Repository navigation
fix(api): resync OpenAPI surfaces and keep dropped admin routes unexposed - #44
Conversation
The change adds three new Apify integration endpoints to the public API surface and updates the route registry accordingly. It also removes several admin and internal routes from the exposed set, reflecting a shift in which operations are considered public versus administrative. Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
…ed list Nine additional admin and internal API routes were discovered during a routine OpenAPI spec sync and have been added to the unexposed routes list, ensuring they remain inaccessible from the public API surface. The excluded admin operation count was also updated to reflect the new total of 47. Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
The expected operation count in the generated routes test is incremented from 240 to 243 to reflect that three Apify routes (run, run-status, and run-results) have been restored to the deployed public specification. Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
…utes The expected number of generated Rust routes is increased from 240 to 243 because three Apify routes that were previously removed have been restored in the deployed OpenAPI specification. Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe API manifest and generated public route list add three Apify routes. The sync script retains eight additional unexposed routes. Manifest count fields and namespace tags change, and sync test expectations are updated. ChangesOpenAPI Route Sync
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The added Apify routes are consistent across the manifest and Rust registry, and the retained admin and internal routes remain blocked. No concrete merge-blocking risk is established. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change restores three public API operations while preserving privileged-route exclusions. No client-side authorization bypass or increase in credential authority was identified. Server-side authentication, run ownership, and provider credential isolation could not be verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
A rabbit checks the routes at dawn, Comment |
Tiny Sweeper reviewResynchronizes the committed OpenAPI manifest, generated public routes, and test assertions with the deployed spec. Adds three Apify integration routes to the public surface and registers dropped admin routes in the raw-transport denylist to keep them unexposed. Updates operation counts and tags accordingly. State: Incomplete Review snapshot
Completeness: Incomplete What changedUpdates the OpenAPI manifest (api/tinyhumans.backend.json) to reflect the current deployed spec: adjusts path/operation counts, adds Apify routes, and updates tags. Adds corresponding routes to generated public routes (src/generated_public_routes.rs). Registers dropped admin routes in scripts/sync-openapi.mjs to prevent exposure. Updates test assertions in tests/openapi_sync.rs to match new counts. Features
TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. FindingsNo active actionable findings. Could not review: api/tinyhumans.backend.json, scripts/sync-openapi.mjs, src/generated_public_routes.rs, tests/openapi_sync.rs Before merge
How this fits togetherflowchart LR
n0["RETAINED_UNEXPOSED_ROUTES<br/>changed"]:::changed
n1["buildManifest"]:::impacted
n2["operation"]:::impacted
n3["buildRustRoutes"]:::impacted
n4["excludedOperations"]:::impacted
n5["isAdminOperation"]:::impacted
n6["entries"]:::impacted
n1 -->|uses| n0
n1 -->|uses| n2
n1 -->|uses| n4
n1 -->|calls| n5
n3 -->|uses| n4
n3 -->|uses| n6
n5 -->|uses| n2
classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
There was a problem hiding this comment.
tinysweeper found nothing blocking, but could not review everything, so this is not an approval: api/tinyhumans.backend.json, scripts/sync-openapi.mjs, src/generated_public_routes.rs, tests/openapi_sync.rs.
$0.0020 · 12,726 in / 6,246 out · 4,352 cached (34%) · deepseek/deepseek-v4-flash
tests: $0.0008 · 4,979 in / 2,224 out · 0 cached (0%) · deepseek/deepseek-v4-flash
description: $0.0003 · 4,526 in / 979 out · 4,352 cached (96%) · deepseek/deepseek-v4-flash
Root cause of the failing Contract drift / Public OpenAPI parity job: the deployed public Swagger document changed (admin routes pre-filtered out, Apify routes added), so
sync-openapi.mjs --checkfound the committed manifest and generated routes stale.api/tinyhumans.backend.jsonandsrc/generated_public_routes.rs.RETAINED_UNEXPOSED_ROUTESso the raw-transport denylist is not silently weakened.tests/openapi_sync.rs(240 -> 243).The check is not disabled. cargo test, fmt, clippy pass locally.
Summary by CodeRabbit