Repository navigation
feat(cli): create draft projects with explicit replay custody - #484
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (15)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe CLI adds ChangesDraft Project Creation
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant CLI
participant APIClient
participant ProjectsEndpoint
CLI->>APIClient: project fields and idempotency key
APIClient->>ProjectsEndpoint: POST /api/v1/projects
ProjectsEndpoint-->>APIClient: HTTP 201 response
APIClient-->>CLI: validated result or failure
Merge Risk: ⚪ Minimal · up to This adds a draft-project creation command with explicit idempotency-key handling and strict response validation. No concrete merge-blocking risk was identified. Confirm that the hosted checks pass on the current head before merging. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 8.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 24 functions across 9 files. (6 skipped: 6 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Change
WS-CLI-001-08 — create a draft project shell through the public API.
Goal and planning context
Add one complete CLI setup step, not another backend lifecycle or authorization
implementation. Bounded record
defines intent, scope, alternatives, acceptance criteria and human focus.
What changed
workstream project create --name TEXT --slug TEXT --idempotency-key UUID [--description TEXT]: one public POST; caller bearer/key unchanged.retain exact 200. Project inspection shares parsing and safe output.
cap, canonical known denials and explicit uncertain outcomes. No automatic
replay, preflight, key generation, guide upload or activation.
navigation in the same change. Core product gates and policy branches do not
change; this exposes an existing public API in the CLI only.
Scope control
Only planned CLI source/tests and CLI documentation/records changed. Backend,
MCP, workflows, Go dependencies and existing test selection are unchanged.
Evidence
Go verify/tidy-diff/vet/gofmt/build; Ruff/style; Markdown links; four stale scans;
Commitrail checks and 16 workflow guards passed.
Current repair head is
637929c2057ba78e956c22c4aa1d2b4dded4ecd5, incorporatingmain
b6e62f0eand migration0022_submission_packet_custody. INDEX retains theCLI08 row from the prior head and the ARCH packet-custody row exactly from main.
CLI source/tests are byte-identical to the prior head; backend, MCP, workflows
and dependencies are byte-identical to current main. README and roadmap retain
both initiatives' updates. Current-head Go/style, link/stale/Commitrail checks
and 16 workflow guards pass. 48 current-head local HTTP/process tests pass.
The fresh hosted full CLI/API journey passed all 49 tests in 50.50s,
after migration
0022. Hosted checkout25ff5571and current review head shareexact tree
22849fc56273a8ea157a57961a1779019ea5f927.Full Backend
passed all nine lanes and the aggregate check. The final authenticated artifact
reconciles 8,693 unique collected/completed backend nodes, no skips/deselections,
all execution exits zero and no interrupted selected lane. Evidence hashes,
PostgreSQL migration
0022, real MinIO probes and database/storage cleanup verified.Agent Gates and MCP CI also passed.
Retry history is preserved: attempt 1 hit the existing 1,200-second task-lifecycle-a
deadline after 449/460 completed nodes, with no failed assertion recorded. The same
source's complete 460-test retry passed in 859.471s; the aggregate uses that passing
lane plus the eight original passing lanes. The interrupted attempt is not passing
evidence. No timeout, selection or CI rule changed. The timing target remains unmet:
aggregate Backend wall time including retry is 2,581.638s (~43m2s). This CLI change
does not solve the existing CI bottleneck.
Eligible human approval is still required after the latest push.
Historical
f99b0bbcproof remains separate: 49 complete local/hosted CLI testsand 8,688 backend completions before incorporating main. Earlier local deadline
failures were not counted as passing evidence; the unchanged local run subsequently
passed in 320s with a local-only budget. No CI deadline or selection changed.
The installed-process suite tests exact wire inputs/output, nullable description,
Unicode/encoded-size boundaries, malformed replies, error credential reflection,
unknown outcomes and HTTP/2 GOAWAY. A scratch build with rewindable mutation
bodies fails the named GOAWAY regression by sending twice.
The public-API journey adds creation/GET parity, unchanged manual replay,
body mismatch, slug non-overwrite, system versus project scope, revoked-grant
recovery/new-key denial and suspension with a valid positive control. It restores
the spare actor and grants before the retained task journey.
Test delta
Two integration sources added; existing public journey extended. No Go unit
suite, skipped/removed tests, weakened assertions or coverage-percentage gate.
Impact-routed internal reviews
Prior implementation head:
f99b0bbcfda17091c57efed9c16893e7da714d00.persisted-state assertions and fixture restoration; no findings remain.
migrated PostgreSQL for stored state and authorization. Inspection is not
substituted for missing execution. Reviews are advisory session evidence.
Current merge-preservation documentation replay: PASS at
637929c2, with exactparent-row preservation and independent README/roadmap three-way blob checks.
QA/test-delta integration replay: PASS at
637929c2, after inspecting the freshhosted 49-test migration-compatibility proof and unchanged test/owner bytes.
Previous reviews are retained as historical scoped evidence, not relabeled as
new-head reviews; there is no CLI behavior or test change in the reconciliation.
External review and CI integrity
CodeRabbit completed a substantive review of
637929c2with no actionablecomments. Its default docstring percentage warning is not a repository policy;
no quota-only source changes are added. Hosted checks and conversations remain GitHub-owned.
No workflow, package command, dependency or complete-test requirement weakened.
Remaining risks and human focus
This is a draft shell, not an approved guide or ready work. Retain the unchanged
input and UUID key if manually recovering an unknown outcome.
The existing project-create API recovers committed results before fresh PREP,
including after creation-grant revocation. This differs from task replay and is
not authority for another creation. Suspended/revoked-link committed recovery is
an explicit preexisting AUTH-owner question, not a client-side guard or new claim.
Source build does not establish binary distribution or hosted deployment.
No subsequent CLI step starts in this PR.
Human merge ownership