Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions .changeset/20752-rest-strings-state-the-decision.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
'@objectstack/rest': patch
---

REST refusals, warnings and the served OpenAPI text no longer cite tracker numbers; each one states the decision behind it in words

Clause-②: no

A few strings `@objectstack/rest` sends to callers and operators pointed at an issue-tracker number for the reason behind them. The number goes; where the sentence did not already say what was decided, it now does.

- `POST /data/:object/import` with a named mapping that declares a `javascript` transform: the `UNSUPPORTED_TRANSFORM` message now says the import path does not execute it (there is no server-side sandbox), so the import is refused rather than run with that transform skipped.
- `GET /openapi.json`: the built-in section's response description says the section is built from the routes this server actually mounts and that payload schemas are deliberately not invented; the request-body description says the document leaves the route-specific shape undescribed rather than invent one.
- The boot warning for a config that still sets the retired `api.requireAuth` drops its citation; it already says the key was removed and anonymous access to object data is always denied.
- `/discovery`'s `capabilities.transactionalBatch.description` cites ADR-0034 alone.

Text only: no status, error code, field, route or control flow moves. A client that matches the old message text (for example the tracker-number suffix the `UNSUPPORTED_TRANSFORM` message used to end with) needs the new spelling.
2 changes: 1 addition & 1 deletion packages/rest/src/import-mapping.ts
Original file line number Diff line number Diff line change
Expand Up @@ -90,7 +90,7 @@ export async function resolveNamedMapping(
if (entry?.transform === 'javascript') {
return {
ok: false, status: 400, code: 'UNSUPPORTED_TRANSFORM',
error: `Mapping "${mappingName}" uses transform "javascript", which the import path does not execute (no server-side sandbox; see framework#2611)`,
error: `Mapping "${mappingName}" uses transform "javascript", which the import path does not execute (there is no server-side sandbox), so the import is refused rather than run with that transform skipped`,
};
}
}
Expand Down
8 changes: 4 additions & 4 deletions packages/rest/src/openapi-builtin-paths.ts
Original file line number Diff line number Diff line change
Expand Up @@ -149,12 +149,12 @@ const PUBLIC_TAG = 'public';
const BODY_METHODS = new Set(['POST', 'PUT', 'PATCH']);

const RESPONSE_NOTE =
'Response envelope. This section describes the route surface — which method and path exist, ' +
'and what each is for. Per-route payload schemas are not derived here and are deliberately not ' +
'invented (#5588).';
'Response envelope. This section is built from the routes this server actually mounts — which method ' +
'and path exist, and what each is for. Per-route payload schemas are not derived here and are ' +
'deliberately not invented.';

const REQUEST_BODY_NOTE =
'JSON request body. Its shape is route-specific and is not described by this document (#5588).';
'JSON request body. Its shape is route-specific; this document leaves it undescribed rather than invent one.';

/**
* Is this wire path served by the document being built for `basePath`?
Expand Down
2 changes: 1 addition & 1 deletion packages/rest/src/rest-api-plugin.ts
Original file line number Diff line number Diff line change
Expand Up @@ -527,7 +527,7 @@ export function createRestApiPlugin(config: RestApiPluginConfig = {}): Plugin {
if ((config.api as any)?.requireAuth !== undefined
|| (config.api as any)?.api?.requireAuth !== undefined) {
ctx.logger.warn(
'[security] `api.requireAuth` was removed (#3963) and is IGNORED — anonymous access to '
'[security] `api.requireAuth` was removed and is IGNORED — anonymous access to '
+ 'object data is always denied. Publish public surfaces by declaration instead: a public '
+ 'form view, a share link, or `book.audience: \'public\'`.',
);
Expand Down
38 changes: 19 additions & 19 deletions packages/rest/src/rest-route-ledger.ts

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion packages/rest/src/rest-server.ts
Original file line number Diff line number Diff line change
Expand Up @@ -4827,7 +4827,7 @@ export class RestServer {
description:
'Atomic cross-object batch endpoint (POST {basePath}/batch): all-or-nothing '
+ 'create/update/delete across objects in one transaction, with intra-batch '
+ '{ $ref: <opIndex> } parent references (#1604 / ADR-0034).',
+ '{ $ref: <opIndex> } parent references (ADR-0034).',
};

// [#7541] Global search — the same two-layer AND, for the
Expand Down
30 changes: 0 additions & 30 deletions scripts/doc-authoring-prose-id.baseline.json
Original file line number Diff line number Diff line change
Expand Up @@ -437,36 +437,6 @@
"packages/qa/downstream-contract/src/stack.ts": {
"#2035": 1
},
"packages/rest/src/import-mapping.ts": {
"#2611": 1
},
"packages/rest/src/openapi-builtin-paths.ts": {
"#5588": 2
},
"packages/rest/src/rest-api-plugin.ts": {
"#3963": 1
},
"packages/rest/src/rest-route-ledger.ts": {
"#10179": 1,
"#11678": 2,
"#11924": 2,
"#12038": 9,
"#12702": 4,
"#3610": 1,
"#3611": 1,
"#4327": 1,
"#5682": 1,
"#5950": 1,
"#6603": 1,
"#7019": 1,
"#7526": 1,
"#7563": 1,
"#8140": 1,
"#9180": 1
},
"packages/rest/src/rest-server.ts": {
"#1604": 1
},
"packages/runtime/src/action-execution.ts": {
"#11519": 1,
"#5933": 1
Expand Down
Loading