Skip to content

fix(api): restore the spend-cap routes and repair two generator bugs - #15

Merged
senamakel merged 1 commit into
tinyhumansai:mainfrom
senamakel:fix/spec-regeneration
Aug 20, 2026
Merged

senamakel merged 1 commit into
tinyhumansai:mainfrom
senamakel:fix/spec-regeneration

Conversation

@senamakel

Copy link
Copy Markdown
Member

Overview

#14 merged a regeneration that had been run against a backend checkout sitting on main rather than on the spend-caps feature branch. The output therefore did not contain the routes that PR existed to add, and the pinned counts were lowered to match — UNEXPOSED_ROUTES.len() went to 44, identical to main, so the regression read as "no change".

I pushed a corrected regeneration to #14, but it landed two seconds after that PR was merged on the stale head, so the fix missed the merge. This restores it.

Changes

  • Regenerated from the spec of the backend commit that actually shipped the routes. Relative to main:

    main this branch removed
    PUBLIC_ROUTES 212 215 none
    UNEXPOSED_ROUTES 44 49 none

    GET/PUT /spend-caps and PUT /api-keys/{keyId}/spend-caps are public; PATCH /admin/users/{userId}/spend-caps is in the denylist. Neither list loses an entry.

  • isCustomLlmSecretOperation made the script unrunnable. It incremented excludedAdminOperationCount, a const declared further down the same function, so every invocation died with a TDZ ReferenceError. The count is derived from excludedOperations anyway, so the increment was redundant — removed. This is why the bad manifest on main could not simply be regenerated in place.

  • SUPPLEMENTAL_PUBLIC_OPERATIONS was appended unconditionally. That list exists for operations the deployed document omits. Feeding a local spec that does describe them (the team routes and /webhooks/core/*, both added to the list recently) emitted 9 duplicate routes and tripped generated_rust_routes_match_the_public_manifest. Now skips any entry the spec already covers.

Testing

  • cargo test — 24 suites, 0 failures
  • cargo clippy --all-targets -- -D warnings clean
  • cargo fmt --check clean
  • Re-ran the generator over the committed output and confirmed it is idempotent (no diff on a second run)
  • Diffed both route lists against origin/main programmatically to confirm nothing was dropped

Notes

The UNEXPOSED_ROUTES.len() pin is what makes this class of mistake findable at all, and it is worth keeping strict — but note it did not prevent the bad merge, because lowering the pin to match the bad output makes the suite green. The stronger invariant is the one used above: the denylist may gain entries but must never lose them relative to main. Worth encoding as a test if this recurs.

Follows tinyhumansai/backend#1285 (merged) and #14 (merged).

Related Issues

The OpenAPI manifest and generated route tables are updated to include a new spend caps resource with GET and PUT endpoints, plus a PUT endpoint on API keys for setting spend caps. The sync script now deduplicates supplemental routes that already appear in the spec, preventing duplicate entries in the generated route list. Several admin and webhook routes are also added to the unexposed routes list, and the corresponding assertion counts are updated to match the regenerated manifest.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@senamakel senamakel added bug Something isn't working priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition. labels Aug 20, 2026
@coderabbitai

coderabbitai Bot commented Aug 20, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Your included review limit has been reached.

You’re in a promotional period — use the checkbox below to run this review for free:

  • Run review for free

On-demand reviews are free for the next 31 days. After that, they cost $0.25 per reviewed file.

How can I continue?

Run this review now using the option above, or comment @coderabbitai review --use-credits.

You can also wait for the limit to reset (next review available in 26 minutes), then comment @coderabbitai review or push new commits to the PR.

An organization admin can change what happens after included review limits in Billing.

How do review limits work?

CodeRabbit enforces per-developer PR review limits within each organization.

For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b0d5c8d3-57bd-4590-8ecb-841804ec38dc

📥 Commits

Reviewing files that changed from the base of the PR and between 627281b and 38329dd.

📒 Files selected for processing (5)
  • api/tinyhumans.backend.json
  • scripts/sync-openapi.mjs
  • src/generated_public_routes.rs
  • src/lib.rs
  • tests/openapi_sync.rs

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking. Approving.

$0.0000 · 0 in / 0 out · 231 embedded · openrouter/openai/text-embedding-3-small

@tinysweeper

tinysweeper Bot commented Aug 20, 2026

Copy link
Copy Markdown

How this change flows

1 changed behaviour across 7 relationships. 6 surrounding behaviours are shown (60 graph nodes walked). 40 further behaviours left out to keep the diagram readable.

flowchart LR
  n0["buildManifest<br/>changed"]:::changed
  n1["Error"]:::impacted
  n2["operation"]:::impacted
  n3["excludedOperations"]:::impacted
  n4["buildRustRoutes"]:::impacted
  n5["send"]:::impacted
  n6["url"]:::impacted
  n0 -->|uses| n2
  n0 -->|uses| n3
  n0 -->|uses| n6
  n4 -->|uses| n3
  n5 -->|uses| n1
  n5 -->|calls| n6
  n6 -->|uses| n1
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading

Green: changed behaviour. Grey: surrounding behaviour. Arrows name the call, use, implementation, or test relationship. Orange: has findings. Red: has a finding that blocks the merge.

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot added priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect. and removed priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition. labels Aug 20, 2026
@senamakel
senamakel merged commit a7432d3 into tinyhumansai:main Aug 20, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant