Skip to content
1,045 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server in Rust; a public index at the API root1//! REST: each route maps an HTTP request onto one operation.
2
3use serde_json::{Map, Value};
4
5use crate::operations::Op;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar6use crate::security::SecurityOp;
API and MCP server in Rust; a public index at the API root7
8pub struct Route {
9 pub method: &'static str,
10 /// Segments starting with `:` are parameters.
11 pub path: &'static str,
12 pub op: Op,
13 /// Query parameters the route reads, as `(name in the URL, input name)`.
14 pub query: &'static [(&'static str, &'static str)],
15}
16
17const fn route(
18 method: &'static str,
19 path: &'static str,
20 op: Op,
21 query: &'static [(&'static str, &'static str)],
22) -> Route {
23 Route {
24 method,
25 path,
26 op,
27 query,
28 }
29}
30
31pub const ROUTES: &[Route] = &[
Agents as a team: lifecycle, merge queue, billing and a new shell32 route("GET", "/user", Op::Whoami, &[]),
33 route("POST", "/workspaces", Op::CreateWorkspace, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look34 route("DELETE", "/workspaces/:workspace", Op::DeleteWorkspace, &[]),
35 route("GET", "/user/emails", Op::ListEmails, &[]),
36 route("POST", "/user/emails", Op::AddEmail, &[]),
37 route("DELETE", "/user/emails/:email", Op::RemoveEmail, &[]),
38 route("PATCH", "/user/email-settings", Op::UpdateEmailSettings, &[]),
39 route("GET", "/user/invites", Op::ListInvites, &[]),
40 route("POST", "/user/invites", Op::CreateInvite, &[]),
41 route("DELETE", "/user/invites/:id", Op::RevokeInvite, &[]),
42 route("GET", "/workspaces/:workspace/invitations", Op::ListWorkspaceInvites, &[]),
43 route("POST", "/workspaces/:workspace/invitations", Op::InviteMember, &[]),
44 route("DELETE", "/workspaces/:workspace/invitations/:id", Op::RevokeWorkspaceInvite, &[]),
45 // Who has access. GitHub's addresses, but for adding someone, which
46 // takes an email address as well as a username.
47 route("GET", "/repos/:owner/:name/collaborators", Op::ListCollaborators, &[]),
48 route("POST", "/repos/:owner/:name/collaborators", Op::AddCollaborator, &[]),
49 route("PATCH", "/repos/:owner/:name/collaborators/:username", Op::UpdateCollaborator, &[]),
50 route("DELETE", "/repos/:owner/:name/collaborators/:username", Op::RemoveCollaborator, &[]),
51 route(
52 "GET",
53 "/repos/:owner/:name/collaborators/:username/permission",
54 Op::GetCollaboratorPermission,
55 &[],
56 ),
57 route("GET", "/repos/:owner/:name/invitations", Op::ListRepoInvitations, &[]),
58 route("DELETE", "/repos/:owner/:name/invitations/:id", Op::RevokeRepoInvitation, &[]),
59 route("GET", "/user/repository_invitations", Op::ListMyRepoInvitations, &[]),
API: notifications over REST and MCP, with notifications scopes60 // Your notifications: threads, marking them, and what you subscribe
61 // to and watch. GitHub's addresses, with g1t's saved and snoozed.
62 route("GET", "/notifications", Op::ListNotifications, &[("all", "all"), ("participating", "participating"), ("view", "view"), ("reason", "reason"), ("severity", "severity"), ("since", "since"), ("before", "before"), ("cursor", "cursor"), ("per_page", "per_page")]),
63 route("PUT", "/notifications", Op::MarkNotificationsRead, &[]),
64 route("GET", "/notifications/threads/:id", Op::GetNotificationThread, &[]),
65 route("PATCH", "/notifications/threads/:id", Op::MarkThreadRead, &[]),
66 route("DELETE", "/notifications/threads/:id", Op::MarkThreadDone, &[]),
67 route("PUT", "/notifications/threads/:id/saved", Op::SaveThread, &[]),
68 route("DELETE", "/notifications/threads/:id/saved", Op::SaveThread, &[]),
69 route("PUT", "/notifications/threads/:id/snooze", Op::SnoozeThread, &[]),
70 route("DELETE", "/notifications/threads/:id/snooze", Op::SnoozeThread, &[]),
71 route("GET", "/notifications/threads/:id/subscription", Op::GetThreadSubscription, &[]),
72 route("PUT", "/notifications/threads/:id/subscription", Op::SetThreadSubscription, &[]),
73 route("DELETE", "/notifications/threads/:id/subscription", Op::DeleteThreadSubscription, &[]),
74 route("GET", "/repos/:owner/:name/notifications", Op::ListNotifications, &[("all", "all"), ("participating", "participating"), ("view", "view"), ("reason", "reason"), ("severity", "severity"), ("since", "since"), ("before", "before"), ("cursor", "cursor"), ("per_page", "per_page")]),
75 route("PUT", "/repos/:owner/:name/notifications", Op::MarkNotificationsRead, &[]),
76 route("GET", "/repos/:owner/:name/subscription", Op::GetRepoSubscription, &[]),
77 route("PUT", "/repos/:owner/:name/subscription", Op::SetRepoSubscription, &[]),
78 route("DELETE", "/repos/:owner/:name/subscription", Op::DeleteRepoSubscription, &[]),
79 route("GET", "/repos/:owner/:name/issues/:number/subscription", Op::GetThreadSubscription, &[]),
80 route("PUT", "/repos/:owner/:name/issues/:number/subscription", Op::SetThreadSubscription, &[]),
81 route("DELETE", "/repos/:owner/:name/issues/:number/subscription", Op::DeleteThreadSubscription, &[]),
82 route("GET", "/user/subscriptions", Op::ListWatchedRepos, &[]),
API: pinned projects over REST and MCP83 // Your pinned projects in a workspace, in your order.
84 route("GET", "/user/pinned_projects/:workspace", Op::ListPinnedProjects, &[]),
85 route("PUT", "/user/pinned_projects/:workspace", Op::ReorderPinnedProjects, &[]),
86 route("PUT", "/user/pinned_projects/:workspace/:project", Op::PinProject, &[]),
87 route("DELETE", "/user/pinned_projects/:workspace/:project", Op::UnpinProject, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look88 route("PATCH", "/user/repository_invitations/:id", Op::AcceptRepoInvitation, &[]),
89 route("DELETE", "/user/repository_invitations/:id", Op::DeclineRepoInvitation, &[]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily90 route("PATCH", "/workspaces/:workspace", Op::UpdateWorkspace, &[]),
91 route("PUT", "/workspaces/:workspace/base_permission", Op::SetBasePermission, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look92 route(
93 "GET",
94 "/workspaces/:workspace/outside_collaborators",
95 Op::ListOutsideCollaborators,
96 &[],
97 ),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar98 // Teams: a workspace's groups of members, with roles on repositories.
99 route("GET", "/workspaces/:workspace/teams", Op::ListTeams, &[("q", "query")]),
100 route("POST", "/workspaces/:workspace/teams", Op::CreateTeam, &[]),
101 route("GET", "/workspaces/:workspace/teams/:team", Op::GetTeam, &[]),
102 route("PATCH", "/workspaces/:workspace/teams/:team", Op::UpdateTeam, &[]),
103 route("DELETE", "/workspaces/:workspace/teams/:team", Op::DeleteTeam, &[]),
104 route(
105 "GET",
106 "/workspaces/:workspace/teams/:team/members",
107 Op::ListTeamMembers,
108 &[("include_child_teams", "include_child_teams")],
109 ),
110 route("PUT", "/workspaces/:workspace/teams/:team/members/:username", Op::SetTeamMember, &[]),
111 route("DELETE", "/workspaces/:workspace/teams/:team/members/:username", Op::RemoveTeamMember, &[]),
112 route("GET", "/workspaces/:workspace/teams/:team/teams", Op::ListChildTeams, &[]),
113 route("GET", "/workspaces/:workspace/teams/:team/repos", Op::ListTeamRepos, &[]),
114 route("PUT", "/workspaces/:workspace/teams/:team/repos/:repo", Op::SetTeamRepo, &[]),
115 route("DELETE", "/workspaces/:workspace/teams/:team/repos/:repo", Op::RemoveTeamRepo, &[]),
116 route(
117 "PUT",
118 "/workspaces/:workspace/teams/:team/review_assignment",
119 Op::SetTeamReviewAssignment,
120 &[],
121 ),
122 route("GET", "/workspaces/:workspace/members/:username/teams", Op::ListUserTeams, &[]),
123 // Code owners: the CODEOWNERS file, checked.
124 route("GET", "/repos/:owner/:name/codeowners/errors", Op::GetCodeownersErrors, &[("ref", "ref")]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily125 // Security alerts: secrets and vulnerable dependencies.
126 route(
127 "GET",
128 "/repos/:owner/:name/security/alerts",
129 Op::ListSecurityAlerts,
130 &[("state", "state"), ("kind", "kind")],
131 ),
132 route("POST", "/repos/:owner/:name/security/alerts/:id/dismiss", Op::DismissSecurityAlert, &[]),
133 route("POST", "/repos/:owner/:name/security/alerts/:id/reopen", Op::ReopenSecurityAlert, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar134 // The security suite: secret scanning, code scanning, vulnerability
135 // alerts and the supply chain, at the common addresses.
136 route("GET", "/repos/:owner/:name/secret-scanning/alerts", Op::Security(SecurityOp::ListSecretAlerts), &[("state", "state"), ("secret_type", "secret_type"), ("validity", "validity"), ("bypassed", "bypassed")]),
137 route("GET", "/workspaces/:workspace/secret-scanning/alerts", Op::Security(SecurityOp::ListSecretAlerts), &[("state", "state"), ("secret_type", "secret_type"), ("validity", "validity"), ("bypassed", "bypassed")]),
138 route("GET", "/repos/:owner/:name/secret-scanning/alerts/:id", Op::Security(SecurityOp::GetSecretAlert), &[]),
139 route("PATCH", "/repos/:owner/:name/secret-scanning/alerts/:id", Op::Security(SecurityOp::UpdateSecretAlert), &[]),
140 route("GET", "/repos/:owner/:name/secret-scanning/alerts/:id/locations", Op::Security(SecurityOp::ListSecretLocations), &[]),
141 route("POST", "/repos/:owner/:name/secret-scanning/alerts/:id/bypass", Op::Security(SecurityOp::BypassPushProtection), &[]),
142 route("POST", "/repos/:owner/:name/secret-scanning/alerts/:id/validity", Op::Security(SecurityOp::CheckSecretValidity), &[]),
143 route("GET", "/workspaces/:workspace/secret-scanning/bypass-requests", Op::Security(SecurityOp::ListBypassRequests), &[("state", "state"), ("repo", "repo")]),
144 route("PATCH", "/workspaces/:workspace/secret-scanning/bypass-requests/:id", Op::Security(SecurityOp::ReviewBypassRequest), &[]),
145 route("POST", "/repos/:owner/:name/secret-scanning/custom-patterns/dry-run", Op::Security(SecurityOp::DryRunCustomPattern), &[]),
146 route("POST", "/workspaces/:workspace/secret-scanning/custom-patterns/dry-run", Op::Security(SecurityOp::DryRunCustomPattern), &[]),
147 route("GET", "/repos/:owner/:name/secret-scanning/custom-patterns", Op::Security(SecurityOp::ListCustomPatterns), &[]),
148 route("GET", "/workspaces/:workspace/secret-scanning/custom-patterns", Op::Security(SecurityOp::ListCustomPatterns), &[]),
149 route("POST", "/repos/:owner/:name/secret-scanning/custom-patterns", Op::Security(SecurityOp::CreateCustomPattern), &[]),
150 route("POST", "/workspaces/:workspace/secret-scanning/custom-patterns", Op::Security(SecurityOp::CreateCustomPattern), &[]),
151 route("PATCH", "/repos/:owner/:name/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::UpdateCustomPattern), &[]),
152 route("PATCH", "/workspaces/:workspace/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::UpdateCustomPattern), &[]),
153 route("DELETE", "/repos/:owner/:name/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::DeleteCustomPattern), &[]),
154 route("DELETE", "/workspaces/:workspace/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::DeleteCustomPattern), &[]),
155 route("GET", "/repos/:owner/:name/code-scanning/alerts", Op::Security(SecurityOp::ListCodeAlerts), &[("state", "state"), ("severity", "severity"), ("tool", "tool"), ("rule_id", "rule_id")]),
156 route("GET", "/workspaces/:workspace/code-scanning/alerts", Op::Security(SecurityOp::ListCodeAlerts), &[("state", "state"), ("severity", "severity"), ("tool", "tool"), ("rule_id", "rule_id")]),
157 route("GET", "/repos/:owner/:name/code-scanning/alerts/:number", Op::Security(SecurityOp::GetCodeAlert), &[]),
158 route("PATCH", "/repos/:owner/:name/code-scanning/alerts/:number", Op::Security(SecurityOp::UpdateCodeAlert), &[]),
159 route("GET", "/repos/:owner/:name/code-scanning/analyses", Op::Security(SecurityOp::ListAnalyses), &[]),
160 route("POST", "/repos/:owner/:name/code-scanning/sarifs", Op::Security(SecurityOp::UploadSarif), &[]),
161 route("GET", "/repos/:owner/:name/code-scanning/sarifs/:id", Op::Security(SecurityOp::GetSarifUpload), &[]),
162 route("GET", "/repos/:owner/:name/vulnerability-alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), &[("state", "state"), ("severity", "severity"), ("ecosystem", "ecosystem"), ("package", "package")]),
163 route("GET", "/workspaces/:workspace/vulnerability-alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), &[("state", "state"), ("severity", "severity"), ("ecosystem", "ecosystem"), ("package", "package")]),
164 route("GET", "/repos/:owner/:name/vulnerability-alerts/:id", Op::Security(SecurityOp::GetVulnerabilityAlert), &[]),
165 route("PATCH", "/repos/:owner/:name/vulnerability-alerts/:id", Op::Security(SecurityOp::UpdateVulnerabilityAlert), &[]),
166 route("POST", "/repos/:owner/:name/security/alerts/:id/fix", Op::Security(SecurityOp::FixAlert), &[]),
167 route("GET", "/repos/:owner/:name/dependency-graph", Op::Security(SecurityOp::GetDependencyGraph), &[]),
168 route("GET", "/repos/:owner/:name/dependency-graph/sbom", Op::Security(SecurityOp::GetSbom), &[]),
169 route("GET", "/repos/:owner/:name/dependency-graph/compare/:basehead", Op::Security(SecurityOp::CompareDependencies), &[]),
170 route("GET", "/repos/:owner/:name/security/settings", Op::Security(SecurityOp::GetSettings), &[]),
171 route("PATCH", "/repos/:owner/:name/security/settings", Op::Security(SecurityOp::UpdateSettings), &[]),
172 route("GET", "/workspaces/:workspace/security/settings", Op::Security(SecurityOp::GetWorkspaceSettings), &[]),
173 route("PATCH", "/workspaces/:workspace/security/settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), &[]),
174 route("GET", "/workspaces/:workspace/security/overview", Op::Security(SecurityOp::GetOverview), &[("days", "days")]),
Agents as a team: lifecycle, merge queue, billing and a new shell175 route("GET", "/repos", Op::ListRepos, &[("q", "query")]),
Search across all of g1t, Explore, and a command palette176 route(
177 "GET",
178 "/search",
179 Op::Search,
180 &[("q", "query"), ("type", "type"), ("page", "page"), ("per_page", "per_page")],
181 ),
Agents as a team: lifecycle, merge queue, billing and a new shell182 route("POST", "/repos", Op::CreateRepo, &[]),
183 route("GET", "/repos/:owner/:name", Op::GetRepo, &[]),
184 route("PATCH", "/repos/:owner/:name", Op::UpdateRepo, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look185 route("POST", "/repos/:owner/:name/transfer", Op::TransferRepo, &[]),
186 route("DELETE", "/repos/:owner/:name", Op::DeleteRepo, &[]),
187 route(
188 "GET",
189 "/workspaces/:workspace/repos/deleted",
190 Op::ListDeletedRepos,
191 &[],
192 ),
193 route("POST", "/repos/:owner/:name/restore", Op::RestoreRepo, &[]),
194 route("POST", "/repos/:owner/:name/purge", Op::PurgeRepo, &[]),
195 route("POST", "/repos/:owner/:name/rename", Op::RenameRepo, &[]),
196 route("POST", "/repos/:owner/:name/archive", Op::ArchiveRepo, &[]),
197 route("POST", "/repos/:owner/:name/unarchive", Op::UnarchiveRepo, &[]),
198 route(
199 "POST",
200 "/repos/:owner/:name/visibility",
201 Op::SetRepoVisibility,
202 &[],
203 ),
204 route(
205 "POST",
206 "/repos/:owner/:name/branches/:branch/rename",
207 Op::RenameBranch,
208 &[],
209 ),
Agents as a team: lifecycle, merge queue, billing and a new shell210 route(
211 "GET",
212 "/repos/:owner/:name/settings",
213 Op::GetRepoSettings,
214 &[],
215 ),
216 route(
217 "PATCH",
218 "/repos/:owner/:name/settings",
219 Op::UpdateRepoSettings,
220 &[],
221 ),
Fast pages, required checks on the branch, self-hosted runners, honest incidents222 route("GET", "/repos/:owner/:name/check-names", Op::ListCheckNames, &[]),
Agents as a team: lifecycle, merge queue, billing and a new shell223 route("GET", "/repos/:owner/:name/queue", Op::GetMergeQueue, &[]),
API and MCP server in Rust; a public index at the API root224 route(
Usage, like a hosting provider's: what agents cost, per day, task, repository and pull request225 "POST",
226 "/repos/:owner/:name/pulls/:number/messages",
227 Op::MessageAgent,
228 &[],
229 ),
230 route(
231 "POST",
232 "/repos/:owner/:name/pulls/:number/messages/take",
233 Op::TakeMessages,
234 &[],
235 ),
236 route(
Docs worth reading, and kept that way237 "POST",
238 "/repos/:owner/:name/messages/:id/answer",
239 Op::AnswerMessage,
240 &[],
241 ),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains242 route("POST", "/repos/:owner/:name/memory", Op::Remember, &[]),
243 route(
244 "GET",
245 "/repos/:owner/:name/memory",
246 Op::Recall,
247 &[("q", "query"), ("limit", "limit")],
248 ),
Docs worth reading, and kept that way249 route(
API and MCP server in Rust; a public index at the API root250 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell251 "/repos/:owner/:name/events",
API and MCP server in Rust; a public index at the API root252 Op::ListEvents,
253 &[("before", "before")],
254 ),
Agents as a team: lifecycle, merge queue, billing and a new shell255 route("GET", "/repos/:owner/:name/labels", Op::ListLabels, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar256 route("POST", "/repos/:owner/:name/labels", Op::CreateLabel, &[]),
257 route("POST", "/repos/:owner/:name/labels/defaults", Op::AddDefaultLabels, &[]),
258 route("PATCH", "/repos/:owner/:name/labels/:label", Op::UpdateLabel, &[]),
259 route("DELETE", "/repos/:owner/:name/labels/:label", Op::DeleteLabel, &[]),
260 route("GET", "/repos/:owner/:name/issues/:number/labels", Op::ListIssueLabels, &[]),
261 route("POST", "/repos/:owner/:name/issues/:number/labels", Op::AddIssueLabels, &[]),
262 route("PUT", "/repos/:owner/:name/issues/:number/labels", Op::SetIssueLabels, &[]),
263 route("DELETE", "/repos/:owner/:name/issues/:number/labels", Op::RemoveIssueLabels, &[]),
264 route("DELETE", "/repos/:owner/:name/issues/:number/labels/:label", Op::RemoveIssueLabels, &[]),
265 route("GET", "/repos/:owner/:name/milestones", Op::ListMilestones, &[("state", "state")]),
266 route("POST", "/repos/:owner/:name/milestones", Op::CreateMilestone, &[]),
267 route("GET", "/repos/:owner/:name/milestones/:milestone", Op::GetMilestone, &[]),
268 route("PATCH", "/repos/:owner/:name/milestones/:milestone", Op::UpdateMilestone, &[]),
269 route("DELETE", "/repos/:owner/:name/milestones/:milestone", Op::DeleteMilestone, &[]),
API and MCP server in Rust; a public index at the API root270 route(
271 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell272 "/repos/:owner/:name/issues",
API and MCP server in Rust; a public index at the API root273 Op::ListIssues,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar274 &[("state", "state"), ("label", "label"), ("milestone", "milestone")],
API and MCP server in Rust; a public index at the API root275 ),
Agents as a team: lifecycle, merge queue, billing and a new shell276 route("POST", "/repos/:owner/:name/issues", Op::CreateIssue, &[]),
API and MCP server in Rust; a public index at the API root277 route(
278 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell279 "/repos/:owner/:name/issues/:number",
API and MCP server in Rust; a public index at the API root280 Op::GetIssue,
281 &[],
282 ),
283 route(
284 "PATCH",
Agents as a team: lifecycle, merge queue, billing and a new shell285 "/repos/:owner/:name/issues/:number",
API and MCP server in Rust; a public index at the API root286 Op::UpdateIssue,
287 &[],
288 ),
289 route(
290 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell291 "/repos/:owner/:name/issues/:number/close",
API and MCP server in Rust; a public index at the API root292 Op::CloseIssue,
293 &[],
294 ),
295 route(
296 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell297 "/repos/:owner/:name/issues/:number/reopen",
API and MCP server in Rust; a public index at the API root298 Op::ReopenIssue,
299 &[],
300 ),
301 route(
302 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell303 "/repos/:owner/:name/issues/:number/assign",
304 Op::AssignIssue,
305 &[],
306 ),
Integrations: your own model provider, alerts that open issues, tickets agents read307 route(
308 "POST",
309 "/repos/:owner/:name/issues/import",
310 Op::ImportIssue,
311 &[],
312 ),
313 route(
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step314 "POST",
315 "/repos/:owner/:name/issues/delegate",
316 Op::Delegate,
317 &[],
318 ),
319 route(
Integrations: your own model provider, alerts that open issues, tickets agents read320 "GET",
321 "/repos/:owner/:name/context",
322 Op::GetContext,
323 &[("reference", "reference")],
324 ),
325 route(
326 "GET",
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API327 "/workspaces/:workspace/context/search",
328 Op::SearchContext,
329 &[("q", "query"), ("project", "project"), ("kinds", "kinds"), ("limit", "limit")],
330 ),
331 route(
332 "GET",
333 "/workspaces/:workspace/context/:kind/:id",
334 Op::GetEntity,
335 &[],
336 ),
337 route(
338 "GET",
Integrations: your own model provider, alerts that open issues, tickets agents read339 "/workspaces/:workspace/integrations",
340 Op::ListIntegrations,
341 &[],
342 ),
343 route(
344 "POST",
345 "/workspaces/:workspace/integrations",
346 Op::ConnectIntegration,
347 &[],
348 ),
349 route(
Models per workspace: several providers, routed by kind of work350 "GET",
Webhooks: every event, to your own addresses, signed and retried351 "/repos/:owner/:name/hooks",
352 Op::ListWebhooks,
353 &[],
354 ),
355 route(
356 "POST",
357 "/repos/:owner/:name/hooks",
358 Op::CreateWebhook,
359 &[],
360 ),
361 route(
362 "PATCH",
363 "/repos/:owner/:name/hooks/:id",
364 Op::UpdateWebhook,
365 &[],
366 ),
367 route(
368 "DELETE",
369 "/repos/:owner/:name/hooks/:id",
370 Op::DeleteWebhook,
371 &[],
372 ),
373 route(
374 "POST",
375 "/repos/:owner/:name/hooks/:id/pings",
376 Op::PingWebhook,
377 &[],
378 ),
379 route(
380 "GET",
381 "/repos/:owner/:name/hooks/:id/deliveries",
382 Op::ListWebhookDeliveries,
383 &[],
384 ),
385 route(
386 "POST",
387 "/repos/:owner/:name/hooks/:id/deliveries/:delivery/redeliver",
388 Op::RedeliverWebhook,
389 &[],
390 ),
391 route(
392 "GET",
393 "/workspaces/:workspace/hooks",
394 Op::ListWebhooks,
395 &[],
396 ),
397 route(
398 "POST",
399 "/workspaces/:workspace/hooks",
400 Op::CreateWebhook,
401 &[],
402 ),
403 route(
404 "PATCH",
405 "/workspaces/:workspace/hooks/:id",
406 Op::UpdateWebhook,
407 &[],
408 ),
409 route(
410 "DELETE",
411 "/workspaces/:workspace/hooks/:id",
412 Op::DeleteWebhook,
413 &[],
414 ),
415 route(
416 "POST",
417 "/workspaces/:workspace/hooks/:id/pings",
418 Op::PingWebhook,
419 &[],
420 ),
421 route(
422 "GET",
423 "/workspaces/:workspace/hooks/:id/deliveries",
424 Op::ListWebhookDeliveries,
425 &[],
426 ),
427 route(
428 "POST",
429 "/workspaces/:workspace/hooks/:id/deliveries/:delivery/redeliver",
430 Op::RedeliverWebhook,
431 &[],
432 ),
433 route(
434 "GET",
Models per workspace: several providers, routed by kind of work435 "/workspaces/:workspace/model-routes",
436 Op::GetModelRoutes,
437 &[],
438 ),
439 route(
440 "PUT",
441 "/workspaces/:workspace/model-routes",
442 Op::SetModelRoutes,
443 &[],
444 ),
445 route(
Integrations: your own model provider, alerts that open issues, tickets agents read446 "DELETE",
447 "/workspaces/:workspace/integrations/:id",
448 Op::DisconnectIntegration,
449 &[],
450 ),
451 route(
452 "POST",
453 "/workspaces/:workspace/integrations/:id/test",
454 Op::TestIntegration,
455 &[],
456 ),
Automations: rules in .g1t/automations that act when something happens457 route(
458 "GET",
GitHub Actions on g1t, part two: running workflows459 "/repos/:owner/:name/actions/workflows",
460 Op::ListWorkflows,
461 &[],
462 ),
463 route(
464 "GET",
465 "/repos/:owner/:name/actions/workflows/:workflow/runs",
466 Op::ListWorkflowRuns,
467 &[("branch", "branch"), ("event", "event"), ("per_page", "limit")],
468 ),
469 route(
470 "POST",
471 "/repos/:owner/:name/actions/workflows/:workflow/dispatches",
472 Op::DispatchWorkflow,
473 &[],
474 ),
475 route(
476 "PATCH",
477 "/repos/:owner/:name/actions/workflows/:workflow",
478 Op::UpdateWorkflow,
479 &[],
480 ),
481 route(
482 "PUT",
483 "/repos/:owner/:name/actions/workflows/:workflow/enable",
484 Op::UpdateWorkflow,
485 &[],
486 ),
487 route(
488 "PUT",
489 "/repos/:owner/:name/actions/workflows/:workflow/disable",
490 Op::UpdateWorkflow,
491 &[],
492 ),
493 route(
494 "GET",
495 "/repos/:owner/:name/actions/runs",
496 Op::ListWorkflowRuns,
497 &[("workflow", "workflow"), ("branch", "branch"), ("event", "event"), ("pull", "pull"), ("head_sha", "sha"), ("per_page", "limit")],
498 ),
499 route(
500 "GET",
501 "/repos/:owner/:name/actions/runs/:id",
502 Op::GetWorkflowRun,
503 &[],
504 ),
505 route(
506 "POST",
507 "/repos/:owner/:name/actions/runs/:id/cancel",
508 Op::CancelWorkflowRun,
509 &[],
510 ),
511 route(
512 "POST",
513 "/repos/:owner/:name/actions/runs/:id/rerun",
514 Op::RerunWorkflowRun,
515 &[],
516 ),
517 route(
518 "POST",
519 "/repos/:owner/:name/actions/runs/:id/rerun-failed-jobs",
520 Op::RerunWorkflowRun,
521 &[],
522 ),
523 route(
524 "GET",
525 "/repos/:owner/:name/actions/jobs/:job/logs",
526 Op::GetJobLogs,
527 &[("after", "after")],
528 ),
529 route(
530 "GET",
531 "/repos/:owner/:name/actions/secrets",
532 Op::ListActionsSecrets,
533 &[],
534 ),
535 route(
536 "PUT",
537 "/repos/:owner/:name/actions/secrets/:setting",
538 Op::SetActionsSecret,
539 &[],
540 ),
541 route(
542 "DELETE",
543 "/repos/:owner/:name/actions/secrets/:setting",
544 Op::DeleteActionsSecret,
545 &[],
546 ),
547 route(
548 "GET",
549 "/repos/:owner/:name/actions/variables",
550 Op::ListActionsVariables,
551 &[],
552 ),
553 route(
554 "POST",
555 "/repos/:owner/:name/actions/variables",
556 Op::SetActionsVariable,
557 &[],
558 ),
559 route(
560 "PATCH",
561 "/repos/:owner/:name/actions/variables/:setting",
562 Op::SetActionsVariable,
563 &[],
564 ),
565 route(
566 "DELETE",
567 "/repos/:owner/:name/actions/variables/:setting",
568 Op::DeleteActionsVariable,
569 &[],
570 ),
571 route(
572 "GET",
573 "/workspaces/:workspace/actions/secrets",
574 Op::ListActionsSecrets,
575 &[],
576 ),
577 route(
578 "PUT",
579 "/workspaces/:workspace/actions/secrets/:setting",
580 Op::SetActionsSecret,
581 &[],
582 ),
583 route(
584 "DELETE",
585 "/workspaces/:workspace/actions/secrets/:setting",
586 Op::DeleteActionsSecret,
587 &[],
588 ),
589 route(
590 "GET",
591 "/workspaces/:workspace/actions/variables",
592 Op::ListActionsVariables,
593 &[],
594 ),
595 route(
596 "POST",
597 "/workspaces/:workspace/actions/variables",
598 Op::SetActionsVariable,
599 &[],
600 ),
601 route(
602 "PATCH",
603 "/workspaces/:workspace/actions/variables/:setting",
604 Op::SetActionsVariable,
605 &[],
606 ),
607 route(
608 "DELETE",
609 "/workspaces/:workspace/actions/variables/:setting",
610 Op::DeleteActionsVariable,
611 &[],
612 ),
Fast pages, required checks on the branch, self-hosted runners, honest incidents613 // Self-hosted runners: a repository's own, or a workspace's.
614 route("GET", "/repos/:owner/:name/actions/runners", Op::ListRunners, &[]),
615 route("POST", "/repos/:owner/:name/actions/runners/registration-token", Op::CreateRunnerRegistrationToken, &[]),
616 route("DELETE", "/repos/:owner/:name/actions/runners/:id", Op::RemoveRunner, &[]),
617 route("GET", "/repos/:owner/:name/actions/runner-settings", Op::GetRunnerSettings, &[]),
618 route("PATCH", "/repos/:owner/:name/actions/runner-settings", Op::UpdateRunnerSettings, &[]),
619 route("GET", "/workspaces/:workspace/actions/runners", Op::ListRunners, &[]),
620 route("POST", "/workspaces/:workspace/actions/runners/registration-token", Op::CreateRunnerRegistrationToken, &[]),
621 route("DELETE", "/workspaces/:workspace/actions/runners/:id", Op::RemoveRunner, &[]),
622 route("GET", "/workspaces/:workspace/actions/runner-settings", Op::GetRunnerSettings, &[]),
623 route("PATCH", "/workspaces/:workspace/actions/runner-settings", Op::UpdateRunnerSettings, &[]),
624 route("GET", "/workspaces/:workspace/actions/runner-groups", Op::ListRunnerGroups, &[]),
625 route("POST", "/workspaces/:workspace/actions/runner-groups", Op::CreateRunnerGroup, &[]),
626 route("PATCH", "/workspaces/:workspace/actions/runner-groups/:id", Op::UpdateRunnerGroup, &[]),
627 route("DELETE", "/workspaces/:workspace/actions/runner-groups/:id", Op::DeleteRunnerGroup, &[]),
Agents as a team: lifecycle, merge queue, billing and a new shell628 route("POST", "/repos/:owner/:name/plans", Op::PlanWork, &[]),
629 route("GET", "/repos/:owner/:name/plans/:plan", Op::GetPlan, &[]),
630 route(
631 "POST",
632 "/repos/:owner/:name/plans/:plan/apply",
633 Op::ApplyPlan,
634 &[],
635 ),
636 route(
637 "POST",
638 "/repos/:owner/:name/issues/:number/comments",
API and MCP server in Rust; a public index at the API root639 Op::AddComment,
640 &[],
641 ),
642 route(
643 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell644 "/repos/:owner/:name/pulls",
API and MCP server in Rust; a public index at the API root645 Op::ListPullRequests,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar646 &[("state", "state"), ("label", "label"), ("milestone", "milestone"), ("base", "base")],
API and MCP server in Rust; a public index at the API root647 ),
648 route(
649 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell650 "/repos/:owner/:name/pulls",
API and MCP server in Rust; a public index at the API root651 Op::CreatePullRequest,
652 &[],
653 ),
654 route(
655 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell656 "/repos/:owner/:name/pulls/:number",
API and MCP server in Rust; a public index at the API root657 Op::GetPullRequest,
658 &[],
659 ),
660 route(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar661 "PATCH",
662 "/repos/:owner/:name/pulls/:number",
663 Op::UpdatePullRequest,
664 &[],
665 ),
666 route(
API and MCP server in Rust; a public index at the API root667 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell668 "/repos/:owner/:name/pulls/:number/changes",
API and MCP server in Rust; a public index at the API root669 Op::GetPullRequestChanges,
670 &[],
671 ),
672 route(
Acceptance checks in sandboxes, line comments and review verdicts673 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell674 "/repos/:owner/:name/pulls/:number/reviews",
Acceptance checks in sandboxes, line comments and review verdicts675 Op::ReviewPullRequest,
676 &[],
677 ),
678 route(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar679 "POST",
680 "/repos/:owner/:name/pulls/:number/requested_reviewers",
681 Op::RequestReviewers,
682 &[],
683 ),
684 route(
685 "DELETE",
686 "/repos/:owner/:name/pulls/:number/requested_reviewers",
687 Op::RemoveRequestedReviewers,
688 &[],
689 ),
690 route(
API and MCP server in Rust; a public index at the API root691 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell692 "/repos/:owner/:name/pulls/:number/session",
API and MCP server in Rust; a public index at the API root693 Op::ReadSession,
694 &[("after", "after")],
695 ),
696 route(
697 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell698 "/repos/:owner/:name/pulls/:number/session",
API and MCP server in Rust; a public index at the API root699 Op::RecordSession,
700 &[],
701 ),
702 route(
703 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell704 "/repos/:owner/:name/pulls/:number/ready",
API and MCP server in Rust; a public index at the API root705 Op::MarkPullRequestReady,
706 &[],
707 ),
708 route(
709 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell710 "/repos/:owner/:name/pulls/:number/close",
API and MCP server in Rust; a public index at the API root711 Op::ClosePullRequest,
712 &[],
713 ),
714 route(
715 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell716 "/repos/:owner/:name/pulls/:number/merge",
API and MCP server in Rust; a public index at the API root717 Op::MergePullRequest,
718 &[],
719 ),
720];
721
722impl Route {
723 /// The names of the route's path parameters, in order.
724 pub fn params(&self) -> impl Iterator<Item = &'static str> {
725 self.path
726 .split('/')
727 .filter_map(|segment| segment.strip_prefix(':'))
728 }
729
730 /// The values of the path parameters, if `path` is this route's.
731 fn matches<'a>(&self, path: &'a str) -> Option<Vec<(&'static str, &'a str)>> {
732 let mut values = Vec::new();
733 let mut actual = path.trim_end_matches('/').split('/');
734 for expected in self.path.split('/') {
735 let segment = actual.next()?;
736 match expected.strip_prefix(':') {
737 Some(name) if !segment.is_empty() => values.push((name, segment)),
738 Some(_) => return None,
739 None if expected == segment => {}
740 None => return None,
741 }
742 }
743 actual.next().is_none().then_some(values)
744 }
745}
746
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look747/// A path segment with its `%XX` escapes decoded; as given when that is not
748/// UTF-8.
749fn percent_decoded(segment: &str) -> String {
750 let bytes = segment.as_bytes();
751 let mut out = Vec::with_capacity(bytes.len());
752 let mut i = 0;
753 while i < bytes.len() {
754 let escaped = (bytes[i] == b'%')
755 .then(|| segment.get(i + 1..i + 3))
756 .flatten()
757 .filter(|hex| hex.bytes().all(|byte| byte.is_ascii_hexdigit()))
758 .and_then(|hex| u8::from_str_radix(hex, 16).ok());
759 match escaped {
760 Some(byte) => {
761 out.push(byte);
762 i += 3;
763 }
764 None => {
765 out.push(bytes[i]);
766 i += 1;
767 }
768 }
769 }
770 String::from_utf8(out).unwrap_or_else(|_| segment.to_owned())
771}
772
API and MCP server in Rust; a public index at the API root773/// The route for a request, and the operation input it describes.
774///
775/// The input is the JSON body, overlaid with the query parameters the route
776/// reads and then with what the path names: `owner` and `name` become
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar777/// `repo`, as does a team's `repo` with its `workspace`, and `number`
778/// becomes an integer.
API and MCP server in Rust; a public index at the API root779pub fn resolve(
780 method: &str,
781 path: &str,
782 query: &[(String, String)],
783 body: Value,
784) -> Option<(&'static Route, Value)> {
785 let (route, params) = ROUTES
786 .iter()
787 .filter(|route| route.method == method)
788 .find_map(|route| Some((route, route.matches(path)?)))?;
789
790 let mut input = match body {
791 Value::Object(fields) => fields,
792 _ => Map::new(),
793 };
794 for (name, key) in route.query {
795 if let Some((_, value)) = query.iter().find(|(query_name, _)| query_name == name) {
796 input.insert((*key).to_owned(), Value::String(value.clone()));
797 }
798 }
799 let param = |wanted: &str| {
800 params
801 .iter()
802 .find(|(name, _)| *name == wanted)
803 .map(|(_, value)| *value)
804 };
805 if let (Some(owner), Some(name)) = (param("owner"), param("name")) {
806 input.insert("repo".to_owned(), Value::String(format!("{owner}/{name}")));
807 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar808 for key in ["plan", "id", "workspace", "delivery", "workflow", "job", "setting", "username", "team", "basehead"] {
Docs worth reading, and kept that way809 if let Some(value) = param(key) {
810 input.insert(key.to_owned(), Value::String(value.to_owned()));
811 }
Agents as a team: lifecycle, merge queue, billing and a new shell812 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar813 // A repository of a team's workspace, named by itself.
814 if let (Some(workspace), Some(name)) = (param("workspace"), param("repo")) {
815 input.insert("repo".to_owned(), Value::String(format!("{workspace}/{name}")));
816 }
817 // A branch name may hold slashes, sent URL-encoded as one segment, and
818 // a label's name spaces.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look819 if let Some(branch) = param("branch") {
820 input.insert("branch".to_owned(), Value::String(percent_decoded(branch)));
821 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar822 if let Some(label) = param("label") {
823 input.insert("label".to_owned(), Value::String(percent_decoded(label)));
824 }
825 if let Some(milestone) = param("milestone") {
826 // Not a number: zero, which no milestone has.
827 input.insert("milestone".to_owned(), milestone.parse::<u32>().unwrap_or(0).into());
828 }
GitHub Actions on g1t, part two: running workflows829 // GitHub says some things with the path alone.
830 if route.path.ends_with("/enable") || route.path.ends_with("/disable") {
831 input.insert("enabled".to_owned(), Value::Bool(route.path.ends_with("/enable")));
832 }
833 if route.path.ends_with("/rerun-failed-jobs") {
834 input.insert("failed_only".to_owned(), Value::Bool(true));
835 }
API: notifications over REST and MCP, with notifications scopes836 // Unsaving and waking a thread are a DELETE of what PUT made.
837 if route.method == "DELETE" && route.path.ends_with("/saved") {
838 input.insert("saved".to_owned(), Value::Bool(false));
839 }
840 if route.method == "DELETE" && route.path.ends_with("/snooze") {
841 input.remove("until");
842 }
API and MCP server in Rust; a public index at the API root843 if let Some(number) = param("number") {
844 // Not a number: zero, which no issue or pull request has.
845 input.insert(
846 "number".to_owned(),
847 number.parse::<u32>().unwrap_or(0).into(),
848 );
849 }
850 Some((route, Value::Object(input)))
851}
852
853#[cfg(test)]
854mod tests {
855 use serde_json::json;
856
857 use super::*;
858
859 #[test]
860 fn a_path_resolves_to_its_operation_and_input() {
861 let (route, input) = resolve(
862 "POST",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look863 "/repos/flagon-io/hello/pulls/14/merge",
API and MCP server in Rust; a public index at the API root864 &[],
865 json!({ "keep_issue_open": true, "number": 99, "repo": "someone/else" }),
866 )
867 .unwrap();
868 assert_eq!(route.op, Op::MergePullRequest);
869 // What the path names wins over the body.
870 assert_eq!(
871 input,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look872 json!({ "keep_issue_open": true, "number": 14, "repo": "flagon-io/hello" })
API and MCP server in Rust; a public index at the API root873 );
874 }
875
876 #[test]
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look877 fn a_branch_with_slashes_is_one_encoded_segment() {
878 let (route, input) = resolve(
879 "POST",
880 "/repos/flagon-io/hello/branches/feature%2Flogin/rename",
881 &[],
882 json!({ "new_name": "feature/sign-in" }),
883 )
884 .unwrap();
885 assert_eq!(route.op, Op::RenameBranch);
886 assert_eq!(
887 input,
888 json!({ "new_name": "feature/sign-in", "branch": "feature/login", "repo": "flagon-io/hello" })
889 );
890 assert_eq!(percent_decoded("100%"), "100%");
891 assert_eq!(percent_decoded("a%2bb%zz"), "a+b%zz");
892 }
893
894 #[test]
895 fn a_collaborator_is_named_by_username() {
896 let (route, input) = resolve(
897 "PATCH",
898 "/repos/flagon-io/hello/collaborators/ada",
899 &[],
900 json!({ "role": "maintain" }),
901 )
902 .unwrap();
903 assert_eq!(route.op, Op::UpdateCollaborator);
904 assert_eq!(input, json!({ "role": "maintain", "username": "ada", "repo": "flagon-io/hello" }));
905 let (route, input) = resolve("DELETE", "/user/repository_invitations/rin_1", &[], Value::Null).unwrap();
906 assert_eq!(route.op, Op::DeclineRepoInvitation);
907 assert_eq!(input, json!({ "id": "rin_1" }));
908 }
909
910 #[test]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar911 fn teams_are_addressed_by_workspace_and_slug() {
912 let query = [("q".to_owned(), "back".to_owned())];
913 let (route, input) = resolve("GET", "/workspaces/acme/teams", &query, Value::Null).unwrap();
914 assert_eq!(route.op, Op::ListTeams);
915 assert_eq!(input, json!({ "query": "back", "workspace": "acme" }));
916 let (route, input) = resolve("PATCH", "/workspaces/acme/teams/backend", &[], json!({ "name": "Back end" })).unwrap();
917 assert_eq!(route.op, Op::UpdateTeam);
918 assert_eq!(input, json!({ "name": "Back end", "workspace": "acme", "team": "backend" }));
919 let (route, input) =
920 resolve("PUT", "/workspaces/acme/teams/backend/members/ana", &[], json!({ "role": "maintainer" })).unwrap();
921 assert_eq!(route.op, Op::SetTeamMember);
922 assert_eq!(input, json!({ "role": "maintainer", "workspace": "acme", "team": "backend", "username": "ana" }));
923 let query = [("include_child_teams".to_owned(), "true".to_owned())];
924 let (route, input) = resolve("GET", "/workspaces/acme/teams/backend/members", &query, Value::Null).unwrap();
925 assert_eq!(route.op, Op::ListTeamMembers);
926 assert_eq!(input, json!({ "include_child_teams": "true", "workspace": "acme", "team": "backend" }));
927 // A repository is named by itself, in the team's workspace.
928 let (route, input) =
929 resolve("PUT", "/workspaces/acme/teams/backend/repos/rocket", &[], json!({ "role": "write" })).unwrap();
930 assert_eq!(route.op, Op::SetTeamRepo);
931 assert_eq!(input, json!({ "role": "write", "workspace": "acme", "team": "backend", "repo": "acme/rocket" }));
932 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
933 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend/repos/rocket"), Op::RemoveTeamRepo);
934 assert_eq!(op("GET", "/workspaces/acme/teams/backend/teams"), Op::ListChildTeams);
935 assert_eq!(op("GET", "/workspaces/acme/teams/backend/repos"), Op::ListTeamRepos);
936 assert_eq!(op("PUT", "/workspaces/acme/teams/backend/review_assignment"), Op::SetTeamReviewAssignment);
937 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend"), Op::DeleteTeam);
938 assert_eq!(op("POST", "/workspaces/acme/teams"), Op::CreateTeam);
939 assert_eq!(op("GET", "/workspaces/acme/teams/backend"), Op::GetTeam);
940 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend/members/ana"), Op::RemoveTeamMember);
941 let (route, input) = resolve("GET", "/workspaces/acme/members/ana/teams", &[], Value::Null).unwrap();
942 assert_eq!(route.op, Op::ListUserTeams);
943 assert_eq!(input, json!({ "workspace": "acme", "username": "ana" }));
944 }
945
946 #[test]
947 fn reviewers_are_requested_and_code_owners_checked_on_a_repository() {
948 let body = json!({ "reviewers": ["ana"], "team_reviewers": ["backend"] });
949 let (route, input) = resolve("POST", "/repos/acme/rocket/pulls/7/requested_reviewers", &[], body.clone()).unwrap();
950 assert_eq!(route.op, Op::RequestReviewers);
951 assert_eq!(
952 input,
953 json!({ "reviewers": ["ana"], "team_reviewers": ["backend"], "repo": "acme/rocket", "number": 7 })
954 );
955 let (route, _) = resolve("DELETE", "/repos/acme/rocket/pulls/7/requested_reviewers", &[], body).unwrap();
956 assert_eq!(route.op, Op::RemoveRequestedReviewers);
957 let query = [("ref".to_owned(), "main".to_owned())];
958 let (route, input) = resolve("GET", "/repos/acme/rocket/codeowners/errors", &query, Value::Null).unwrap();
959 assert_eq!(route.op, Op::GetCodeownersErrors);
960 assert_eq!(input, json!({ "ref": "main", "repo": "acme/rocket" }));
961 }
962
963 #[test]
API: notifications over REST and MCP, with notifications scopes964 fn notifications_are_addressed_as_threads_and_by_issue() {
965 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1", &[], Value::Null).unwrap();
966 assert_eq!(route.op, Op::MarkThreadDone);
967 assert_eq!(input, json!({ "id": "ntf_1" }));
968 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1/saved", &[], Value::Null).unwrap();
969 assert_eq!(route.op, Op::SaveThread);
970 assert_eq!(input, json!({ "id": "ntf_1", "saved": false }));
971 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1/snooze", &[], json!({ "until": "x" })).unwrap();
972 assert_eq!(route.op, Op::SnoozeThread);
973 assert_eq!(input, json!({ "id": "ntf_1" }));
974 let query = [("all".to_owned(), "true".to_owned()), ("per_page".to_owned(), "50".to_owned())];
975 let (route, input) = resolve("GET", "/repos/acme/rocket/notifications", &query, Value::Null).unwrap();
976 assert_eq!(route.op, Op::ListNotifications);
977 assert_eq!(input, json!({ "all": "true", "per_page": "50", "repo": "acme/rocket" }));
978 let (route, input) = resolve("PUT", "/repos/acme/rocket/issues/7/subscription", &[], json!({ "ignored": true })).unwrap();
979 assert_eq!(route.op, Op::SetThreadSubscription);
980 assert_eq!(input, json!({ "ignored": true, "number": 7, "repo": "acme/rocket" }));
981 assert_eq!(resolve("GET", "/user/subscriptions", &[], Value::Null).unwrap().0.op, Op::ListWatchedRepos);
982 }
983
984 #[test]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar985 fn labels_and_milestones_are_named_in_the_path() {
986 let (route, input) = resolve("PATCH", "/repos/acme/web/labels/good%20first%20issue", &[], json!({ "color": "7057ff" })).unwrap();
987 assert_eq!(route.op, Op::UpdateLabel);
988 assert_eq!(input, json!({ "color": "7057ff", "label": "good first issue", "repo": "acme/web" }));
989 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/7/labels/bug", &[], Value::Null).unwrap();
990 assert_eq!(route.op, Op::RemoveIssueLabels);
991 assert_eq!(input, json!({ "label": "bug", "number": 7, "repo": "acme/web" }));
992 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/7/labels", &[], Value::Null).unwrap();
993 assert_eq!(route.op, Op::RemoveIssueLabels);
994 assert_eq!(input, json!({ "number": 7, "repo": "acme/web" }));
995 let (route, _) = resolve("POST", "/repos/acme/web/labels/defaults", &[], Value::Null).unwrap();
996 assert_eq!(route.op, Op::AddDefaultLabels);
997 let (route, input) = resolve("PATCH", "/repos/acme/web/milestones/3", &[], json!({ "state": "closed" })).unwrap();
998 assert_eq!(route.op, Op::UpdateMilestone);
999 assert_eq!(input, json!({ "state": "closed", "milestone": 3, "repo": "acme/web" }));
1000 let (route, input) = resolve("PATCH", "/repos/acme/web/pulls/9", &[], json!({ "base": "release" })).unwrap();
1001 assert_eq!(route.op, Op::UpdatePullRequest);
1002 assert_eq!(input, json!({ "base": "release", "number": 9, "repo": "acme/web" }));
1003 }
1004
1005 #[test]
API and MCP server in Rust; a public index at the API root1006 fn query_parameters_are_renamed() {
1007 let query = [
1008 ("q".to_owned(), "parser".to_owned()),
1009 ("x".to_owned(), "y".to_owned()),
1010 ];
Agents as a team: lifecycle, merge queue, billing and a new shell1011 let (route, input) = resolve("GET", "/repos", &query, Value::Null).unwrap();
API and MCP server in Rust; a public index at the API root1012 assert_eq!(route.op, Op::ListRepos);
1013 assert_eq!(input, json!({ "query": "parser" }));
1014 }
1015
1016 #[test]
1017 fn method_and_shape_must_match() {
Agents as a team: lifecycle, merge queue, billing and a new shell1018 assert!(resolve("GET", "/repos/a/b/issues/1/close", &[], Value::Null).is_none());
1019 assert!(resolve("GET", "/repos/a", &[], Value::Null).is_none());
1020 assert!(resolve("GET", "/repos/a/b/issues/1/extra", &[], Value::Null).is_none());
1021 assert!(resolve("GET", "/repos/a/b/", &[], Value::Null).is_some());
API and MCP server in Rust; a public index at the API root1022 }
1023
1024 #[test]
1025 fn every_parameter_and_query_name_is_an_input() {
1026 for route in ROUTES {
1027 let properties = route.op.properties();
1028 for (_, key) in route.query {
1029 assert!(properties.contains_key(*key), "{}: {key}", route.path);
1030 }
1031 for name in route.params() {
1032 let covered = matches!(name, "owner" | "name") && properties.contains_key("repo")
1033 || properties.contains_key(name);
1034 assert!(covered, "{}: {name}", route.path);
1035 }
1036 }
1037 }
1038
1039 #[test]
1040 fn every_operation_has_a_route() {
1041 for op in Op::ALL {
1042 assert!(ROUTES.iter().any(|route| route.op == op), "{}", op.name());
1043 }
1044 }
1045}