Repository navigation
feat(cli): upload declared guide originals through public API - #513
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (9)
🚧 Files skipped from review as they are similar to previous changes (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe CLI adds a command to upload declared guide documents. It streams bounded files and validates storage receipts against the source hash and size. HTTP and live API integration tests cover request handling, receipt outcomes, replay, and authorization. Documentation distinguishes upload from setup, approval, and activation. ChangesGuide Original Upload
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant GuideUploadCommand
participant api.Client
participant PublicBinaryAPI
GuideUploadCommand->>api.Client: source file, selectors, media type, idempotency key
api.Client->>PublicBinaryAPI: keyed binary POST with content length
PublicBinaryAPI-->>api.Client: HTTP 202 receipt
api.Client-->>GuideUploadCommand: validated receipt or failure
Merge Risk: ⚪ Minimal · up to This change adds a bounded guide-original upload command with receipt and source-change validation. No actionable merge-blocking risk was found. The hosted Backend check is still pending, which is normal pre-merge validation. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 4.35% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 23 functions across 8 files. (5 skipped: 5 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
|
|
CodeRabbit has now reviewed the repair through |
Change
WS-CLI-001-10 — upload one declared guide original through the public API.
workstream project guide upload PROJECT_ID GUIDE_ID DOCUMENT_ID --file FILE --media-type MIME --idempotency-key UUIDBounded intent, design and acceptance.
Design and review repair
guide_document_upload_source_changed, unknown outcome and empty stdout. This is a final observation, not a filesystem lock/snapshot.b169e83f, preserving CLI10's row and ARCH B7's delivered request-custody update. No product/backend, dependency or workflow delta versus that base.Verification
Current head:
4268a123643b4b562e81228b2a78b948a1908961; base/merge-base:36e8a615f01801cecd6ccf83d7411235ab1cfa8f. Incorporating main's merged PILOT-00 experiment changed no CLI, backend, workflow or CI bytes from the repaired implementatione7f9aadd. Source-equivalence was independently verified; evidence below retains its original SHA rather than being relabeled.The synchronized append, truncation and equal-size overwrite/restored-mtime regressions each fail against the old binary at the intended false-success assertion. The repaired upload suite passes all 9 tests. The server captures exactly the original body before mutation and receipt; each case proves one POST, no success output and unknown outcome.
Go build/vet/module verify/tidy-diff, root Ruff/format, links, stale wording, Commitrail and diff checks pass. No tests removed or skipped and no coverage gates changed. The complete exact
e7f9aaddCLI/API suite passed 91 tests against isolated real PostgreSQL in 471.58s; tree binding and database/role cleanup confirmed. Source-compatible proof retains that original SHA. A clean4268a123binary additionally passed all 9 upload tests. Latest-head hosted CLI independently passed 91 tests in 133.05s (job113424400025). The main update cancelled the superseded Backend run while its last lane was running; no test assertion failure occurred.Latest-head full Backend passed: 8,802 unique completions, zero skips/deselections, all nine database cleanups confirmed, aggregate and real API drill passed. Downloaded evidence independently matches every collected/completed identity and GitHub merge-tree
fed41127, whose parents are main36e8a615and reviewed head4268a123. Earlier full Backend results are not reused as this readiness proof. Diagnostic coverage is 94.91%, not a gate; Backend wall time is 25m56s and its timing target remains unmet. No timeout, selection or gate was weakened.The retained real API journey covers original bytes/custody, exact replay, changed-byte conflict, wrong-guide concealment and manager/submitter authority, plus assigned-document read/revocation. It uses development authentication, scripted setup findings and LOCAL ArtifactStore; no live Flow/model or deployment claim. Backend owner tests retain real MinIO proof.
Impact-routed review
e7f9aadd, clean exact target; previous findings remain fixed and merged ARCH claims preserved.security-pr513-e7f9aadd-20261008), independently replayed all three mutation cases; no findings. Mutable-file observation limitations explicitly documented.cli10-repair-qa-testdelta-e7f9aadd-final), exact-head complete CLI/PostgreSQL and hosted CLI results inspected; independent old/fixed binary comparison detects the defect. No weakened proof.All these tracks independently replayed freshness at current
4268a123and passed: relevant source/test/fixture/workflow bytes are identical, and merged PILOT-00 roadmap additions preserve CLI10/ARCH claims. Original execution evidence remains attributed toe7f9aadd.All reviewer sessions are closed and all current-head GitHub checks passed. CodeRabbit completed a fresh substantive review through
4268a123(rune755c50f-3ce2-4e3a-bbc6-7b121515a9db) with no actionable findings. Its default docstring-percentage warning is advisory, not a repository merge gate; public behavior is documented rather than padded to meet a percentage. No unresolved threads remain. Human approval was recorded for4268a123; the maintainer merged this PR as3b9fbf64. The agent did not merge it.Human focus and remaining scope
Keep the original unchanged during transfer and manual replay. The server may have stored original bytes even when the local source check fails; do not replay a changed file as if it were the same request. Confirmed upload is storage only, not guide readiness. Setup inspection/approval/activation and binary distribution remain future CLI work. No hidden submission exposure or TUI.
Human approval and merge remain with the maintainer; no automatic merge or next chunk.