Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 1 | //! Every response the REST routes give, run through the converter the API |
| 2 | //! sends them with, checked for `camelCase` that would leak out. | |
| 3 | //! | |
| 4 | //! The samples are the reference's example responses, put back into the | |
| 5 | //! `camelCase` the services send (as serde's `rename_all` writes it) and, | |
| 6 | //! where an operation returns a contract type, decoded into that type and | |
| 7 | //! encoded again, so that every field the type has is sent, not only the | |
| 8 | //! ones an example shows. | |
| 9 | ||
| Merge rulesets: branch and tag rules, agent-first, enforced on push and merge | 10 | use g1t_contracts::{access, actions, codeowners, integrations, repos, rules, search, teams, webhooks, work}; |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 11 | use g1t_kit::wire::{self, USER_KEYED}; |
| 12 | use serde::Serialize; | |
| 13 | use serde::de::DeserializeOwned; | |
| 14 | use serde_json::{Map, Value, json}; | |
| 15 | ||
| 16 | use crate::openapi::document; | |
| 17 | use crate::operations::Op; | |
| Merge rulesets: branch and tag rules, agent-first, enforced on push and merge | 18 | use crate::rules::RulesOp; |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 19 | |
| 20 | /// A key as `#[serde(rename_all = "camelCase")]` writes it. | |
| 21 | fn camel_key(key: &str) -> String { | |
| 22 | let mut out = String::with_capacity(key.len()); | |
| 23 | let mut upper = false; | |
| 24 | for c in key.chars() { | |
| 25 | if c == '_' { | |
| 26 | upper = true; | |
| 27 | } else if upper { | |
| 28 | out.extend(c.to_uppercase()); | |
| 29 | upper = false; | |
| 30 | } else { | |
| 31 | out.push(c); | |
| 32 | } | |
| 33 | } | |
| 34 | out | |
| 35 | } | |
| 36 | ||
| 37 | /// A response as the services send it: `camelCase`, but for the maps the | |
| 38 | /// converter passes through, which are data. | |
| 39 | fn as_services_send(value: &Value) -> Value { | |
| 40 | match value { | |
| 41 | Value::Object(fields) => { | |
| 42 | let mut out = Map::new(); | |
| 43 | for (key, value) in fields { | |
| 44 | let user_keyed = value.is_object() | |
| 45 | && (USER_KEYED.contains(&key.as_str()) || key.starts_with("by_")); | |
| 46 | let value = if user_keyed { value.clone() } else { as_services_send(value) }; | |
| 47 | // A `by_…` map keeps its name in the converter's spelling. | |
| 48 | let key = if key.starts_with("by_") { key.clone() } else { camel_key(key) }; | |
| 49 | out.insert(key, value); | |
| 50 | } | |
| 51 | Value::Object(out) | |
| 52 | } | |
| 53 | Value::Array(items) => Value::Array(items.iter().map(as_services_send).collect()), | |
| 54 | other => other.clone(), | |
| 55 | } | |
| 56 | } | |
| 57 | ||
| 58 | /// `value` decoded as `T` and encoded again, as the service would send it. | |
| 59 | fn through<T: DeserializeOwned + Serialize>(op: Op, value: Value) -> Value { | |
| 60 | let decoded: T = serde_json::from_value(value) | |
| 61 | .unwrap_or_else(|error| panic!("{}: the example is not a {}: {error}", op.name(), std::any::type_name::<T>())); | |
| 62 | serde_json::to_value(decoded).unwrap() | |
| 63 | } | |
| 64 | ||
| 65 | /// What the service behind an operation sends, from its example. | |
| 66 | fn sample(op: Op, example: &Value) -> Value { | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 67 | // Types serde already writes in `snake_case`: a person, and who has |
| 68 | // access. Sent as they are. | |
| 69 | let as_is = example.clone(); | |
| 70 | match op { | |
| 71 | Op::Whoami => return through::<g1t_contracts::User>(op, as_is), | |
| 72 | Op::ListCollaborators => return through::<access::RepoAccess>(op, as_is), | |
| 73 | Op::AddCollaborator => return through::<access::Added>(op, as_is), | |
| 74 | Op::UpdateCollaborator => return through::<access::Collaborator>(op, as_is), | |
| 75 | Op::GetCollaboratorPermission => return through::<access::PermissionInfo>(op, as_is), | |
| 76 | Op::ListRepoInvitations | Op::ListMyRepoInvitations => { | |
| 77 | return through::<Vec<access::RepoInvitation>>(op, as_is); | |
| 78 | } | |
| 79 | Op::RevokeRepoInvitation | Op::AcceptRepoInvitation | Op::DeclineRepoInvitation => { | |
| 80 | return through::<access::RepoInvitation>(op, as_is); | |
| 81 | } | |
| 82 | Op::ListOutsideCollaborators => return through::<Vec<access::OutsideCollaborator>>(op, as_is), | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 83 | // Teams and code owners, also `snake_case`. |
| 84 | Op::ListTeams | Op::ListChildTeams | Op::ListUserTeams => return through::<Vec<teams::Team>>(op, as_is), | |
| 85 | Op::GetTeam | Op::CreateTeam | Op::UpdateTeam | Op::SetTeamReviewAssignment => { | |
| 86 | return through::<teams::Team>(op, as_is); | |
| 87 | } | |
| 88 | Op::ListTeamMembers => return through::<Vec<teams::TeamMember>>(op, as_is), | |
| 89 | Op::SetTeamMember => return through::<teams::TeamMember>(op, as_is), | |
| 90 | Op::ListTeamRepos => return through::<Vec<teams::TeamRepo>>(op, as_is), | |
| 91 | Op::SetTeamRepo => return through::<teams::TeamRepo>(op, as_is), | |
| 92 | Op::DeleteTeam | Op::RemoveTeamMember | Op::RemoveTeamRepo => return through::<bool>(op, as_is), | |
| 93 | Op::GetCodeownersErrors => return through::<codeowners::CodeOwnersReport>(op, as_is), | |
| Merge rulesets: branch and tag rules, agent-first, enforced on push and merge | 94 | // Rulesets travel in `snake_case` between services too. |
| 95 | Op::Rules(RulesOp::ListRepoRulesets | RulesOp::ListWorkspaceRulesets) => { | |
| 96 | return through::<Vec<rules::Ruleset>>(op, as_is); | |
| 97 | } | |
| 98 | Op::Rules( | |
| 99 | RulesOp::GetRepoRuleset | |
| 100 | | RulesOp::CreateRepoRuleset | |
| 101 | | RulesOp::UpdateRepoRuleset | |
| 102 | | RulesOp::GetWorkspaceRuleset | |
| 103 | | RulesOp::CreateWorkspaceRuleset | |
| 104 | | RulesOp::UpdateWorkspaceRuleset, | |
| 105 | ) => return through::<rules::Ruleset>(op, as_is), | |
| 106 | Op::Rules(RulesOp::GetBranchRules) => return through::<rules::EffectiveRules>(op, as_is), | |
| 107 | Op::Rules(RulesOp::ListRuleEvaluations | RulesOp::ListWorkspaceRuleEvaluations) => { | |
| 108 | return through::<rules::EvaluationPage>(op, as_is); | |
| 109 | } | |
| 110 | // Built by the API itself. | |
| 111 | Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset) => return as_is, | |
| Merge main: Deployments panel in the About, project homepage, both sides' operations | 112 | // Deployments travel in `snake_case` between services too. |
| 113 | Op::Deployments(_) => return as_is, | |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 114 | // Built by the API itself, in `snake_case`. |
| 115 | Op::ListSecurityAlerts => return through::<Vec<crate::alerts::SecurityAlert>>(op, as_is), | |
| 116 | Op::DismissSecurityAlert | Op::ReopenSecurityAlert => { | |
| 117 | return through::<crate::alerts::SecurityAlert>(op, as_is); | |
| 118 | } | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 119 | _ => {} |
| 120 | } | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 121 | let mut sent = as_services_send(example); |
| 122 | // A pull request's code owners are `snake_case` inside it. | |
| 123 | if op == Op::GetPullRequest | |
| 124 | && let Some(code_owners) = example.get("code_owners") | |
| 125 | { | |
| 126 | sent["codeOwners"] = code_owners.clone(); | |
| 127 | } | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 128 | match op { |
| Merge branch 'worktree-agent-ad7c6d88d93adc817' | 129 | Op::GetWorkspace | Op::CreateWorkspace | Op::UpdateWorkspace => through::<g1t_contracts::identity::Workspace>(op, sent), |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 130 | Op::ListRepos => through::<Vec<repos::Repo>>(op, sent), |
| Search across all of g1t, Explore, and a command palette | 131 | Op::Search => through::<search::SearchResults>(op, sent), |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 132 | Op::GetRepo |
| 133 | | Op::CreateRepo | |
| 134 | | Op::UpdateRepo | |
| 135 | | Op::TransferRepo | |
| 136 | | Op::RenameRepo | |
| 137 | | Op::RenameBranch | |
| 138 | | Op::ArchiveRepo | |
| 139 | | Op::UnarchiveRepo | |
| 140 | | Op::SetRepoVisibility | |
| 141 | | Op::RestoreRepo => through::<repos::Repo>(op, sent), | |
| 142 | Op::DeleteRepo => through::<repos::DeletedRepo>(op, sent), | |
| 143 | Op::ListDeletedRepos => through::<Vec<repos::DeletedRepo>>(op, sent), | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 144 | Op::GetRepoSettings | Op::UpdateRepoSettings => through::<work::RepoSettings>(op, sent), |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 145 | Op::ListCheckNames => through::<Vec<work::SeenCheck>>(op, sent), |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 146 | Op::GetMergeQueue => through::<work::QueueView>(op, sent), |
| 147 | Op::ListIssues => through::<Vec<work::Issue>>(op, sent), | |
| 148 | Op::CreateIssue | Op::UpdateIssue | Op::CloseIssue | Op::ReopenIssue => { | |
| 149 | through::<work::Issue>(op, sent) | |
| 150 | } | |
| 151 | Op::GetIssue => through::<work::IssueDetail>(op, sent), | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 152 | Op::Delegate => through::<work::Delegated>(op, sent), |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 153 | Op::ListPullRequests => through::<Vec<work::Pull>>(op, sent), |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 154 | Op::UpdatePullRequest => through::<work::Pull>(op, sent), |
| 155 | Op::ListLabels | Op::AddDefaultLabels | Op::ListIssueLabels => through::<Vec<work::Label>>(op, sent), | |
| 156 | Op::CreateLabel | Op::UpdateLabel => through::<work::Label>(op, sent), | |
| 157 | Op::ListMilestones => through::<Vec<work::Milestone>>(op, sent), | |
| 158 | Op::CreateMilestone | Op::UpdateMilestone => through::<work::Milestone>(op, sent), | |
| 159 | Op::GetMilestone => through::<work::MilestoneDetail>(op, sent), | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 160 | Op::GetPullRequest => through::<work::PullDetail>(op, sent), |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 161 | Op::MarkPullRequestReady |
| 162 | | Op::ClosePullRequest | |
| 163 | | Op::MergePullRequest | |
| 164 | | Op::AssignIssue | |
| 165 | | Op::RequestReviewers | |
| 166 | | Op::RemoveRequestedReviewers => { | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 167 | through::<work::Pull>(op, sent) |
| 168 | } | |
| 169 | Op::ListWorkflows => through::<Vec<actions::Workflow>>(op, sent), | |
| 170 | Op::ListWorkflowRuns => through::<Vec<actions::WorkflowRun>>(op, sent), | |
| 171 | Op::GetWorkflowRun => through::<actions::RunDetail>(op, sent), | |
| 172 | Op::GetJobLogs => through::<actions::JobLog>(op, sent), | |
| 173 | Op::DispatchWorkflow | Op::CancelWorkflowRun | Op::RerunWorkflowRun => { | |
| 174 | through::<actions::WorkflowRun>(op, sent) | |
| 175 | } | |
| 176 | Op::ListActionsSecrets | Op::ListActionsVariables => through::<Vec<actions::Setting>>(op, sent), | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 177 | Op::ListRunners => through::<Vec<g1t_contracts::runners::Runner>>(op, sent), |
| 178 | Op::ListRunnerGroups => through::<Vec<g1t_contracts::runners::RunnerGroup>>(op, sent), | |
| 179 | Op::CreateRunnerGroup | Op::UpdateRunnerGroup => through::<g1t_contracts::runners::RunnerGroup>(op, sent), | |
| 180 | Op::GetRunnerSettings | Op::UpdateRunnerSettings => through::<g1t_contracts::runners::RunnerSettings>(op, sent), | |
| 181 | Op::CreateRunnerRegistrationToken => through::<g1t_contracts::runners::RegistrationToken>(op, sent), | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 182 | Op::ListWebhooks => through::<Vec<webhooks::Hook>>(op, sent), |
| 183 | Op::ListIntegrations => through::<Vec<integrations::Connection>>(op, sent), | |
| 184 | Op::GetModelRoutes | Op::SetModelRoutes => through::<Vec<integrations::ModelRoute>>(op, sent), | |
| 185 | Op::ListEvents => through::<Vec<g1t_contracts::events::Event>>(op, sent), | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 186 | Op::ListEmails | Op::AddEmail | Op::RemoveEmail | Op::UpdateEmailSettings => { |
| 187 | through::<g1t_contracts::accounts::AccountEmails>(op, sent) | |
| 188 | } | |
| 189 | Op::ListInvites => through::<g1t_contracts::identity::InvitesOverview>(op, sent), | |
| 190 | Op::CreateInvite | Op::RevokeInvite | Op::InviteMember | Op::RevokeWorkspaceInvite => { | |
| 191 | through::<g1t_contracts::identity::Invite>(op, sent) | |
| 192 | } | |
| 193 | Op::ListWorkspaceInvites => through::<Vec<g1t_contracts::identity::Invite>>(op, sent), | |
| API: notifications over REST and MCP, with notifications scopes | 194 | Op::ListNotifications => through::<g1t_contracts::inbox::InboxPage>(op, sent), |
| 195 | Op::GetNotificationThread | Op::MarkThreadRead | Op::MarkThreadDone | Op::SaveThread | Op::SnoozeThread => { | |
| 196 | through::<g1t_contracts::inbox::InboxThread>(op, sent) | |
| 197 | } | |
| 198 | Op::GetThreadSubscription | Op::SetThreadSubscription | Op::DeleteThreadSubscription => { | |
| 199 | through::<g1t_contracts::inbox::ThreadSubscription>(op, sent) | |
| 200 | } | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 201 | _ => sent, |
| 202 | } | |
| 203 | } | |
| 204 | ||
| 205 | /// Every key of `example`, as paths, outside the maps passed through. | |
| 206 | fn paths(value: &Value, path: &str, out: &mut Vec<String>) { | |
| 207 | match value { | |
| 208 | Value::Object(fields) => { | |
| 209 | for (key, value) in fields { | |
| 210 | let here = format!("{path}.{key}"); | |
| 211 | out.push(here.clone()); | |
| 212 | let user_keyed = value.is_object() | |
| 213 | && (USER_KEYED.contains(&key.as_str()) || key.starts_with("by_")); | |
| 214 | if !user_keyed { | |
| 215 | paths(value, &here, out); | |
| 216 | } | |
| 217 | } | |
| 218 | } | |
| 219 | Value::Array(items) => { | |
| 220 | for item in items { | |
| 221 | paths(item, &format!("{path}[]"), out); | |
| 222 | } | |
| 223 | } | |
| 224 | _ => {} | |
| 225 | } | |
| 226 | } | |
| 227 | ||
| 228 | #[test] | |
| 229 | fn no_route_answers_with_camel_case() { | |
| 230 | let document = document(); | |
| 231 | let (mut checked, mut converted) = (0, 0); | |
| 232 | for (path, methods) in document["paths"].as_object().unwrap() { | |
| 233 | for (method, operation) in methods.as_object().unwrap() { | |
| 234 | let example = &operation["responses"]["200"]["content"]["application/json"]["example"]; | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 235 | let tool = operation["x-operation"].as_str().unwrap_or_default(); |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 236 | let Some(op) = Op::by_name(tool) else { |
| 237 | // Device sign-in, which is written in `snake_case` by hand. | |
| 238 | assert!(wire::camel_case_keys(example).is_empty(), "{method} {path}"); | |
| 239 | continue; | |
| 240 | }; | |
| 241 | let sample = sample(op, example); | |
| 242 | converted += wire::camel_case_keys(&sample).len(); | |
| 243 | let sent = wire::snake_case(sample); | |
| 244 | let leaked = wire::camel_case_keys(&sent); | |
| 245 | assert!(leaked.is_empty(), "{method} {path} sends {leaked:?}"); | |
| 246 | // The reference shows what is sent: each of its names is one. | |
| 247 | let (mut shown, mut real) = (Vec::new(), Vec::new()); | |
| 248 | paths(example, "", &mut shown); | |
| 249 | paths(&sent, "", &mut real); | |
| 250 | for name in shown { | |
| 251 | assert!(real.contains(&name), "{method} {path}: the reference shows {name}, which is not sent"); | |
| 252 | } | |
| 253 | checked += 1; | |
| 254 | } | |
| 255 | } | |
| 256 | assert!(checked >= Op::ALL.len()); | |
| 257 | // The samples are in the services' spelling, so there was something to | |
| 258 | // convert. | |
| 259 | assert!(converted > 100, "{converted}"); | |
| 260 | } | |
| 261 | ||
| 262 | #[test] | |
| 263 | fn every_route_has_a_sample() { | |
| 264 | let document = document(); | |
| 265 | for route in crate::rest::ROUTES { | |
| 266 | let path = route | |
| 267 | .path | |
| 268 | .split('/') | |
| 269 | .map(|segment| match segment.strip_prefix(':') { | |
| 270 | Some(name) => format!("{{{name}}}"), | |
| 271 | None => segment.to_owned(), | |
| 272 | }) | |
| 273 | .collect::<Vec<_>>() | |
| 274 | .join("/"); | |
| 275 | let example = &document["paths"][&path][route.method.to_lowercase()]["responses"]["200"] | |
| 276 | ["content"]["application/json"]["example"]; | |
| 277 | assert!(!example.is_null(), "{} {path}", route.method); | |
| 278 | } | |
| 279 | } | |
| 280 | ||
| 281 | #[test] | |
| 282 | fn errors_and_reports_are_snake_case() { | |
| 283 | let failure = g1t_contracts::Failure { | |
| 284 | code: g1t_contracts::FailureCode::NotFound, | |
| 285 | message: "No such endpoint.".to_owned(), | |
| 286 | }; | |
| 287 | assert!(wire::camel_case_keys(&wire::snake_case(json!({ "error": failure }))).is_empty()); | |
| 288 | } | |
| 289 | ||
| 290 | #[test] | |
| 291 | fn a_job_spec_keeps_github_s_spelling() { | |
| 292 | let spec = json!({ | |
| 293 | "job": "job_1", | |
| 294 | "spec": { "runs-on": "ubuntu-latest", "timeoutMinutes": 5 }, | |
| 295 | "workflow": { "env": { "nodeEnv": "x" } }, | |
| 296 | "github": { "eventName": "push", "headRef": "" }, | |
| 297 | "event": { "pull_request": { "headSha": "x" } }, | |
| 298 | "contexts": { "inputs": { "dryRun": true }, "matrix": { "nodeVersion": 20 } }, | |
| 299 | "checkout": { "ref": "main" }, | |
| 300 | "timeoutMinutes": 30, | |
| 301 | "masks": [], | |
| 302 | }); | |
| 303 | let sent = wire::snake_case_keeping(spec.clone(), crate::JOB_SPEC_AS_GIVEN); | |
| 304 | assert_eq!(sent["timeout_minutes"], 30); | |
| 305 | assert!(sent.get("timeoutMinutes").is_none()); | |
| 306 | for kept in ["spec", "workflow", "github", "event", "contexts", "checkout"] { | |
| 307 | assert_eq!(sent[kept], spec[kept], "{kept}"); | |
| 308 | } | |
| 309 | } |
This file's history is long; its oldest lines are credited to the oldest commit read.