_eq!(sent["timeout_minutes"], 30); | |
| 316 | assert!(sent.get("timeoutMinutes").is_none()); | |
| 317 | for kept in ["spec", "workflow", "github", "event", "contexts", "checkout"] { | |
| 318 | assert_eq!(sent[kept], spec[kept], "{kept}"); | |
| 319 | } | |
| 320 | } |
This file's history is long; its oldest lines are credited to the oldest commit read.