Repository navigation
fix(api): restore the spend-cap routes and repair two generator bugs - #15
Conversation
The OpenAPI manifest and generated route tables are updated to include a new spend caps resource with GET and PUT endpoints, plus a PUT endpoint on API keys for setting spend caps. The sync script now deduplicates supplemental routes that already appear in the spec, preventing duplicate entries in the generated route list. Several admin and webhook routes are also added to the unexposed routes list, and the corresponding assertion counts are updated to match the regenerated manifest. Auto-committed-on: macbook Co-authored-by: Medulla <medulla@tinyhumans.ai>
|
Warning Review limit reachedYour included review limit has been reached. You’re in a promotional period — use the checkbox below to run this review for free:
On-demand reviews are free for the next 31 days. After that, they cost $0.25 per reviewed file. How can I continue?Run this review now using the option above, or comment You can also wait for the limit to reset (next review available in 26 minutes), then comment An organization admin can change what happens after included review limits in Billing. How do review limits work?CodeRabbit enforces per-developer PR review limits within each organization. For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (5)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
How this change flows1 changed behaviour across 7 relationships. 6 surrounding behaviours are shown (60 graph nodes walked). 40 further behaviours left out to keep the diagram readable. flowchart LR
n0["buildManifest<br/>changed"]:::changed
n1["Error"]:::impacted
n2["operation"]:::impacted
n3["excludedOperations"]:::impacted
n4["buildRustRoutes"]:::impacted
n5["send"]:::impacted
n6["url"]:::impacted
n0 -->|uses| n2
n0 -->|uses| n3
n0 -->|uses| n6
n4 -->|uses| n3
n5 -->|uses| n1
n5 -->|calls| n6
n6 -->|uses| n1
classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Green: changed behaviour. Grey: surrounding behaviour. Arrows name the call, use, implementation, or test relationship. Orange: has findings. Red: has a finding that blocks the merge. |
Overview
#14 merged a regeneration that had been run against a backend checkout sitting on
mainrather than on the spend-caps feature branch. The output therefore did not contain the routes that PR existed to add, and the pinned counts were lowered to match —UNEXPOSED_ROUTES.len()went to 44, identical tomain, so the regression read as "no change".I pushed a corrected regeneration to #14, but it landed two seconds after that PR was merged on the stale head, so the fix missed the merge. This restores it.
Changes
Regenerated from the spec of the backend commit that actually shipped the routes. Relative to
main:PUBLIC_ROUTESUNEXPOSED_ROUTESGET/PUT /spend-capsandPUT /api-keys/{keyId}/spend-capsare public;PATCH /admin/users/{userId}/spend-capsis in the denylist. Neither list loses an entry.isCustomLlmSecretOperationmade the script unrunnable. It incrementedexcludedAdminOperationCount, aconstdeclared further down the same function, so every invocation died with a TDZReferenceError. The count is derived fromexcludedOperationsanyway, so the increment was redundant — removed. This is why the bad manifest onmaincould not simply be regenerated in place.SUPPLEMENTAL_PUBLIC_OPERATIONSwas appended unconditionally. That list exists for operations the deployed document omits. Feeding a local spec that does describe them (the team routes and/webhooks/core/*, both added to the list recently) emitted 9 duplicate routes and trippedgenerated_rust_routes_match_the_public_manifest. Now skips any entry the spec already covers.Testing
cargo test— 24 suites, 0 failurescargo clippy --all-targets -- -D warningscleancargo fmt --checkcleanorigin/mainprogrammatically to confirm nothing was droppedNotes
The
UNEXPOSED_ROUTES.len()pin is what makes this class of mistake findable at all, and it is worth keeping strict — but note it did not prevent the bad merge, because lowering the pin to match the bad output makes the suite green. The stronger invariant is the one used above: the denylist may gain entries but must never lose them relative tomain. Worth encoding as a test if this recurs.Follows tinyhumansai/backend#1285 (merged) and #14 (merged).
Related Issues