Skip to content

g1t/apps/api/src/responses.rs

335 lines16,698 bytesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API1//! Every response the REST routes give, run through the converter the API
2//! sends them with, checked for `camelCase` that would leak out.
3//!
4//! The samples are the reference's example responses, put back into the
5//! `camelCase` the services send (as serde's `rename_all` writes it) and,
6//! where an operation returns a contract type, decoded into that type and
7//! encoded again, so that every field the type has is sent, not only the
8//! ones an example shows.
9
Merge checks: statuses and check runs on every commit10use g1t_contracts::{access, actions, checks, codeowners, integrations, repos, rules, search, teams, webhooks, work};
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API11use g1t_kit::wire::{self, USER_KEYED};
12use serde::Serialize;
13use serde::de::DeserializeOwned;
14use serde_json::{Map, Value, json};
15
16use crate::openapi::document;
17use crate::operations::Op;
Merge checks: statuses and check runs on every commit18use crate::checks::ChecksOp;
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge19use crate::rules::RulesOp;
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca20use crate::deploy_keys::DeployKeysOp;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API21
22/// A key as `#[serde(rename_all = "camelCase")]` writes it.
23fn camel_key(key: &str) -> String {
24 let mut out = String::with_capacity(key.len());
25 let mut upper = false;
26 for c in key.chars() {
27 if c == '_' {
28 upper = true;
29 } else if upper {
30 out.extend(c.to_uppercase());
31 upper = false;
32 } else {
33 out.push(c);
34 }
35 }
36 out
37}
38
39/// A response as the services send it: `camelCase`, but for the maps the
40/// converter passes through, which are data.
41fn as_services_send(value: &Value) -> Value {
42 match value {
43 Value::Object(fields) => {
44 let mut out = Map::new();
45 for (key, value) in fields {
46 let user_keyed = value.is_object()
47 && (USER_KEYED.contains(&key.as_str()) || key.starts_with("by_"));
48 let value = if user_keyed { value.clone() } else { as_services_send(value) };
49 // A `by_…` map keeps its name in the converter's spelling.
50 let key = if key.starts_with("by_") { key.clone() } else { camel_key(key) };
51 out.insert(key, value);
52 }
53 Value::Object(out)
54 }
55 Value::Array(items) => Value::Array(items.iter().map(as_services_send).collect()),
56 other => other.clone(),
57 }
58}
59
60/// `value` decoded as `T` and encoded again, as the service would send it.
61fn through<T: DeserializeOwned + Serialize>(op: Op, value: Value) -> Value {
62 let decoded: T = serde_json::from_value(value)
63 .unwrap_or_else(|error| panic!("{}: the example is not a {}: {error}", op.name(), std::any::type_name::<T>()));
64 serde_json::to_value(decoded).unwrap()
65}
66
67/// What the service behind an operation sends, from its example.
68fn sample(op: Op, example: &Value) -> Value {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look69 // Types serde already writes in `snake_case`: a person, and who has
70 // access. Sent as they are.
71 let as_is = example.clone();
72 match op {
73 Op::Whoami => return through::<g1t_contracts::User>(op, as_is),
74 Op::ListCollaborators => return through::<access::RepoAccess>(op, as_is),
75 Op::AddCollaborator => return through::<access::Added>(op, as_is),
76 Op::UpdateCollaborator => return through::<access::Collaborator>(op, as_is),
77 Op::GetCollaboratorPermission => return through::<access::PermissionInfo>(op, as_is),
78 Op::ListRepoInvitations | Op::ListMyRepoInvitations => {
79 return through::<Vec<access::RepoInvitation>>(op, as_is);
80 }
81 Op::RevokeRepoInvitation | Op::AcceptRepoInvitation | Op::DeclineRepoInvitation => {
82 return through::<access::RepoInvitation>(op, as_is);
83 }
84 Op::ListOutsideCollaborators => return through::<Vec<access::OutsideCollaborator>>(op, as_is),
Merge main (membership, two-factor, GitHub repo roles) into tokens85 // Members, also `snake_case`.
86 Op::ListMembers => return through::<Vec<g1t_contracts::identity::Member>>(op, as_is),
87 Op::UpdateMember => return through::<g1t_contracts::identity::Member>(op, as_is),
88 Op::RemoveMember | Op::TransferOwnership | Op::LeaveWorkspace => return through::<bool>(op, as_is),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar89 // Teams and code owners, also `snake_case`.
90 Op::ListTeams | Op::ListChildTeams | Op::ListUserTeams => return through::<Vec<teams::Team>>(op, as_is),
91 Op::GetTeam | Op::CreateTeam | Op::UpdateTeam | Op::SetTeamReviewAssignment => {
92 return through::<teams::Team>(op, as_is);
93 }
94 Op::ListTeamMembers => return through::<Vec<teams::TeamMember>>(op, as_is),
95 Op::SetTeamMember => return through::<teams::TeamMember>(op, as_is),
96 Op::ListTeamRepos => return through::<Vec<teams::TeamRepo>>(op, as_is),
97 Op::SetTeamRepo => return through::<teams::TeamRepo>(op, as_is),
98 Op::DeleteTeam | Op::RemoveTeamMember | Op::RemoveTeamRepo => return through::<bool>(op, as_is),
99 Op::GetCodeownersErrors => return through::<codeowners::CodeOwnersReport>(op, as_is),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge100 // Rulesets travel in `snake_case` between services too.
101 Op::Rules(RulesOp::ListRepoRulesets | RulesOp::ListWorkspaceRulesets) => {
102 return through::<Vec<rules::Ruleset>>(op, as_is);
103 }
104 Op::Rules(
105 RulesOp::GetRepoRuleset
106 | RulesOp::CreateRepoRuleset
107 | RulesOp::UpdateRepoRuleset
108 | RulesOp::GetWorkspaceRuleset
109 | RulesOp::CreateWorkspaceRuleset
110 | RulesOp::UpdateWorkspaceRuleset,
111 ) => return through::<rules::Ruleset>(op, as_is),
112 Op::Rules(RulesOp::GetBranchRules) => return through::<rules::EffectiveRules>(op, as_is),
113 Op::Rules(RulesOp::ListRuleEvaluations | RulesOp::ListWorkspaceRuleEvaluations) => {
114 return through::<rules::EvaluationPage>(op, as_is);
115 }
116 // Built by the API itself.
117 Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset) => return as_is,
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97118 // Deployments travel in `snake_case` between services too.
119 Op::Deployments(_) => return as_is,
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2120 // Artifacts are shaped by the API itself, in `snake_case`.
121 Op::Artifacts(_) => return as_is,
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca122 // Deploy keys travel in `snake_case` from identity.
123 Op::DeployKeys(DeployKeysOp::ListDeployKeys) => return through::<Vec<g1t_contracts::deploy_keys::DeployKey>>(op, as_is),
124 Op::DeployKeys(DeployKeysOp::GetDeployKey | DeployKeysOp::CreateDeployKey) => {
125 return through::<g1t_contracts::deploy_keys::DeployKey>(op, as_is);
126 }
127 Op::DeployKeys(DeployKeysOp::DeleteDeployKey) => return through::<bool>(op, as_is),
Merge packages: roles, Actions access, source label, soft delete, API128 // Packages are shaped by the API itself, in `snake_case`.
129 Op::Packages(_) => return as_is,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily130 // Built by the API itself, in `snake_case`.
131 Op::ListSecurityAlerts => return through::<Vec<crate::alerts::SecurityAlert>>(op, as_is),
132 Op::DismissSecurityAlert | Op::ReopenSecurityAlert => {
133 return through::<crate::alerts::SecurityAlert>(op, as_is);
134 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look135 _ => {}
136 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar137 let mut sent = as_services_send(example);
138 // A pull request's code owners are `snake_case` inside it.
139 if op == Op::GetPullRequest
140 && let Some(code_owners) = example.get("code_owners")
141 {
142 sent["codeOwners"] = code_owners.clone();
143 }
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API144 match op {
Merge branch 'worktree-agent-ad7c6d88d93adc817'145 Op::GetWorkspace | Op::CreateWorkspace | Op::UpdateWorkspace => through::<g1t_contracts::identity::Workspace>(op, sent),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API146 Op::ListRepos => through::<Vec<repos::Repo>>(op, sent),
Search across all of g1t, Explore, and a command palette147 Op::Search => through::<search::SearchResults>(op, sent),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look148 Op::GetRepo
149 | Op::CreateRepo
150 | Op::UpdateRepo
151 | Op::TransferRepo
152 | Op::RenameRepo
153 | Op::RenameBranch
154 | Op::ArchiveRepo
155 | Op::UnarchiveRepo
156 | Op::SetRepoVisibility
157 | Op::RestoreRepo => through::<repos::Repo>(op, sent),
158 Op::DeleteRepo => through::<repos::DeletedRepo>(op, sent),
159 Op::ListDeletedRepos => through::<Vec<repos::DeletedRepo>>(op, sent),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API160 Op::GetRepoSettings | Op::UpdateRepoSettings => through::<work::RepoSettings>(op, sent),
Fast pages, required checks on the branch, self-hosted runners, honest incidents161 Op::ListCheckNames => through::<Vec<work::SeenCheck>>(op, sent),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API162 Op::GetMergeQueue => through::<work::QueueView>(op, sent),
163 Op::ListIssues => through::<Vec<work::Issue>>(op, sent),
164 Op::CreateIssue | Op::UpdateIssue | Op::CloseIssue | Op::ReopenIssue => {
165 through::<work::Issue>(op, sent)
166 }
167 Op::GetIssue => through::<work::IssueDetail>(op, sent),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step168 Op::Delegate => through::<work::Delegated>(op, sent),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API169 Op::ListPullRequests => through::<Vec<work::Pull>>(op, sent),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar170 Op::UpdatePullRequest => through::<work::Pull>(op, sent),
171 Op::ListLabels | Op::AddDefaultLabels | Op::ListIssueLabels => through::<Vec<work::Label>>(op, sent),
172 Op::CreateLabel | Op::UpdateLabel => through::<work::Label>(op, sent),
173 Op::ListMilestones => through::<Vec<work::Milestone>>(op, sent),
174 Op::CreateMilestone | Op::UpdateMilestone => through::<work::Milestone>(op, sent),
175 Op::GetMilestone => through::<work::MilestoneDetail>(op, sent),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API176 Op::GetPullRequest => through::<work::PullDetail>(op, sent),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar177 Op::MarkPullRequestReady
178 | Op::ClosePullRequest
179 | Op::MergePullRequest
180 | Op::AssignIssue
181 | Op::RequestReviewers
182 | Op::RemoveRequestedReviewers => {
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API183 through::<work::Pull>(op, sent)
184 }
185 Op::ListWorkflows => through::<Vec<actions::Workflow>>(op, sent),
186 Op::ListWorkflowRuns => through::<Vec<actions::WorkflowRun>>(op, sent),
187 Op::GetWorkflowRun => through::<actions::RunDetail>(op, sent),
188 Op::GetJobLogs => through::<actions::JobLog>(op, sent),
189 Op::DispatchWorkflow | Op::CancelWorkflowRun | Op::RerunWorkflowRun => {
190 through::<actions::WorkflowRun>(op, sent)
191 }
192 Op::ListActionsSecrets | Op::ListActionsVariables => through::<Vec<actions::Setting>>(op, sent),
Fast pages, required checks on the branch, self-hosted runners, honest incidents193 Op::ListRunners => through::<Vec<g1t_contracts::runners::Runner>>(op, sent),
194 Op::ListRunnerGroups => through::<Vec<g1t_contracts::runners::RunnerGroup>>(op, sent),
195 Op::CreateRunnerGroup | Op::UpdateRunnerGroup => through::<g1t_contracts::runners::RunnerGroup>(op, sent),
196 Op::GetRunnerSettings | Op::UpdateRunnerSettings => through::<g1t_contracts::runners::RunnerSettings>(op, sent),
197 Op::CreateRunnerRegistrationToken => through::<g1t_contracts::runners::RegistrationToken>(op, sent),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API198 Op::ListWebhooks => through::<Vec<webhooks::Hook>>(op, sent),
199 Op::ListIntegrations => through::<Vec<integrations::Connection>>(op, sent),
200 Op::GetModelRoutes | Op::SetModelRoutes => through::<Vec<integrations::ModelRoute>>(op, sent),
201 Op::ListEvents => through::<Vec<g1t_contracts::events::Event>>(op, sent),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look202 Op::ListEmails | Op::AddEmail | Op::RemoveEmail | Op::UpdateEmailSettings => {
203 through::<g1t_contracts::accounts::AccountEmails>(op, sent)
204 }
205 Op::ListInvites => through::<g1t_contracts::identity::InvitesOverview>(op, sent),
206 Op::CreateInvite | Op::RevokeInvite | Op::InviteMember | Op::RevokeWorkspaceInvite => {
207 through::<g1t_contracts::identity::Invite>(op, sent)
208 }
209 Op::ListWorkspaceInvites => through::<Vec<g1t_contracts::identity::Invite>>(op, sent),
API: notifications over REST and MCP, with notifications scopes210 Op::ListNotifications => through::<g1t_contracts::inbox::InboxPage>(op, sent),
211 Op::GetNotificationThread | Op::MarkThreadRead | Op::MarkThreadDone | Op::SaveThread | Op::SnoozeThread => {
212 through::<g1t_contracts::inbox::InboxThread>(op, sent)
213 }
214 Op::GetThreadSubscription | Op::SetThreadSubscription | Op::DeleteThreadSubscription => {
215 through::<g1t_contracts::inbox::ThreadSubscription>(op, sent)
216 }
Merge checks: statuses and check runs on every commit217 Op::Checks(ChecksOp::CreateCommitStatus) => through::<work::CommitStatus>(op, sent),
218 Op::Checks(ChecksOp::ListCommitStatuses) => through::<Vec<work::CommitStatus>>(op, sent),
219 Op::Checks(ChecksOp::GetCombinedStatus) => through::<checks::CombinedStatus>(op, sent),
220 Op::Checks(ChecksOp::CreateCheckRun | ChecksOp::UpdateCheckRun | ChecksOp::GetCheckRun) => {
221 through::<checks::CommitCheckRun>(op, sent)
222 }
223 Op::Checks(ChecksOp::ListCheckRunAnnotations) => through::<Vec<checks::CheckAnnotation>>(op, sent),
224 Op::Checks(ChecksOp::ListCheckRunsForRef) => through::<checks::CheckRunList>(op, sent),
225 Op::Checks(ChecksOp::ListCheckSuitesForRef) => through::<checks::CheckSuiteList>(op, sent),
226 Op::Checks(ChecksOp::GetCheckSuite) => through::<checks::CommitCheckSuite>(op, sent),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API227 _ => sent,
228 }
229}
230
231/// Every key of `example`, as paths, outside the maps passed through.
232fn paths(value: &Value, path: &str, out: &mut Vec<String>) {
233 match value {
234 Value::Object(fields) => {
235 for (key, value) in fields {
236 let here = format!("{path}.{key}");
237 out.push(here.clone());
238 let user_keyed = value.is_object()
239 && (USER_KEYED.contains(&key.as_str()) || key.starts_with("by_"));
240 if !user_keyed {
241 paths(value, &here, out);
242 }
243 }
244 }
245 Value::Array(items) => {
246 for item in items {
247 paths(item, &format!("{path}[]"), out);
248 }
249 }
250 _ => {}
251 }
252}
253
254#[test]
255fn no_route_answers_with_camel_case() {
256 let document = document();
257 let (mut checked, mut converted) = (0, 0);
258 for (path, methods) in document["paths"].as_object().unwrap() {
259 for (method, operation) in methods.as_object().unwrap() {
260 let example = &operation["responses"]["200"]["content"]["application/json"]["example"];
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step261 let tool = operation["x-operation"].as_str().unwrap_or_default();
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API262 let Some(op) = Op::by_name(tool) else {
263 // Device sign-in, which is written in `snake_case` by hand.
264 assert!(wire::camel_case_keys(example).is_empty(), "{method} {path}");
265 continue;
266 };
267 let sample = sample(op, example);
268 converted += wire::camel_case_keys(&sample).len();
269 let sent = wire::snake_case(sample);
270 let leaked = wire::camel_case_keys(&sent);
271 assert!(leaked.is_empty(), "{method} {path} sends {leaked:?}");
272 // The reference shows what is sent: each of its names is one.
273 let (mut shown, mut real) = (Vec::new(), Vec::new());
274 paths(example, "", &mut shown);
275 paths(&sent, "", &mut real);
276 for name in shown {
277 assert!(real.contains(&name), "{method} {path}: the reference shows {name}, which is not sent");
278 }
279 checked += 1;
280 }
281 }
282 assert!(checked >= Op::ALL.len());
283 // The samples are in the services' spelling, so there was something to
284 // convert.
285 assert!(converted > 100, "{converted}");
286}
287
288#[test]
289fn every_route_has_a_sample() {
290 let document = document();
291 for route in crate::rest::ROUTES {
292 let path = route
293 .path
294 .split('/')
295 .map(|segment| match segment.strip_prefix(':') {
296 Some(name) => format!("{{{name}}}"),
297 None => segment.to_owned(),
298 })
299 .collect::<Vec<_>>()
300 .join("/");
301 let example = &document["paths"][&path][route.method.to_lowercase()]["responses"]["200"]
302 ["content"]["application/json"]["example"];
303 assert!(!example.is_null(), "{} {path}", route.method);
304 }
305}
306
307#[test]
308fn errors_and_reports_are_snake_case() {
309 let failure = g1t_contracts::Failure {
310 code: g1t_contracts::FailureCode::NotFound,
311 message: "No such endpoint.".to_owned(),
312 };
313 assert!(wire::camel_case_keys(&wire::snake_case(json!({ "error": failure }))).is_empty());
314}
315
316#[test]
317fn a_job_spec_keeps_github_s_spelling() {
318 let spec = json!({
319 "job": "job_1",
320 "spec": { "runs-on": "ubuntu-latest", "timeoutMinutes": 5 },
321 "workflow": { "env": { "nodeEnv": "x" } },
322 "github": { "eventName": "push", "headRef": "" },
323 "event": { "pull_request": { "headSha": "x" } },
324 "contexts": { "inputs": { "dryRun": true }, "matrix": { "nodeVersion": 20 } },
325 "checkout": { "ref": "main" },
326 "timeoutMinutes": 30,
327 "masks": [],
328 });
329 let sent = wire::snake_case_keeping(spec.clone(), crate::JOB_SPEC_AS_GIVEN);
330 assert_eq!(sent["timeout_minutes"], 30);
331 assert!(sent.get("timeoutMinutes").is_none());
332 for kept in ["spec", "workflow", "github", "event", "contexts", "checkout"] {
333 assert_eq!(sent[kept], spec[kept], "{kept}");
334 }
335}

This file's history is long; its oldest lines are credited to the oldest commit read.