Skip to content

fix(api): resync OpenAPI surfaces and keep dropped admin routes unexposed - #44

Merged
senamakel merged 4 commits into
mainfrom
sync-latest
Oct 2, 2026
Merged

senamakel merged 4 commits into
mainfrom
sync-latest

Conversation

@senamakel

@senamakel senamakel commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Root cause of the failing Contract drift / Public OpenAPI parity job: the deployed public Swagger document changed (admin routes pre-filtered out, Apify routes added), so sync-openapi.mjs --check found the committed manifest and generated routes stale.

  • Regenerated api/tinyhumans.backend.json and src/generated_public_routes.rs.
  • Declared the admin/service routes that vanished from the deployed spec (blog-posts writes, admin settings, spend-caps, triage link, orchestrator token) in RETAINED_UNEXPOSED_ROUTES so the raw-transport denylist is not silently weakened.
  • Updated the count assertions in tests/openapi_sync.rs (240 -> 243).

The check is not disabled. cargo test, fmt, clippy pass locally.

Summary by CodeRabbit

  • New Features
    • The public API now supports starting Apify runs, retrieving run details, and fetching run results.
  • Documentation
    • Updated API tags for teams and webhooks to use the “OpenHuman parity” label.

senamakel and others added 4 commits October 2, 2026 13:59
The change adds three new Apify integration endpoints to the public API surface and updates the route registry accordingly. It also removes several admin and internal routes from the exposed set, reflecting a shift in which operations are considered public versus administrative.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
…ed list

Nine additional admin and internal API routes were discovered during a routine OpenAPI spec sync and have been added to the unexposed routes list, ensuring they remain inaccessible from the public API surface. The excluded admin operation count was also updated to reflect the new total of 47.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The expected operation count in the generated routes test is incremented from 240 to 243 to reflect that three Apify routes (run, run-status, and run-results) have been restored to the deployed public specification.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
…utes

The expected number of generated Rust routes is increased from 240 to 243 because three Apify routes that were previously removed have been restored in the deployed OpenAPI specification.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T11:04:51.176113Z 04eb1b1 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: f551c73c-ef6b-4c21-91d8-d8837051037c

📥 Commits

Reviewing files that changed from the base of the PR and between b7ef3b7 and 04eb1b1.

📒 Files selected for processing (4)
  • api/tinyhumans.backend.json
  • scripts/sync-openapi.mjs
  • src/generated_public_routes.rs
  • tests/openapi_sync.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The API manifest and generated public route list add three Apify routes. The sync script retains eight additional unexposed routes. Manifest count fields and namespace tags change, and sync test expectations are updated.

Changes

OpenAPI Route Sync

Layer / File(s) Summary
Apify routes and manifest metadata
api/tinyhumans.backend.json, src/generated_public_routes.rs, tests/openapi_sync.rs
The manifest and Rust route list add routes to start an Apify run, retrieve a run, and retrieve its results. Sync tests expect 243 operations and routes. The manifest count fields and the teams and webhooks tags also change.
Retained unexposed routes
scripts/sync-openapi.mjs
The retained route set adds eight method/path pairs covering admin blog posts, settings, user spend caps, feedback triage linking, and OpenCompany orchestrator token operations.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: codeghost21

Merge Risk: ⚪ Minimal · up to 04eb1

The added Apify routes are consistent across the manifest and Rust registry, and the retained admin and internal routes remain blocked. No concrete merge-blocking risk is established.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 04eb1

The change restores three public API operations while preserving privileged-route exclusions. No client-side authorization bypass or increase in credential authority was identified. Server-side authentication, run ownership, and provider credential isolation could not be verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated change affects SDK contract consumers and future regeneration of privileged-route exclusions. Adding the Apify entries does not independently expand raw transport reachability because those paths are not governed by the public inventory as an allowlist. Backend tenant, asset, and provider-account exposure cannot be bounded from this client-side evidence.

Trust Boundaries and Controls

  • observed — The shared transport sends caller-configured bearer and API-key credentials and retains structural blocking for admin paths, the internal prefix, and undocumented webhook paths. The changed route inventory introduces no new service credential or Apify provider secret. These SDK controls do not establish backend authentication or runId ownership enforcement.

Resilience and Maintainability Implications

  • observed — Generation deduplicates retained exclusions and sorts route output, supporting repeatable regeneration for a fixed input. Normal publication writes the two files concurrently without an atomic commit or rollback, so interruption can leave inconsistent outputs; subsequent check-only can detect drift but does not repair it. This publication weakness predates the PR and is not an active introduced concern.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main changes: resynchronizing OpenAPI surfaces and retaining dropped admin routes as unexposed.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 3 files. (1 skipped: 1 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


A rabbit checks the routes at dawn,
Three Apify paths are neatly drawn.
Eight more stay on the list,
The tests confirm each route exists.
Then off the rabbit hops, quite pleased.

Comment @coderabbitai help to get the list of available commands.

@tinysweeper

tinysweeper Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Resynchronizes the committed OpenAPI manifest, generated public routes, and test assertions with the deployed spec. Adds three Apify integration routes to the public surface and registers dropped admin routes in the raw-transport denylist to keep them unexposed. Updates operation counts and tags accordingly.

State: Incomplete
Priority: none
Reviewed head: 04eb1b1c4931
Updated: 1790939240 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 2 Active findings 0
Tests 1 Noted findings 0
Documentation 0 Resolved findings 0
Configuration 1 Pending checks/questions 8

Completeness: Incomplete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

Updates the OpenAPI manifest (api/tinyhumans.backend.json) to reflect the current deployed spec: adjusts path/operation counts, adds Apify routes, and updates tags. Adds corresponding routes to generated public routes (src/generated_public_routes.rs). Registers dropped admin routes in scripts/sync-openapi.mjs to prevent exposure. Updates test assertions in tests/openapi_sync.rs to match new counts.

Features

  • Modified — Resync OpenAPI manifest operation counts and tags: Updates the committed OpenAPI manifest to reflect the deployed spec, including corrected path/operation counts and added OpenHuman parity tags. (api/tinyhumans.backend.json)
  • Added — Add Apify integration routes to public surface: Exposes three new endpoints (POST /agent-integrations/apify/run, GET /agent-integrations/apify/runs/{runId}, GET /agent-integrations/apify/runs/{runId}/results) in the generated public routes and the manifest. (src/generated_public_routes.rs, api/tinyhumans.backend.json)
  • Added — Add dropped admin routes to raw-transport denylist: Registers previously exposed admin and internal routes (blog-posts, settings, feedback triage, opencompany token) in RETAINED_UNEXPOSED_ROUTES to prevent them from being served via the raw transport layer. (scripts/sync-openapi.mjs, scripts/sync-openapi.mjs#const RETAINED_UNEXPOSED_ROUTES = [)

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

No active actionable findings.

Could not review: api/tinyhumans.backend.json, scripts/sync-openapi.mjs, src/generated_public_routes.rs, tests/openapi_sync.rs

Before merge

  • Complete the critique review for api/tinyhumans.backend.json, scripts/sync-openapi.mjs, src/generated_public_routes.rs, tests/openapi_sync.rs.
  • Complete the security review for api/tinyhumans.backend.json, scripts/sync-openapi.mjs, src/generated_public_routes.rs, tests/openapi_sync.rs.

How this fits together

flowchart LR
  n0["RETAINED_UNEXPOSED_ROUTES<br/>changed"]:::changed
  n1["buildManifest"]:::impacted
  n2["operation"]:::impacted
  n3["buildRustRoutes"]:::impacted
  n4["excludedOperations"]:::impacted
  n5["isAdminOperation"]:::impacted
  n6["entries"]:::impacted
  n1 -->|uses| n0
  n1 -->|uses| n2
  n1 -->|uses| n4
  n1 -->|calls| n5
  n3 -->|uses| n4
  n3 -->|uses| n6
  n5 -->|uses| n2
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: api/tinyhumans.backend.json, scripts/sync-openapi.mjs, src/generated_public_routes.rs, tests/openapi_sync.rs
  • Lane summary: Reviewed 0 files; 0 findings. 4 files could not be reviewed: api/tinyhumans.backend.json, scripts/sync-openapi.mjs, src/generated_public_routes.rs, tests/openapi_sync.rs.

security

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: api/tinyhumans.backend.json, scripts/sync-openapi.mjs, src/generated_public_routes.rs, tests/openapi_sync.rs
  • Lane summary: Reviewed 0 files; 0 findings. 4 files could not be reviewed: api/tinyhumans.backend.json, scripts/sync-openapi.mjs, src/generated_public_routes.rs, tests/openapi_sync.rs.

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: _Code retrieval was unavailable (model: ladder embeddings returned 502 Bad Gateway: {"error":{"message":"no rung of ladder vectors could serve the request","skipped":[{"model":"text-embedding-bge-m3","provider":"venice","reason":"rate limited, retry in 22s","rung":0}],"type":"ladder_router_error"}}), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The pull request resynchronises the committed OpenAPI manifest, generated public routes, and test assertions with the deployed public spec. It adds three Apify integration routes to the public surface, registers the dropped admin routes in the raw-transport denylist, and updates the corresponding count assertions. The changes are consistent, minimal, and follow the repository's conventions. No problems are introduced. _Code retrieval was unavailable (model: ladder embeddings returned 502 Bad Gateway: {"error":{"message":"no rung of ladder vectors could serve the request","skipped":[{"model":"text-embedding-bge-m3","provider":"venice","reason":"rate limited, retry in 22s","rung":0}],"type":"ladder_router_error"}}), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No end-to-end harness in this repository: no e2e test files and no e2e workflow.
Evidence and run details
  • Models: deepseek/deepseek-v4-flash
  • Spend: $0.001956
  • Tokens: 12726 input · 6246 output · 4352 cached · 0 embedding
Head State Pass summary
04eb1b1c4931 incomplete 0 active finding(s), 0 resolved finding(s) (at 1790939240)

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking, but could not review everything, so this is not an approval: api/tinyhumans.backend.json, scripts/sync-openapi.mjs, src/generated_public_routes.rs, tests/openapi_sync.rs.

             $0.0020 · 12,726 in / 6,246 out · 4,352 cached (34%) · deepseek/deepseek-v4-flash
tests:       $0.0008 · 4,979 in  / 2,224 out · 0 cached (0%)      · deepseek/deepseek-v4-flash
description: $0.0003 · 4,526 in  / 979 out   · 4,352 cached (96%) · deepseek/deepseek-v4-flash

@tinysweeper tinysweeper Bot added the priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect. label Oct 2, 2026
@senamakel
senamakel merged commit 8bb2302 into main Oct 2, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant