Repository navigation
feat: expose priced Exa REST routes in public SDK registry - #38
Conversation
Tiny Sweeper reviewThis pull request adds Exa agent, batch, search, answer, contents, and findSimilar routes as well as a telemetry route to the public SDK registry and generated route constants. The review identifies that the changes are missing the typed SDK surface (methods and request/response types) and route tests, and that unrelated route families (Exa and telemetry) are combined in a single change, violating repository coherence rules. The parity test assertion is updated to reflect the new route count. State: Ready for maintainer review Review snapshot
Completeness: Complete What changedThe pull request modifies api/tinyhumans.backend.json to add 16 new Exa routes and 1 telemetry route, increasing the total operation count from 212 to 229. It updates src/generated_public_routes.rs to include the same routes in the PUBLIC_ROUTES constant. It updates tests/openapi_sync.rs to expect the new operation count and asserts that the generated routes match the manifest routes. Features
Tests
Findings
Resolved this pass
Before mergeNone. How this fits togetherflowchart LR
n0["..._api_key_request_uses_openapi_field_names"]:::impacted
n1["path_segments_are_encoded_on_typed_routes"]:::impacted
n2["create"]:::impacted
n3["try_from"]:::impacted
n4["get_feedback"]:::impacted
n5["...ejects_the_machine_only_connections_scope"]:::impacted
n0 -->|calls| n2
n0 -->|tests| n2
n1 -->|calls| n4
n1 -->|tests| n4
n5 -->|calls| n3
n5 -->|tests| n3
classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe OpenAPI manifest and Rust public route list add Exa search and authenticated Langfuse telemetry routes. The sync test updates its expected operation and route counts to 214. ChangesRoute additions
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to The SDK registry now exposes the routes. Confirm Exa backend availability as part of rollout; the available evidence does not show a merge-blocking defect. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The two endpoints are newly declared as public, but the SDK’s existing restrictions on admin and webhook routes remain in place. Backend authorization and deployment behavior are not yet established, so the risk cannot be treated as zero. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings
🛠️ Fix failing CI checks 💡
A rabbit checks the routes in place, Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b7813fa6a8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "POST /agent-integrations/composio/triggers", | ||
| "POST /agent-integrations/crypto/bridge", | ||
| "POST /agent-integrations/crypto/swap", | ||
| "POST /agent-integrations/exa/search", |
There was a problem hiding this comment.
Wait to advertise the Exa route until it is deployed
If this SDK ships while the backend implementation is still pending, callers that trust this generated manifest will see POST /agent-integrations/exa/search advertised as part of the deployed contract but receive a missing-route response in production. Keep it out of the public registry until it appears in the deployed Swagger document, or land the backend deployment first.
AGENTS.md reference: AGENTS.md:L12-L19
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Requesting changes: 1 lane(s) blocking, worst finding is critical.
Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.
$0.0092 · 171,580 in / 12,788 out · 19,619 cached (11%) · ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash · 141 embedded
critique: $0.0036 · 82,874 in / 2,060 out · 17,837 cached (22%) · gpt-5.6-luna
security: $0.0017 · 62,958 in / 2,165 out · 1,782 cached (3%) · gpt-5.6-luna
tests: $0.0020 · 15,828 in / 3,104 out · 0 cached (0%) · deepseek/deepseek-v4-flash
description: $0.0012 · 7,015 in / 2,964 out · 0 cached (0%) · deepseek/deepseek-v4-flash
| "Telemetry" | ||
| ], | ||
| "routes": [ | ||
| "POST /telemetry/langfuse/otel/v1/traces" |
There was a problem hiding this comment.
Generate the telemetry route in the SDK registry
This adds a public manifest route, but the route is absent from src/generated_public_routes.rs. The manifest/registry parity test will therefore fail, and the raw SDK route guard will reject this endpoint. Regenerate the public route registry from the matching contract and add the required route test and typed client surface before merging.
[RULE] generated-surface-sync ·
| "POST /agent-integrations/composio/triggers", | ||
| "POST /agent-integrations/crypto/bridge", | ||
| "POST /agent-integrations/crypto/swap", | ||
| "POST /agent-integrations/exa/search", |
There was a problem hiding this comment.
Add the Exa operation to the typed SDK surface
This manifest entry introduces a public operation, but no Rust API method or request/response types for /agent-integrations/exa/search exist under src. Although the generated raw-route registry contains the route, the repository contract requires each public operation to have matching Rust methods, types, and route tests. Add the typed Exa client surface and its tests, or remove the manifest entry if the operation is not intended to be public.
[RULE] contract-sync ·
| ("POST", "/agent-integrations/crypto/bridge"), | ||
| ("GET", "/agent-integrations/crypto/routes"), | ||
| ("POST", "/agent-integrations/crypto/swap"), | ||
| ("POST", "/agent-integrations/exa/search"), |
There was a problem hiding this comment.
Add typed methods and route tests for the new Exa search and telemetry routes
The diff adds POST /agent-integrations/exa/search and POST /telemetry/langfuse/otel/v1/traces to the public route registry and manifest, but does not add corresponding typed Rust methods, request/response types, or route tests. The repository's OpenAPI discipline rule (AGENTS.md) requires: "Add matching Rust methods, request/response types, and route tests." Without these, the new routes are only callable through the raw escape hatch, and no SDK-level test exercises them, so regressions in serialization or contract would go undetected. Add an exa module under src/api/agent_integrations/ (or a new src/api/telemetry.rs namespace), define request/response types, implement the client methods, and write at least a mock-server route test for each. The parity test already validates the route list, so that part is fine; the gap is the typed surface and its coverage.
[RULE] missing-typed-methods ·
There was a problem hiding this comment.
The previously-blocking findings are resolved. Clearing the changes request.
$0.0125 · 250,286 in / 24,494 out · 7,766 cached (3%) · ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash · 170 embedded
critique: $0.0052 · 130,934 in / 8,807 out · 4,127 cached (3%) · gpt-5.6-luna, deepseek/deepseek-v4-flash
security: $0.0027 · 89,456 in / 4,763 out · 3,639 cached (4%) · gpt-5.6-luna
tests: $0.0024 · 17,098 in / 4,612 out · 0 cached (0%) · deepseek/deepseek-v4-flash
description: $0.0016 · 8,380 in / 4,554 out · 0 cached (0%) · deepseek/deepseek-v4-flash
| "POST /agent-integrations/exa/batches/{batchId}/cancel", | ||
| "POST /agent-integrations/exa/contents", | ||
| "POST /agent-integrations/exa/findSimilar", | ||
| "POST /agent-integrations/exa/search", |
There was a problem hiding this comment.
Add the Exa operation to the typed SDK surface
This adds the Exa search operation to the public contract, but the repository search shows no Exa module, request/response types, or typed client method. Callers can only use the raw escape hatch despite this being presented as part of the stable SDK surface. Add the typed operation in the matching namespace and keep its request and response types aligned with the deployed contract.
[RULE] typed-sdk-surface ·
| "Telemetry" | ||
| ], | ||
| "routes": [ | ||
| "POST /telemetry/langfuse/otel/v1/traces" |
There was a problem hiding this comment.
Add typed methods and route tests for the new Exa search and telemetry routes
The manifest and generated registry expose these new routes, but the repository contains no typed Exa or telemetry client methods and no mock-server route tests for them. This leaves serialization, paths, and envelope handling unverified and violates the repository rule requiring matching Rust methods, types, and route tests for contract changes. Add those methods and tests before merging.
Additional security observation
Add typed methods and route tests for the new Exa search and telemetry routes
[RULE] missing-typed-methods
The new Exa and telemetry routes are present in the manifest and route registry, but there are no corresponding typed Rust methods, request/response types, or mock-server route tests. The repository's SDK discipline requires those pieces to be added together so serialization and route regressions are exercised.
Additional security observation
Keep unrelated Exa and telemetry routes in separate changes
[RULE] incoherent-contract-change
This change combines a large Exa integration expansion with an unrelated Langfuse telemetry route, while neither has its matching typed SDK surface and tests in the same contract update. Split the unrelated route families or include their complete, independently testable implementations together.
[RULE] missing-route-tests ·
| ("POST", "/agent-integrations/exa/batches/{batchId}/cancel"), | ||
| ("POST", "/agent-integrations/exa/contents"), | ||
| ("POST", "/agent-integrations/exa/findSimilar"), | ||
| ("POST", "/agent-integrations/exa/search"), |
There was a problem hiding this comment.
Add the Exa operation to the typed SDK surface
The Exa search route is now allowlisted in the generated raw-route registry, but there is still no corresponding typed client method anywhere under src. This leaves the newly advertised operation available only through the escape hatch and violates the repository's requirement to add matching Rust methods and request/response types. Add the typed Exa operation using the deployed Swagger contract.
Additional security observation
Add the Exa operation to the typed SDK surface
[RULE] missing-typed-methods
This adds the Exa search operation only to the raw route registry; no typed Exa client method or request/response types are present in the changed surface. Callers are therefore forced to use the raw escape hatch, contrary to the repository rule requiring named namespace clients for public routes. Add the typed operation based on the deployed contract.
[RULE] typed-sdk-surface ·
| ("POST", "/teams/{teamId}/switch"), | ||
| ("POST", "/teams/join"), | ||
| ("GET", "/teams/me/usage"), | ||
| ("POST", "/telemetry/langfuse/otel/v1/traces"), |
There was a problem hiding this comment.
Add typed methods and route tests for the new Exa and telemetry routes
This change adds 16 additional Exa routes and the Langfuse telemetry route to the public contract, but the repository contains no typed methods or route tests for them. The parity test only checks route-list synchronization; it does not exercise request serialization, response handling, or the actual paths. Add the matching typed clients and mock-server tests for the new Exa and telemetry operations.
Additional security observation
Add typed methods and route tests for the new Exa search and telemetry routes
[RULE] missing-typed-methods
The registry now exposes the new Exa and Langfuse telemetry routes, but the repository contains no corresponding typed methods, request/response types, or mock-server route tests. The parity test checks only route-list synchronization and cannot catch serialization or request-path regressions. Add the required typed surfaces and tests for these new operations.
Additional tests observation
Keep changes coherent: add unrelated routes in separate pull requests
[RULE] coherence
This change adds both Exa agent/batch routes and a Langfuse OTLP telemetry route in a single pull request. The repository rule "Keep changes small and coherent" (AGENTS.md) expects unrelated route families to be introduced in separate, focused changes. Splitting them reduces review surface and avoids conflating two distinct contract updates.
[RULE] route-test-coverage ·
| ] | ||
| }, | ||
| { | ||
| "name": "telemetry", |
There was a problem hiding this comment.
Include the telemetry route in the pull request description
The pull request description does not document the newly added telemetry route, even though it introduces a distinct public namespace and ingestion endpoint. Update the pull request description to explain the route, its authentication, and why it is part of the public SDK contract.
[RULE] contract-documentation ·
| ] | ||
| }, | ||
| { | ||
| "name": "telemetry", |
There was a problem hiding this comment.
Keep unrelated route families in separate changes
This change bundles a large Exa integration expansion with an unrelated Langfuse telemetry namespace. The repository requires small, coherent contract changes; splitting telemetry from the Exa integration would make review, regeneration, and rollback of each route family independent.
[RULE] coherent-changes ·
| // `POST .../gemini/live/sessions` and `GET .../gemini/live/sessions/{sessionId}`. | ||
| // 211 -> 212: the retired orchestration session-list compatibility route. | ||
| assert_eq!(manifest["source"]["operationCount"], 212); | ||
| // 212 -> 214: Exa search plus the authenticated Langfuse telemetry route. |
There was a problem hiding this comment.
Keep unrelated route families in separate changes
This contract change combines the Exa integration's search, batch, contents, answer, and agent-run routes with the unrelated Langfuse telemetry route. Splitting the route families would keep the generated registry, typed implementations, tests, and contract changes reviewable and independently attributable.
[RULE] incoherent-change-scope ·
Summary
Expose the priced Exa Search, Contents, Answer, Find Similar, Agent Run, and Batch operations in the SDK public route registry and contract manifest. Agent and Batch resources are user-scoped by the backend.
Validation
Related
Backend implementation: https://github.com/tinyhumansai/backend/pull/1386