chore(ci): harden api-sync coverage (enum, nested-object, delivery manifest) - #70
Merged
Merged
Conversation
.api-sync/sync.py --check now walks every mapped schema for enum-constrained properties (bare enum, items.enum, and anyOf/oneOf wrapped forms) and for inline object/array-item shapes, and fails if either lacks a spec-map.json entry or a recorded unmodeled.json exclusion. Only ~17 shared enums were previously mapped while domain Literals already in the SDK (AccountClass, Country, BusinessIndustry, etc.) were invisible to the patcher; this makes every such gap mechanically visible instead of silently unchecked. Also wires the api-sync workflow to verify the delivery manifest (.api-sync/delivery.json) committed alongside spec-current.json on the api-sync-data branch before running the patcher: fails loudly if either file is missing, if the spec's sha256 does not match the manifest, or if the triggering repository_dispatch payload's spec_sha256 is stale against what is currently on that branch. Claude-Session: https://claude.ai/code/session_01F1stiNzuNtJXoXtiW9ZCbs
Collaborator
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Three infra hardenings to .api-sync, no user-visible SDK change:
Enum coverage check (blocking).
sync.py --checknow walks every mapped schema for enum-constrained properties in any shape the spec uses (bareenum, arrayitems.enum, or either wrapped inanyOf/oneOf) and fails if the locator has noenumsmap entry and no recorded.api-sync/unmodeled.jsonexclusion. Only 17 shared enums were mapped before this; running the new check against the real spec surfaced ~194 enum-constrained properties that were invisible to the patcher, most already backed by existing SDK Literals (AccountClass, Country, BusinessIndustry, Network, TransactionStatus, ...) that simply had never been registered. 92 of those got wired intospec-map.json'senumslist; wiring them surfaced 4 additional real membership drifts (missing values on BusinessIndustry, LimitIncreaseRequestSupportingDocumentType, Currency, ManualExecutionStatus) plus one bad-fit case (CustomerOut.kyc_type is a discriminated union with per-variant singleton Literals, not one shared enum) -- all recorded as honest, attributedunmodeled.jsonentries rather than silently patched, since fixing them is real SDK behavior change out of scope for an infra PR. The remaining 101 gaps are properties genuinely typed as barestrtoday (mostly the tracking_* sub-object family shared across every payin/payout response and webhook schema) -- also recorded, each with a reason and owner.Nested-object coverage check (blocking). Recursively enumerates inline object and array-item-object shapes under every mapped schema's mapped path; each must have its own map entry or a recorded omission. Found 18 such shapes (offramp_wallets, owners, tracking_bridge_swap/tracking_paymaster/tracking_transaction_monitoring, limit, us, etc.) that are already modeled by real SDK TypedDicts but were never registered as
specPathmap entries -- recorded asnested_objectexclusions naming the existing TypedDict, pending a human pass to wire the actual specPath.Delivery manifest verification. The api-sync workflow now fetches
.api-sync/delivery.jsonalongsidespec-current.jsonfrom theapi-sync-databranch and verifies it before running the patcher: fails loudly if either file is missing, ifsha256sum(spec-current.json)doesn't match the manifest'sspec_sha256, or if the triggeringrepository_dispatchpayload'sspec_sha256is non-empty and stale against what's currently on that branch.Also reviewed
.github/workflows/pipeline-alert.ymlper request: it already passes all four injection-safety criteria (event fields viaenv:,jq -n --argfor payload construction, quoted webhook URL, missingSLACK_WEBHOOK_URLexits non-zero). No changes needed there.Two new
unmodeled.jsonkinds added:enum_coverage(schema + property [+ optional path]) andnested_object(schema + path), both validated byload_unmodeled()the same wayproperty/enumalready are.Test plan
find_enum_locator,reconcile_enum_coverage,reconcile_nested_coverage, and the two newunmodeled.jsonkinds (233 tests total, all passing)python3 .api-sync/sync.py --checkpasses clean (exit 0) against the real spec-snapshotpython3 .api-sync/sync.py --validate-mapand--coverageunaffectedcheck_contract.py,pytest,pyright,mypy,ruffall passClaude-Session: https://claude.ai/code/session_01F1stiNzuNtJXoXtiW9ZCbs