Skip to content

ci: fail when the committed API client carries non-public routes - #131

Merged
Bre77 merged 1 commit into
mainfrom
fm/ts-teslemetry-hidden-route-leak
Sep 23, 2026
Merged

Bre77 merged 1 commit into
mainfrom
fm/ts-teslemetry-hidden-route-leak

Conversation

@Bre77

@Bre77 Bre77 commented Sep 23, 2026

Copy link
Copy Markdown
Member

openapi-ts.config.ts reads the live api.teslemetry.com/openapi.yaml, which is the public surface, but nothing stopped a regeneration from the api repo's committed openapi.json or from a dev server, both of which are the full internal surface and include routes production never serves. This adds pnpm --filter @teslemetry/api verify:client, a small script that collects every url: literal in the committed src/client and fails, naming each offender, when one is absent from the live public spec's paths; CI runs it next to the existing codegen-toolchain check, so it gates publish.yml's validate job as well as every PR. AGENTS.md's Codegen note now states the constraint and drops the line that pointed at the internal document, and packages/api/tsconfig.json picks up scripts/**/*.ts so the new file is typechecked like the rest. I verified it both ways against the real spec: it reports all 180 routes clean on the current client, and exits 1 listing 72 routes when pointed at an internally-generated one. Two behaviours worth knowing before merge: it fetches the spec at CI time, so it fails closed if api.teslemetry.com is unreachable after one retry, and if a route is ever removed from the public spec it will fail on unrelated PRs until the client is regenerated. No changeset, since nothing in the published dist/ changes.

`openapi-ts.config.ts` reads the live `api.teslemetry.com/openapi.yaml`,
which is the public surface, but nothing stopped a regeneration from the
api repo's committed `openapi.json` or a dev server - both of which are
the full internal surface, including routes production never serves.

`pnpm --filter @teslemetry/api verify:client` now compares every `url:`
literal in `src/client` against the live public spec's paths and fails,
naming each offender, when one is absent from it. CI runs it alongside
the existing codegen-toolchain check, so it also gates `publish.yml`'s
`validate` job. AGENTS.md's Codegen note records the constraint and drops
the advice that pointed at the internal document.
@Bre77
Bre77 merged commit 24a0d5f into main Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant