Repository navigation
feat: sync the /memory/v1 dialect routes into the public surface - #45
Conversation
Syncs against the backend branch that adds `/memory/v1/*`: the same hosted
memory as `/memory/*`, answered in CortexDB's own dialect -- memory-api's
status, memory-api's body, no `{ success, data }` envelope -- for a client
written against the engine rather than against this API. The envelope collapses
a 409 into a 400 and a 202 into a 200, and the `cortex` memory driver's retry
safety and read-after-write barrier are built on seeing both.
Run as `sync-openapi.mjs --input` against that branch's dumped spec, per
backend CLAUDE.md, so it also brings in four opencompany routes (`.../open`,
`GET`/`PUT .../password`, `.../password/reset`) that were already public on
backend `main` and absent here only because this repo's manifest had been
generated from a deployed spec that predated them. Same situation as the
`GET /opencompany/companies` entry already noted in the ratchet comments.
Two pinned counts move, both to 254, each with its reason inline:
`manifest["source"]["operationCount"]` and `rust_routes.len()`. Nothing was
unblocked: `excludedAdminOperationCount` (47), `excludedWebhookOperationCount`
(12) and `UNEXPOSED_ROUTES` (59) are all unchanged, and no public route was
removed.
The manifest will diverge from the deployed spec until the backend change
ships. That divergence is expected and closes on deploy.
No typed client methods are added for these routes. The consumer is OpenHuman's
`cortex` memory driver, which speaks the engine's dialect over its own HTTP
client rather than through this SDK.
Tiny Sweeper reviewTiny Sweeper reviewed this change across 6 lane(s) and found 1 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below. State: Ready for maintainer review Review snapshot
Completeness: Complete What changedThe review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below. FeaturesNone identified with supported citations. TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. Findings
Before mergeNone. How this fits togetherflowchart LR
n0["..._api_key_request_uses_openapi_field_names"]:::impacted
n1["path_segments_are_encoded_on_typed_routes"]:::impacted
n2["create"]:::impacted
n3["try_from"]:::impacted
n4["get_feedback"]:::impacted
n5["...ejects_the_machine_only_connections_scope"]:::impacted
n0 -->|calls| n2
n0 -->|tests| n2
n1 -->|calls| n4
n1 -->|tests| n4
n5 -->|calls| n3
n5 -->|tests| n3
classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe OpenAPI manifest adds memory and OpenCompany routes and updates operation counts and namespace tags. The Rust public route list and OpenAPI sync test update to reflect the route additions. ChangesPublic API route inventory
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to The added routes match between the manifest and Rust inventory, and the sync test checks their identities and totals. No material merge-blocking risk is established. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change updates endpoint inventories rather than adding server handlers or weakening client-side restrictions. No introduced security issue was established. Backend authentication, tenant isolation, and instance ownership checks remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
A rabbit checks the route list twice, Comment |
There was a problem hiding this comment.
tinysweeper found nothing blocking. Approving.
$0.0053 · 125,596 in / 7,836 out · 12,032 cached (10%) · gpt-5.6-luna, glm-5.3-flash, deepseek-v4.1-flash
critique: $0.0039 · 80,846 in / 4,462 out · 8,329 cached (10%) · gpt-5.6-luna, glm-5.3-flash
security: $0.0011 · 21,983 in / 789 out · 3,639 cached (17%) · gpt-5.6-luna
tests: $0.0002 · 12,138 in / 1,134 out · 0 cached (0%) · glm-5.3-flash
description: $0.0001 · 5,923 in / 780 out · 64 cached (1%) · glm-5.3-flash
|
Verified the sync against the branch spec. One fix: the body says "Eleven routes … seven Minor: the sync also retags the Teams and Webhooks groups (drops the "OpenHuman parity" tag). Cosmetic, carried in from backend The four opencompany password/open routes swept in are legitimate — already public on backend Post-merge: point the backend |
Why
Syncs against tinyhumansai/backend#1403, which adds
/memory/v1/*: the samehosted memory as
/memory/*, answered in CortexDB's own dialect (memory-api'sstatus, memory-api's body, no
{ success, data }envelope) for a client writtenagainst the engine rather than against this API. The envelope collapses a
409into a
400and a202into a200, and thecortexmemory driver's retrysafety and read-after-write barrier are built on seeing both.
What
Run as
sync-openapi.mjs --inputagainst that branch's dumped spec, per thebackend's CLAUDE.md. Eleven routes enter the public surface:
/memory/v1/*:experience,experience/bulk,recall,forget,answer,events,events/{id},scopes/list,beliefs,beliefs/build..../open,GET/PUT .../password,.../password/reset— which were already public on backendmainand absenthere only because this repo's manifest had been generated from a deployed spec
that predated them. Same situation as the
GET /opencompany/companiesentryalready noted in the ratchet comments.
Two pinned counts move, both to 257, each with its reason inline:
manifest["source"]["operationCount"]andrust_routes.len().Nothing was unblocked.
excludedAdminOperationCount(47),excludedWebhookOperationCount(12) andUNEXPOSED_ROUTES(59) are allunchanged, and no public route was removed. The backend deliberately does not
expose
/v1/admin/healthfor exactly this reason — no published path may carryan
adminsegment, whichrust_routesasserts structurally.Testing
cargo fmt --all -- --check,cargo clippy --all-targets -- -D warnings,cargo test(28 suites),cargo package— all clean.Notes
No typed client methods are added for these routes. The consumer is OpenHuman's
cortexmemory engine, which speaks the engine's dialect over its own HTTPclient rather than through this SDK; the generated route registry is what it
needs, so the raw transport admits them.
The manifest will diverge from the deployed spec until the backend change ships.
That divergence is expected and closes on deploy — please don't "fix" it by
resyncing from production.
Point the backend's
sdkgitlink at this repo'smainafter merge.Summary by CodeRabbit