Skip to content

g1t/apps/api/src/rest.rs

1,102 lines47,135 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server in Rust; a public index at the API root1//! REST: each route maps an HTTP request onto one operation.
2
3use serde_json::{Map, Value};
4
5use crate::operations::Op;
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge6use crate::rules::RulesOp;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar7use crate::security::SecurityOp;
API and MCP server in Rust; a public index at the API root8
9pub struct Route {
10 pub method: &'static str,
11 /// Segments starting with `:` are parameters.
12 pub path: &'static str,
13 pub op: Op,
14 /// Query parameters the route reads, as `(name in the URL, input name)`.
15 pub query: &'static [(&'static str, &'static str)],
16}
17
18const fn route(
19 method: &'static str,
20 path: &'static str,
21 op: Op,
22 query: &'static [(&'static str, &'static str)],
23) -> Route {
24 Route {
25 method,
26 path,
27 op,
28 query,
29 }
30}
31
32pub const ROUTES: &[Route] = &[
Agents as a team: lifecycle, merge queue, billing and a new shell33 route("GET", "/user", Op::Whoami, &[]),
34 route("POST", "/workspaces", Op::CreateWorkspace, &[]),
Merge branch 'worktree-agent-ad7c6d88d93adc817'35 route("GET", "/workspaces/:workspace", Op::GetWorkspace, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look36 route("DELETE", "/workspaces/:workspace", Op::DeleteWorkspace, &[]),
37 route("GET", "/user/emails", Op::ListEmails, &[]),
38 route("POST", "/user/emails", Op::AddEmail, &[]),
39 route("DELETE", "/user/emails/:email", Op::RemoveEmail, &[]),
40 route("PATCH", "/user/email-settings", Op::UpdateEmailSettings, &[]),
41 route("GET", "/user/invites", Op::ListInvites, &[]),
42 route("POST", "/user/invites", Op::CreateInvite, &[]),
43 route("DELETE", "/user/invites/:id", Op::RevokeInvite, &[]),
44 route("GET", "/workspaces/:workspace/invitations", Op::ListWorkspaceInvites, &[]),
45 route("POST", "/workspaces/:workspace/invitations", Op::InviteMember, &[]),
46 route("DELETE", "/workspaces/:workspace/invitations/:id", Op::RevokeWorkspaceInvite, &[]),
47 // Who has access. GitHub's addresses, but for adding someone, which
48 // takes an email address as well as a username.
49 route("GET", "/repos/:owner/:name/collaborators", Op::ListCollaborators, &[]),
50 route("POST", "/repos/:owner/:name/collaborators", Op::AddCollaborator, &[]),
51 route("PATCH", "/repos/:owner/:name/collaborators/:username", Op::UpdateCollaborator, &[]),
52 route("DELETE", "/repos/:owner/:name/collaborators/:username", Op::RemoveCollaborator, &[]),
53 route(
54 "GET",
55 "/repos/:owner/:name/collaborators/:username/permission",
56 Op::GetCollaboratorPermission,
57 &[],
58 ),
59 route("GET", "/repos/:owner/:name/invitations", Op::ListRepoInvitations, &[]),
60 route("DELETE", "/repos/:owner/:name/invitations/:id", Op::RevokeRepoInvitation, &[]),
61 route("GET", "/user/repository_invitations", Op::ListMyRepoInvitations, &[]),
API: notifications over REST and MCP, with notifications scopes62 // Your notifications: threads, marking them, and what you subscribe
63 // to and watch. GitHub's addresses, with g1t's saved and snoozed.
64 route("GET", "/notifications", Op::ListNotifications, &[("all", "all"), ("participating", "participating"), ("view", "view"), ("reason", "reason"), ("severity", "severity"), ("since", "since"), ("before", "before"), ("cursor", "cursor"), ("per_page", "per_page")]),
65 route("PUT", "/notifications", Op::MarkNotificationsRead, &[]),
66 route("GET", "/notifications/threads/:id", Op::GetNotificationThread, &[]),
67 route("PATCH", "/notifications/threads/:id", Op::MarkThreadRead, &[]),
68 route("DELETE", "/notifications/threads/:id", Op::MarkThreadDone, &[]),
69 route("PUT", "/notifications/threads/:id/saved", Op::SaveThread, &[]),
70 route("DELETE", "/notifications/threads/:id/saved", Op::SaveThread, &[]),
71 route("PUT", "/notifications/threads/:id/snooze", Op::SnoozeThread, &[]),
72 route("DELETE", "/notifications/threads/:id/snooze", Op::SnoozeThread, &[]),
73 route("GET", "/notifications/threads/:id/subscription", Op::GetThreadSubscription, &[]),
74 route("PUT", "/notifications/threads/:id/subscription", Op::SetThreadSubscription, &[]),
75 route("DELETE", "/notifications/threads/:id/subscription", Op::DeleteThreadSubscription, &[]),
76 route("GET", "/repos/:owner/:name/notifications", Op::ListNotifications, &[("all", "all"), ("participating", "participating"), ("view", "view"), ("reason", "reason"), ("severity", "severity"), ("since", "since"), ("before", "before"), ("cursor", "cursor"), ("per_page", "per_page")]),
77 route("PUT", "/repos/:owner/:name/notifications", Op::MarkNotificationsRead, &[]),
78 route("GET", "/repos/:owner/:name/subscription", Op::GetRepoSubscription, &[]),
79 route("PUT", "/repos/:owner/:name/subscription", Op::SetRepoSubscription, &[]),
80 route("DELETE", "/repos/:owner/:name/subscription", Op::DeleteRepoSubscription, &[]),
81 route("GET", "/repos/:owner/:name/issues/:number/subscription", Op::GetThreadSubscription, &[]),
82 route("PUT", "/repos/:owner/:name/issues/:number/subscription", Op::SetThreadSubscription, &[]),
83 route("DELETE", "/repos/:owner/:name/issues/:number/subscription", Op::DeleteThreadSubscription, &[]),
84 route("GET", "/user/subscriptions", Op::ListWatchedRepos, &[]),
API: pinned projects over REST and MCP85 // Your pinned projects in a workspace, in your order.
86 route("GET", "/user/pinned_projects/:workspace", Op::ListPinnedProjects, &[]),
87 route("PUT", "/user/pinned_projects/:workspace", Op::ReorderPinnedProjects, &[]),
88 route("PUT", "/user/pinned_projects/:workspace/:project", Op::PinProject, &[]),
89 route("DELETE", "/user/pinned_projects/:workspace/:project", Op::UnpinProject, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look90 route("PATCH", "/user/repository_invitations/:id", Op::AcceptRepoInvitation, &[]),
91 route("DELETE", "/user/repository_invitations/:id", Op::DeclineRepoInvitation, &[]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily92 route("PATCH", "/workspaces/:workspace", Op::UpdateWorkspace, &[]),
93 route("PUT", "/workspaces/:workspace/base_permission", Op::SetBasePermission, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look94 route(
95 "GET",
96 "/workspaces/:workspace/outside_collaborators",
97 Op::ListOutsideCollaborators,
98 &[],
99 ),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar100 // Teams: a workspace's groups of members, with roles on repositories.
101 route("GET", "/workspaces/:workspace/teams", Op::ListTeams, &[("q", "query")]),
102 route("POST", "/workspaces/:workspace/teams", Op::CreateTeam, &[]),
103 route("GET", "/workspaces/:workspace/teams/:team", Op::GetTeam, &[]),
104 route("PATCH", "/workspaces/:workspace/teams/:team", Op::UpdateTeam, &[]),
105 route("DELETE", "/workspaces/:workspace/teams/:team", Op::DeleteTeam, &[]),
106 route(
107 "GET",
108 "/workspaces/:workspace/teams/:team/members",
109 Op::ListTeamMembers,
110 &[("include_child_teams", "include_child_teams")],
111 ),
112 route("PUT", "/workspaces/:workspace/teams/:team/members/:username", Op::SetTeamMember, &[]),
113 route("DELETE", "/workspaces/:workspace/teams/:team/members/:username", Op::RemoveTeamMember, &[]),
114 route("GET", "/workspaces/:workspace/teams/:team/teams", Op::ListChildTeams, &[]),
115 route("GET", "/workspaces/:workspace/teams/:team/repos", Op::ListTeamRepos, &[]),
116 route("PUT", "/workspaces/:workspace/teams/:team/repos/:repo", Op::SetTeamRepo, &[]),
117 route("DELETE", "/workspaces/:workspace/teams/:team/repos/:repo", Op::RemoveTeamRepo, &[]),
118 route(
119 "PUT",
120 "/workspaces/:workspace/teams/:team/review_assignment",
121 Op::SetTeamReviewAssignment,
122 &[],
123 ),
124 route("GET", "/workspaces/:workspace/members/:username/teams", Op::ListUserTeams, &[]),
Usage, Billing settings and prepaid AI credit; fixes from the UX audit125 // A workspace's billing: usage, budget, AI credit and invoices.
126 route(
127 "GET",
128 "/workspaces/:workspace/usage",
129 Op::GetUsage,
130 &[("from", "from"), ("until", "until"), ("products", "products"), ("projects", "projects"), ("group_by", "group_by")],
131 ),
132 route("GET", "/workspaces/:workspace/budget", Op::GetBudget, &[]),
133 route("PUT", "/workspaces/:workspace/budget", Op::SetBudget, &[]),
134 route("GET", "/workspaces/:workspace/ai_credit", Op::GetAiCredit, &[]),
135 route("POST", "/workspaces/:workspace/ai_credit/checkout", Op::BuyAiCredit, &[]),
136 route("GET", "/workspaces/:workspace/invoices", Op::ListInvoices, &[]),
137 route("GET", "/workspaces/:workspace/billing_details", Op::GetBillingDetails, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar138 // Code owners: the CODEOWNERS file, checked.
139 route("GET", "/repos/:owner/:name/codeowners/errors", Op::GetCodeownersErrors, &[("ref", "ref")]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily140 // Security alerts: secrets and vulnerable dependencies.
141 route(
142 "GET",
143 "/repos/:owner/:name/security/alerts",
144 Op::ListSecurityAlerts,
145 &[("state", "state"), ("kind", "kind")],
146 ),
147 route("POST", "/repos/:owner/:name/security/alerts/:id/dismiss", Op::DismissSecurityAlert, &[]),
148 route("POST", "/repos/:owner/:name/security/alerts/:id/reopen", Op::ReopenSecurityAlert, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar149 // The security suite: secret scanning, code scanning, vulnerability
150 // alerts and the supply chain, at the common addresses.
151 route("GET", "/repos/:owner/:name/secret-scanning/alerts", Op::Security(SecurityOp::ListSecretAlerts), &[("state", "state"), ("secret_type", "secret_type"), ("validity", "validity"), ("bypassed", "bypassed")]),
152 route("GET", "/workspaces/:workspace/secret-scanning/alerts", Op::Security(SecurityOp::ListSecretAlerts), &[("state", "state"), ("secret_type", "secret_type"), ("validity", "validity"), ("bypassed", "bypassed")]),
153 route("GET", "/repos/:owner/:name/secret-scanning/alerts/:id", Op::Security(SecurityOp::GetSecretAlert), &[]),
154 route("PATCH", "/repos/:owner/:name/secret-scanning/alerts/:id", Op::Security(SecurityOp::UpdateSecretAlert), &[]),
155 route("GET", "/repos/:owner/:name/secret-scanning/alerts/:id/locations", Op::Security(SecurityOp::ListSecretLocations), &[]),
156 route("POST", "/repos/:owner/:name/secret-scanning/alerts/:id/bypass", Op::Security(SecurityOp::BypassPushProtection), &[]),
157 route("POST", "/repos/:owner/:name/secret-scanning/alerts/:id/validity", Op::Security(SecurityOp::CheckSecretValidity), &[]),
158 route("GET", "/workspaces/:workspace/secret-scanning/bypass-requests", Op::Security(SecurityOp::ListBypassRequests), &[("state", "state"), ("repo", "repo")]),
159 route("PATCH", "/workspaces/:workspace/secret-scanning/bypass-requests/:id", Op::Security(SecurityOp::ReviewBypassRequest), &[]),
160 route("POST", "/repos/:owner/:name/secret-scanning/custom-patterns/dry-run", Op::Security(SecurityOp::DryRunCustomPattern), &[]),
161 route("POST", "/workspaces/:workspace/secret-scanning/custom-patterns/dry-run", Op::Security(SecurityOp::DryRunCustomPattern), &[]),
162 route("GET", "/repos/:owner/:name/secret-scanning/custom-patterns", Op::Security(SecurityOp::ListCustomPatterns), &[]),
163 route("GET", "/workspaces/:workspace/secret-scanning/custom-patterns", Op::Security(SecurityOp::ListCustomPatterns), &[]),
164 route("POST", "/repos/:owner/:name/secret-scanning/custom-patterns", Op::Security(SecurityOp::CreateCustomPattern), &[]),
165 route("POST", "/workspaces/:workspace/secret-scanning/custom-patterns", Op::Security(SecurityOp::CreateCustomPattern), &[]),
166 route("PATCH", "/repos/:owner/:name/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::UpdateCustomPattern), &[]),
167 route("PATCH", "/workspaces/:workspace/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::UpdateCustomPattern), &[]),
168 route("DELETE", "/repos/:owner/:name/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::DeleteCustomPattern), &[]),
169 route("DELETE", "/workspaces/:workspace/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::DeleteCustomPattern), &[]),
170 route("GET", "/repos/:owner/:name/code-scanning/alerts", Op::Security(SecurityOp::ListCodeAlerts), &[("state", "state"), ("severity", "severity"), ("tool", "tool"), ("rule_id", "rule_id")]),
171 route("GET", "/workspaces/:workspace/code-scanning/alerts", Op::Security(SecurityOp::ListCodeAlerts), &[("state", "state"), ("severity", "severity"), ("tool", "tool"), ("rule_id", "rule_id")]),
172 route("GET", "/repos/:owner/:name/code-scanning/alerts/:number", Op::Security(SecurityOp::GetCodeAlert), &[]),
173 route("PATCH", "/repos/:owner/:name/code-scanning/alerts/:number", Op::Security(SecurityOp::UpdateCodeAlert), &[]),
174 route("GET", "/repos/:owner/:name/code-scanning/analyses", Op::Security(SecurityOp::ListAnalyses), &[]),
175 route("POST", "/repos/:owner/:name/code-scanning/sarifs", Op::Security(SecurityOp::UploadSarif), &[]),
176 route("GET", "/repos/:owner/:name/code-scanning/sarifs/:id", Op::Security(SecurityOp::GetSarifUpload), &[]),
177 route("GET", "/repos/:owner/:name/vulnerability-alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), &[("state", "state"), ("severity", "severity"), ("ecosystem", "ecosystem"), ("package", "package")]),
178 route("GET", "/workspaces/:workspace/vulnerability-alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), &[("state", "state"), ("severity", "severity"), ("ecosystem", "ecosystem"), ("package", "package")]),
179 route("GET", "/repos/:owner/:name/vulnerability-alerts/:id", Op::Security(SecurityOp::GetVulnerabilityAlert), &[]),
180 route("PATCH", "/repos/:owner/:name/vulnerability-alerts/:id", Op::Security(SecurityOp::UpdateVulnerabilityAlert), &[]),
181 route("POST", "/repos/:owner/:name/security/alerts/:id/fix", Op::Security(SecurityOp::FixAlert), &[]),
182 route("GET", "/repos/:owner/:name/dependency-graph", Op::Security(SecurityOp::GetDependencyGraph), &[]),
183 route("GET", "/repos/:owner/:name/dependency-graph/sbom", Op::Security(SecurityOp::GetSbom), &[]),
184 route("GET", "/repos/:owner/:name/dependency-graph/compare/:basehead", Op::Security(SecurityOp::CompareDependencies), &[]),
185 route("GET", "/repos/:owner/:name/security/settings", Op::Security(SecurityOp::GetSettings), &[]),
186 route("PATCH", "/repos/:owner/:name/security/settings", Op::Security(SecurityOp::UpdateSettings), &[]),
187 route("GET", "/workspaces/:workspace/security/settings", Op::Security(SecurityOp::GetWorkspaceSettings), &[]),
188 route("PATCH", "/workspaces/:workspace/security/settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), &[]),
189 route("GET", "/workspaces/:workspace/security/overview", Op::Security(SecurityOp::GetOverview), &[("days", "days")]),
Agents as a team: lifecycle, merge queue, billing and a new shell190 route("GET", "/repos", Op::ListRepos, &[("q", "query")]),
Search across all of g1t, Explore, and a command palette191 route(
192 "GET",
193 "/search",
194 Op::Search,
195 &[("q", "query"), ("type", "type"), ("page", "page"), ("per_page", "per_page")],
196 ),
Agents as a team: lifecycle, merge queue, billing and a new shell197 route("POST", "/repos", Op::CreateRepo, &[]),
198 route("GET", "/repos/:owner/:name", Op::GetRepo, &[]),
199 route("PATCH", "/repos/:owner/:name", Op::UpdateRepo, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look200 route("POST", "/repos/:owner/:name/transfer", Op::TransferRepo, &[]),
201 route("DELETE", "/repos/:owner/:name", Op::DeleteRepo, &[]),
202 route(
203 "GET",
204 "/workspaces/:workspace/repos/deleted",
205 Op::ListDeletedRepos,
206 &[],
207 ),
208 route("POST", "/repos/:owner/:name/restore", Op::RestoreRepo, &[]),
209 route("POST", "/repos/:owner/:name/purge", Op::PurgeRepo, &[]),
210 route("POST", "/repos/:owner/:name/rename", Op::RenameRepo, &[]),
211 route("POST", "/repos/:owner/:name/archive", Op::ArchiveRepo, &[]),
212 route("POST", "/repos/:owner/:name/unarchive", Op::UnarchiveRepo, &[]),
213 route(
214 "POST",
215 "/repos/:owner/:name/visibility",
216 Op::SetRepoVisibility,
217 &[],
218 ),
219 route(
220 "POST",
221 "/repos/:owner/:name/branches/:branch/rename",
222 Op::RenameBranch,
223 &[],
224 ),
Agents as a team: lifecycle, merge queue, billing and a new shell225 route(
226 "GET",
227 "/repos/:owner/:name/settings",
228 Op::GetRepoSettings,
229 &[],
230 ),
231 route(
232 "PATCH",
233 "/repos/:owner/:name/settings",
234 Op::UpdateRepoSettings,
235 &[],
236 ),
Fast pages, required checks on the branch, self-hosted runners, honest incidents237 route("GET", "/repos/:owner/:name/check-names", Op::ListCheckNames, &[]),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge238 // Rulesets: a repository's, a workspace's, the rules of one branch,
239 // and how they judged pushes and merges.
240 route("GET", "/repos/:owner/:name/rulesets", Op::Rules(RulesOp::ListRepoRulesets), &[("include_parents", "include_parents")]),
241 route("POST", "/repos/:owner/:name/rulesets", Op::Rules(RulesOp::CreateRepoRuleset), &[]),
242 route("GET", "/repos/:owner/:name/rulesets/:id", Op::Rules(RulesOp::GetRepoRuleset), &[]),
243 route("PUT", "/repos/:owner/:name/rulesets/:id", Op::Rules(RulesOp::UpdateRepoRuleset), &[]),
244 route("DELETE", "/repos/:owner/:name/rulesets/:id", Op::Rules(RulesOp::DeleteRepoRuleset), &[]),
245 route("GET", "/repos/:owner/:name/rules/branches/:branch", Op::Rules(RulesOp::GetBranchRules), &[("target", "target")]),
246 route(
247 "GET",
248 "/repos/:owner/:name/rules/evaluations",
249 Op::Rules(RulesOp::ListRuleEvaluations),
250 &[("ruleset_id", "ruleset_id"), ("verdict", "verdict"), ("problems_only", "problems_only"), ("before", "before"), ("limit", "limit")],
251 ),
252 route("GET", "/workspaces/:workspace/rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), &[]),
253 route("POST", "/workspaces/:workspace/rulesets", Op::Rules(RulesOp::CreateWorkspaceRuleset), &[]),
254 route("GET", "/workspaces/:workspace/rulesets/:id", Op::Rules(RulesOp::GetWorkspaceRuleset), &[]),
255 route("PUT", "/workspaces/:workspace/rulesets/:id", Op::Rules(RulesOp::UpdateWorkspaceRuleset), &[]),
256 route("DELETE", "/workspaces/:workspace/rulesets/:id", Op::Rules(RulesOp::DeleteWorkspaceRuleset), &[]),
257 route(
258 "GET",
259 "/workspaces/:workspace/rules/evaluations",
260 Op::Rules(RulesOp::ListWorkspaceRuleEvaluations),
261 &[("ruleset_id", "ruleset_id"), ("verdict", "verdict"), ("problems_only", "problems_only"), ("before", "before"), ("limit", "limit")],
262 ),
Agents as a team: lifecycle, merge queue, billing and a new shell263 route("GET", "/repos/:owner/:name/queue", Op::GetMergeQueue, &[]),
API and MCP server in Rust; a public index at the API root264 route(
Usage, like a hosting provider's: what agents cost, per day, task, repository and pull request265 "POST",
266 "/repos/:owner/:name/pulls/:number/messages",
267 Op::MessageAgent,
268 &[],
269 ),
270 route(
271 "POST",
272 "/repos/:owner/:name/pulls/:number/messages/take",
273 Op::TakeMessages,
274 &[],
275 ),
276 route(
Docs worth reading, and kept that way277 "POST",
278 "/repos/:owner/:name/messages/:id/answer",
279 Op::AnswerMessage,
280 &[],
281 ),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains282 route("POST", "/repos/:owner/:name/memory", Op::Remember, &[]),
283 route(
284 "GET",
285 "/repos/:owner/:name/memory",
286 Op::Recall,
287 &[("q", "query"), ("limit", "limit")],
288 ),
Docs worth reading, and kept that way289 route(
API and MCP server in Rust; a public index at the API root290 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell291 "/repos/:owner/:name/events",
API and MCP server in Rust; a public index at the API root292 Op::ListEvents,
293 &[("before", "before")],
294 ),
Agents as a team: lifecycle, merge queue, billing and a new shell295 route("GET", "/repos/:owner/:name/labels", Op::ListLabels, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar296 route("POST", "/repos/:owner/:name/labels", Op::CreateLabel, &[]),
297 route("POST", "/repos/:owner/:name/labels/defaults", Op::AddDefaultLabels, &[]),
298 route("PATCH", "/repos/:owner/:name/labels/:label", Op::UpdateLabel, &[]),
299 route("DELETE", "/repos/:owner/:name/labels/:label", Op::DeleteLabel, &[]),
300 route("GET", "/repos/:owner/:name/issues/:number/labels", Op::ListIssueLabels, &[]),
301 route("POST", "/repos/:owner/:name/issues/:number/labels", Op::AddIssueLabels, &[]),
302 route("PUT", "/repos/:owner/:name/issues/:number/labels", Op::SetIssueLabels, &[]),
303 route("DELETE", "/repos/:owner/:name/issues/:number/labels", Op::RemoveIssueLabels, &[]),
304 route("DELETE", "/repos/:owner/:name/issues/:number/labels/:label", Op::RemoveIssueLabels, &[]),
305 route("GET", "/repos/:owner/:name/milestones", Op::ListMilestones, &[("state", "state")]),
306 route("POST", "/repos/:owner/:name/milestones", Op::CreateMilestone, &[]),
307 route("GET", "/repos/:owner/:name/milestones/:milestone", Op::GetMilestone, &[]),
308 route("PATCH", "/repos/:owner/:name/milestones/:milestone", Op::UpdateMilestone, &[]),
309 route("DELETE", "/repos/:owner/:name/milestones/:milestone", Op::DeleteMilestone, &[]),
API and MCP server in Rust; a public index at the API root310 route(
311 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell312 "/repos/:owner/:name/issues",
API and MCP server in Rust; a public index at the API root313 Op::ListIssues,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar314 &[("state", "state"), ("label", "label"), ("milestone", "milestone")],
API and MCP server in Rust; a public index at the API root315 ),
Agents as a team: lifecycle, merge queue, billing and a new shell316 route("POST", "/repos/:owner/:name/issues", Op::CreateIssue, &[]),
API and MCP server in Rust; a public index at the API root317 route(
318 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell319 "/repos/:owner/:name/issues/:number",
API and MCP server in Rust; a public index at the API root320 Op::GetIssue,
321 &[],
322 ),
323 route(
324 "PATCH",
Agents as a team: lifecycle, merge queue, billing and a new shell325 "/repos/:owner/:name/issues/:number",
API and MCP server in Rust; a public index at the API root326 Op::UpdateIssue,
327 &[],
328 ),
329 route(
330 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell331 "/repos/:owner/:name/issues/:number/close",
API and MCP server in Rust; a public index at the API root332 Op::CloseIssue,
333 &[],
334 ),
335 route(
336 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell337 "/repos/:owner/:name/issues/:number/reopen",
API and MCP server in Rust; a public index at the API root338 Op::ReopenIssue,
339 &[],
340 ),
341 route(
342 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell343 "/repos/:owner/:name/issues/:number/assign",
344 Op::AssignIssue,
345 &[],
346 ),
Integrations: your own model provider, alerts that open issues, tickets agents read347 route(
348 "POST",
349 "/repos/:owner/:name/issues/import",
350 Op::ImportIssue,
351 &[],
352 ),
353 route(
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step354 "POST",
355 "/repos/:owner/:name/issues/delegate",
356 Op::Delegate,
357 &[],
358 ),
359 route(
Integrations: your own model provider, alerts that open issues, tickets agents read360 "GET",
361 "/repos/:owner/:name/context",
362 Op::GetContext,
363 &[("reference", "reference")],
364 ),
365 route(
366 "GET",
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API367 "/workspaces/:workspace/context/search",
368 Op::SearchContext,
369 &[("q", "query"), ("project", "project"), ("kinds", "kinds"), ("limit", "limit")],
370 ),
371 route(
372 "GET",
373 "/workspaces/:workspace/context/:kind/:id",
374 Op::GetEntity,
375 &[],
376 ),
377 route(
378 "GET",
Integrations: your own model provider, alerts that open issues, tickets agents read379 "/workspaces/:workspace/integrations",
380 Op::ListIntegrations,
381 &[],
382 ),
383 route(
384 "POST",
385 "/workspaces/:workspace/integrations",
386 Op::ConnectIntegration,
387 &[],
388 ),
389 route(
Models per workspace: several providers, routed by kind of work390 "GET",
Webhooks: every event, to your own addresses, signed and retried391 "/repos/:owner/:name/hooks",
392 Op::ListWebhooks,
393 &[],
394 ),
395 route(
396 "POST",
397 "/repos/:owner/:name/hooks",
398 Op::CreateWebhook,
399 &[],
400 ),
401 route(
402 "PATCH",
403 "/repos/:owner/:name/hooks/:id",
404 Op::UpdateWebhook,
405 &[],
406 ),
407 route(
408 "DELETE",
409 "/repos/:owner/:name/hooks/:id",
410 Op::DeleteWebhook,
411 &[],
412 ),
413 route(
414 "POST",
415 "/repos/:owner/:name/hooks/:id/pings",
416 Op::PingWebhook,
417 &[],
418 ),
419 route(
420 "GET",
421 "/repos/:owner/:name/hooks/:id/deliveries",
422 Op::ListWebhookDeliveries,
423 &[],
424 ),
425 route(
426 "POST",
427 "/repos/:owner/:name/hooks/:id/deliveries/:delivery/redeliver",
428 Op::RedeliverWebhook,
429 &[],
430 ),
431 route(
432 "GET",
433 "/workspaces/:workspace/hooks",
434 Op::ListWebhooks,
435 &[],
436 ),
437 route(
438 "POST",
439 "/workspaces/:workspace/hooks",
440 Op::CreateWebhook,
441 &[],
442 ),
443 route(
444 "PATCH",
445 "/workspaces/:workspace/hooks/:id",
446 Op::UpdateWebhook,
447 &[],
448 ),
449 route(
450 "DELETE",
451 "/workspaces/:workspace/hooks/:id",
452 Op::DeleteWebhook,
453 &[],
454 ),
455 route(
456 "POST",
457 "/workspaces/:workspace/hooks/:id/pings",
458 Op::PingWebhook,
459 &[],
460 ),
461 route(
462 "GET",
463 "/workspaces/:workspace/hooks/:id/deliveries",
464 Op::ListWebhookDeliveries,
465 &[],
466 ),
467 route(
468 "POST",
469 "/workspaces/:workspace/hooks/:id/deliveries/:delivery/redeliver",
470 Op::RedeliverWebhook,
471 &[],
472 ),
473 route(
474 "GET",
Models per workspace: several providers, routed by kind of work475 "/workspaces/:workspace/model-routes",
476 Op::GetModelRoutes,
477 &[],
478 ),
479 route(
480 "PUT",
481 "/workspaces/:workspace/model-routes",
482 Op::SetModelRoutes,
483 &[],
484 ),
485 route(
Integrations: your own model provider, alerts that open issues, tickets agents read486 "DELETE",
487 "/workspaces/:workspace/integrations/:id",
488 Op::DisconnectIntegration,
489 &[],
490 ),
491 route(
492 "POST",
493 "/workspaces/:workspace/integrations/:id/test",
494 Op::TestIntegration,
495 &[],
496 ),
Automations: rules in .g1t/automations that act when something happens497 route(
498 "GET",
GitHub Actions on g1t, part two: running workflows499 "/repos/:owner/:name/actions/workflows",
500 Op::ListWorkflows,
501 &[],
502 ),
503 route(
504 "GET",
505 "/repos/:owner/:name/actions/workflows/:workflow/runs",
506 Op::ListWorkflowRuns,
507 &[("branch", "branch"), ("event", "event"), ("per_page", "limit")],
508 ),
509 route(
510 "POST",
511 "/repos/:owner/:name/actions/workflows/:workflow/dispatches",
512 Op::DispatchWorkflow,
513 &[],
514 ),
515 route(
516 "PATCH",
517 "/repos/:owner/:name/actions/workflows/:workflow",
518 Op::UpdateWorkflow,
519 &[],
520 ),
521 route(
522 "PUT",
523 "/repos/:owner/:name/actions/workflows/:workflow/enable",
524 Op::UpdateWorkflow,
525 &[],
526 ),
527 route(
528 "PUT",
529 "/repos/:owner/:name/actions/workflows/:workflow/disable",
530 Op::UpdateWorkflow,
531 &[],
532 ),
533 route(
534 "GET",
535 "/repos/:owner/:name/actions/runs",
536 Op::ListWorkflowRuns,
537 &[("workflow", "workflow"), ("branch", "branch"), ("event", "event"), ("pull", "pull"), ("head_sha", "sha"), ("per_page", "limit")],
538 ),
539 route(
540 "GET",
541 "/repos/:owner/:name/actions/runs/:id",
542 Op::GetWorkflowRun,
543 &[],
544 ),
545 route(
546 "POST",
547 "/repos/:owner/:name/actions/runs/:id/cancel",
548 Op::CancelWorkflowRun,
549 &[],
550 ),
551 route(
552 "POST",
553 "/repos/:owner/:name/actions/runs/:id/rerun",
554 Op::RerunWorkflowRun,
555 &[],
556 ),
557 route(
558 "POST",
559 "/repos/:owner/:name/actions/runs/:id/rerun-failed-jobs",
560 Op::RerunWorkflowRun,
561 &[],
562 ),
563 route(
564 "GET",
565 "/repos/:owner/:name/actions/jobs/:job/logs",
566 Op::GetJobLogs,
567 &[("after", "after")],
568 ),
569 route(
570 "GET",
571 "/repos/:owner/:name/actions/secrets",
572 Op::ListActionsSecrets,
573 &[],
574 ),
575 route(
576 "PUT",
577 "/repos/:owner/:name/actions/secrets/:setting",
578 Op::SetActionsSecret,
579 &[],
580 ),
581 route(
582 "DELETE",
583 "/repos/:owner/:name/actions/secrets/:setting",
584 Op::DeleteActionsSecret,
585 &[],
586 ),
587 route(
588 "GET",
589 "/repos/:owner/:name/actions/variables",
590 Op::ListActionsVariables,
591 &[],
592 ),
593 route(
594 "POST",
595 "/repos/:owner/:name/actions/variables",
596 Op::SetActionsVariable,
597 &[],
598 ),
599 route(
600 "PATCH",
601 "/repos/:owner/:name/actions/variables/:setting",
602 Op::SetActionsVariable,
603 &[],
604 ),
605 route(
606 "DELETE",
607 "/repos/:owner/:name/actions/variables/:setting",
608 Op::DeleteActionsVariable,
609 &[],
610 ),
611 route(
612 "GET",
613 "/workspaces/:workspace/actions/secrets",
614 Op::ListActionsSecrets,
615 &[],
616 ),
617 route(
618 "PUT",
619 "/workspaces/:workspace/actions/secrets/:setting",
620 Op::SetActionsSecret,
621 &[],
622 ),
623 route(
624 "DELETE",
625 "/workspaces/:workspace/actions/secrets/:setting",
626 Op::DeleteActionsSecret,
627 &[],
628 ),
629 route(
630 "GET",
631 "/workspaces/:workspace/actions/variables",
632 Op::ListActionsVariables,
633 &[],
634 ),
635 route(
636 "POST",
637 "/workspaces/:workspace/actions/variables",
638 Op::SetActionsVariable,
639 &[],
640 ),
641 route(
642 "PATCH",
643 "/workspaces/:workspace/actions/variables/:setting",
644 Op::SetActionsVariable,
645 &[],
646 ),
647 route(
648 "DELETE",
649 "/workspaces/:workspace/actions/variables/:setting",
650 Op::DeleteActionsVariable,
651 &[],
652 ),
Fast pages, required checks on the branch, self-hosted runners, honest incidents653 // Self-hosted runners: a repository's own, or a workspace's.
654 route("GET", "/repos/:owner/:name/actions/runners", Op::ListRunners, &[]),
655 route("POST", "/repos/:owner/:name/actions/runners/registration-token", Op::CreateRunnerRegistrationToken, &[]),
656 route("DELETE", "/repos/:owner/:name/actions/runners/:id", Op::RemoveRunner, &[]),
657 route("GET", "/repos/:owner/:name/actions/runner-settings", Op::GetRunnerSettings, &[]),
658 route("PATCH", "/repos/:owner/:name/actions/runner-settings", Op::UpdateRunnerSettings, &[]),
659 route("GET", "/workspaces/:workspace/actions/runners", Op::ListRunners, &[]),
660 route("POST", "/workspaces/:workspace/actions/runners/registration-token", Op::CreateRunnerRegistrationToken, &[]),
661 route("DELETE", "/workspaces/:workspace/actions/runners/:id", Op::RemoveRunner, &[]),
662 route("GET", "/workspaces/:workspace/actions/runner-settings", Op::GetRunnerSettings, &[]),
663 route("PATCH", "/workspaces/:workspace/actions/runner-settings", Op::UpdateRunnerSettings, &[]),
664 route("GET", "/workspaces/:workspace/actions/runner-groups", Op::ListRunnerGroups, &[]),
665 route("POST", "/workspaces/:workspace/actions/runner-groups", Op::CreateRunnerGroup, &[]),
666 route("PATCH", "/workspaces/:workspace/actions/runner-groups/:id", Op::UpdateRunnerGroup, &[]),
667 route("DELETE", "/workspaces/:workspace/actions/runner-groups/:id", Op::DeleteRunnerGroup, &[]),
Agents as a team: lifecycle, merge queue, billing and a new shell668 route("POST", "/repos/:owner/:name/plans", Op::PlanWork, &[]),
669 route("GET", "/repos/:owner/:name/plans/:plan", Op::GetPlan, &[]),
670 route(
671 "POST",
672 "/repos/:owner/:name/plans/:plan/apply",
673 Op::ApplyPlan,
674 &[],
675 ),
676 route(
677 "POST",
678 "/repos/:owner/:name/issues/:number/comments",
API and MCP server in Rust; a public index at the API root679 Op::AddComment,
680 &[],
681 ),
682 route(
683 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell684 "/repos/:owner/:name/pulls",
API and MCP server in Rust; a public index at the API root685 Op::ListPullRequests,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar686 &[("state", "state"), ("label", "label"), ("milestone", "milestone"), ("base", "base")],
API and MCP server in Rust; a public index at the API root687 ),
688 route(
689 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell690 "/repos/:owner/:name/pulls",
API and MCP server in Rust; a public index at the API root691 Op::CreatePullRequest,
692 &[],
693 ),
694 route(
695 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell696 "/repos/:owner/:name/pulls/:number",
API and MCP server in Rust; a public index at the API root697 Op::GetPullRequest,
698 &[],
699 ),
700 route(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar701 "PATCH",
702 "/repos/:owner/:name/pulls/:number",
703 Op::UpdatePullRequest,
704 &[],
705 ),
706 route(
API and MCP server in Rust; a public index at the API root707 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell708 "/repos/:owner/:name/pulls/:number/changes",
API and MCP server in Rust; a public index at the API root709 Op::GetPullRequestChanges,
710 &[],
711 ),
712 route(
Acceptance checks in sandboxes, line comments and review verdicts713 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell714 "/repos/:owner/:name/pulls/:number/reviews",
Acceptance checks in sandboxes, line comments and review verdicts715 Op::ReviewPullRequest,
716 &[],
717 ),
718 route(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar719 "POST",
720 "/repos/:owner/:name/pulls/:number/requested_reviewers",
721 Op::RequestReviewers,
722 &[],
723 ),
724 route(
725 "DELETE",
726 "/repos/:owner/:name/pulls/:number/requested_reviewers",
727 Op::RemoveRequestedReviewers,
728 &[],
729 ),
730 route(
API and MCP server in Rust; a public index at the API root731 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell732 "/repos/:owner/:name/pulls/:number/session",
API and MCP server in Rust; a public index at the API root733 Op::ReadSession,
734 &[("after", "after")],
735 ),
736 route(
737 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell738 "/repos/:owner/:name/pulls/:number/session",
API and MCP server in Rust; a public index at the API root739 Op::RecordSession,
740 &[],
741 ),
742 route(
743 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell744 "/repos/:owner/:name/pulls/:number/ready",
API and MCP server in Rust; a public index at the API root745 Op::MarkPullRequestReady,
746 &[],
747 ),
748 route(
749 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell750 "/repos/:owner/:name/pulls/:number/close",
API and MCP server in Rust; a public index at the API root751 Op::ClosePullRequest,
752 &[],
753 ),
754 route(
755 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell756 "/repos/:owner/:name/pulls/:number/merge",
API and MCP server in Rust; a public index at the API root757 Op::MergePullRequest,
758 &[],
759 ),
760];
761
762impl Route {
763 /// The names of the route's path parameters, in order.
764 pub fn params(&self) -> impl Iterator<Item = &'static str> {
765 self.path
766 .split('/')
767 .filter_map(|segment| segment.strip_prefix(':'))
768 }
769
770 /// The values of the path parameters, if `path` is this route's.
771 fn matches<'a>(&self, path: &'a str) -> Option<Vec<(&'static str, &'a str)>> {
772 let mut values = Vec::new();
773 let mut actual = path.trim_end_matches('/').split('/');
774 for expected in self.path.split('/') {
775 let segment = actual.next()?;
776 match expected.strip_prefix(':') {
777 Some(name) if !segment.is_empty() => values.push((name, segment)),
778 Some(_) => return None,
779 None if expected == segment => {}
780 None => return None,
781 }
782 }
783 actual.next().is_none().then_some(values)
784 }
785}
786
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look787/// A path segment with its `%XX` escapes decoded; as given when that is not
788/// UTF-8.
789fn percent_decoded(segment: &str) -> String {
790 let bytes = segment.as_bytes();
791 let mut out = Vec::with_capacity(bytes.len());
792 let mut i = 0;
793 while i < bytes.len() {
794 let escaped = (bytes[i] == b'%')
795 .then(|| segment.get(i + 1..i + 3))
796 .flatten()
797 .filter(|hex| hex.bytes().all(|byte| byte.is_ascii_hexdigit()))
798 .and_then(|hex| u8::from_str_radix(hex, 16).ok());
799 match escaped {
800 Some(byte) => {
801 out.push(byte);
802 i += 3;
803 }
804 None => {
805 out.push(bytes[i]);
806 i += 1;
807 }
808 }
809 }
810 String::from_utf8(out).unwrap_or_else(|_| segment.to_owned())
811}
812
API and MCP server in Rust; a public index at the API root813/// The route for a request, and the operation input it describes.
814///
815/// The input is the JSON body, overlaid with the query parameters the route
816/// reads and then with what the path names: `owner` and `name` become
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar817/// `repo`, as does a team's `repo` with its `workspace`, and `number`
818/// becomes an integer.
API and MCP server in Rust; a public index at the API root819pub fn resolve(
820 method: &str,
821 path: &str,
822 query: &[(String, String)],
823 body: Value,
824) -> Option<(&'static Route, Value)> {
825 let (route, params) = ROUTES
826 .iter()
827 .filter(|route| route.method == method)
828 .find_map(|route| Some((route, route.matches(path)?)))?;
829
830 let mut input = match body {
831 Value::Object(fields) => fields,
832 _ => Map::new(),
833 };
834 for (name, key) in route.query {
835 if let Some((_, value)) = query.iter().find(|(query_name, _)| query_name == name) {
836 input.insert((*key).to_owned(), Value::String(value.clone()));
837 }
838 }
839 let param = |wanted: &str| {
840 params
841 .iter()
842 .find(|(name, _)| *name == wanted)
843 .map(|(_, value)| *value)
844 };
845 if let (Some(owner), Some(name)) = (param("owner"), param("name")) {
846 input.insert("repo".to_owned(), Value::String(format!("{owner}/{name}")));
847 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar848 for key in ["plan", "id", "workspace", "delivery", "workflow", "job", "setting", "username", "team", "basehead"] {
Docs worth reading, and kept that way849 if let Some(value) = param(key) {
850 input.insert(key.to_owned(), Value::String(value.to_owned()));
851 }
Agents as a team: lifecycle, merge queue, billing and a new shell852 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar853 // A repository of a team's workspace, named by itself.
854 if let (Some(workspace), Some(name)) = (param("workspace"), param("repo")) {
855 input.insert("repo".to_owned(), Value::String(format!("{workspace}/{name}")));
856 }
857 // A branch name may hold slashes, sent URL-encoded as one segment, and
858 // a label's name spaces.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look859 if let Some(branch) = param("branch") {
860 input.insert("branch".to_owned(), Value::String(percent_decoded(branch)));
861 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar862 if let Some(label) = param("label") {
863 input.insert("label".to_owned(), Value::String(percent_decoded(label)));
864 }
865 if let Some(milestone) = param("milestone") {
866 // Not a number: zero, which no milestone has.
867 input.insert("milestone".to_owned(), milestone.parse::<u32>().unwrap_or(0).into());
868 }
GitHub Actions on g1t, part two: running workflows869 // GitHub says some things with the path alone.
870 if route.path.ends_with("/enable") || route.path.ends_with("/disable") {
871 input.insert("enabled".to_owned(), Value::Bool(route.path.ends_with("/enable")));
872 }
873 if route.path.ends_with("/rerun-failed-jobs") {
874 input.insert("failed_only".to_owned(), Value::Bool(true));
875 }
API: notifications over REST and MCP, with notifications scopes876 // Unsaving and waking a thread are a DELETE of what PUT made.
877 if route.method == "DELETE" && route.path.ends_with("/saved") {
878 input.insert("saved".to_owned(), Value::Bool(false));
879 }
880 if route.method == "DELETE" && route.path.ends_with("/snooze") {
881 input.remove("until");
882 }
API and MCP server in Rust; a public index at the API root883 if let Some(number) = param("number") {
884 // Not a number: zero, which no issue or pull request has.
885 input.insert(
886 "number".to_owned(),
887 number.parse::<u32>().unwrap_or(0).into(),
888 );
889 }
890 Some((route, Value::Object(input)))
891}
892
893#[cfg(test)]
894mod tests {
895 use serde_json::json;
896
897 use super::*;
898
899 #[test]
900 fn a_path_resolves_to_its_operation_and_input() {
901 let (route, input) = resolve(
902 "POST",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look903 "/repos/flagon-io/hello/pulls/14/merge",
API and MCP server in Rust; a public index at the API root904 &[],
905 json!({ "keep_issue_open": true, "number": 99, "repo": "someone/else" }),
906 )
907 .unwrap();
908 assert_eq!(route.op, Op::MergePullRequest);
909 // What the path names wins over the body.
910 assert_eq!(
911 input,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look912 json!({ "keep_issue_open": true, "number": 14, "repo": "flagon-io/hello" })
API and MCP server in Rust; a public index at the API root913 );
914 }
915
916 #[test]
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look917 fn a_branch_with_slashes_is_one_encoded_segment() {
918 let (route, input) = resolve(
919 "POST",
920 "/repos/flagon-io/hello/branches/feature%2Flogin/rename",
921 &[],
922 json!({ "new_name": "feature/sign-in" }),
923 )
924 .unwrap();
925 assert_eq!(route.op, Op::RenameBranch);
926 assert_eq!(
927 input,
928 json!({ "new_name": "feature/sign-in", "branch": "feature/login", "repo": "flagon-io/hello" })
929 );
930 assert_eq!(percent_decoded("100%"), "100%");
931 assert_eq!(percent_decoded("a%2bb%zz"), "a+b%zz");
932 }
933
934 #[test]
935 fn a_collaborator_is_named_by_username() {
936 let (route, input) = resolve(
937 "PATCH",
938 "/repos/flagon-io/hello/collaborators/ada",
939 &[],
940 json!({ "role": "maintain" }),
941 )
942 .unwrap();
943 assert_eq!(route.op, Op::UpdateCollaborator);
944 assert_eq!(input, json!({ "role": "maintain", "username": "ada", "repo": "flagon-io/hello" }));
945 let (route, input) = resolve("DELETE", "/user/repository_invitations/rin_1", &[], Value::Null).unwrap();
946 assert_eq!(route.op, Op::DeclineRepoInvitation);
947 assert_eq!(input, json!({ "id": "rin_1" }));
948 }
949
950 #[test]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar951 fn teams_are_addressed_by_workspace_and_slug() {
952 let query = [("q".to_owned(), "back".to_owned())];
953 let (route, input) = resolve("GET", "/workspaces/acme/teams", &query, Value::Null).unwrap();
954 assert_eq!(route.op, Op::ListTeams);
955 assert_eq!(input, json!({ "query": "back", "workspace": "acme" }));
956 let (route, input) = resolve("PATCH", "/workspaces/acme/teams/backend", &[], json!({ "name": "Back end" })).unwrap();
957 assert_eq!(route.op, Op::UpdateTeam);
958 assert_eq!(input, json!({ "name": "Back end", "workspace": "acme", "team": "backend" }));
959 let (route, input) =
960 resolve("PUT", "/workspaces/acme/teams/backend/members/ana", &[], json!({ "role": "maintainer" })).unwrap();
961 assert_eq!(route.op, Op::SetTeamMember);
962 assert_eq!(input, json!({ "role": "maintainer", "workspace": "acme", "team": "backend", "username": "ana" }));
963 let query = [("include_child_teams".to_owned(), "true".to_owned())];
964 let (route, input) = resolve("GET", "/workspaces/acme/teams/backend/members", &query, Value::Null).unwrap();
965 assert_eq!(route.op, Op::ListTeamMembers);
966 assert_eq!(input, json!({ "include_child_teams": "true", "workspace": "acme", "team": "backend" }));
967 // A repository is named by itself, in the team's workspace.
968 let (route, input) =
969 resolve("PUT", "/workspaces/acme/teams/backend/repos/rocket", &[], json!({ "role": "write" })).unwrap();
970 assert_eq!(route.op, Op::SetTeamRepo);
971 assert_eq!(input, json!({ "role": "write", "workspace": "acme", "team": "backend", "repo": "acme/rocket" }));
972 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
973 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend/repos/rocket"), Op::RemoveTeamRepo);
974 assert_eq!(op("GET", "/workspaces/acme/teams/backend/teams"), Op::ListChildTeams);
975 assert_eq!(op("GET", "/workspaces/acme/teams/backend/repos"), Op::ListTeamRepos);
976 assert_eq!(op("PUT", "/workspaces/acme/teams/backend/review_assignment"), Op::SetTeamReviewAssignment);
977 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend"), Op::DeleteTeam);
978 assert_eq!(op("POST", "/workspaces/acme/teams"), Op::CreateTeam);
979 assert_eq!(op("GET", "/workspaces/acme/teams/backend"), Op::GetTeam);
980 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend/members/ana"), Op::RemoveTeamMember);
981 let (route, input) = resolve("GET", "/workspaces/acme/members/ana/teams", &[], Value::Null).unwrap();
982 assert_eq!(route.op, Op::ListUserTeams);
983 assert_eq!(input, json!({ "workspace": "acme", "username": "ana" }));
984 }
985
986 #[test]
987 fn reviewers_are_requested_and_code_owners_checked_on_a_repository() {
988 let body = json!({ "reviewers": ["ana"], "team_reviewers": ["backend"] });
989 let (route, input) = resolve("POST", "/repos/acme/rocket/pulls/7/requested_reviewers", &[], body.clone()).unwrap();
990 assert_eq!(route.op, Op::RequestReviewers);
991 assert_eq!(
992 input,
993 json!({ "reviewers": ["ana"], "team_reviewers": ["backend"], "repo": "acme/rocket", "number": 7 })
994 );
995 let (route, _) = resolve("DELETE", "/repos/acme/rocket/pulls/7/requested_reviewers", &[], body).unwrap();
996 assert_eq!(route.op, Op::RemoveRequestedReviewers);
997 let query = [("ref".to_owned(), "main".to_owned())];
998 let (route, input) = resolve("GET", "/repos/acme/rocket/codeowners/errors", &query, Value::Null).unwrap();
999 assert_eq!(route.op, Op::GetCodeownersErrors);
1000 assert_eq!(input, json!({ "ref": "main", "repo": "acme/rocket" }));
1001 }
1002
1003 #[test]
API: notifications over REST and MCP, with notifications scopes1004 fn notifications_are_addressed_as_threads_and_by_issue() {
1005 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1", &[], Value::Null).unwrap();
1006 assert_eq!(route.op, Op::MarkThreadDone);
1007 assert_eq!(input, json!({ "id": "ntf_1" }));
1008 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1/saved", &[], Value::Null).unwrap();
1009 assert_eq!(route.op, Op::SaveThread);
1010 assert_eq!(input, json!({ "id": "ntf_1", "saved": false }));
1011 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1/snooze", &[], json!({ "until": "x" })).unwrap();
1012 assert_eq!(route.op, Op::SnoozeThread);
1013 assert_eq!(input, json!({ "id": "ntf_1" }));
1014 let query = [("all".to_owned(), "true".to_owned()), ("per_page".to_owned(), "50".to_owned())];
1015 let (route, input) = resolve("GET", "/repos/acme/rocket/notifications", &query, Value::Null).unwrap();
1016 assert_eq!(route.op, Op::ListNotifications);
1017 assert_eq!(input, json!({ "all": "true", "per_page": "50", "repo": "acme/rocket" }));
1018 let (route, input) = resolve("PUT", "/repos/acme/rocket/issues/7/subscription", &[], json!({ "ignored": true })).unwrap();
1019 assert_eq!(route.op, Op::SetThreadSubscription);
1020 assert_eq!(input, json!({ "ignored": true, "number": 7, "repo": "acme/rocket" }));
1021 assert_eq!(resolve("GET", "/user/subscriptions", &[], Value::Null).unwrap().0.op, Op::ListWatchedRepos);
1022 }
1023
1024 #[test]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1025 fn labels_and_milestones_are_named_in_the_path() {
1026 let (route, input) = resolve("PATCH", "/repos/acme/web/labels/good%20first%20issue", &[], json!({ "color": "7057ff" })).unwrap();
1027 assert_eq!(route.op, Op::UpdateLabel);
1028 assert_eq!(input, json!({ "color": "7057ff", "label": "good first issue", "repo": "acme/web" }));
1029 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/7/labels/bug", &[], Value::Null).unwrap();
1030 assert_eq!(route.op, Op::RemoveIssueLabels);
1031 assert_eq!(input, json!({ "label": "bug", "number": 7, "repo": "acme/web" }));
1032 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/7/labels", &[], Value::Null).unwrap();
1033 assert_eq!(route.op, Op::RemoveIssueLabels);
1034 assert_eq!(input, json!({ "number": 7, "repo": "acme/web" }));
1035 let (route, _) = resolve("POST", "/repos/acme/web/labels/defaults", &[], Value::Null).unwrap();
1036 assert_eq!(route.op, Op::AddDefaultLabels);
1037 let (route, input) = resolve("PATCH", "/repos/acme/web/milestones/3", &[], json!({ "state": "closed" })).unwrap();
1038 assert_eq!(route.op, Op::UpdateMilestone);
1039 assert_eq!(input, json!({ "state": "closed", "milestone": 3, "repo": "acme/web" }));
1040 let (route, input) = resolve("PATCH", "/repos/acme/web/pulls/9", &[], json!({ "base": "release" })).unwrap();
1041 assert_eq!(route.op, Op::UpdatePullRequest);
1042 assert_eq!(input, json!({ "base": "release", "number": 9, "repo": "acme/web" }));
1043 }
1044
1045 #[test]
Usage, Billing settings and prepaid AI credit; fixes from the UX audit1046 fn billing_is_addressed_by_workspace() {
1047 let query = [("from".to_owned(), "2026-10-01".to_owned()), ("products".to_owned(), "agent,sandboxes".to_owned())];
1048 let (route, input) = resolve("GET", "/workspaces/acme/usage", &query, Value::Null).unwrap();
1049 assert_eq!(route.op, Op::GetUsage);
1050 assert_eq!(input, json!({ "from": "2026-10-01", "products": "agent,sandboxes", "workspace": "acme" }));
1051 let (route, input) = resolve("PUT", "/workspaces/acme/budget", &[], json!({ "alerts": [50] })).unwrap();
1052 assert_eq!(route.op, Op::SetBudget);
1053 assert_eq!(input, json!({ "alerts": [50], "workspace": "acme" }));
1054 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
1055 assert_eq!(op("GET", "/workspaces/acme/budget"), Op::GetBudget);
1056 assert_eq!(op("GET", "/workspaces/acme/ai_credit"), Op::GetAiCredit);
1057 assert_eq!(op("POST", "/workspaces/acme/ai_credit/checkout"), Op::BuyAiCredit);
1058 assert_eq!(op("GET", "/workspaces/acme/invoices"), Op::ListInvoices);
1059 assert_eq!(op("GET", "/workspaces/acme/billing_details"), Op::GetBillingDetails);
1060 }
1061
1062 #[test]
API and MCP server in Rust; a public index at the API root1063 fn query_parameters_are_renamed() {
1064 let query = [
1065 ("q".to_owned(), "parser".to_owned()),
1066 ("x".to_owned(), "y".to_owned()),
1067 ];
Agents as a team: lifecycle, merge queue, billing and a new shell1068 let (route, input) = resolve("GET", "/repos", &query, Value::Null).unwrap();
API and MCP server in Rust; a public index at the API root1069 assert_eq!(route.op, Op::ListRepos);
1070 assert_eq!(input, json!({ "query": "parser" }));
1071 }
1072
1073 #[test]
1074 fn method_and_shape_must_match() {
Agents as a team: lifecycle, merge queue, billing and a new shell1075 assert!(resolve("GET", "/repos/a/b/issues/1/close", &[], Value::Null).is_none());
1076 assert!(resolve("GET", "/repos/a", &[], Value::Null).is_none());
1077 assert!(resolve("GET", "/repos/a/b/issues/1/extra", &[], Value::Null).is_none());
1078 assert!(resolve("GET", "/repos/a/b/", &[], Value::Null).is_some());
API and MCP server in Rust; a public index at the API root1079 }
1080
1081 #[test]
1082 fn every_parameter_and_query_name_is_an_input() {
1083 for route in ROUTES {
1084 let properties = route.op.properties();
1085 for (_, key) in route.query {
1086 assert!(properties.contains_key(*key), "{}: {key}", route.path);
1087 }
1088 for name in route.params() {
1089 let covered = matches!(name, "owner" | "name") && properties.contains_key("repo")
1090 || properties.contains_key(name);
1091 assert!(covered, "{}: {name}", route.path);
1092 }
1093 }
1094 }
1095
1096 #[test]
1097 fn every_operation_has_a_route() {
1098 for op in Op::ALL {
1099 assert!(ROUTES.iter().any(|route| route.op == op), "{}", op.name());
1100 }
1101 }
1102}

This file's history is long; its oldest lines are credited to the oldest commit read.