pr_01m47d15m3e54sn21z27rpy5n9/apps/api/src/index.ts
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| API and MCP server, Rust identity service, registration, site redesign | 1 | import { Hono } from "hono"; |
| 2 | ||
| 3 | import { type Viewer, httpStatus, identityClient } from "@g1t/contracts"; | |
| 4 | ||
| 5 | import { handleMcp } from "./mcp"; | |
| 6 | import { type ApiEnv, operations, operationsByName } from "./operations"; | |
| 7 | ||
| 8 | type Input = Record<string, unknown>; | |
| 9 | type App = { Bindings: ApiEnv; Variables: { viewer: Viewer } }; | |
| 10 | ||
| 11 | /** | |
| 12 | * REST routes. Each maps an HTTP request onto one operation; `input` builds | |
| 13 | * the operation's input from the path, query string and JSON body. | |
| 14 | */ | |
| 15 | const ROUTES: { | |
| 16 | method: "GET" | "POST"; | |
| 17 | path: string; | |
| 18 | operation: string; | |
| 19 | input?: (params: Record<string, string>, query: Input, body: Input) => Input; | |
| 20 | }[] = [ | |
| 21 | { method: "GET", path: "/v1/user", operation: "whoami" }, | |
| 22 | { method: "GET", path: "/v1/repos", operation: "list_repos", input: (_p, q) => ({ query: q.q }) }, | |
| 23 | { method: "POST", path: "/v1/repos", operation: "create_repo", input: (_p, _q, b) => b }, | |
| 24 | { method: "GET", path: "/v1/repos/:owner/:name", operation: "get_repo", input: repo }, | |
| 25 | { method: "GET", path: "/v1/repos/:owner/:name/intents", operation: "list_intents", input: (p, q) => ({ ...repo(p), status: q.status }) }, | |
| 26 | { method: "POST", path: "/v1/repos/:owner/:name/intents", operation: "open_intent", input: (p, _q, b) => ({ ...b, ...repo(p) }) }, | |
| 27 | { method: "GET", path: "/v1/repos/:owner/:name/intents/:number", operation: "get_intent", input: (p) => ({ ...repo(p), number: Number(p.number) }) }, | |
| 28 | { method: "GET", path: "/v1/repos/:owner/:name/events", operation: "list_events", input: (p, q) => ({ ...repo(p), before: q.before }) }, | |
| 29 | { method: "POST", path: "/v1/intents/:intent_id/attempts", operation: "start_attempt", input: (p, _q, b) => ({ ...b, intent_id: p.intent_id }) }, | |
| 30 | { method: "GET", path: "/v1/attempts/:attempt_id", operation: "get_attempt", input: (p) => p }, | |
| 31 | { method: "GET", path: "/v1/attempts/:attempt_id/session", operation: "read_session", input: (p, q) => ({ ...p, after: Number(q.after) || 0 }) }, | |
| 32 | { method: "POST", path: "/v1/attempts/:attempt_id/session", operation: "record_session", input: (p, _q, b) => ({ ...b, ...p }) }, | |
| 33 | { method: "POST", path: "/v1/attempts/:attempt_id/submit", operation: "submit_attempt", input: (p, _q, b) => ({ ...b, ...p }) }, | |
| 34 | { method: "POST", path: "/v1/attempts/:attempt_id/abandon", operation: "abandon_attempt", input: (p) => p }, | |
| 35 | ]; | |
| 36 | ||
| 37 | function repo(params: Record<string, string>): Input { | |
| 38 | return { repo: `${params.owner}/${params.name}` }; | |
| 39 | } | |
| 40 | ||
| 41 | const app = new Hono<App>(); | |
| 42 | ||
| 43 | // `Authorization: Bearer g1t_…`. A missing token is an anonymous viewer; a | |
| 44 | // wrong one is rejected so a typo does not silently look signed out. | |
| 45 | app.use(async (c, next) => { | |
| 46 | const [scheme, token] = (c.req.header("authorization") ?? "").split(" "); | |
| 47 | let viewer: Viewer = null; | |
| 48 | if (scheme?.toLowerCase() === "bearer" && token) { | |
| 49 | viewer = await identityClient(c.env.IDENTITY).userForAccessToken(token); | |
| 50 | if (!viewer) { | |
| 51 | return c.json( | |
| 52 | { error: { code: "unauthenticated", message: "Invalid access token." } }, | |
| 53 | 401, | |
| 54 | ); | |
| 55 | } | |
| 56 | } | |
| 57 | c.set("viewer", viewer); | |
| 58 | await next(); | |
| 59 | }); | |
| 60 | ||
| 61 | app.all("*", async (c, next) => { | |
| 62 | if (new URL(c.req.url).hostname.startsWith("mcp.")) { | |
| 63 | return handleMcp(c.req.raw, c.env, c.get("viewer")); | |
| 64 | } | |
| 65 | await next(); | |
| 66 | }); | |
| 67 | ||
| 68 | app.get("/", (c) => | |
| 69 | c.json({ | |
| 70 | name: "g1t API", | |
| 71 | version: "v1", | |
| 72 | documentation: "https://g1t.sh/syntaqx/g1t", | |
| 73 | operations: operations.map(({ name, description }) => ({ name, description })), | |
| 74 | }), | |
| 75 | ); | |
| 76 | ||
| 77 | for (const route of ROUTES) { | |
| 78 | const operation = operationsByName.get(route.operation)!; | |
| 79 | app.on(route.method, route.path, async (c) => { | |
| 80 | let body: Input = {}; | |
| 81 | if (route.method === "POST") { | |
| 82 | try { | |
| 83 | body = await c.req.json(); | |
| 84 | } catch { | |
| 85 | // An empty or non-JSON body is treated as no input. | |
| 86 | } | |
| 87 | } | |
| 88 | const input = route.input?.(c.req.param(), c.req.query(), body) ?? {}; | |
| 89 | const outcome = await operation.run(c.env, c.get("viewer"), input); | |
| 90 | if (outcome.ok) return c.json(outcome.value); | |
| 91 | return c.json( | |
| 92 | { error: outcome.error }, | |
| 93 | httpStatus(outcome.error) as 401 | 403 | 404 | 409 | 422, | |
| 94 | ); | |
| 95 | }); | |
| 96 | } | |
| 97 | ||
| 98 | app.notFound((c) => | |
| 99 | c.json({ error: { code: "not_found", message: "No such endpoint." } }, 404), | |
| 100 | ); | |
| 101 | ||
| 102 | export default app; |