Skip to content

g1t/apps/api/src/rest.rs

1,075 lines45,195 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server in Rust; a public index at the API root1//! REST: each route maps an HTTP request onto one operation.
2
3use serde_json::{Map, Value};
4
5use crate::operations::Op;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar6use crate::security::SecurityOp;
API and MCP server in Rust; a public index at the API root7
8pub struct Route {
9 pub method: &'static str,
10 /// Segments starting with `:` are parameters.
11 pub path: &'static str,
12 pub op: Op,
13 /// Query parameters the route reads, as `(name in the URL, input name)`.
14 pub query: &'static [(&'static str, &'static str)],
15}
16
17const fn route(
18 method: &'static str,
19 path: &'static str,
20 op: Op,
21 query: &'static [(&'static str, &'static str)],
22) -> Route {
23 Route {
24 method,
25 path,
26 op,
27 query,
28 }
29}
30
31pub const ROUTES: &[Route] = &[
Agents as a team: lifecycle, merge queue, billing and a new shell32 route("GET", "/user", Op::Whoami, &[]),
33 route("POST", "/workspaces", Op::CreateWorkspace, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look34 route("DELETE", "/workspaces/:workspace", Op::DeleteWorkspace, &[]),
35 route("GET", "/user/emails", Op::ListEmails, &[]),
36 route("POST", "/user/emails", Op::AddEmail, &[]),
37 route("DELETE", "/user/emails/:email", Op::RemoveEmail, &[]),
38 route("PATCH", "/user/email-settings", Op::UpdateEmailSettings, &[]),
39 route("GET", "/user/invites", Op::ListInvites, &[]),
40 route("POST", "/user/invites", Op::CreateInvite, &[]),
41 route("DELETE", "/user/invites/:id", Op::RevokeInvite, &[]),
42 route("GET", "/workspaces/:workspace/invitations", Op::ListWorkspaceInvites, &[]),
43 route("POST", "/workspaces/:workspace/invitations", Op::InviteMember, &[]),
44 route("DELETE", "/workspaces/:workspace/invitations/:id", Op::RevokeWorkspaceInvite, &[]),
45 // Who has access. GitHub's addresses, but for adding someone, which
46 // takes an email address as well as a username.
47 route("GET", "/repos/:owner/:name/collaborators", Op::ListCollaborators, &[]),
48 route("POST", "/repos/:owner/:name/collaborators", Op::AddCollaborator, &[]),
49 route("PATCH", "/repos/:owner/:name/collaborators/:username", Op::UpdateCollaborator, &[]),
50 route("DELETE", "/repos/:owner/:name/collaborators/:username", Op::RemoveCollaborator, &[]),
51 route(
52 "GET",
53 "/repos/:owner/:name/collaborators/:username/permission",
54 Op::GetCollaboratorPermission,
55 &[],
56 ),
57 route("GET", "/repos/:owner/:name/invitations", Op::ListRepoInvitations, &[]),
58 route("DELETE", "/repos/:owner/:name/invitations/:id", Op::RevokeRepoInvitation, &[]),
59 route("GET", "/user/repository_invitations", Op::ListMyRepoInvitations, &[]),
API: notifications over REST and MCP, with notifications scopes60 // Your notifications: threads, marking them, and what you subscribe
61 // to and watch. GitHub's addresses, with g1t's saved and snoozed.
62 route("GET", "/notifications", Op::ListNotifications, &[("all", "all"), ("participating", "participating"), ("view", "view"), ("reason", "reason"), ("severity", "severity"), ("since", "since"), ("before", "before"), ("cursor", "cursor"), ("per_page", "per_page")]),
63 route("PUT", "/notifications", Op::MarkNotificationsRead, &[]),
64 route("GET", "/notifications/threads/:id", Op::GetNotificationThread, &[]),
65 route("PATCH", "/notifications/threads/:id", Op::MarkThreadRead, &[]),
66 route("DELETE", "/notifications/threads/:id", Op::MarkThreadDone, &[]),
67 route("PUT", "/notifications/threads/:id/saved", Op::SaveThread, &[]),
68 route("DELETE", "/notifications/threads/:id/saved", Op::SaveThread, &[]),
69 route("PUT", "/notifications/threads/:id/snooze", Op::SnoozeThread, &[]),
70 route("DELETE", "/notifications/threads/:id/snooze", Op::SnoozeThread, &[]),
71 route("GET", "/notifications/threads/:id/subscription", Op::GetThreadSubscription, &[]),
72 route("PUT", "/notifications/threads/:id/subscription", Op::SetThreadSubscription, &[]),
73 route("DELETE", "/notifications/threads/:id/subscription", Op::DeleteThreadSubscription, &[]),
74 route("GET", "/repos/:owner/:name/notifications", Op::ListNotifications, &[("all", "all"), ("participating", "participating"), ("view", "view"), ("reason", "reason"), ("severity", "severity"), ("since", "since"), ("before", "before"), ("cursor", "cursor"), ("per_page", "per_page")]),
75 route("PUT", "/repos/:owner/:name/notifications", Op::MarkNotificationsRead, &[]),
76 route("GET", "/repos/:owner/:name/subscription", Op::GetRepoSubscription, &[]),
77 route("PUT", "/repos/:owner/:name/subscription", Op::SetRepoSubscription, &[]),
78 route("DELETE", "/repos/:owner/:name/subscription", Op::DeleteRepoSubscription, &[]),
79 route("GET", "/repos/:owner/:name/issues/:number/subscription", Op::GetThreadSubscription, &[]),
80 route("PUT", "/repos/:owner/:name/issues/:number/subscription", Op::SetThreadSubscription, &[]),
81 route("DELETE", "/repos/:owner/:name/issues/:number/subscription", Op::DeleteThreadSubscription, &[]),
82 route("GET", "/user/subscriptions", Op::ListWatchedRepos, &[]),
API: pinned projects over REST and MCP83 // Your pinned projects in a workspace, in your order.
84 route("GET", "/user/pinned_projects/:workspace", Op::ListPinnedProjects, &[]),
85 route("PUT", "/user/pinned_projects/:workspace", Op::ReorderPinnedProjects, &[]),
86 route("PUT", "/user/pinned_projects/:workspace/:project", Op::PinProject, &[]),
87 route("DELETE", "/user/pinned_projects/:workspace/:project", Op::UnpinProject, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look88 route("PATCH", "/user/repository_invitations/:id", Op::AcceptRepoInvitation, &[]),
89 route("DELETE", "/user/repository_invitations/:id", Op::DeclineRepoInvitation, &[]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily90 route("PATCH", "/workspaces/:workspace", Op::UpdateWorkspace, &[]),
91 route("PUT", "/workspaces/:workspace/base_permission", Op::SetBasePermission, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look92 route(
93 "GET",
94 "/workspaces/:workspace/outside_collaborators",
95 Op::ListOutsideCollaborators,
96 &[],
97 ),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar98 // Teams: a workspace's groups of members, with roles on repositories.
99 route("GET", "/workspaces/:workspace/teams", Op::ListTeams, &[("q", "query")]),
100 route("POST", "/workspaces/:workspace/teams", Op::CreateTeam, &[]),
101 route("GET", "/workspaces/:workspace/teams/:team", Op::GetTeam, &[]),
102 route("PATCH", "/workspaces/:workspace/teams/:team", Op::UpdateTeam, &[]),
103 route("DELETE", "/workspaces/:workspace/teams/:team", Op::DeleteTeam, &[]),
104 route(
105 "GET",
106 "/workspaces/:workspace/teams/:team/members",
107 Op::ListTeamMembers,
108 &[("include_child_teams", "include_child_teams")],
109 ),
110 route("PUT", "/workspaces/:workspace/teams/:team/members/:username", Op::SetTeamMember, &[]),
111 route("DELETE", "/workspaces/:workspace/teams/:team/members/:username", Op::RemoveTeamMember, &[]),
112 route("GET", "/workspaces/:workspace/teams/:team/teams", Op::ListChildTeams, &[]),
113 route("GET", "/workspaces/:workspace/teams/:team/repos", Op::ListTeamRepos, &[]),
114 route("PUT", "/workspaces/:workspace/teams/:team/repos/:repo", Op::SetTeamRepo, &[]),
115 route("DELETE", "/workspaces/:workspace/teams/:team/repos/:repo", Op::RemoveTeamRepo, &[]),
116 route(
117 "PUT",
118 "/workspaces/:workspace/teams/:team/review_assignment",
119 Op::SetTeamReviewAssignment,
120 &[],
121 ),
122 route("GET", "/workspaces/:workspace/members/:username/teams", Op::ListUserTeams, &[]),
Usage, Billing settings and prepaid AI credit; fixes from the UX audit123 // A workspace's billing: usage, budget, AI credit and invoices.
124 route(
125 "GET",
126 "/workspaces/:workspace/usage",
127 Op::GetUsage,
128 &[("from", "from"), ("until", "until"), ("products", "products"), ("projects", "projects"), ("group_by", "group_by")],
129 ),
130 route("GET", "/workspaces/:workspace/budget", Op::GetBudget, &[]),
131 route("PUT", "/workspaces/:workspace/budget", Op::SetBudget, &[]),
132 route("GET", "/workspaces/:workspace/ai_credit", Op::GetAiCredit, &[]),
133 route("POST", "/workspaces/:workspace/ai_credit/checkout", Op::BuyAiCredit, &[]),
134 route("GET", "/workspaces/:workspace/invoices", Op::ListInvoices, &[]),
135 route("GET", "/workspaces/:workspace/billing_details", Op::GetBillingDetails, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar136 // Code owners: the CODEOWNERS file, checked.
137 route("GET", "/repos/:owner/:name/codeowners/errors", Op::GetCodeownersErrors, &[("ref", "ref")]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily138 // Security alerts: secrets and vulnerable dependencies.
139 route(
140 "GET",
141 "/repos/:owner/:name/security/alerts",
142 Op::ListSecurityAlerts,
143 &[("state", "state"), ("kind", "kind")],
144 ),
145 route("POST", "/repos/:owner/:name/security/alerts/:id/dismiss", Op::DismissSecurityAlert, &[]),
146 route("POST", "/repos/:owner/:name/security/alerts/:id/reopen", Op::ReopenSecurityAlert, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar147 // The security suite: secret scanning, code scanning, vulnerability
148 // alerts and the supply chain, at the common addresses.
149 route("GET", "/repos/:owner/:name/secret-scanning/alerts", Op::Security(SecurityOp::ListSecretAlerts), &[("state", "state"), ("secret_type", "secret_type"), ("validity", "validity"), ("bypassed", "bypassed")]),
150 route("GET", "/workspaces/:workspace/secret-scanning/alerts", Op::Security(SecurityOp::ListSecretAlerts), &[("state", "state"), ("secret_type", "secret_type"), ("validity", "validity"), ("bypassed", "bypassed")]),
151 route("GET", "/repos/:owner/:name/secret-scanning/alerts/:id", Op::Security(SecurityOp::GetSecretAlert), &[]),
152 route("PATCH", "/repos/:owner/:name/secret-scanning/alerts/:id", Op::Security(SecurityOp::UpdateSecretAlert), &[]),
153 route("GET", "/repos/:owner/:name/secret-scanning/alerts/:id/locations", Op::Security(SecurityOp::ListSecretLocations), &[]),
154 route("POST", "/repos/:owner/:name/secret-scanning/alerts/:id/bypass", Op::Security(SecurityOp::BypassPushProtection), &[]),
155 route("POST", "/repos/:owner/:name/secret-scanning/alerts/:id/validity", Op::Security(SecurityOp::CheckSecretValidity), &[]),
156 route("GET", "/workspaces/:workspace/secret-scanning/bypass-requests", Op::Security(SecurityOp::ListBypassRequests), &[("state", "state"), ("repo", "repo")]),
157 route("PATCH", "/workspaces/:workspace/secret-scanning/bypass-requests/:id", Op::Security(SecurityOp::ReviewBypassRequest), &[]),
158 route("POST", "/repos/:owner/:name/secret-scanning/custom-patterns/dry-run", Op::Security(SecurityOp::DryRunCustomPattern), &[]),
159 route("POST", "/workspaces/:workspace/secret-scanning/custom-patterns/dry-run", Op::Security(SecurityOp::DryRunCustomPattern), &[]),
160 route("GET", "/repos/:owner/:name/secret-scanning/custom-patterns", Op::Security(SecurityOp::ListCustomPatterns), &[]),
161 route("GET", "/workspaces/:workspace/secret-scanning/custom-patterns", Op::Security(SecurityOp::ListCustomPatterns), &[]),
162 route("POST", "/repos/:owner/:name/secret-scanning/custom-patterns", Op::Security(SecurityOp::CreateCustomPattern), &[]),
163 route("POST", "/workspaces/:workspace/secret-scanning/custom-patterns", Op::Security(SecurityOp::CreateCustomPattern), &[]),
164 route("PATCH", "/repos/:owner/:name/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::UpdateCustomPattern), &[]),
165 route("PATCH", "/workspaces/:workspace/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::UpdateCustomPattern), &[]),
166 route("DELETE", "/repos/:owner/:name/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::DeleteCustomPattern), &[]),
167 route("DELETE", "/workspaces/:workspace/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::DeleteCustomPattern), &[]),
168 route("GET", "/repos/:owner/:name/code-scanning/alerts", Op::Security(SecurityOp::ListCodeAlerts), &[("state", "state"), ("severity", "severity"), ("tool", "tool"), ("rule_id", "rule_id")]),
169 route("GET", "/workspaces/:workspace/code-scanning/alerts", Op::Security(SecurityOp::ListCodeAlerts), &[("state", "state"), ("severity", "severity"), ("tool", "tool"), ("rule_id", "rule_id")]),
170 route("GET", "/repos/:owner/:name/code-scanning/alerts/:number", Op::Security(SecurityOp::GetCodeAlert), &[]),
171 route("PATCH", "/repos/:owner/:name/code-scanning/alerts/:number", Op::Security(SecurityOp::UpdateCodeAlert), &[]),
172 route("GET", "/repos/:owner/:name/code-scanning/analyses", Op::Security(SecurityOp::ListAnalyses), &[]),
173 route("POST", "/repos/:owner/:name/code-scanning/sarifs", Op::Security(SecurityOp::UploadSarif), &[]),
174 route("GET", "/repos/:owner/:name/code-scanning/sarifs/:id", Op::Security(SecurityOp::GetSarifUpload), &[]),
175 route("GET", "/repos/:owner/:name/vulnerability-alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), &[("state", "state"), ("severity", "severity"), ("ecosystem", "ecosystem"), ("package", "package")]),
176 route("GET", "/workspaces/:workspace/vulnerability-alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), &[("state", "state"), ("severity", "severity"), ("ecosystem", "ecosystem"), ("package", "package")]),
177 route("GET", "/repos/:owner/:name/vulnerability-alerts/:id", Op::Security(SecurityOp::GetVulnerabilityAlert), &[]),
178 route("PATCH", "/repos/:owner/:name/vulnerability-alerts/:id", Op::Security(SecurityOp::UpdateVulnerabilityAlert), &[]),
179 route("POST", "/repos/:owner/:name/security/alerts/:id/fix", Op::Security(SecurityOp::FixAlert), &[]),
180 route("GET", "/repos/:owner/:name/dependency-graph", Op::Security(SecurityOp::GetDependencyGraph), &[]),
181 route("GET", "/repos/:owner/:name/dependency-graph/sbom", Op::Security(SecurityOp::GetSbom), &[]),
182 route("GET", "/repos/:owner/:name/dependency-graph/compare/:basehead", Op::Security(SecurityOp::CompareDependencies), &[]),
183 route("GET", "/repos/:owner/:name/security/settings", Op::Security(SecurityOp::GetSettings), &[]),
184 route("PATCH", "/repos/:owner/:name/security/settings", Op::Security(SecurityOp::UpdateSettings), &[]),
185 route("GET", "/workspaces/:workspace/security/settings", Op::Security(SecurityOp::GetWorkspaceSettings), &[]),
186 route("PATCH", "/workspaces/:workspace/security/settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), &[]),
187 route("GET", "/workspaces/:workspace/security/overview", Op::Security(SecurityOp::GetOverview), &[("days", "days")]),
Agents as a team: lifecycle, merge queue, billing and a new shell188 route("GET", "/repos", Op::ListRepos, &[("q", "query")]),
Search across all of g1t, Explore, and a command palette189 route(
190 "GET",
191 "/search",
192 Op::Search,
193 &[("q", "query"), ("type", "type"), ("page", "page"), ("per_page", "per_page")],
194 ),
Agents as a team: lifecycle, merge queue, billing and a new shell195 route("POST", "/repos", Op::CreateRepo, &[]),
196 route("GET", "/repos/:owner/:name", Op::GetRepo, &[]),
197 route("PATCH", "/repos/:owner/:name", Op::UpdateRepo, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look198 route("POST", "/repos/:owner/:name/transfer", Op::TransferRepo, &[]),
199 route("DELETE", "/repos/:owner/:name", Op::DeleteRepo, &[]),
200 route(
201 "GET",
202 "/workspaces/:workspace/repos/deleted",
203 Op::ListDeletedRepos,
204 &[],
205 ),
206 route("POST", "/repos/:owner/:name/restore", Op::RestoreRepo, &[]),
207 route("POST", "/repos/:owner/:name/purge", Op::PurgeRepo, &[]),
208 route("POST", "/repos/:owner/:name/rename", Op::RenameRepo, &[]),
209 route("POST", "/repos/:owner/:name/archive", Op::ArchiveRepo, &[]),
210 route("POST", "/repos/:owner/:name/unarchive", Op::UnarchiveRepo, &[]),
211 route(
212 "POST",
213 "/repos/:owner/:name/visibility",
214 Op::SetRepoVisibility,
215 &[],
216 ),
217 route(
218 "POST",
219 "/repos/:owner/:name/branches/:branch/rename",
220 Op::RenameBranch,
221 &[],
222 ),
Agents as a team: lifecycle, merge queue, billing and a new shell223 route(
224 "GET",
225 "/repos/:owner/:name/settings",
226 Op::GetRepoSettings,
227 &[],
228 ),
229 route(
230 "PATCH",
231 "/repos/:owner/:name/settings",
232 Op::UpdateRepoSettings,
233 &[],
234 ),
Fast pages, required checks on the branch, self-hosted runners, honest incidents235 route("GET", "/repos/:owner/:name/check-names", Op::ListCheckNames, &[]),
Agents as a team: lifecycle, merge queue, billing and a new shell236 route("GET", "/repos/:owner/:name/queue", Op::GetMergeQueue, &[]),
API and MCP server in Rust; a public index at the API root237 route(
Usage, like a hosting provider's: what agents cost, per day, task, repository and pull request238 "POST",
239 "/repos/:owner/:name/pulls/:number/messages",
240 Op::MessageAgent,
241 &[],
242 ),
243 route(
244 "POST",
245 "/repos/:owner/:name/pulls/:number/messages/take",
246 Op::TakeMessages,
247 &[],
248 ),
249 route(
Docs worth reading, and kept that way250 "POST",
251 "/repos/:owner/:name/messages/:id/answer",
252 Op::AnswerMessage,
253 &[],
254 ),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains255 route("POST", "/repos/:owner/:name/memory", Op::Remember, &[]),
256 route(
257 "GET",
258 "/repos/:owner/:name/memory",
259 Op::Recall,
260 &[("q", "query"), ("limit", "limit")],
261 ),
Docs worth reading, and kept that way262 route(
API and MCP server in Rust; a public index at the API root263 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell264 "/repos/:owner/:name/events",
API and MCP server in Rust; a public index at the API root265 Op::ListEvents,
266 &[("before", "before")],
267 ),
Agents as a team: lifecycle, merge queue, billing and a new shell268 route("GET", "/repos/:owner/:name/labels", Op::ListLabels, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar269 route("POST", "/repos/:owner/:name/labels", Op::CreateLabel, &[]),
270 route("POST", "/repos/:owner/:name/labels/defaults", Op::AddDefaultLabels, &[]),
271 route("PATCH", "/repos/:owner/:name/labels/:label", Op::UpdateLabel, &[]),
272 route("DELETE", "/repos/:owner/:name/labels/:label", Op::DeleteLabel, &[]),
273 route("GET", "/repos/:owner/:name/issues/:number/labels", Op::ListIssueLabels, &[]),
274 route("POST", "/repos/:owner/:name/issues/:number/labels", Op::AddIssueLabels, &[]),
275 route("PUT", "/repos/:owner/:name/issues/:number/labels", Op::SetIssueLabels, &[]),
276 route("DELETE", "/repos/:owner/:name/issues/:number/labels", Op::RemoveIssueLabels, &[]),
277 route("DELETE", "/repos/:owner/:name/issues/:number/labels/:label", Op::RemoveIssueLabels, &[]),
278 route("GET", "/repos/:owner/:name/milestones", Op::ListMilestones, &[("state", "state")]),
279 route("POST", "/repos/:owner/:name/milestones", Op::CreateMilestone, &[]),
280 route("GET", "/repos/:owner/:name/milestones/:milestone", Op::GetMilestone, &[]),
281 route("PATCH", "/repos/:owner/:name/milestones/:milestone", Op::UpdateMilestone, &[]),
282 route("DELETE", "/repos/:owner/:name/milestones/:milestone", Op::DeleteMilestone, &[]),
API and MCP server in Rust; a public index at the API root283 route(
284 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell285 "/repos/:owner/:name/issues",
API and MCP server in Rust; a public index at the API root286 Op::ListIssues,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar287 &[("state", "state"), ("label", "label"), ("milestone", "milestone")],
API and MCP server in Rust; a public index at the API root288 ),
Agents as a team: lifecycle, merge queue, billing and a new shell289 route("POST", "/repos/:owner/:name/issues", Op::CreateIssue, &[]),
API and MCP server in Rust; a public index at the API root290 route(
291 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell292 "/repos/:owner/:name/issues/:number",
API and MCP server in Rust; a public index at the API root293 Op::GetIssue,
294 &[],
295 ),
296 route(
297 "PATCH",
Agents as a team: lifecycle, merge queue, billing and a new shell298 "/repos/:owner/:name/issues/:number",
API and MCP server in Rust; a public index at the API root299 Op::UpdateIssue,
300 &[],
301 ),
302 route(
303 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell304 "/repos/:owner/:name/issues/:number/close",
API and MCP server in Rust; a public index at the API root305 Op::CloseIssue,
306 &[],
307 ),
308 route(
309 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell310 "/repos/:owner/:name/issues/:number/reopen",
API and MCP server in Rust; a public index at the API root311 Op::ReopenIssue,
312 &[],
313 ),
314 route(
315 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell316 "/repos/:owner/:name/issues/:number/assign",
317 Op::AssignIssue,
318 &[],
319 ),
Integrations: your own model provider, alerts that open issues, tickets agents read320 route(
321 "POST",
322 "/repos/:owner/:name/issues/import",
323 Op::ImportIssue,
324 &[],
325 ),
326 route(
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step327 "POST",
328 "/repos/:owner/:name/issues/delegate",
329 Op::Delegate,
330 &[],
331 ),
332 route(
Integrations: your own model provider, alerts that open issues, tickets agents read333 "GET",
334 "/repos/:owner/:name/context",
335 Op::GetContext,
336 &[("reference", "reference")],
337 ),
338 route(
339 "GET",
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API340 "/workspaces/:workspace/context/search",
341 Op::SearchContext,
342 &[("q", "query"), ("project", "project"), ("kinds", "kinds"), ("limit", "limit")],
343 ),
344 route(
345 "GET",
346 "/workspaces/:workspace/context/:kind/:id",
347 Op::GetEntity,
348 &[],
349 ),
350 route(
351 "GET",
Integrations: your own model provider, alerts that open issues, tickets agents read352 "/workspaces/:workspace/integrations",
353 Op::ListIntegrations,
354 &[],
355 ),
356 route(
357 "POST",
358 "/workspaces/:workspace/integrations",
359 Op::ConnectIntegration,
360 &[],
361 ),
362 route(
Models per workspace: several providers, routed by kind of work363 "GET",
Webhooks: every event, to your own addresses, signed and retried364 "/repos/:owner/:name/hooks",
365 Op::ListWebhooks,
366 &[],
367 ),
368 route(
369 "POST",
370 "/repos/:owner/:name/hooks",
371 Op::CreateWebhook,
372 &[],
373 ),
374 route(
375 "PATCH",
376 "/repos/:owner/:name/hooks/:id",
377 Op::UpdateWebhook,
378 &[],
379 ),
380 route(
381 "DELETE",
382 "/repos/:owner/:name/hooks/:id",
383 Op::DeleteWebhook,
384 &[],
385 ),
386 route(
387 "POST",
388 "/repos/:owner/:name/hooks/:id/pings",
389 Op::PingWebhook,
390 &[],
391 ),
392 route(
393 "GET",
394 "/repos/:owner/:name/hooks/:id/deliveries",
395 Op::ListWebhookDeliveries,
396 &[],
397 ),
398 route(
399 "POST",
400 "/repos/:owner/:name/hooks/:id/deliveries/:delivery/redeliver",
401 Op::RedeliverWebhook,
402 &[],
403 ),
404 route(
405 "GET",
406 "/workspaces/:workspace/hooks",
407 Op::ListWebhooks,
408 &[],
409 ),
410 route(
411 "POST",
412 "/workspaces/:workspace/hooks",
413 Op::CreateWebhook,
414 &[],
415 ),
416 route(
417 "PATCH",
418 "/workspaces/:workspace/hooks/:id",
419 Op::UpdateWebhook,
420 &[],
421 ),
422 route(
423 "DELETE",
424 "/workspaces/:workspace/hooks/:id",
425 Op::DeleteWebhook,
426 &[],
427 ),
428 route(
429 "POST",
430 "/workspaces/:workspace/hooks/:id/pings",
431 Op::PingWebhook,
432 &[],
433 ),
434 route(
435 "GET",
436 "/workspaces/:workspace/hooks/:id/deliveries",
437 Op::ListWebhookDeliveries,
438 &[],
439 ),
440 route(
441 "POST",
442 "/workspaces/:workspace/hooks/:id/deliveries/:delivery/redeliver",
443 Op::RedeliverWebhook,
444 &[],
445 ),
446 route(
447 "GET",
Models per workspace: several providers, routed by kind of work448 "/workspaces/:workspace/model-routes",
449 Op::GetModelRoutes,
450 &[],
451 ),
452 route(
453 "PUT",
454 "/workspaces/:workspace/model-routes",
455 Op::SetModelRoutes,
456 &[],
457 ),
458 route(
Integrations: your own model provider, alerts that open issues, tickets agents read459 "DELETE",
460 "/workspaces/:workspace/integrations/:id",
461 Op::DisconnectIntegration,
462 &[],
463 ),
464 route(
465 "POST",
466 "/workspaces/:workspace/integrations/:id/test",
467 Op::TestIntegration,
468 &[],
469 ),
Automations: rules in .g1t/automations that act when something happens470 route(
471 "GET",
GitHub Actions on g1t, part two: running workflows472 "/repos/:owner/:name/actions/workflows",
473 Op::ListWorkflows,
474 &[],
475 ),
476 route(
477 "GET",
478 "/repos/:owner/:name/actions/workflows/:workflow/runs",
479 Op::ListWorkflowRuns,
480 &[("branch", "branch"), ("event", "event"), ("per_page", "limit")],
481 ),
482 route(
483 "POST",
484 "/repos/:owner/:name/actions/workflows/:workflow/dispatches",
485 Op::DispatchWorkflow,
486 &[],
487 ),
488 route(
489 "PATCH",
490 "/repos/:owner/:name/actions/workflows/:workflow",
491 Op::UpdateWorkflow,
492 &[],
493 ),
494 route(
495 "PUT",
496 "/repos/:owner/:name/actions/workflows/:workflow/enable",
497 Op::UpdateWorkflow,
498 &[],
499 ),
500 route(
501 "PUT",
502 "/repos/:owner/:name/actions/workflows/:workflow/disable",
503 Op::UpdateWorkflow,
504 &[],
505 ),
506 route(
507 "GET",
508 "/repos/:owner/:name/actions/runs",
509 Op::ListWorkflowRuns,
510 &[("workflow", "workflow"), ("branch", "branch"), ("event", "event"), ("pull", "pull"), ("head_sha", "sha"), ("per_page", "limit")],
511 ),
512 route(
513 "GET",
514 "/repos/:owner/:name/actions/runs/:id",
515 Op::GetWorkflowRun,
516 &[],
517 ),
518 route(
519 "POST",
520 "/repos/:owner/:name/actions/runs/:id/cancel",
521 Op::CancelWorkflowRun,
522 &[],
523 ),
524 route(
525 "POST",
526 "/repos/:owner/:name/actions/runs/:id/rerun",
527 Op::RerunWorkflowRun,
528 &[],
529 ),
530 route(
531 "POST",
532 "/repos/:owner/:name/actions/runs/:id/rerun-failed-jobs",
533 Op::RerunWorkflowRun,
534 &[],
535 ),
536 route(
537 "GET",
538 "/repos/:owner/:name/actions/jobs/:job/logs",
539 Op::GetJobLogs,
540 &[("after", "after")],
541 ),
542 route(
543 "GET",
544 "/repos/:owner/:name/actions/secrets",
545 Op::ListActionsSecrets,
546 &[],
547 ),
548 route(
549 "PUT",
550 "/repos/:owner/:name/actions/secrets/:setting",
551 Op::SetActionsSecret,
552 &[],
553 ),
554 route(
555 "DELETE",
556 "/repos/:owner/:name/actions/secrets/:setting",
557 Op::DeleteActionsSecret,
558 &[],
559 ),
560 route(
561 "GET",
562 "/repos/:owner/:name/actions/variables",
563 Op::ListActionsVariables,
564 &[],
565 ),
566 route(
567 "POST",
568 "/repos/:owner/:name/actions/variables",
569 Op::SetActionsVariable,
570 &[],
571 ),
572 route(
573 "PATCH",
574 "/repos/:owner/:name/actions/variables/:setting",
575 Op::SetActionsVariable,
576 &[],
577 ),
578 route(
579 "DELETE",
580 "/repos/:owner/:name/actions/variables/:setting",
581 Op::DeleteActionsVariable,
582 &[],
583 ),
584 route(
585 "GET",
586 "/workspaces/:workspace/actions/secrets",
587 Op::ListActionsSecrets,
588 &[],
589 ),
590 route(
591 "PUT",
592 "/workspaces/:workspace/actions/secrets/:setting",
593 Op::SetActionsSecret,
594 &[],
595 ),
596 route(
597 "DELETE",
598 "/workspaces/:workspace/actions/secrets/:setting",
599 Op::DeleteActionsSecret,
600 &[],
601 ),
602 route(
603 "GET",
604 "/workspaces/:workspace/actions/variables",
605 Op::ListActionsVariables,
606 &[],
607 ),
608 route(
609 "POST",
610 "/workspaces/:workspace/actions/variables",
611 Op::SetActionsVariable,
612 &[],
613 ),
614 route(
615 "PATCH",
616 "/workspaces/:workspace/actions/variables/:setting",
617 Op::SetActionsVariable,
618 &[],
619 ),
620 route(
621 "DELETE",
622 "/workspaces/:workspace/actions/variables/:setting",
623 Op::DeleteActionsVariable,
624 &[],
625 ),
Fast pages, required checks on the branch, self-hosted runners, honest incidents626 // Self-hosted runners: a repository's own, or a workspace's.
627 route("GET", "/repos/:owner/:name/actions/runners", Op::ListRunners, &[]),
628 route("POST", "/repos/:owner/:name/actions/runners/registration-token", Op::CreateRunnerRegistrationToken, &[]),
629 route("DELETE", "/repos/:owner/:name/actions/runners/:id", Op::RemoveRunner, &[]),
630 route("GET", "/repos/:owner/:name/actions/runner-settings", Op::GetRunnerSettings, &[]),
631 route("PATCH", "/repos/:owner/:name/actions/runner-settings", Op::UpdateRunnerSettings, &[]),
632 route("GET", "/workspaces/:workspace/actions/runners", Op::ListRunners, &[]),
633 route("POST", "/workspaces/:workspace/actions/runners/registration-token", Op::CreateRunnerRegistrationToken, &[]),
634 route("DELETE", "/workspaces/:workspace/actions/runners/:id", Op::RemoveRunner, &[]),
635 route("GET", "/workspaces/:workspace/actions/runner-settings", Op::GetRunnerSettings, &[]),
636 route("PATCH", "/workspaces/:workspace/actions/runner-settings", Op::UpdateRunnerSettings, &[]),
637 route("GET", "/workspaces/:workspace/actions/runner-groups", Op::ListRunnerGroups, &[]),
638 route("POST", "/workspaces/:workspace/actions/runner-groups", Op::CreateRunnerGroup, &[]),
639 route("PATCH", "/workspaces/:workspace/actions/runner-groups/:id", Op::UpdateRunnerGroup, &[]),
640 route("DELETE", "/workspaces/:workspace/actions/runner-groups/:id", Op::DeleteRunnerGroup, &[]),
Agents as a team: lifecycle, merge queue, billing and a new shell641 route("POST", "/repos/:owner/:name/plans", Op::PlanWork, &[]),
642 route("GET", "/repos/:owner/:name/plans/:plan", Op::GetPlan, &[]),
643 route(
644 "POST",
645 "/repos/:owner/:name/plans/:plan/apply",
646 Op::ApplyPlan,
647 &[],
648 ),
649 route(
650 "POST",
651 "/repos/:owner/:name/issues/:number/comments",
API and MCP server in Rust; a public index at the API root652 Op::AddComment,
653 &[],
654 ),
655 route(
656 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell657 "/repos/:owner/:name/pulls",
API and MCP server in Rust; a public index at the API root658 Op::ListPullRequests,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar659 &[("state", "state"), ("label", "label"), ("milestone", "milestone"), ("base", "base")],
API and MCP server in Rust; a public index at the API root660 ),
661 route(
662 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell663 "/repos/:owner/:name/pulls",
API and MCP server in Rust; a public index at the API root664 Op::CreatePullRequest,
665 &[],
666 ),
667 route(
668 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell669 "/repos/:owner/:name/pulls/:number",
API and MCP server in Rust; a public index at the API root670 Op::GetPullRequest,
671 &[],
672 ),
673 route(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar674 "PATCH",
675 "/repos/:owner/:name/pulls/:number",
676 Op::UpdatePullRequest,
677 &[],
678 ),
679 route(
API and MCP server in Rust; a public index at the API root680 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell681 "/repos/:owner/:name/pulls/:number/changes",
API and MCP server in Rust; a public index at the API root682 Op::GetPullRequestChanges,
683 &[],
684 ),
685 route(
Acceptance checks in sandboxes, line comments and review verdicts686 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell687 "/repos/:owner/:name/pulls/:number/reviews",
Acceptance checks in sandboxes, line comments and review verdicts688 Op::ReviewPullRequest,
689 &[],
690 ),
691 route(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar692 "POST",
693 "/repos/:owner/:name/pulls/:number/requested_reviewers",
694 Op::RequestReviewers,
695 &[],
696 ),
697 route(
698 "DELETE",
699 "/repos/:owner/:name/pulls/:number/requested_reviewers",
700 Op::RemoveRequestedReviewers,
701 &[],
702 ),
703 route(
API and MCP server in Rust; a public index at the API root704 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell705 "/repos/:owner/:name/pulls/:number/session",
API and MCP server in Rust; a public index at the API root706 Op::ReadSession,
707 &[("after", "after")],
708 ),
709 route(
710 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell711 "/repos/:owner/:name/pulls/:number/session",
API and MCP server in Rust; a public index at the API root712 Op::RecordSession,
713 &[],
714 ),
715 route(
716 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell717 "/repos/:owner/:name/pulls/:number/ready",
API and MCP server in Rust; a public index at the API root718 Op::MarkPullRequestReady,
719 &[],
720 ),
721 route(
722 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell723 "/repos/:owner/:name/pulls/:number/close",
API and MCP server in Rust; a public index at the API root724 Op::ClosePullRequest,
725 &[],
726 ),
727 route(
728 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell729 "/repos/:owner/:name/pulls/:number/merge",
API and MCP server in Rust; a public index at the API root730 Op::MergePullRequest,
731 &[],
732 ),
733];
734
735impl Route {
736 /// The names of the route's path parameters, in order.
737 pub fn params(&self) -> impl Iterator<Item = &'static str> {
738 self.path
739 .split('/')
740 .filter_map(|segment| segment.strip_prefix(':'))
741 }
742
743 /// The values of the path parameters, if `path` is this route's.
744 fn matches<'a>(&self, path: &'a str) -> Option<Vec<(&'static str, &'a str)>> {
745 let mut values = Vec::new();
746 let mut actual = path.trim_end_matches('/').split('/');
747 for expected in self.path.split('/') {
748 let segment = actual.next()?;
749 match expected.strip_prefix(':') {
750 Some(name) if !segment.is_empty() => values.push((name, segment)),
751 Some(_) => return None,
752 None if expected == segment => {}
753 None => return None,
754 }
755 }
756 actual.next().is_none().then_some(values)
757 }
758}
759
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look760/// A path segment with its `%XX` escapes decoded; as given when that is not
761/// UTF-8.
762fn percent_decoded(segment: &str) -> String {
763 let bytes = segment.as_bytes();
764 let mut out = Vec::with_capacity(bytes.len());
765 let mut i = 0;
766 while i < bytes.len() {
767 let escaped = (bytes[i] == b'%')
768 .then(|| segment.get(i + 1..i + 3))
769 .flatten()
770 .filter(|hex| hex.bytes().all(|byte| byte.is_ascii_hexdigit()))
771 .and_then(|hex| u8::from_str_radix(hex, 16).ok());
772 match escaped {
773 Some(byte) => {
774 out.push(byte);
775 i += 3;
776 }
777 None => {
778 out.push(bytes[i]);
779 i += 1;
780 }
781 }
782 }
783 String::from_utf8(out).unwrap_or_else(|_| segment.to_owned())
784}
785
API and MCP server in Rust; a public index at the API root786/// The route for a request, and the operation input it describes.
787///
788/// The input is the JSON body, overlaid with the query parameters the route
789/// reads and then with what the path names: `owner` and `name` become
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar790/// `repo`, as does a team's `repo` with its `workspace`, and `number`
791/// becomes an integer.
API and MCP server in Rust; a public index at the API root792pub fn resolve(
793 method: &str,
794 path: &str,
795 query: &[(String, String)],
796 body: Value,
797) -> Option<(&'static Route, Value)> {
798 let (route, params) = ROUTES
799 .iter()
800 .filter(|route| route.method == method)
801 .find_map(|route| Some((route, route.matches(path)?)))?;
802
803 let mut input = match body {
804 Value::Object(fields) => fields,
805 _ => Map::new(),
806 };
807 for (name, key) in route.query {
808 if let Some((_, value)) = query.iter().find(|(query_name, _)| query_name == name) {
809 input.insert((*key).to_owned(), Value::String(value.clone()));
810 }
811 }
812 let param = |wanted: &str| {
813 params
814 .iter()
815 .find(|(name, _)| *name == wanted)
816 .map(|(_, value)| *value)
817 };
818 if let (Some(owner), Some(name)) = (param("owner"), param("name")) {
819 input.insert("repo".to_owned(), Value::String(format!("{owner}/{name}")));
820 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar821 for key in ["plan", "id", "workspace", "delivery", "workflow", "job", "setting", "username", "team", "basehead"] {
Docs worth reading, and kept that way822 if let Some(value) = param(key) {
823 input.insert(key.to_owned(), Value::String(value.to_owned()));
824 }
Agents as a team: lifecycle, merge queue, billing and a new shell825 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar826 // A repository of a team's workspace, named by itself.
827 if let (Some(workspace), Some(name)) = (param("workspace"), param("repo")) {
828 input.insert("repo".to_owned(), Value::String(format!("{workspace}/{name}")));
829 }
830 // A branch name may hold slashes, sent URL-encoded as one segment, and
831 // a label's name spaces.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look832 if let Some(branch) = param("branch") {
833 input.insert("branch".to_owned(), Value::String(percent_decoded(branch)));
834 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar835 if let Some(label) = param("label") {
836 input.insert("label".to_owned(), Value::String(percent_decoded(label)));
837 }
838 if let Some(milestone) = param("milestone") {
839 // Not a number: zero, which no milestone has.
840 input.insert("milestone".to_owned(), milestone.parse::<u32>().unwrap_or(0).into());
841 }
GitHub Actions on g1t, part two: running workflows842 // GitHub says some things with the path alone.
843 if route.path.ends_with("/enable") || route.path.ends_with("/disable") {
844 input.insert("enabled".to_owned(), Value::Bool(route.path.ends_with("/enable")));
845 }
846 if route.path.ends_with("/rerun-failed-jobs") {
847 input.insert("failed_only".to_owned(), Value::Bool(true));
848 }
API: notifications over REST and MCP, with notifications scopes849 // Unsaving and waking a thread are a DELETE of what PUT made.
850 if route.method == "DELETE" && route.path.ends_with("/saved") {
851 input.insert("saved".to_owned(), Value::Bool(false));
852 }
853 if route.method == "DELETE" && route.path.ends_with("/snooze") {
854 input.remove("until");
855 }
API and MCP server in Rust; a public index at the API root856 if let Some(number) = param("number") {
857 // Not a number: zero, which no issue or pull request has.
858 input.insert(
859 "number".to_owned(),
860 number.parse::<u32>().unwrap_or(0).into(),
861 );
862 }
863 Some((route, Value::Object(input)))
864}
865
866#[cfg(test)]
867mod tests {
868 use serde_json::json;
869
870 use super::*;
871
872 #[test]
873 fn a_path_resolves_to_its_operation_and_input() {
874 let (route, input) = resolve(
875 "POST",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look876 "/repos/flagon-io/hello/pulls/14/merge",
API and MCP server in Rust; a public index at the API root877 &[],
878 json!({ "keep_issue_open": true, "number": 99, "repo": "someone/else" }),
879 )
880 .unwrap();
881 assert_eq!(route.op, Op::MergePullRequest);
882 // What the path names wins over the body.
883 assert_eq!(
884 input,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look885 json!({ "keep_issue_open": true, "number": 14, "repo": "flagon-io/hello" })
API and MCP server in Rust; a public index at the API root886 );
887 }
888
889 #[test]
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look890 fn a_branch_with_slashes_is_one_encoded_segment() {
891 let (route, input) = resolve(
892 "POST",
893 "/repos/flagon-io/hello/branches/feature%2Flogin/rename",
894 &[],
895 json!({ "new_name": "feature/sign-in" }),
896 )
897 .unwrap();
898 assert_eq!(route.op, Op::RenameBranch);
899 assert_eq!(
900 input,
901 json!({ "new_name": "feature/sign-in", "branch": "feature/login", "repo": "flagon-io/hello" })
902 );
903 assert_eq!(percent_decoded("100%"), "100%");
904 assert_eq!(percent_decoded("a%2bb%zz"), "a+b%zz");
905 }
906
907 #[test]
908 fn a_collaborator_is_named_by_username() {
909 let (route, input) = resolve(
910 "PATCH",
911 "/repos/flagon-io/hello/collaborators/ada",
912 &[],
913 json!({ "role": "maintain" }),
914 )
915 .unwrap();
916 assert_eq!(route.op, Op::UpdateCollaborator);
917 assert_eq!(input, json!({ "role": "maintain", "username": "ada", "repo": "flagon-io/hello" }));
918 let (route, input) = resolve("DELETE", "/user/repository_invitations/rin_1", &[], Value::Null).unwrap();
919 assert_eq!(route.op, Op::DeclineRepoInvitation);
920 assert_eq!(input, json!({ "id": "rin_1" }));
921 }
922
923 #[test]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar924 fn teams_are_addressed_by_workspace_and_slug() {
925 let query = [("q".to_owned(), "back".to_owned())];
926 let (route, input) = resolve("GET", "/workspaces/acme/teams", &query, Value::Null).unwrap();
927 assert_eq!(route.op, Op::ListTeams);
928 assert_eq!(input, json!({ "query": "back", "workspace": "acme" }));
929 let (route, input) = resolve("PATCH", "/workspaces/acme/teams/backend", &[], json!({ "name": "Back end" })).unwrap();
930 assert_eq!(route.op, Op::UpdateTeam);
931 assert_eq!(input, json!({ "name": "Back end", "workspace": "acme", "team": "backend" }));
932 let (route, input) =
933 resolve("PUT", "/workspaces/acme/teams/backend/members/ana", &[], json!({ "role": "maintainer" })).unwrap();
934 assert_eq!(route.op, Op::SetTeamMember);
935 assert_eq!(input, json!({ "role": "maintainer", "workspace": "acme", "team": "backend", "username": "ana" }));
936 let query = [("include_child_teams".to_owned(), "true".to_owned())];
937 let (route, input) = resolve("GET", "/workspaces/acme/teams/backend/members", &query, Value::Null).unwrap();
938 assert_eq!(route.op, Op::ListTeamMembers);
939 assert_eq!(input, json!({ "include_child_teams": "true", "workspace": "acme", "team": "backend" }));
940 // A repository is named by itself, in the team's workspace.
941 let (route, input) =
942 resolve("PUT", "/workspaces/acme/teams/backend/repos/rocket", &[], json!({ "role": "write" })).unwrap();
943 assert_eq!(route.op, Op::SetTeamRepo);
944 assert_eq!(input, json!({ "role": "write", "workspace": "acme", "team": "backend", "repo": "acme/rocket" }));
945 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
946 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend/repos/rocket"), Op::RemoveTeamRepo);
947 assert_eq!(op("GET", "/workspaces/acme/teams/backend/teams"), Op::ListChildTeams);
948 assert_eq!(op("GET", "/workspaces/acme/teams/backend/repos"), Op::ListTeamRepos);
949 assert_eq!(op("PUT", "/workspaces/acme/teams/backend/review_assignment"), Op::SetTeamReviewAssignment);
950 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend"), Op::DeleteTeam);
951 assert_eq!(op("POST", "/workspaces/acme/teams"), Op::CreateTeam);
952 assert_eq!(op("GET", "/workspaces/acme/teams/backend"), Op::GetTeam);
953 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend/members/ana"), Op::RemoveTeamMember);
954 let (route, input) = resolve("GET", "/workspaces/acme/members/ana/teams", &[], Value::Null).unwrap();
955 assert_eq!(route.op, Op::ListUserTeams);
956 assert_eq!(input, json!({ "workspace": "acme", "username": "ana" }));
957 }
958
959 #[test]
960 fn reviewers_are_requested_and_code_owners_checked_on_a_repository() {
961 let body = json!({ "reviewers": ["ana"], "team_reviewers": ["backend"] });
962 let (route, input) = resolve("POST", "/repos/acme/rocket/pulls/7/requested_reviewers", &[], body.clone()).unwrap();
963 assert_eq!(route.op, Op::RequestReviewers);
964 assert_eq!(
965 input,
966 json!({ "reviewers": ["ana"], "team_reviewers": ["backend"], "repo": "acme/rocket", "number": 7 })
967 );
968 let (route, _) = resolve("DELETE", "/repos/acme/rocket/pulls/7/requested_reviewers", &[], body).unwrap();
969 assert_eq!(route.op, Op::RemoveRequestedReviewers);
970 let query = [("ref".to_owned(), "main".to_owned())];
971 let (route, input) = resolve("GET", "/repos/acme/rocket/codeowners/errors", &query, Value::Null).unwrap();
972 assert_eq!(route.op, Op::GetCodeownersErrors);
973 assert_eq!(input, json!({ "ref": "main", "repo": "acme/rocket" }));
974 }
975
976 #[test]
API: notifications over REST and MCP, with notifications scopes977 fn notifications_are_addressed_as_threads_and_by_issue() {
978 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1", &[], Value::Null).unwrap();
979 assert_eq!(route.op, Op::MarkThreadDone);
980 assert_eq!(input, json!({ "id": "ntf_1" }));
981 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1/saved", &[], Value::Null).unwrap();
982 assert_eq!(route.op, Op::SaveThread);
983 assert_eq!(input, json!({ "id": "ntf_1", "saved": false }));
984 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1/snooze", &[], json!({ "until": "x" })).unwrap();
985 assert_eq!(route.op, Op::SnoozeThread);
986 assert_eq!(input, json!({ "id": "ntf_1" }));
987 let query = [("all".to_owned(), "true".to_owned()), ("per_page".to_owned(), "50".to_owned())];
988 let (route, input) = resolve("GET", "/repos/acme/rocket/notifications", &query, Value::Null).unwrap();
989 assert_eq!(route.op, Op::ListNotifications);
990 assert_eq!(input, json!({ "all": "true", "per_page": "50", "repo": "acme/rocket" }));
991 let (route, input) = resolve("PUT", "/repos/acme/rocket/issues/7/subscription", &[], json!({ "ignored": true })).unwrap();
992 assert_eq!(route.op, Op::SetThreadSubscription);
993 assert_eq!(input, json!({ "ignored": true, "number": 7, "repo": "acme/rocket" }));
994 assert_eq!(resolve("GET", "/user/subscriptions", &[], Value::Null).unwrap().0.op, Op::ListWatchedRepos);
995 }
996
997 #[test]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar998 fn labels_and_milestones_are_named_in_the_path() {
999 let (route, input) = resolve("PATCH", "/repos/acme/web/labels/good%20first%20issue", &[], json!({ "color": "7057ff" })).unwrap();
1000 assert_eq!(route.op, Op::UpdateLabel);
1001 assert_eq!(input, json!({ "color": "7057ff", "label": "good first issue", "repo": "acme/web" }));
1002 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/7/labels/bug", &[], Value::Null).unwrap();
1003 assert_eq!(route.op, Op::RemoveIssueLabels);
1004 assert_eq!(input, json!({ "label": "bug", "number": 7, "repo": "acme/web" }));
1005 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/7/labels", &[], Value::Null).unwrap();
1006 assert_eq!(route.op, Op::RemoveIssueLabels);
1007 assert_eq!(input, json!({ "number": 7, "repo": "acme/web" }));
1008 let (route, _) = resolve("POST", "/repos/acme/web/labels/defaults", &[], Value::Null).unwrap();
1009 assert_eq!(route.op, Op::AddDefaultLabels);
1010 let (route, input) = resolve("PATCH", "/repos/acme/web/milestones/3", &[], json!({ "state": "closed" })).unwrap();
1011 assert_eq!(route.op, Op::UpdateMilestone);
1012 assert_eq!(input, json!({ "state": "closed", "milestone": 3, "repo": "acme/web" }));
1013 let (route, input) = resolve("PATCH", "/repos/acme/web/pulls/9", &[], json!({ "base": "release" })).unwrap();
1014 assert_eq!(route.op, Op::UpdatePullRequest);
1015 assert_eq!(input, json!({ "base": "release", "number": 9, "repo": "acme/web" }));
1016 }
1017
1018 #[test]
Usage, Billing settings and prepaid AI credit; fixes from the UX audit1019 fn billing_is_addressed_by_workspace() {
1020 let query = [("from".to_owned(), "2026-10-01".to_owned()), ("products".to_owned(), "agent,sandboxes".to_owned())];
1021 let (route, input) = resolve("GET", "/workspaces/acme/usage", &query, Value::Null).unwrap();
1022 assert_eq!(route.op, Op::GetUsage);
1023 assert_eq!(input, json!({ "from": "2026-10-01", "products": "agent,sandboxes", "workspace": "acme" }));
1024 let (route, input) = resolve("PUT", "/workspaces/acme/budget", &[], json!({ "alerts": [50] })).unwrap();
1025 assert_eq!(route.op, Op::SetBudget);
1026 assert_eq!(input, json!({ "alerts": [50], "workspace": "acme" }));
1027 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
1028 assert_eq!(op("GET", "/workspaces/acme/budget"), Op::GetBudget);
1029 assert_eq!(op("GET", "/workspaces/acme/ai_credit"), Op::GetAiCredit);
1030 assert_eq!(op("POST", "/workspaces/acme/ai_credit/checkout"), Op::BuyAiCredit);
1031 assert_eq!(op("GET", "/workspaces/acme/invoices"), Op::ListInvoices);
1032 assert_eq!(op("GET", "/workspaces/acme/billing_details"), Op::GetBillingDetails);
1033 }
1034
1035 #[test]
API and MCP server in Rust; a public index at the API root1036 fn query_parameters_are_renamed() {
1037 let query = [
1038 ("q".to_owned(), "parser".to_owned()),
1039 ("x".to_owned(), "y".to_owned()),
1040 ];
Agents as a team: lifecycle, merge queue, billing and a new shell1041 let (route, input) = resolve("GET", "/repos", &query, Value::Null).unwrap();
API and MCP server in Rust; a public index at the API root1042 assert_eq!(route.op, Op::ListRepos);
1043 assert_eq!(input, json!({ "query": "parser" }));
1044 }
1045
1046 #[test]
1047 fn method_and_shape_must_match() {
Agents as a team: lifecycle, merge queue, billing and a new shell1048 assert!(resolve("GET", "/repos/a/b/issues/1/close", &[], Value::Null).is_none());
1049 assert!(resolve("GET", "/repos/a", &[], Value::Null).is_none());
1050 assert!(resolve("GET", "/repos/a/b/issues/1/extra", &[], Value::Null).is_none());
1051 assert!(resolve("GET", "/repos/a/b/", &[], Value::Null).is_some());
API and MCP server in Rust; a public index at the API root1052 }
1053
1054 #[test]
1055 fn every_parameter_and_query_name_is_an_input() {
1056 for route in ROUTES {
1057 let properties = route.op.properties();
1058 for (_, key) in route.query {
1059 assert!(properties.contains_key(*key), "{}: {key}", route.path);
1060 }
1061 for name in route.params() {
1062 let covered = matches!(name, "owner" | "name") && properties.contains_key("repo")
1063 || properties.contains_key(name);
1064 assert!(covered, "{}: {name}", route.path);
1065 }
1066 }
1067 }
1068
1069 #[test]
1070 fn every_operation_has_a_route() {
1071 for op in Op::ALL {
1072 assert!(ROUTES.iter().any(|route| route.op == op), "{}", op.name());
1073 }
1074 }
1075}