fix(openapi): document /v1/opportunities/find + /v1/issue-rag/retrieve - #9439
fix(openapi): document /v1/opportunities/find + /v1/issue-rag/retrieve#9439hurryup52 wants to merge 1 commit into
Conversation
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
Both routes were fully implemented and gated correctly but never wired
into the OpenAPI generator, so they were invisible in GET /openapi.json
and the committed apps/loopover-ui/public/openapi.json even though their
MCP tool counterparts (loopover_find_opportunities,
loopover_retrieve_issue_context) already validate full Zod shapes.
Adds FindOpportunitiesRequestSchema/ResponseSchema and
IssueRagRetrieveRequestSchema/ResponseSchema to src/openapi/schemas.ts,
mirroring the MCP tools' own shapes field-for-field
(findOpportunitiesShape/findOpportunitiesOutputSchema and
issueRagShape/issueRagOutputSchema in src/mcp/server.ts) so the contract
can't silently drift from what the tools actually validate. Registers
both response schemas as OpenAPI components and both routes as POST
paths in src/openapi/spec.ts, following the same pattern used for
GET /v1/repos/{owner}/{repo}/gate-config/effective.
Regenerates apps/loopover-ui/public/openapi.json via `npm run
ui:openapi` and extends test/unit/openapi.test.ts with assertions that
both paths are defined and that the response schemas' fields match the
MCP output shapes.
Closes JSONbored#9310
42914d9 to
780e8e2
Compare
|
This repository reviews pull requests one-shot: the PR must be correct as originally opened. Pushing an additional commit closes it automatically instead of restarting review — open a fresh pull request with every fix included. |
|
Important 🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨 ⏳ LoopOver is waiting…LoopOver has seen this pull request and is waiting on CI checks to finish before reviewing it. This comment will update once the review runs. 🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed · 🟨 Waiting |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #9439 +/- ##
==========================================
+ Coverage 75.51% 75.68% +0.17%
==========================================
Files 275 277 +2
Lines 58032 58464 +432
Branches 6209 6216 +7
==========================================
+ Hits 43820 44251 +431
Misses 13942 13942
- Partials 270 271 +1
Flags with carried forward coverage won't be shown. Click here to find out more.
|
Closes #9310
(Third attempt — #9423 and #9428 were both auto-closed by the gate for a base-branch conflict in the generated
apps/loopover-ui/public/openapi.json. This area of the spec is being actively documented by several parallel PRs for other issues, each landing in quick succession and touching the same generated file/import blocks. This PR is rebased onto the currentmaintip with all conflicts resolved; no content changes from the prior attempts.)What
/v1/opportunities/find(OPPORTUNITIES_FIND_PATH, backing theloopover_find_opportunitiesMCP tool) and/v1/issue-rag/retrieve(ISSUE_RAG_RETRIEVE_PATH, backingloopover_retrieve_issue_context) are fully implemented and access-gated insrc/api/routes.ts, but were never registered with the OpenAPI generator — grep foropportunities/find/issue-raginsrc/openapi/spec.tspreviously returned nothing, so neither route appeared inGET /openapi.jsonor the committedapps/loopover-ui/public/openapi.json.Changes
src/openapi/schemas.ts: addedFindOpportunitiesRequestSchema/FindOpportunitiesResponseSchemaandIssueRagRetrieveRequestSchema/IssueRagRetrieveResponseSchema. Field shapes mirror the MCP tools' own Zod shapes verbatim (findOpportunitiesShape/findOpportunitiesOutputSchemaandissueRagShape/issueRagOutputSchemainsrc/mcp/server.ts) so the contract can't silently drift from what the tools actually validate — reused the sameMAX_FIND_OPPORTUNITIES_*/MAX_ISSUE_RAG_*/PREFLIGHT_LIMITSconstants those shapes already use.src/openapi/spec.ts: registered both response schemas as named components (FindOpportunitiesResponse,IssueRagRetrieveResponse) and added tworegisterPathPOST entries, following the same pattern used forGET /v1/repos/{owner}/{repo}/gate-config/effective(OpenAPI spec is missing GET /v1/repos/{owner}/{repo}/gate-config/effective (documented sibling: live-gate-thresholds) #6611) and the existing POST-with-body routes (e.g. the incident-reports pair). Response codes (400/401/403) are matched to each route handler's actual behavior inroutes.ts.apps/loopover-ui/public/openapi.json: regenerated vianpm run ui:openapiand committed.npm run ui:openapi:checkpasses.test/unit/openapi.test.ts: added assertions that both paths are defined, that both response schema components are registered, and that their fields (aiPolicyAllowed,retrievedPathCount) match the MCP output shapes — a regression guard against future drift between the two.Verification
npx vitest run test/unit/openapi.test.ts— 7/7 pass (merges cleanly alongside the other recently-landed OpenAPI-documentation tests in this file).npm run ui:openapi:check— passes.npm run typecheck— clean.maintip immediately before opening this PR.