Skip to content
1,414 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Get started on mission control1//! REST: each route maps an HTTP request onto one operation.
2
3use serde_json::{Map, Value};
4
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb975use crate::about::AboutOp;
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R26use crate::artifacts::ArtifactsOp;
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca7use crate::deploy_keys::DeployKeysOp;
Merge branch 'mirroring' into artifacts-mode8use crate::mirrors::MirrorsOp;
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb979use crate::deployments::DeploymentsOp;
Merge packages: roles, Actions access, source label, soft delete, API10use crate::packages::PackagesOp;
Merge branch 'worktree-agent-a3abfcce648e87dca'11use crate::protection::ProtectionOp;
API and MCP for a workspace's personal access token rules, members' tokens and approvals12use crate::token_policy::TokenOp;
Get started on mission control13use crate::operations::Op;
Merge checks: statuses and check runs on every commit14use crate::checks::ChecksOp;
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge15use crate::rules::RulesOp;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar16use crate::security::SecurityOp;
Get started on mission control17
18pub struct Route {
19 pub method: &'static str,
20 /// Segments starting with `:` are parameters.
21 pub path: &'static str,
22 pub op: Op,
23 /// Query parameters the route reads, as `(name in the URL, input name)`.
24 pub query: &'static [(&'static str, &'static str)],
25}
26
27const fn route(
28 method: &'static str,
29 path: &'static str,
30 op: Op,
31 query: &'static [(&'static str, &'static str)],
32) -> Route {
33 Route {
34 method,
35 path,
36 op,
37 query,
38 }
39}
40
41pub const ROUTES: &[Route] = &[
42 route("GET", "/user", Op::Whoami, &[]),
43 route("POST", "/workspaces", Op::CreateWorkspace, &[]),
Merge branch 'worktree-agent-ad7c6d88d93adc817'44 route("GET", "/workspaces/:workspace", Op::GetWorkspace, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look45 route("DELETE", "/workspaces/:workspace", Op::DeleteWorkspace, &[]),
46 route("GET", "/user/emails", Op::ListEmails, &[]),
47 route("POST", "/user/emails", Op::AddEmail, &[]),
Merge email confirmation gate: a code and a link, nothing until confirmed (identity 0036)48 route("POST", "/user/emails/confirm", Op::ConfirmEmail, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look49 route("DELETE", "/user/emails/:email", Op::RemoveEmail, &[]),
50 route("PATCH", "/user/email-settings", Op::UpdateEmailSettings, &[]),
51 route("GET", "/user/invites", Op::ListInvites, &[]),
52 route("POST", "/user/invites", Op::CreateInvite, &[]),
53 route("DELETE", "/user/invites/:id", Op::RevokeInvite, &[]),
Merge workspace invitations: nobody joins a workspace without saying yes, people are found by username, your own invites can bring someone in, and nobody is left without a workspace (identity 0040)54 // Invitations to workspaces waiting for your answer.
55 route("GET", "/user/invitations", Op::ListInvitations, &[]),
56 route("POST", "/user/invitations/:id/accept", Op::AcceptInvitation, &[]),
57 route("POST", "/user/invitations/:id/decline", Op::DeclineInvitation, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look58 route("GET", "/workspaces/:workspace/invitations", Op::ListWorkspaceInvites, &[]),
API and MCP for a workspace's personal access token rules, members' tokens and approvals59 // A workspace's rules for personal access tokens, and its members' tokens.
60 route("GET", "/workspaces/:workspace/personal-access-token-policy", Op::Tokens(TokenOp::GetTokenPolicy), &[]),
61 route("PATCH", "/workspaces/:workspace/personal-access-token-policy", Op::Tokens(TokenOp::SetTokenPolicy), &[]),
One kind of access token; presence and status; usernames keep their case; the tour is a miniature of the real app; icons for password managers62 route("GET", "/workspaces/:workspace/personal-access-tokens", Op::Tokens(TokenOp::ListMemberTokens), &[]),
API and MCP for a workspace's personal access token rules, members' tokens and approvals63 route("POST", "/workspaces/:workspace/personal-access-tokens/:id", Op::Tokens(TokenOp::RevokeMemberToken), &[]),
64 route("GET", "/workspaces/:workspace/personal-access-token-requests", Op::Tokens(TokenOp::ListTokenRequests), &[]),
65 route("POST", "/workspaces/:workspace/personal-access-token-requests/:id", Op::Tokens(TokenOp::ReviewTokenRequest), &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look66 route("POST", "/workspaces/:workspace/invitations", Op::InviteMember, &[]),
67 route("DELETE", "/workspaces/:workspace/invitations/:id", Op::RevokeWorkspaceInvite, &[]),
68 // Who has access. GitHub's addresses, but for adding someone, which
69 // takes an email address as well as a username.
70 route("GET", "/repos/:owner/:name/collaborators", Op::ListCollaborators, &[]),
71 route("POST", "/repos/:owner/:name/collaborators", Op::AddCollaborator, &[]),
72 route("PATCH", "/repos/:owner/:name/collaborators/:username", Op::UpdateCollaborator, &[]),
73 route("DELETE", "/repos/:owner/:name/collaborators/:username", Op::RemoveCollaborator, &[]),
74 route(
75 "GET",
76 "/repos/:owner/:name/collaborators/:username/permission",
77 Op::GetCollaboratorPermission,
78 &[],
79 ),
80 route("GET", "/repos/:owner/:name/invitations", Op::ListRepoInvitations, &[]),
81 route("DELETE", "/repos/:owner/:name/invitations/:id", Op::RevokeRepoInvitation, &[]),
82 route("GET", "/user/repository_invitations", Op::ListMyRepoInvitations, &[]),
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca83 // Deploy keys, at GitHub's addresses.
84 route("GET", "/repos/:owner/:name/keys", Op::DeployKeys(DeployKeysOp::ListDeployKeys), &[]),
85 route("POST", "/repos/:owner/:name/keys", Op::DeployKeys(DeployKeysOp::CreateDeployKey), &[]),
86 route("GET", "/repos/:owner/:name/keys/:id", Op::DeployKeys(DeployKeysOp::GetDeployKey), &[]),
87 route("DELETE", "/repos/:owner/:name/keys/:id", Op::DeployKeys(DeployKeysOp::DeleteDeployKey), &[]),
Merge branch 'mirroring' into artifacts-mode88 // Mirroring: a repository's remotes, takeovers and hand-backs.
89 route("GET", "/repos/:owner/:name/mirror", Op::Mirrors(MirrorsOp::GetMirror), &[]),
90 route("GET", "/repos/:owner/:name/mirror/hand-back", Op::Mirrors(MirrorsOp::GetHandBackPlan), &[]),
91 route("POST", "/repos/:owner/:name/mirror/take-over", Op::Mirrors(MirrorsOp::TakeOver), &[]),
92 route("POST", "/repos/:owner/:name/mirror/ci", Op::Mirrors(MirrorsOp::SetCiFailover), &[]),
93 route("POST", "/repos/:owner/:name/mirror/hand-back", Op::Mirrors(MirrorsOp::HandBack), &[]),
94 route("POST", "/repos/:owner/:name/mirror/move-to-g1t", Op::Mirrors(MirrorsOp::MoveToG1t), &[]),
95 route("POST", "/repos/:owner/:name/mirror/sync", Op::Mirrors(MirrorsOp::SyncMirror), &[]),
96 route("POST", "/repos/:owner/:name/mirror/remotes", Op::Mirrors(MirrorsOp::AddRemote), &[]),
97 route("PATCH", "/repos/:owner/:name/mirror/remotes/:id", Op::Mirrors(MirrorsOp::UpdateRemote), &[]),
98 route("DELETE", "/repos/:owner/:name/mirror/remotes/:id", Op::Mirrors(MirrorsOp::RemoveRemote), &[]),
API: notifications over REST and MCP, with notifications scopes99 // Your notifications: threads, marking them, and what you subscribe
100 // to and watch. GitHub's addresses, with g1t's saved and snoozed.
101 route("GET", "/notifications", Op::ListNotifications, &[("all", "all"), ("participating", "participating"), ("view", "view"), ("reason", "reason"), ("severity", "severity"), ("since", "since"), ("before", "before"), ("cursor", "cursor"), ("per_page", "per_page")]),
102 route("PUT", "/notifications", Op::MarkNotificationsRead, &[]),
103 route("GET", "/notifications/threads/:id", Op::GetNotificationThread, &[]),
104 route("PATCH", "/notifications/threads/:id", Op::MarkThreadRead, &[]),
105 route("DELETE", "/notifications/threads/:id", Op::MarkThreadDone, &[]),
106 route("PUT", "/notifications/threads/:id/saved", Op::SaveThread, &[]),
107 route("DELETE", "/notifications/threads/:id/saved", Op::SaveThread, &[]),
108 route("PUT", "/notifications/threads/:id/snooze", Op::SnoozeThread, &[]),
109 route("DELETE", "/notifications/threads/:id/snooze", Op::SnoozeThread, &[]),
110 route("GET", "/notifications/threads/:id/subscription", Op::GetThreadSubscription, &[]),
111 route("PUT", "/notifications/threads/:id/subscription", Op::SetThreadSubscription, &[]),
112 route("DELETE", "/notifications/threads/:id/subscription", Op::DeleteThreadSubscription, &[]),
113 route("GET", "/repos/:owner/:name/notifications", Op::ListNotifications, &[("all", "all"), ("participating", "participating"), ("view", "view"), ("reason", "reason"), ("severity", "severity"), ("since", "since"), ("before", "before"), ("cursor", "cursor"), ("per_page", "per_page")]),
114 route("PUT", "/repos/:owner/:name/notifications", Op::MarkNotificationsRead, &[]),
115 route("GET", "/repos/:owner/:name/subscription", Op::GetRepoSubscription, &[]),
116 route("PUT", "/repos/:owner/:name/subscription", Op::SetRepoSubscription, &[]),
117 route("DELETE", "/repos/:owner/:name/subscription", Op::DeleteRepoSubscription, &[]),
118 route("GET", "/repos/:owner/:name/issues/:number/subscription", Op::GetThreadSubscription, &[]),
119 route("PUT", "/repos/:owner/:name/issues/:number/subscription", Op::SetThreadSubscription, &[]),
120 route("DELETE", "/repos/:owner/:name/issues/:number/subscription", Op::DeleteThreadSubscription, &[]),
121 route("GET", "/user/subscriptions", Op::ListWatchedRepos, &[]),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97122 // Stars: yours, and who starred a repository.
123 route("GET", "/user/starred", Op::About(AboutOp::ListStarred), &[]),
124 route("GET", "/user/starred/:owner/:name", Op::About(AboutOp::CheckStarred), &[]),
125 route("PUT", "/user/starred/:owner/:name", Op::About(AboutOp::Star), &[]),
126 route("DELETE", "/user/starred/:owner/:name", Op::About(AboutOp::Unstar), &[]),
127 route("GET", "/repos/:owner/:name/stargazers", Op::About(AboutOp::ListStargazers), &[("page", "page")]),
128 // What the default branch says about a repository, kept by commit.
129 route("GET", "/repos/:owner/:name/languages", Op::About(AboutOp::GetLanguages), &[]),
130 route("GET", "/repos/:owner/:name/contributors", Op::About(AboutOp::ListContributors), &[]),
131 route("GET", "/repos/:owner/:name/license", Op::About(AboutOp::GetLicense), &[]),
132 // Releases: `latest` and `tags/…` before an id.
133 route("GET", "/repos/:owner/:name/releases", Op::About(AboutOp::ListReleases), &[]),
134 route("POST", "/repos/:owner/:name/releases", Op::About(AboutOp::CreateRelease), &[]),
135 route("GET", "/repos/:owner/:name/releases/latest", Op::About(AboutOp::GetLatestRelease), &[]),
136 route("GET", "/repos/:owner/:name/releases/tags/:tag", Op::About(AboutOp::GetReleaseByTag), &[]),
137 route("GET", "/repos/:owner/:name/releases/:id", Op::About(AboutOp::GetRelease), &[]),
138 route("PATCH", "/repos/:owner/:name/releases/:id", Op::About(AboutOp::UpdateRelease), &[]),
139 route("DELETE", "/repos/:owner/:name/releases/:id", Op::About(AboutOp::DeleteRelease), &[]),
API: pinned projects over REST and MCP140 // Your pinned projects in a workspace, in your order.
141 route("GET", "/user/pinned_projects/:workspace", Op::ListPinnedProjects, &[]),
142 route("PUT", "/user/pinned_projects/:workspace", Op::ReorderPinnedProjects, &[]),
143 route("PUT", "/user/pinned_projects/:workspace/:project", Op::PinProject, &[]),
144 route("DELETE", "/user/pinned_projects/:workspace/:project", Op::UnpinProject, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look145 route("PATCH", "/user/repository_invitations/:id", Op::AcceptRepoInvitation, &[]),
146 route("DELETE", "/user/repository_invitations/:id", Op::DeclineRepoInvitation, &[]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily147 route("PATCH", "/workspaces/:workspace", Op::UpdateWorkspace, &[]),
Merge main (membership, two-factor, GitHub repo roles) into tokens148 // Members and owners: GitHub's organization members, by username.
149 route("GET", "/workspaces/:workspace/members", Op::ListMembers, &[]),
150 route("PATCH", "/workspaces/:workspace/members/:username", Op::UpdateMember, &[]),
151 route("DELETE", "/workspaces/:workspace/members/:username", Op::RemoveMember, &[]),
152 route("POST", "/workspaces/:workspace/transfer_ownership", Op::TransferOwnership, &[]),
153 route("DELETE", "/user/memberships/:workspace", Op::LeaveWorkspace, &[]),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97154 // A workspace's projects: what each is, where it runs, its links.
155 route("GET", "/workspaces/:workspace/projects", Op::ListProjects, &[]),
156 route("GET", "/workspaces/:workspace/projects/:project", Op::GetProject, &[]),
157 route("PATCH", "/workspaces/:workspace/projects/:project", Op::UpdateProject, &[]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily158 route("PUT", "/workspaces/:workspace/base_permission", Op::SetBasePermission, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look159 route(
160 "GET",
161 "/workspaces/:workspace/outside_collaborators",
162 Op::ListOutsideCollaborators,
163 &[],
164 ),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar165 // Teams: a workspace's groups of members, with roles on repositories.
166 route("GET", "/workspaces/:workspace/teams", Op::ListTeams, &[("q", "query")]),
167 route("POST", "/workspaces/:workspace/teams", Op::CreateTeam, &[]),
168 route("GET", "/workspaces/:workspace/teams/:team", Op::GetTeam, &[]),
169 route("PATCH", "/workspaces/:workspace/teams/:team", Op::UpdateTeam, &[]),
170 route("DELETE", "/workspaces/:workspace/teams/:team", Op::DeleteTeam, &[]),
171 route(
172 "GET",
173 "/workspaces/:workspace/teams/:team/members",
174 Op::ListTeamMembers,
175 &[("include_child_teams", "include_child_teams")],
176 ),
177 route("PUT", "/workspaces/:workspace/teams/:team/members/:username", Op::SetTeamMember, &[]),
178 route("DELETE", "/workspaces/:workspace/teams/:team/members/:username", Op::RemoveTeamMember, &[]),
179 route("GET", "/workspaces/:workspace/teams/:team/teams", Op::ListChildTeams, &[]),
180 route("GET", "/workspaces/:workspace/teams/:team/repos", Op::ListTeamRepos, &[]),
181 route("PUT", "/workspaces/:workspace/teams/:team/repos/:repo", Op::SetTeamRepo, &[]),
182 route("DELETE", "/workspaces/:workspace/teams/:team/repos/:repo", Op::RemoveTeamRepo, &[]),
183 route(
184 "PUT",
185 "/workspaces/:workspace/teams/:team/review_assignment",
186 Op::SetTeamReviewAssignment,
187 &[],
188 ),
189 route("GET", "/workspaces/:workspace/members/:username/teams", Op::ListUserTeams, &[]),
Usage, Billing settings and prepaid AI credit; fixes from the UX audit190 // A workspace's billing: usage, budget, AI credit and invoices.
191 route(
192 "GET",
193 "/workspaces/:workspace/usage",
194 Op::GetUsage,
195 &[("from", "from"), ("until", "until"), ("products", "products"), ("projects", "projects"), ("group_by", "group_by")],
196 ),
197 route("GET", "/workspaces/:workspace/budget", Op::GetBudget, &[]),
198 route("PUT", "/workspaces/:workspace/budget", Op::SetBudget, &[]),
199 route("GET", "/workspaces/:workspace/ai_credit", Op::GetAiCredit, &[]),
200 route("POST", "/workspaces/:workspace/ai_credit/checkout", Op::BuyAiCredit, &[]),
201 route("GET", "/workspaces/:workspace/invoices", Op::ListInvoices, &[]),
202 route("GET", "/workspaces/:workspace/billing_details", Op::GetBillingDetails, &[]),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens203 // The AI Gateway's log of a workspace's requests.
204 route("GET", "/workspaces/:workspace/gateway/requests", Op::ListGatewayRequests, &[("limit", "limit"), ("before", "before")]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar205 // Code owners: the CODEOWNERS file, checked.
206 route("GET", "/repos/:owner/:name/codeowners/errors", Op::GetCodeownersErrors, &[("ref", "ref")]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily207 // Security alerts: secrets and vulnerable dependencies.
208 route(
209 "GET",
210 "/repos/:owner/:name/security/alerts",
211 Op::ListSecurityAlerts,
212 &[("state", "state"), ("kind", "kind")],
213 ),
214 route("POST", "/repos/:owner/:name/security/alerts/:id/dismiss", Op::DismissSecurityAlert, &[]),
215 route("POST", "/repos/:owner/:name/security/alerts/:id/reopen", Op::ReopenSecurityAlert, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar216 // The security suite: secret scanning, code scanning, vulnerability
217 // alerts and the supply chain, at the common addresses.
218 route("GET", "/repos/:owner/:name/secret-scanning/alerts", Op::Security(SecurityOp::ListSecretAlerts), &[("state", "state"), ("secret_type", "secret_type"), ("validity", "validity"), ("bypassed", "bypassed")]),
219 route("GET", "/workspaces/:workspace/secret-scanning/alerts", Op::Security(SecurityOp::ListSecretAlerts), &[("state", "state"), ("secret_type", "secret_type"), ("validity", "validity"), ("bypassed", "bypassed")]),
220 route("GET", "/repos/:owner/:name/secret-scanning/alerts/:id", Op::Security(SecurityOp::GetSecretAlert), &[]),
221 route("PATCH", "/repos/:owner/:name/secret-scanning/alerts/:id", Op::Security(SecurityOp::UpdateSecretAlert), &[]),
222 route("GET", "/repos/:owner/:name/secret-scanning/alerts/:id/locations", Op::Security(SecurityOp::ListSecretLocations), &[]),
223 route("POST", "/repos/:owner/:name/secret-scanning/alerts/:id/bypass", Op::Security(SecurityOp::BypassPushProtection), &[]),
224 route("POST", "/repos/:owner/:name/secret-scanning/alerts/:id/validity", Op::Security(SecurityOp::CheckSecretValidity), &[]),
225 route("GET", "/workspaces/:workspace/secret-scanning/bypass-requests", Op::Security(SecurityOp::ListBypassRequests), &[("state", "state"), ("repo", "repo")]),
226 route("PATCH", "/workspaces/:workspace/secret-scanning/bypass-requests/:id", Op::Security(SecurityOp::ReviewBypassRequest), &[]),
227 route("POST", "/repos/:owner/:name/secret-scanning/custom-patterns/dry-run", Op::Security(SecurityOp::DryRunCustomPattern), &[]),
228 route("POST", "/workspaces/:workspace/secret-scanning/custom-patterns/dry-run", Op::Security(SecurityOp::DryRunCustomPattern), &[]),
229 route("GET", "/repos/:owner/:name/secret-scanning/custom-patterns", Op::Security(SecurityOp::ListCustomPatterns), &[]),
230 route("GET", "/workspaces/:workspace/secret-scanning/custom-patterns", Op::Security(SecurityOp::ListCustomPatterns), &[]),
231 route("POST", "/repos/:owner/:name/secret-scanning/custom-patterns", Op::Security(SecurityOp::CreateCustomPattern), &[]),
232 route("POST", "/workspaces/:workspace/secret-scanning/custom-patterns", Op::Security(SecurityOp::CreateCustomPattern), &[]),
233 route("PATCH", "/repos/:owner/:name/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::UpdateCustomPattern), &[]),
234 route("PATCH", "/workspaces/:workspace/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::UpdateCustomPattern), &[]),
235 route("DELETE", "/repos/:owner/:name/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::DeleteCustomPattern), &[]),
236 route("DELETE", "/workspaces/:workspace/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::DeleteCustomPattern), &[]),
237 route("GET", "/repos/:owner/:name/code-scanning/alerts", Op::Security(SecurityOp::ListCodeAlerts), &[("state", "state"), ("severity", "severity"), ("tool", "tool"), ("rule_id", "rule_id")]),
238 route("GET", "/workspaces/:workspace/code-scanning/alerts", Op::Security(SecurityOp::ListCodeAlerts), &[("state", "state"), ("severity", "severity"), ("tool", "tool"), ("rule_id", "rule_id")]),
239 route("GET", "/repos/:owner/:name/code-scanning/alerts/:number", Op::Security(SecurityOp::GetCodeAlert), &[]),
240 route("PATCH", "/repos/:owner/:name/code-scanning/alerts/:number", Op::Security(SecurityOp::UpdateCodeAlert), &[]),
241 route("GET", "/repos/:owner/:name/code-scanning/analyses", Op::Security(SecurityOp::ListAnalyses), &[]),
242 route("POST", "/repos/:owner/:name/code-scanning/sarifs", Op::Security(SecurityOp::UploadSarif), &[]),
243 route("GET", "/repos/:owner/:name/code-scanning/sarifs/:id", Op::Security(SecurityOp::GetSarifUpload), &[]),
244 route("GET", "/repos/:owner/:name/vulnerability-alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), &[("state", "state"), ("severity", "severity"), ("ecosystem", "ecosystem"), ("package", "package")]),
245 route("GET", "/workspaces/:workspace/vulnerability-alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), &[("state", "state"), ("severity", "severity"), ("ecosystem", "ecosystem"), ("package", "package")]),
246 route("GET", "/repos/:owner/:name/vulnerability-alerts/:id", Op::Security(SecurityOp::GetVulnerabilityAlert), &[]),
247 route("PATCH", "/repos/:owner/:name/vulnerability-alerts/:id", Op::Security(SecurityOp::UpdateVulnerabilityAlert), &[]),
248 route("POST", "/repos/:owner/:name/security/alerts/:id/fix", Op::Security(SecurityOp::FixAlert), &[]),
249 route("GET", "/repos/:owner/:name/dependency-graph", Op::Security(SecurityOp::GetDependencyGraph), &[]),
250 route("GET", "/repos/:owner/:name/dependency-graph/sbom", Op::Security(SecurityOp::GetSbom), &[]),
251 route("GET", "/repos/:owner/:name/dependency-graph/compare/:basehead", Op::Security(SecurityOp::CompareDependencies), &[]),
252 route("GET", "/repos/:owner/:name/security/settings", Op::Security(SecurityOp::GetSettings), &[]),
253 route("PATCH", "/repos/:owner/:name/security/settings", Op::Security(SecurityOp::UpdateSettings), &[]),
254 route("GET", "/workspaces/:workspace/security/settings", Op::Security(SecurityOp::GetWorkspaceSettings), &[]),
255 route("PATCH", "/workspaces/:workspace/security/settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), &[]),
256 route("GET", "/workspaces/:workspace/security/overview", Op::Security(SecurityOp::GetOverview), &[("days", "days")]),
Get started on mission control257 route("GET", "/repos", Op::ListRepos, &[("q", "query")]),
Search across all of g1t, Explore, and a command palette258 route(
259 "GET",
260 "/search",
261 Op::Search,
262 &[("q", "query"), ("type", "type"), ("page", "page"), ("per_page", "per_page")],
263 ),
Get started on mission control264 route("POST", "/repos", Op::CreateRepo, &[]),
265 route("GET", "/repos/:owner/:name", Op::GetRepo, &[]),
266 route("PATCH", "/repos/:owner/:name", Op::UpdateRepo, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look267 route("POST", "/repos/:owner/:name/transfer", Op::TransferRepo, &[]),
268 route("DELETE", "/repos/:owner/:name", Op::DeleteRepo, &[]),
269 route(
270 "GET",
271 "/workspaces/:workspace/repos/deleted",
272 Op::ListDeletedRepos,
273 &[],
274 ),
275 route("POST", "/repos/:owner/:name/restore", Op::RestoreRepo, &[]),
276 route("POST", "/repos/:owner/:name/purge", Op::PurgeRepo, &[]),
277 route("POST", "/repos/:owner/:name/rename", Op::RenameRepo, &[]),
278 route("POST", "/repos/:owner/:name/archive", Op::ArchiveRepo, &[]),
279 route("POST", "/repos/:owner/:name/unarchive", Op::UnarchiveRepo, &[]),
280 route(
281 "POST",
282 "/repos/:owner/:name/visibility",
283 Op::SetRepoVisibility,
284 &[],
285 ),
286 route(
287 "POST",
288 "/repos/:owner/:name/branches/:branch/rename",
289 Op::RenameBranch,
290 &[],
291 ),
Get started on mission control292 route(
293 "GET",
294 "/repos/:owner/:name/settings",
295 Op::GetRepoSettings,
296 &[],
297 ),
298 route(
299 "PATCH",
300 "/repos/:owner/:name/settings",
301 Op::UpdateRepoSettings,
302 &[],
303 ),
Fast pages, required checks on the branch, self-hosted runners, honest incidents304 route("GET", "/repos/:owner/:name/check-names", Op::ListCheckNames, &[]),
Merge checks: statuses and check runs on every commit305 // Checks: GitHub's addresses for statuses, check runs and check suites.
306 route("POST", "/repos/:owner/:name/statuses/:sha", Op::Checks(ChecksOp::CreateCommitStatus), &[]),
307 route("GET", "/repos/:owner/:name/commits/:ref/statuses", Op::Checks(ChecksOp::ListCommitStatuses), &[]),
308 route("GET", "/repos/:owner/:name/commits/:ref/status", Op::Checks(ChecksOp::GetCombinedStatus), &[]),
309 route(
310 "GET",
311 "/repos/:owner/:name/commits/:ref/check-runs",
312 Op::Checks(ChecksOp::ListCheckRunsForRef),
313 &[("check_name", "check_name"), ("status", "status"), ("app", "app"), ("filter", "filter")],
314 ),
315 route(
316 "GET",
317 "/repos/:owner/:name/commits/:ref/check-suites",
318 Op::Checks(ChecksOp::ListCheckSuitesForRef),
319 &[("app", "app"), ("check_name", "check_name")],
320 ),
321 route("POST", "/repos/:owner/:name/check-runs", Op::Checks(ChecksOp::CreateCheckRun), &[]),
322 route("GET", "/repos/:owner/:name/check-runs/:id", Op::Checks(ChecksOp::GetCheckRun), &[]),
323 route("PATCH", "/repos/:owner/:name/check-runs/:id", Op::Checks(ChecksOp::UpdateCheckRun), &[]),
324 route("GET", "/repos/:owner/:name/check-runs/:id/annotations", Op::Checks(ChecksOp::ListCheckRunAnnotations), &[]),
325 route("POST", "/repos/:owner/:name/check-runs/:id/rerequest", Op::Checks(ChecksOp::RerequestCheckRun), &[]),
326 route("GET", "/repos/:owner/:name/check-suites/:id", Op::Checks(ChecksOp::GetCheckSuite), &[]),
327 route("POST", "/repos/:owner/:name/check-suites/:id/rerequest", Op::Checks(ChecksOp::RerequestCheckSuite), &[]),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge328 // Rulesets: a repository's, a workspace's, the rules of one branch,
329 // and how they judged pushes and merges.
330 route("GET", "/repos/:owner/:name/rulesets", Op::Rules(RulesOp::ListRepoRulesets), &[("include_parents", "include_parents")]),
331 route("POST", "/repos/:owner/:name/rulesets", Op::Rules(RulesOp::CreateRepoRuleset), &[]),
332 route("GET", "/repos/:owner/:name/rulesets/:id", Op::Rules(RulesOp::GetRepoRuleset), &[]),
333 route("PUT", "/repos/:owner/:name/rulesets/:id", Op::Rules(RulesOp::UpdateRepoRuleset), &[]),
334 route("DELETE", "/repos/:owner/:name/rulesets/:id", Op::Rules(RulesOp::DeleteRepoRuleset), &[]),
335 route("GET", "/repos/:owner/:name/rules/branches/:branch", Op::Rules(RulesOp::GetBranchRules), &[("target", "target")]),
336 route(
337 "GET",
338 "/repos/:owner/:name/rules/evaluations",
339 Op::Rules(RulesOp::ListRuleEvaluations),
340 &[("ruleset_id", "ruleset_id"), ("verdict", "verdict"), ("problems_only", "problems_only"), ("before", "before"), ("limit", "limit")],
341 ),
342 route("GET", "/workspaces/:workspace/rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), &[]),
343 route("POST", "/workspaces/:workspace/rulesets", Op::Rules(RulesOp::CreateWorkspaceRuleset), &[]),
344 route("GET", "/workspaces/:workspace/rulesets/:id", Op::Rules(RulesOp::GetWorkspaceRuleset), &[]),
345 route("PUT", "/workspaces/:workspace/rulesets/:id", Op::Rules(RulesOp::UpdateWorkspaceRuleset), &[]),
346 route("DELETE", "/workspaces/:workspace/rulesets/:id", Op::Rules(RulesOp::DeleteWorkspaceRuleset), &[]),
347 route(
348 "GET",
349 "/workspaces/:workspace/rules/evaluations",
350 Op::Rules(RulesOp::ListWorkspaceRuleEvaluations),
351 &[("ruleset_id", "ruleset_id"), ("verdict", "verdict"), ("problems_only", "problems_only"), ("before", "before"), ("limit", "limit")],
352 ),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97353 // Deployments wherever they run, their statuses, and environments.
354 route(
355 "GET",
356 "/repos/:owner/:name/deployments",
357 Op::Deployments(DeploymentsOp::ListDeployments),
358 &[("environment", "environment"), ("ref", "ref"), ("sha", "sha"), ("task", "task"), ("state", "state"), ("source", "source"), ("creator", "creator"), ("page", "page"), ("per_page", "per_page")],
359 ),
360 route("POST", "/repos/:owner/:name/deployments", Op::Deployments(DeploymentsOp::CreateDeployment), &[]),
361 route("GET", "/repos/:owner/:name/deployments/:id", Op::Deployments(DeploymentsOp::GetDeployment), &[]),
362 route("GET", "/repos/:owner/:name/deployments/:id/statuses", Op::Deployments(DeploymentsOp::ListDeploymentStatuses), &[]),
363 route("POST", "/repos/:owner/:name/deployments/:id/statuses", Op::Deployments(DeploymentsOp::CreateDeploymentStatus), &[]),
364 route("GET", "/repos/:owner/:name/environments", Op::Deployments(DeploymentsOp::ListEnvironments), &[]),
365 route("GET", "/repos/:owner/:name/environments/:environment", Op::Deployments(DeploymentsOp::GetEnvironment), &[]),
Merge branch 'worktree-agent-a3abfcce648e87dca'366 // Environments' protection rules, and the runs they hold.
367 route("PUT", "/repos/:owner/:name/environments/:environment", Op::Protection(ProtectionOp::UpdateEnvironment), &[]),
368 route("DELETE", "/repos/:owner/:name/environments/:environment", Op::Protection(ProtectionOp::DeleteEnvironment), &[]),
369 route(
370 "GET",
371 "/repos/:owner/:name/actions/runs/:id/pending_deployments",
372 Op::Protection(ProtectionOp::GetPendingDeployments),
373 &[],
374 ),
375 route(
376 "POST",
377 "/repos/:owner/:name/actions/runs/:id/pending_deployments",
378 Op::Protection(ProtectionOp::ReviewPendingDeployments),
379 &[],
380 ),
381 route("POST", "/repos/:owner/:name/actions/runs/:id/approve", Op::Protection(ProtectionOp::ApproveWorkflowRun), &[]),
382 route("GET", "/repos/:owner/:name/actions/permissions/workflow", Op::Protection(ProtectionOp::GetWorkflowPermissions), &[]),
383 route("PUT", "/repos/:owner/:name/actions/permissions/workflow", Op::Protection(ProtectionOp::SetWorkflowPermissions), &[]),
384 route(
385 "GET",
386 "/repos/:owner/:name/actions/permissions/fork-pr-contributor-approval",
387 Op::Protection(ProtectionOp::GetForkPrApproval),
388 &[],
389 ),
390 route(
391 "PUT",
392 "/repos/:owner/:name/actions/permissions/fork-pr-contributor-approval",
393 Op::Protection(ProtectionOp::SetForkPrApproval),
394 &[],
395 ),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts396 route("GET", "/repos/:owner/:name/actions/permissions/access", Op::Protection(ProtectionOp::GetActionsAccess), &[]),
397 route("PUT", "/repos/:owner/:name/actions/permissions/access", Op::Protection(ProtectionOp::SetActionsAccess), &[]),
Merge branch 'worktree-agent-a3abfcce648e87dca'398 route("POST", "/repos/:owner/:name/dispatches", Op::Protection(ProtectionOp::CreateRepositoryDispatch), &[]),
399 route(
400 "GET",
401 "/workspaces/:workspace/actions/permissions/workflow",
402 Op::Protection(ProtectionOp::GetWorkspaceWorkflowPermissions),
403 &[],
404 ),
405 route(
406 "PUT",
407 "/workspaces/:workspace/actions/permissions/workflow",
408 Op::Protection(ProtectionOp::SetWorkspaceWorkflowPermissions),
409 &[],
410 ),
Get started on mission control411 route("GET", "/repos/:owner/:name/queue", Op::GetMergeQueue, &[]),
412 route(
413 "POST",
414 "/repos/:owner/:name/pulls/:number/messages",
415 Op::MessageAgent,
416 &[],
417 ),
418 route(
419 "POST",
420 "/repos/:owner/:name/pulls/:number/messages/take",
421 Op::TakeMessages,
422 &[],
423 ),
424 route(
Docs worth reading, and kept that way425 "POST",
426 "/repos/:owner/:name/messages/:id/answer",
427 Op::AnswerMessage,
428 &[],
429 ),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains430 route("POST", "/repos/:owner/:name/memory", Op::Remember, &[]),
431 route(
432 "GET",
433 "/repos/:owner/:name/memory",
434 Op::Recall,
435 &[("q", "query"), ("limit", "limit")],
436 ),
Docs worth reading, and kept that way437 route(
Get started on mission control438 "GET",
439 "/repos/:owner/:name/events",
440 Op::ListEvents,
441 &[("before", "before")],
442 ),
443 route("GET", "/repos/:owner/:name/labels", Op::ListLabels, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar444 route("POST", "/repos/:owner/:name/labels", Op::CreateLabel, &[]),
445 route("POST", "/repos/:owner/:name/labels/defaults", Op::AddDefaultLabels, &[]),
446 route("PATCH", "/repos/:owner/:name/labels/:label", Op::UpdateLabel, &[]),
447 route("DELETE", "/repos/:owner/:name/labels/:label", Op::DeleteLabel, &[]),
448 route("GET", "/repos/:owner/:name/issues/:number/labels", Op::ListIssueLabels, &[]),
449 route("POST", "/repos/:owner/:name/issues/:number/labels", Op::AddIssueLabels, &[]),
450 route("PUT", "/repos/:owner/:name/issues/:number/labels", Op::SetIssueLabels, &[]),
451 route("DELETE", "/repos/:owner/:name/issues/:number/labels", Op::RemoveIssueLabels, &[]),
452 route("DELETE", "/repos/:owner/:name/issues/:number/labels/:label", Op::RemoveIssueLabels, &[]),
453 route("GET", "/repos/:owner/:name/milestones", Op::ListMilestones, &[("state", "state")]),
454 route("POST", "/repos/:owner/:name/milestones", Op::CreateMilestone, &[]),
455 route("GET", "/repos/:owner/:name/milestones/:milestone", Op::GetMilestone, &[]),
456 route("PATCH", "/repos/:owner/:name/milestones/:milestone", Op::UpdateMilestone, &[]),
457 route("DELETE", "/repos/:owner/:name/milestones/:milestone", Op::DeleteMilestone, &[]),
Get started on mission control458 route(
459 "GET",
460 "/repos/:owner/:name/issues",
461 Op::ListIssues,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar462 &[("state", "state"), ("label", "label"), ("milestone", "milestone")],
Get started on mission control463 ),
464 route("POST", "/repos/:owner/:name/issues", Op::CreateIssue, &[]),
465 route(
466 "GET",
467 "/repos/:owner/:name/issues/:number",
468 Op::GetIssue,
469 &[],
470 ),
471 route(
472 "PATCH",
473 "/repos/:owner/:name/issues/:number",
474 Op::UpdateIssue,
475 &[],
476 ),
477 route(
478 "POST",
479 "/repos/:owner/:name/issues/:number/close",
480 Op::CloseIssue,
481 &[],
482 ),
483 route(
484 "POST",
485 "/repos/:owner/:name/issues/:number/reopen",
486 Op::ReopenIssue,
487 &[],
488 ),
489 route(
490 "POST",
491 "/repos/:owner/:name/issues/:number/assign",
492 Op::AssignIssue,
493 &[],
494 ),
Integrations: your own model provider, alerts that open issues, tickets agents read495 route(
496 "POST",
497 "/repos/:owner/:name/issues/import",
498 Op::ImportIssue,
499 &[],
500 ),
501 route(
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step502 "POST",
503 "/repos/:owner/:name/issues/delegate",
504 Op::Delegate,
505 &[],
506 ),
507 route(
Integrations: your own model provider, alerts that open issues, tickets agents read508 "GET",
509 "/repos/:owner/:name/context",
510 Op::GetContext,
511 &[("reference", "reference")],
512 ),
513 route(
514 "GET",
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API515 "/workspaces/:workspace/context/search",
516 Op::SearchContext,
517 &[("q", "query"), ("project", "project"), ("kinds", "kinds"), ("limit", "limit")],
518 ),
519 route(
520 "GET",
521 "/workspaces/:workspace/context/:kind/:id",
522 Op::GetEntity,
523 &[],
524 ),
525 route(
526 "GET",
Integrations: your own model provider, alerts that open issues, tickets agents read527 "/workspaces/:workspace/integrations",
528 Op::ListIntegrations,
529 &[],
530 ),
531 route(
532 "POST",
533 "/workspaces/:workspace/integrations",
534 Op::ConnectIntegration,
535 &[],
536 ),
537 route(
Models per workspace: several providers, routed by kind of work538 "GET",
Webhooks: every event, to your own addresses, signed and retried539 "/repos/:owner/:name/hooks",
540 Op::ListWebhooks,
541 &[],
542 ),
543 route(
544 "POST",
545 "/repos/:owner/:name/hooks",
546 Op::CreateWebhook,
547 &[],
548 ),
549 route(
550 "PATCH",
551 "/repos/:owner/:name/hooks/:id",
552 Op::UpdateWebhook,
553 &[],
554 ),
555 route(
556 "DELETE",
557 "/repos/:owner/:name/hooks/:id",
558 Op::DeleteWebhook,
559 &[],
560 ),
561 route(
562 "POST",
563 "/repos/:owner/:name/hooks/:id/pings",
564 Op::PingWebhook,
565 &[],
566 ),
567 route(
568 "GET",
569 "/repos/:owner/:name/hooks/:id/deliveries",
570 Op::ListWebhookDeliveries,
571 &[],
572 ),
573 route(
574 "POST",
575 "/repos/:owner/:name/hooks/:id/deliveries/:delivery/redeliver",
576 Op::RedeliverWebhook,
577 &[],
578 ),
579 route(
580 "GET",
581 "/workspaces/:workspace/hooks",
582 Op::ListWebhooks,
583 &[],
584 ),
585 route(
586 "POST",
587 "/workspaces/:workspace/hooks",
588 Op::CreateWebhook,
589 &[],
590 ),
591 route(
592 "PATCH",
593 "/workspaces/:workspace/hooks/:id",
594 Op::UpdateWebhook,
595 &[],
596 ),
597 route(
598 "DELETE",
599 "/workspaces/:workspace/hooks/:id",
600 Op::DeleteWebhook,
601 &[],
602 ),
603 route(
604 "POST",
605 "/workspaces/:workspace/hooks/:id/pings",
606 Op::PingWebhook,
607 &[],
608 ),
609 route(
610 "GET",
611 "/workspaces/:workspace/hooks/:id/deliveries",
612 Op::ListWebhookDeliveries,
613 &[],
614 ),
615 route(
616 "POST",
617 "/workspaces/:workspace/hooks/:id/deliveries/:delivery/redeliver",
618 Op::RedeliverWebhook,
619 &[],
620 ),
621 route(
622 "GET",
Models per workspace: several providers, routed by kind of work623 "/workspaces/:workspace/model-routes",
624 Op::GetModelRoutes,
625 &[],
626 ),
627 route(
628 "PUT",
629 "/workspaces/:workspace/model-routes",
630 Op::SetModelRoutes,
631 &[],
632 ),
633 route(
AI Gateway: OpenAI's format, open models, and your own providers634 "PATCH",
635 "/workspaces/:workspace/integrations/:id",
636 Op::UpdateIntegration,
637 &[],
638 ),
639 route(
Integrations: your own model provider, alerts that open issues, tickets agents read640 "DELETE",
641 "/workspaces/:workspace/integrations/:id",
642 Op::DisconnectIntegration,
643 &[],
644 ),
645 route(
646 "POST",
647 "/workspaces/:workspace/integrations/:id/test",
648 Op::TestIntegration,
649 &[],
650 ),
Automations: rules in .g1t/automations that act when something happens651 route(
652 "GET",
GitHub Actions on g1t, part two: running workflows653 "/repos/:owner/:name/actions/workflows",
654 Op::ListWorkflows,
655 &[],
656 ),
657 route(
658 "GET",
659 "/repos/:owner/:name/actions/workflows/:workflow/runs",
660 Op::ListWorkflowRuns,
661 &[("branch", "branch"), ("event", "event"), ("per_page", "limit")],
662 ),
663 route(
664 "POST",
665 "/repos/:owner/:name/actions/workflows/:workflow/dispatches",
666 Op::DispatchWorkflow,
667 &[],
668 ),
669 route(
670 "PATCH",
671 "/repos/:owner/:name/actions/workflows/:workflow",
672 Op::UpdateWorkflow,
673 &[],
674 ),
675 route(
676 "PUT",
677 "/repos/:owner/:name/actions/workflows/:workflow/enable",
678 Op::UpdateWorkflow,
679 &[],
680 ),
681 route(
682 "PUT",
683 "/repos/:owner/:name/actions/workflows/:workflow/disable",
684 Op::UpdateWorkflow,
685 &[],
686 ),
687 route(
688 "GET",
689 "/repos/:owner/:name/actions/runs",
690 Op::ListWorkflowRuns,
691 &[("workflow", "workflow"), ("branch", "branch"), ("event", "event"), ("pull", "pull"), ("head_sha", "sha"), ("per_page", "limit")],
692 ),
693 route(
694 "GET",
695 "/repos/:owner/:name/actions/runs/:id",
696 Op::GetWorkflowRun,
697 &[],
698 ),
699 route(
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)700 "GET",
701 "/repos/:owner/:name/actions/runs/:id/attempts/:attempt",
702 Op::GetWorkflowRun,
703 &[],
704 ),
705 route(
GitHub Actions on g1t, part two: running workflows706 "POST",
707 "/repos/:owner/:name/actions/runs/:id/cancel",
708 Op::CancelWorkflowRun,
709 &[],
710 ),
711 route(
712 "POST",
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)713 "/repos/:owner/:name/actions/runs/:id/force-cancel",
714 Op::CancelWorkflowRun,
715 &[],
716 ),
717 route(
718 "POST",
GitHub Actions on g1t, part two: running workflows719 "/repos/:owner/:name/actions/runs/:id/rerun",
720 Op::RerunWorkflowRun,
721 &[],
722 ),
723 route(
724 "POST",
725 "/repos/:owner/:name/actions/runs/:id/rerun-failed-jobs",
726 Op::RerunWorkflowRun,
727 &[],
728 ),
729 route(
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)730 "POST",
731 "/repos/:owner/:name/actions/jobs/:job/rerun",
732 Op::RerunWorkflowRun,
733 &[],
734 ),
735 route(
GitHub Actions on g1t, part two: running workflows736 "GET",
737 "/repos/:owner/:name/actions/jobs/:job/logs",
738 Op::GetJobLogs,
739 &[("after", "after")],
740 ),
Merge packages: roles, Actions access, source label, soft delete, API741 // Packages, at GitHub's addresses with the workspace in place of the
742 // organization. A name with a slash is one URL-encoded segment.
743 route("GET", "/workspaces/:workspace/packages", Op::Packages(PackagesOp::ListPackages), &[("package_type", "package_type"), ("q", "q"), ("state", "state")]),
744 route("GET", "/workspaces/:workspace/packages/:package_type/:package_name", Op::Packages(PackagesOp::GetPackage), &[]),
745 route("PATCH", "/workspaces/:workspace/packages/:package_type/:package_name", Op::Packages(PackagesOp::UpdatePackage), &[]),
746 route("DELETE", "/workspaces/:workspace/packages/:package_type/:package_name", Op::Packages(PackagesOp::DeletePackage), &[]),
747 route("POST", "/workspaces/:workspace/packages/:package_type/:package_name/restore", Op::Packages(PackagesOp::RestorePackage), &[]),
748 route("GET", "/workspaces/:workspace/packages/:package_type/:package_name/versions", Op::Packages(PackagesOp::ListVersions), &[("state", "state")]),
749 route("GET", "/workspaces/:workspace/packages/:package_type/:package_name/versions/:version_id", Op::Packages(PackagesOp::GetVersion), &[]),
750 route("DELETE", "/workspaces/:workspace/packages/:package_type/:package_name/versions/:version_id", Op::Packages(PackagesOp::DeleteVersion), &[]),
751 route("POST", "/workspaces/:workspace/packages/:package_type/:package_name/versions/:version_id/restore", Op::Packages(PackagesOp::RestoreVersion), &[]),
752 route("PUT", "/workspaces/:workspace/packages/:package_type/:package_name/repository", Op::Packages(PackagesOp::LinkPackage), &[]),
753 route("DELETE", "/workspaces/:workspace/packages/:package_type/:package_name/repository", Op::Packages(PackagesOp::UnlinkPackage), &[]),
754 route("GET", "/workspaces/:workspace/packages/:package_type/:package_name/access", Op::Packages(PackagesOp::ListAccess), &[]),
755 route("PUT", "/workspaces/:workspace/packages/:package_type/:package_name/access", Op::Packages(PackagesOp::SetAccess), &[]),
756 route("DELETE", "/workspaces/:workspace/packages/:package_type/:package_name/access", Op::Packages(PackagesOp::RemoveAccess), &[("username", "username"), ("team", "team")]),
757 route("GET", "/workspaces/:workspace/packages/:package_type/:package_name/actions-access", Op::Packages(PackagesOp::ListActionsAccess), &[]),
758 route("PUT", "/workspaces/:workspace/packages/:package_type/:package_name/actions-access", Op::Packages(PackagesOp::SetActionsAccess), &[]),
759 route("DELETE", "/workspaces/:workspace/packages/:package_type/:package_name/actions-access/:repository", Op::Packages(PackagesOp::RemoveActionsAccess), &[]),
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2760 // Artifacts, at GitHub's addresses. `…/zip` answers with a redirect to
761 // a signed link (lib.rs).
762 route("GET", "/repos/:owner/:name/actions/artifacts", Op::Artifacts(ArtifactsOp::ListArtifacts), &[("name", "name"), ("page", "page"), ("per_page", "per_page")]),
763 route("GET", "/repos/:owner/:name/actions/runs/:id/artifacts", Op::Artifacts(ArtifactsOp::ListRunArtifacts), &[("name", "name")]),
764 route("GET", "/repos/:owner/:name/actions/artifacts/:id", Op::Artifacts(ArtifactsOp::GetArtifact), &[]),
765 route("GET", "/repos/:owner/:name/actions/artifacts/:id/zip", Op::Artifacts(ArtifactsOp::DownloadArtifact), &[]),
766 route("DELETE", "/repos/:owner/:name/actions/artifacts/:id", Op::Artifacts(ArtifactsOp::DeleteArtifact), &[]),
767 route("GET", "/repos/:owner/:name/actions/permissions/artifact-and-log-retention", Op::Artifacts(ArtifactsOp::GetArtifactRetention), &[]),
768 route("PUT", "/repos/:owner/:name/actions/permissions/artifact-and-log-retention", Op::Artifacts(ArtifactsOp::SetArtifactRetention), &[]),
GitHub Actions on g1t, part two: running workflows769 route(
770 "GET",
771 "/repos/:owner/:name/actions/secrets",
772 Op::ListActionsSecrets,
773 &[],
774 ),
775 route(
776 "PUT",
777 "/repos/:owner/:name/actions/secrets/:setting",
778 Op::SetActionsSecret,
779 &[],
780 ),
781 route(
782 "DELETE",
783 "/repos/:owner/:name/actions/secrets/:setting",
784 Op::DeleteActionsSecret,
785 &[],
786 ),
787 route(
788 "GET",
789 "/repos/:owner/:name/actions/variables",
790 Op::ListActionsVariables,
791 &[],
792 ),
793 route(
794 "POST",
795 "/repos/:owner/:name/actions/variables",
796 Op::SetActionsVariable,
797 &[],
798 ),
799 route(
800 "PATCH",
801 "/repos/:owner/:name/actions/variables/:setting",
802 Op::SetActionsVariable,
803 &[],
804 ),
805 route(
806 "DELETE",
807 "/repos/:owner/:name/actions/variables/:setting",
808 Op::DeleteActionsVariable,
809 &[],
810 ),
811 route(
812 "GET",
813 "/workspaces/:workspace/actions/secrets",
814 Op::ListActionsSecrets,
815 &[],
816 ),
817 route(
818 "PUT",
819 "/workspaces/:workspace/actions/secrets/:setting",
820 Op::SetActionsSecret,
821 &[],
822 ),
823 route(
824 "DELETE",
825 "/workspaces/:workspace/actions/secrets/:setting",
826 Op::DeleteActionsSecret,
827 &[],
828 ),
829 route(
830 "GET",
831 "/workspaces/:workspace/actions/variables",
832 Op::ListActionsVariables,
833 &[],
834 ),
835 route(
836 "POST",
837 "/workspaces/:workspace/actions/variables",
838 Op::SetActionsVariable,
839 &[],
840 ),
841 route(
842 "PATCH",
843 "/workspaces/:workspace/actions/variables/:setting",
844 Op::SetActionsVariable,
845 &[],
846 ),
847 route(
848 "DELETE",
849 "/workspaces/:workspace/actions/variables/:setting",
850 Op::DeleteActionsVariable,
851 &[],
852 ),
Fast pages, required checks on the branch, self-hosted runners, honest incidents853 // Self-hosted runners: a repository's own, or a workspace's.
854 route("GET", "/repos/:owner/:name/actions/runners", Op::ListRunners, &[]),
855 route("POST", "/repos/:owner/:name/actions/runners/registration-token", Op::CreateRunnerRegistrationToken, &[]),
856 route("DELETE", "/repos/:owner/:name/actions/runners/:id", Op::RemoveRunner, &[]),
857 route("GET", "/repos/:owner/:name/actions/runner-settings", Op::GetRunnerSettings, &[]),
858 route("PATCH", "/repos/:owner/:name/actions/runner-settings", Op::UpdateRunnerSettings, &[]),
859 route("GET", "/workspaces/:workspace/actions/runners", Op::ListRunners, &[]),
860 route("POST", "/workspaces/:workspace/actions/runners/registration-token", Op::CreateRunnerRegistrationToken, &[]),
861 route("DELETE", "/workspaces/:workspace/actions/runners/:id", Op::RemoveRunner, &[]),
862 route("GET", "/workspaces/:workspace/actions/runner-settings", Op::GetRunnerSettings, &[]),
863 route("PATCH", "/workspaces/:workspace/actions/runner-settings", Op::UpdateRunnerSettings, &[]),
864 route("GET", "/workspaces/:workspace/actions/runner-groups", Op::ListRunnerGroups, &[]),
865 route("POST", "/workspaces/:workspace/actions/runner-groups", Op::CreateRunnerGroup, &[]),
866 route("PATCH", "/workspaces/:workspace/actions/runner-groups/:id", Op::UpdateRunnerGroup, &[]),
867 route("DELETE", "/workspaces/:workspace/actions/runner-groups/:id", Op::DeleteRunnerGroup, &[]),
Get started on mission control868 route("POST", "/repos/:owner/:name/plans", Op::PlanWork, &[]),
869 route("GET", "/repos/:owner/:name/plans/:plan", Op::GetPlan, &[]),
870 route(
871 "POST",
872 "/repos/:owner/:name/plans/:plan/apply",
873 Op::ApplyPlan,
874 &[],
875 ),
876 route(
877 "POST",
878 "/repos/:owner/:name/issues/:number/comments",
879 Op::AddComment,
880 &[],
881 ),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts882 route("PATCH", "/repos/:owner/:name/issues/comments/:comment_id", Op::EditComment, &[]),
883 route("DELETE", "/repos/:owner/:name/issues/comments/:comment_id", Op::DeleteComment, &[]),
Get started on mission control884 route(
885 "GET",
886 "/repos/:owner/:name/pulls",
887 Op::ListPullRequests,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar888 &[("state", "state"), ("label", "label"), ("milestone", "milestone"), ("base", "base")],
Get started on mission control889 ),
890 route(
891 "POST",
892 "/repos/:owner/:name/pulls",
893 Op::CreatePullRequest,
894 &[],
895 ),
896 route(
897 "GET",
898 "/repos/:owner/:name/pulls/:number",
899 Op::GetPullRequest,
900 &[],
901 ),
902 route(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar903 "PATCH",
904 "/repos/:owner/:name/pulls/:number",
905 Op::UpdatePullRequest,
906 &[],
907 ),
908 route(
Get started on mission control909 "GET",
910 "/repos/:owner/:name/pulls/:number/changes",
911 Op::GetPullRequestChanges,
912 &[],
913 ),
914 route(
915 "POST",
916 "/repos/:owner/:name/pulls/:number/reviews",
917 Op::ReviewPullRequest,
918 &[],
919 ),
920 route(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar921 "POST",
922 "/repos/:owner/:name/pulls/:number/requested_reviewers",
923 Op::RequestReviewers,
924 &[],
925 ),
926 route(
927 "DELETE",
928 "/repos/:owner/:name/pulls/:number/requested_reviewers",
929 Op::RemoveRequestedReviewers,
930 &[],
931 ),
932 route(
Get started on mission control933 "GET",
934 "/repos/:owner/:name/pulls/:number/session",
935 Op::ReadSession,
936 &[("after", "after")],
937 ),
938 route(
939 "POST",
940 "/repos/:owner/:name/pulls/:number/session",
941 Op::RecordSession,
942 &[],
943 ),
944 route(
945 "POST",
946 "/repos/:owner/:name/pulls/:number/ready",
947 Op::MarkPullRequestReady,
948 &[],
949 ),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts950 route("POST", "/repos/:owner/:name/pulls/:number/draft", Op::ConvertPullRequestToDraft, &[]),
Get started on mission control951 route(
952 "POST",
953 "/repos/:owner/:name/pulls/:number/close",
954 Op::ClosePullRequest,
955 &[],
956 ),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts957 route("POST", "/repos/:owner/:name/pulls/:number/reopen", Op::ReopenPullRequest, &[]),
Get started on mission control958 route(
959 "POST",
960 "/repos/:owner/:name/pulls/:number/merge",
961 Op::MergePullRequest,
962 &[],
963 ),
964];
965
966impl Route {
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts967 /// Whether the route answers success with `204` and no body, as
968 /// GitHub's address for the same does. MCP still answers `true`.
969 pub fn no_content(&self) -> bool {
970 self.op == Op::DeleteComment
971 }
972
Get started on mission control973 /// The names of the route's path parameters, in order.
974 pub fn params(&self) -> impl Iterator<Item = &'static str> {
975 self.path
976 .split('/')
977 .filter_map(|segment| segment.strip_prefix(':'))
978 }
979
980 /// The values of the path parameters, if `path` is this route's.
981 fn matches<'a>(&self, path: &'a str) -> Option<Vec<(&'static str, &'a str)>> {
982 let mut values = Vec::new();
983 let mut actual = path.trim_end_matches('/').split('/');
984 for expected in self.path.split('/') {
985 let segment = actual.next()?;
986 match expected.strip_prefix(':') {
987 Some(name) if !segment.is_empty() => values.push((name, segment)),
988 Some(_) => return None,
989 None if expected == segment => {}
990 None => return None,
991 }
992 }
993 actual.next().is_none().then_some(values)
994 }
995}
996
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look997/// A path segment with its `%XX` escapes decoded; as given when that is not
998/// UTF-8.
999fn percent_decoded(segment: &str) -> String {
1000 let bytes = segment.as_bytes();
1001 let mut out = Vec::with_capacity(bytes.len());
1002 let mut i = 0;
1003 while i < bytes.len() {
1004 let escaped = (bytes[i] == b'%')
1005 .then(|| segment.get(i + 1..i + 3))
1006 .flatten()
1007 .filter(|hex| hex.bytes().all(|byte| byte.is_ascii_hexdigit()))
1008 .and_then(|hex| u8::from_str_radix(hex, 16).ok());
1009 match escaped {
1010 Some(byte) => {
1011 out.push(byte);
1012 i += 3;
1013 }
1014 None => {
1015 out.push(bytes[i]);
1016 i += 1;
1017 }
1018 }
1019 }
1020 String::from_utf8(out).unwrap_or_else(|_| segment.to_owned())
1021}
1022
Get started on mission control1023/// The route for a request, and the operation input it describes.
1024///
1025/// The input is the JSON body, overlaid with the query parameters the route
1026/// reads and then with what the path names: `owner` and `name` become
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1027/// `repo`, as does a team's `repo` with its `workspace`, and `number`
1028/// becomes an integer.
Get started on mission control1029pub fn resolve(
1030 method: &str,
1031 path: &str,
1032 query: &[(String, String)],
1033 body: Value,
1034) -> Option<(&'static Route, Value)> {
1035 let (route, params) = ROUTES
1036 .iter()
1037 .filter(|route| route.method == method)
1038 .find_map(|route| Some((route, route.matches(path)?)))?;
1039
1040 let mut input = match body {
1041 Value::Object(fields) => fields,
1042 _ => Map::new(),
1043 };
1044 for (name, key) in route.query {
1045 if let Some((_, value)) = query.iter().find(|(query_name, _)| query_name == name) {
1046 input.insert((*key).to_owned(), Value::String(value.clone()));
1047 }
1048 }
1049 let param = |wanted: &str| {
1050 params
1051 .iter()
1052 .find(|(name, _)| *name == wanted)
1053 .map(|(_, value)| *value)
1054 };
1055 if let (Some(owner), Some(name)) = (param("owner"), param("name")) {
1056 input.insert("repo".to_owned(), Value::String(format!("{owner}/{name}")));
1057 }
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb971058 // Every other name the path gives, under that name; the ones below that
1059 // need more (a repository, a number, an encoded name) are set after.
1060 for (key, value) in &params {
1061 if !matches!(*key, "owner" | "name") {
1062 input.insert((*key).to_owned(), Value::String(percent_decoded(value)));
Docs worth reading, and kept that way1063 }
Get started on mission control1064 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1065 // A repository of a team's workspace, named by itself.
1066 if let (Some(workspace), Some(name)) = (param("workspace"), param("repo")) {
1067 input.insert("repo".to_owned(), Value::String(format!("{workspace}/{name}")));
1068 }
1069 // A branch name may hold slashes, sent URL-encoded as one segment, and
1070 // a label's name spaces.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1071 if let Some(branch) = param("branch") {
1072 input.insert("branch".to_owned(), Value::String(percent_decoded(branch)));
1073 }
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb971074 // An environment's name may hold slashes and spaces, URL-encoded.
1075 if let Some(environment) = param("environment") {
1076 input.insert("environment".to_owned(), Value::String(percent_decoded(environment)));
1077 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1078 if let Some(label) = param("label") {
1079 input.insert("label".to_owned(), Value::String(percent_decoded(label)));
1080 }
1081 if let Some(milestone) = param("milestone") {
1082 // Not a number: zero, which no milestone has.
1083 input.insert("milestone".to_owned(), milestone.parse::<u32>().unwrap_or(0).into());
1084 }
GitHub Actions on g1t, part two: running workflows1085 // GitHub says some things with the path alone.
1086 if route.path.ends_with("/enable") || route.path.ends_with("/disable") {
1087 input.insert("enabled".to_owned(), Value::Bool(route.path.ends_with("/enable")));
1088 }
1089 if route.path.ends_with("/rerun-failed-jobs") {
1090 input.insert("failed_only".to_owned(), Value::Bool(true));
1091 }
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)1092 if route.path.ends_with("/force-cancel") {
1093 input.insert("force".to_owned(), Value::Bool(true));
1094 }
API: notifications over REST and MCP, with notifications scopes1095 // Unsaving and waking a thread are a DELETE of what PUT made.
1096 if route.method == "DELETE" && route.path.ends_with("/saved") {
1097 input.insert("saved".to_owned(), Value::Bool(false));
1098 }
1099 if route.method == "DELETE" && route.path.ends_with("/snooze") {
1100 input.remove("until");
1101 }
Get started on mission control1102 if let Some(number) = param("number") {
1103 // Not a number: zero, which no issue or pull request has.
1104 input.insert(
1105 "number".to_owned(),
1106 number.parse::<u32>().unwrap_or(0).into(),
1107 );
1108 }
1109 Some((route, Value::Object(input)))
1110}
1111
1112#[cfg(test)]
1113mod tests {
1114 use serde_json::json;
1115
1116 use super::*;
1117
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb971118 /// Every name a route's path gives reaches the operation: a name left
1119 /// off the lists above is dropped, and the operation answers that it
1120 /// was not given (the project routes were, until this test).
1121 #[test]
1122 fn every_path_parameter_reaches_the_input() {
1123 for route in ROUTES.iter() {
1124 let names: Vec<&str> = route.path.split('/').filter_map(|part| part.strip_prefix(':')).collect();
1125 if names.is_empty() {
1126 continue;
1127 }
1128 let path: String = route
1129 .path
1130 .split('/')
1131 .map(|part| match part.strip_prefix(':') {
1132 Some("number" | "milestone") => "7".to_owned(),
1133 Some(name) => format!("{name}-x"),
1134 None => part.to_owned(),
1135 })
1136 .collect::<Vec<_>>()
1137 .join("/");
1138 let (found, input) = resolve(route.method, &path, &[], json!({})).unwrap();
1139 // A path two routes could take is checked under the first.
1140 if found.path != route.path {
1141 continue;
1142 }
1143 for name in names {
1144 let key = match name {
1145 "owner" | "name" => "repo",
1146 "repo" if names_has_workspace(route.path) => "repo",
1147 other => other,
1148 };
1149 assert!(
1150 input.get(key).is_some_and(|value| !value.is_null()),
1151 "{} {}: :{name} does not reach the input",
1152 route.method,
1153 route.path
1154 );
1155 }
1156 }
1157 }
1158
1159 fn names_has_workspace(path: &str) -> bool {
1160 path.split('/').any(|part| part == ":workspace")
1161 }
1162
Get started on mission control1163 #[test]
1164 fn a_path_resolves_to_its_operation_and_input() {
1165 let (route, input) = resolve(
1166 "POST",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1167 "/repos/flagon-io/hello/pulls/14/merge",
Get started on mission control1168 &[],
1169 json!({ "keep_issue_open": true, "number": 99, "repo": "someone/else" }),
1170 )
1171 .unwrap();
1172 assert_eq!(route.op, Op::MergePullRequest);
1173 // What the path names wins over the body.
1174 assert_eq!(
1175 input,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1176 json!({ "keep_issue_open": true, "number": 14, "repo": "flagon-io/hello" })
Get started on mission control1177 );
1178 }
1179
1180 #[test]
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1181 fn a_branch_with_slashes_is_one_encoded_segment() {
1182 let (route, input) = resolve(
1183 "POST",
1184 "/repos/flagon-io/hello/branches/feature%2Flogin/rename",
1185 &[],
1186 json!({ "new_name": "feature/sign-in" }),
1187 )
1188 .unwrap();
1189 assert_eq!(route.op, Op::RenameBranch);
1190 assert_eq!(
1191 input,
1192 json!({ "new_name": "feature/sign-in", "branch": "feature/login", "repo": "flagon-io/hello" })
1193 );
1194 assert_eq!(percent_decoded("100%"), "100%");
1195 assert_eq!(percent_decoded("a%2bb%zz"), "a+b%zz");
1196 }
1197
1198 #[test]
1199 fn a_collaborator_is_named_by_username() {
1200 let (route, input) = resolve(
1201 "PATCH",
1202 "/repos/flagon-io/hello/collaborators/ada",
1203 &[],
1204 json!({ "role": "maintain" }),
1205 )
1206 .unwrap();
1207 assert_eq!(route.op, Op::UpdateCollaborator);
1208 assert_eq!(input, json!({ "role": "maintain", "username": "ada", "repo": "flagon-io/hello" }));
1209 let (route, input) = resolve("DELETE", "/user/repository_invitations/rin_1", &[], Value::Null).unwrap();
1210 assert_eq!(route.op, Op::DeclineRepoInvitation);
1211 assert_eq!(input, json!({ "id": "rin_1" }));
1212 }
1213
1214 #[test]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1215 fn teams_are_addressed_by_workspace_and_slug() {
1216 let query = [("q".to_owned(), "back".to_owned())];
1217 let (route, input) = resolve("GET", "/workspaces/acme/teams", &query, Value::Null).unwrap();
1218 assert_eq!(route.op, Op::ListTeams);
1219 assert_eq!(input, json!({ "query": "back", "workspace": "acme" }));
1220 let (route, input) = resolve("PATCH", "/workspaces/acme/teams/backend", &[], json!({ "name": "Back end" })).unwrap();
1221 assert_eq!(route.op, Op::UpdateTeam);
1222 assert_eq!(input, json!({ "name": "Back end", "workspace": "acme", "team": "backend" }));
1223 let (route, input) =
1224 resolve("PUT", "/workspaces/acme/teams/backend/members/ana", &[], json!({ "role": "maintainer" })).unwrap();
1225 assert_eq!(route.op, Op::SetTeamMember);
1226 assert_eq!(input, json!({ "role": "maintainer", "workspace": "acme", "team": "backend", "username": "ana" }));
1227 let query = [("include_child_teams".to_owned(), "true".to_owned())];
1228 let (route, input) = resolve("GET", "/workspaces/acme/teams/backend/members", &query, Value::Null).unwrap();
1229 assert_eq!(route.op, Op::ListTeamMembers);
1230 assert_eq!(input, json!({ "include_child_teams": "true", "workspace": "acme", "team": "backend" }));
1231 // A repository is named by itself, in the team's workspace.
1232 let (route, input) =
1233 resolve("PUT", "/workspaces/acme/teams/backend/repos/rocket", &[], json!({ "role": "write" })).unwrap();
1234 assert_eq!(route.op, Op::SetTeamRepo);
1235 assert_eq!(input, json!({ "role": "write", "workspace": "acme", "team": "backend", "repo": "acme/rocket" }));
1236 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
1237 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend/repos/rocket"), Op::RemoveTeamRepo);
1238 assert_eq!(op("GET", "/workspaces/acme/teams/backend/teams"), Op::ListChildTeams);
1239 assert_eq!(op("GET", "/workspaces/acme/teams/backend/repos"), Op::ListTeamRepos);
1240 assert_eq!(op("PUT", "/workspaces/acme/teams/backend/review_assignment"), Op::SetTeamReviewAssignment);
1241 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend"), Op::DeleteTeam);
1242 assert_eq!(op("POST", "/workspaces/acme/teams"), Op::CreateTeam);
1243 assert_eq!(op("GET", "/workspaces/acme/teams/backend"), Op::GetTeam);
1244 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend/members/ana"), Op::RemoveTeamMember);
1245 let (route, input) = resolve("GET", "/workspaces/acme/members/ana/teams", &[], Value::Null).unwrap();
1246 assert_eq!(route.op, Op::ListUserTeams);
1247 assert_eq!(input, json!({ "workspace": "acme", "username": "ana" }));
1248 }
1249
1250 #[test]
1251 fn reviewers_are_requested_and_code_owners_checked_on_a_repository() {
1252 let body = json!({ "reviewers": ["ana"], "team_reviewers": ["backend"] });
1253 let (route, input) = resolve("POST", "/repos/acme/rocket/pulls/7/requested_reviewers", &[], body.clone()).unwrap();
1254 assert_eq!(route.op, Op::RequestReviewers);
1255 assert_eq!(
1256 input,
1257 json!({ "reviewers": ["ana"], "team_reviewers": ["backend"], "repo": "acme/rocket", "number": 7 })
1258 );
1259 let (route, _) = resolve("DELETE", "/repos/acme/rocket/pulls/7/requested_reviewers", &[], body).unwrap();
1260 assert_eq!(route.op, Op::RemoveRequestedReviewers);
1261 let query = [("ref".to_owned(), "main".to_owned())];
1262 let (route, input) = resolve("GET", "/repos/acme/rocket/codeowners/errors", &query, Value::Null).unwrap();
1263 assert_eq!(route.op, Op::GetCodeownersErrors);
1264 assert_eq!(input, json!({ "ref": "main", "repo": "acme/rocket" }));
1265 }
1266
1267 #[test]
API: notifications over REST and MCP, with notifications scopes1268 fn notifications_are_addressed_as_threads_and_by_issue() {
1269 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1", &[], Value::Null).unwrap();
1270 assert_eq!(route.op, Op::MarkThreadDone);
1271 assert_eq!(input, json!({ "id": "ntf_1" }));
1272 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1/saved", &[], Value::Null).unwrap();
1273 assert_eq!(route.op, Op::SaveThread);
1274 assert_eq!(input, json!({ "id": "ntf_1", "saved": false }));
1275 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1/snooze", &[], json!({ "until": "x" })).unwrap();
1276 assert_eq!(route.op, Op::SnoozeThread);
1277 assert_eq!(input, json!({ "id": "ntf_1" }));
1278 let query = [("all".to_owned(), "true".to_owned()), ("per_page".to_owned(), "50".to_owned())];
1279 let (route, input) = resolve("GET", "/repos/acme/rocket/notifications", &query, Value::Null).unwrap();
1280 assert_eq!(route.op, Op::ListNotifications);
1281 assert_eq!(input, json!({ "all": "true", "per_page": "50", "repo": "acme/rocket" }));
1282 let (route, input) = resolve("PUT", "/repos/acme/rocket/issues/7/subscription", &[], json!({ "ignored": true })).unwrap();
1283 assert_eq!(route.op, Op::SetThreadSubscription);
1284 assert_eq!(input, json!({ "ignored": true, "number": 7, "repo": "acme/rocket" }));
1285 assert_eq!(resolve("GET", "/user/subscriptions", &[], Value::Null).unwrap().0.op, Op::ListWatchedRepos);
1286 }
1287
1288 #[test]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1289 fn labels_and_milestones_are_named_in_the_path() {
1290 let (route, input) = resolve("PATCH", "/repos/acme/web/labels/good%20first%20issue", &[], json!({ "color": "7057ff" })).unwrap();
1291 assert_eq!(route.op, Op::UpdateLabel);
1292 assert_eq!(input, json!({ "color": "7057ff", "label": "good first issue", "repo": "acme/web" }));
1293 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/7/labels/bug", &[], Value::Null).unwrap();
1294 assert_eq!(route.op, Op::RemoveIssueLabels);
1295 assert_eq!(input, json!({ "label": "bug", "number": 7, "repo": "acme/web" }));
1296 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/7/labels", &[], Value::Null).unwrap();
1297 assert_eq!(route.op, Op::RemoveIssueLabels);
1298 assert_eq!(input, json!({ "number": 7, "repo": "acme/web" }));
1299 let (route, _) = resolve("POST", "/repos/acme/web/labels/defaults", &[], Value::Null).unwrap();
1300 assert_eq!(route.op, Op::AddDefaultLabels);
1301 let (route, input) = resolve("PATCH", "/repos/acme/web/milestones/3", &[], json!({ "state": "closed" })).unwrap();
1302 assert_eq!(route.op, Op::UpdateMilestone);
1303 assert_eq!(input, json!({ "state": "closed", "milestone": 3, "repo": "acme/web" }));
1304 let (route, input) = resolve("PATCH", "/repos/acme/web/pulls/9", &[], json!({ "base": "release" })).unwrap();
1305 assert_eq!(route.op, Op::UpdatePullRequest);
1306 assert_eq!(input, json!({ "base": "release", "number": 9, "repo": "acme/web" }));
1307 }
1308
1309 #[test]
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts1310 fn pull_requests_reopen_and_turn_draft_and_comments_are_named_by_id() {
1311 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
1312 assert_eq!(op("POST", "/repos/acme/web/pulls/9/reopen"), Op::ReopenPullRequest);
1313 assert_eq!(op("POST", "/repos/acme/web/pulls/9/draft"), Op::ConvertPullRequestToDraft);
1314 assert_eq!(op("POST", "/repos/acme/web/pulls/9/close"), Op::ClosePullRequest);
1315 // Reopening and closing with a PATCH, as `state`.
1316 let (route, input) = resolve("PATCH", "/repos/acme/web/pulls/9", &[], json!({ "state": "open" })).unwrap();
1317 assert_eq!(route.op, Op::UpdatePullRequest);
1318 assert_eq!(input, json!({ "state": "open", "number": 9, "repo": "acme/web" }));
1319 let (route, input) =
1320 resolve("PATCH", "/repos/acme/web/issues/comments/cmt_1", &[], json!({ "body": "Better" })).unwrap();
1321 assert_eq!(route.op, Op::EditComment);
1322 assert_eq!(input, json!({ "body": "Better", "comment_id": "cmt_1", "repo": "acme/web" }));
1323 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/comments/cmt_1", &[], Value::Null).unwrap();
1324 assert_eq!(route.op, Op::DeleteComment);
1325 assert_eq!(input, json!({ "comment_id": "cmt_1", "repo": "acme/web" }));
1326 // Still an issue's comments, labels and subscription.
1327 assert_eq!(op("POST", "/repos/acme/web/issues/7/comments"), Op::AddComment);
1328 assert_eq!(op("DELETE", "/repos/acme/web/issues/7/labels"), Op::RemoveIssueLabels);
1329 assert_eq!(op("DELETE", "/repos/acme/web/issues/7/subscription"), Op::DeleteThreadSubscription);
1330 }
1331
1332 #[test]
Usage, Billing settings and prepaid AI credit; fixes from the UX audit1333 fn billing_is_addressed_by_workspace() {
1334 let query = [("from".to_owned(), "2026-10-01".to_owned()), ("products".to_owned(), "agent,sandboxes".to_owned())];
1335 let (route, input) = resolve("GET", "/workspaces/acme/usage", &query, Value::Null).unwrap();
1336 assert_eq!(route.op, Op::GetUsage);
1337 assert_eq!(input, json!({ "from": "2026-10-01", "products": "agent,sandboxes", "workspace": "acme" }));
1338 let (route, input) = resolve("PUT", "/workspaces/acme/budget", &[], json!({ "alerts": [50] })).unwrap();
1339 assert_eq!(route.op, Op::SetBudget);
1340 assert_eq!(input, json!({ "alerts": [50], "workspace": "acme" }));
1341 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
1342 assert_eq!(op("GET", "/workspaces/acme/budget"), Op::GetBudget);
1343 assert_eq!(op("GET", "/workspaces/acme/ai_credit"), Op::GetAiCredit);
1344 assert_eq!(op("POST", "/workspaces/acme/ai_credit/checkout"), Op::BuyAiCredit);
1345 assert_eq!(op("GET", "/workspaces/acme/invoices"), Op::ListInvoices);
1346 assert_eq!(op("GET", "/workspaces/acme/billing_details"), Op::GetBillingDetails);
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens1347 assert_eq!(op("GET", "/workspaces/acme/gateway/requests"), Op::ListGatewayRequests);
Usage, Billing settings and prepaid AI credit; fixes from the UX audit1348 }
1349
1350 #[test]
Merge checks: statuses and check runs on every commit1351 fn checks_are_at_githubs_addresses() {
1352 let sha = "a".repeat(40);
1353 let body = json!({ "state": "success", "context": "ci/build" });
1354 let (route, input) = resolve("POST", &format!("/repos/acme/web/statuses/{sha}"), &[], body).unwrap();
1355 assert_eq!(route.op, Op::Checks(ChecksOp::CreateCommitStatus));
1356 assert_eq!(input, json!({ "state": "success", "context": "ci/build", "sha": sha, "repo": "acme/web" }));
1357 let (route, input) = resolve("GET", "/repos/acme/web/commits/release%2F1.x/status", &[], Value::Null).unwrap();
1358 assert_eq!(route.op, Op::Checks(ChecksOp::GetCombinedStatus));
1359 assert_eq!(input, json!({ "ref": "release/1.x", "repo": "acme/web" }));
1360 let query = [("check_name".to_owned(), "lint".to_owned())];
1361 let (route, input) = resolve("GET", "/repos/acme/web/commits/main/check-runs", &query, Value::Null).unwrap();
1362 assert_eq!(route.op, Op::Checks(ChecksOp::ListCheckRunsForRef));
1363 assert_eq!(input, json!({ "check_name": "lint", "ref": "main", "repo": "acme/web" }));
1364 let (route, input) = resolve("PATCH", "/repos/acme/web/check-runs/cr_1", &[], json!({ "conclusion": "success" })).unwrap();
1365 assert_eq!(route.op, Op::Checks(ChecksOp::UpdateCheckRun));
1366 assert_eq!(input, json!({ "conclusion": "success", "id": "cr_1", "repo": "acme/web" }));
1367 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
1368 assert_eq!(op("POST", "/repos/acme/web/check-runs"), Op::Checks(ChecksOp::CreateCheckRun));
1369 assert_eq!(op("GET", "/repos/acme/web/check-runs/cr_1/annotations"), Op::Checks(ChecksOp::ListCheckRunAnnotations));
1370 assert_eq!(op("POST", "/repos/acme/web/check-suites/cs_1/rerequest"), Op::Checks(ChecksOp::RerequestCheckSuite));
1371 assert_eq!(op("GET", "/repos/acme/web/commits/main/check-suites"), Op::Checks(ChecksOp::ListCheckSuitesForRef));
1372 }
1373
1374 #[test]
Get started on mission control1375 fn query_parameters_are_renamed() {
1376 let query = [
1377 ("q".to_owned(), "parser".to_owned()),
1378 ("x".to_owned(), "y".to_owned()),
1379 ];
1380 let (route, input) = resolve("GET", "/repos", &query, Value::Null).unwrap();
1381 assert_eq!(route.op, Op::ListRepos);
1382 assert_eq!(input, json!({ "query": "parser" }));
1383 }
1384
1385 #[test]
1386 fn method_and_shape_must_match() {
1387 assert!(resolve("GET", "/repos/a/b/issues/1/close", &[], Value::Null).is_none());
1388 assert!(resolve("GET", "/repos/a", &[], Value::Null).is_none());
1389 assert!(resolve("GET", "/repos/a/b/issues/1/extra", &[], Value::Null).is_none());
1390 assert!(resolve("GET", "/repos/a/b/", &[], Value::Null).is_some());
1391 }
1392
1393 #[test]
1394 fn every_parameter_and_query_name_is_an_input() {
1395 for route in ROUTES {
1396 let properties = route.op.properties();
1397 for (_, key) in route.query {
1398 assert!(properties.contains_key(*key), "{}: {key}", route.path);
1399 }
1400 for name in route.params() {
1401 let covered = matches!(name, "owner" | "name") && properties.contains_key("repo")
1402 || properties.contains_key(name);
1403 assert!(covered, "{}: {name}", route.path);
1404 }
1405 }
1406 }
1407
1408 #[test]
1409 fn every_operation_has_a_route() {
1410 for op in Op::ALL {
1411 assert!(ROUTES.iter().any(|route| route.op == op), "{}", op.name());
1412 }
1413 }
1414}

This file's history is long; its oldest lines are credited to the oldest commit read.