ci: fail when the committed API client carries non-public routes - #131
Merged
Merged
Conversation
`openapi-ts.config.ts` reads the live `api.teslemetry.com/openapi.yaml`, which is the public surface, but nothing stopped a regeneration from the api repo's committed `openapi.json` or a dev server - both of which are the full internal surface, including routes production never serves. `pnpm --filter @teslemetry/api verify:client` now compares every `url:` literal in `src/client` against the live public spec's paths and fails, naming each offender, when one is absent from it. CI runs it alongside the existing codegen-toolchain check, so it also gates `publish.yml`'s `validate` job. AGENTS.md's Codegen note records the constraint and drops the advice that pointed at the internal document.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
openapi-ts.config.tsreads the liveapi.teslemetry.com/openapi.yaml, which is the public surface, but nothing stopped a regeneration from the api repo's committedopenapi.jsonor from a dev server, both of which are the full internal surface and include routes production never serves. This addspnpm --filter @teslemetry/api verify:client, a small script that collects everyurl:literal in the committedsrc/clientand fails, naming each offender, when one is absent from the live public spec's paths; CI runs it next to the existing codegen-toolchain check, so it gatespublish.yml'svalidatejob as well as every PR. AGENTS.md's Codegen note now states the constraint and drops the line that pointed at the internal document, andpackages/api/tsconfig.jsonpicks upscripts/**/*.tsso the new file is typechecked like the rest. I verified it both ways against the real spec: it reports all 180 routes clean on the current client, and exits 1 listing 72 routes when pointed at an internally-generated one. Two behaviours worth knowing before merge: it fetches the spec at CI time, so it fails closed ifapi.teslemetry.comis unreachable after one retry, and if a route is ever removed from the public spec it will fail on unrelated PRs until the client is regenerated. No changeset, since nothing in the publisheddist/changes.