You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit b6476cc
Browse filesBrowse the repository at this point in the historyBrowse files
* chore(audits): check raw-route parseRequest contracts and enforce surface-neutral application imports
check:route-verbs now resolves the contract each raw withRouteHandler route
passes to parseRequest and checks the exported verb and path against it
(322 sites across 258 files, previously unchecked). check:boundaries now bans
next/server and app/api imports, and runtime route-contract, presenter and
Copilot-handler imports, from application code. listSearchSources takes its
cursor route from the adapter instead of importing the route contract.
* fix(tests): pass cursorRoute in the org source-summary integration case
* fix(audits): resolve aliased contract imports and export-list verbs in check:route-verbs
Read a contract by the name its module exports, not the local alias, and
read handler verbs from export lists (export { GET }, export { h as GET })
as well as inline exports. Both builder and raw parseRequest sites share
the fix.
* fix(audits): follow aliased parseRequest imports and relative application imports
check:route-verbs matched raw parseRequest calls only by the literal name, so
`import { parseRequest as parse }` left the contract unchecked; it now matches
every local name bound to parseRequest from @/lib/api/server(/validation).
check:boundaries applied the application rules only to @/ specifiers, so a
relative import of a contract object, presenter, Copilot handler or app/api
module passed; relative specifiers are now normalized to their @/ form first.
* fix(audits): accept HEAD on a GET contract and treat empty import/export clauses as runtime edges
* fix(audits): keep the HEAD-on-GET allowance off defineScimRoute and catch extension-suffixed presenter imports
* fix(audits): follow exported non-verb helpers when resolving raw-route contracts
Copy file name to clipboardExpand all lines: .agents/skills/migrate-application-operation/SKILL.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -226,7 +226,7 @@ Do not call shared authorization, principal audit attribution, or `recordAudit`
226
226
227
227
Inspect legacy orchestration before reusing it. If it already authorizes, audits, notifies, or captures analytics, call a lower-level primitive or remove duplicate responsibility for migrated callers.
228
228
229
-
Application code must remain surface-neutral. It must not import`app/api/**`, `next/server`, internal/v1/v2 contracts or presenters, or Copilot tool handlers. Return domain values and let each surface presenter project its own wire result.
229
+
Application code stays surface-neutral (`check:boundaries`): never `next/server` or`app/api/**`, and never a runtime import of a route contract object, presenter, or Copilot handler (contract types, schemas, and constants are fine); a surface fact, such as a cursor's route, comes in as input. Return domain values and let each surface presenter project its own wire result.
Copy file name to clipboardExpand all lines: CLAUDE.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -72,7 +72,7 @@ packages/
72
72
- Every protected read, write, canonical resource lookup, or authorization-sensitive reference resolution enters through an authorized application use case.
73
73
- Define one stable semantic operation with its minimum role, workspace-key policy, allowed principal kinds, and delegated services. Internal APIs, v2 APIs, Copilot, and trusted tools call the same use case when the domain behavior is the same.
74
74
- Surface adapters authenticate and construct a `Principal`, apply request-rate policy, parse contracts, map input, and present their own result. They never query protected data, decide resource authorization, implement business transactions, or record semantic audit.
75
-
- Application use cases load canonical context, compare asserted scope, authorize current access, execute managers/repositories, project semantic audit, and trigger shared domain effects. Managers accept canonical IDs and scope, never credentials or principals. Application code stays surface-neutral: it never imports `app/api/**`, `next/server`, route contracts/presenters, or Copilot handlers.
75
+
- Application use cases load canonical context, compare asserted scope, authorize current access, execute managers/repositories, project semantic audit, and trigger shared domain effects. Managers accept canonical IDs and scope, never credentials or principals. Application code stays surface-neutral (`check:boundaries`): never `next/server` or `app/api/**`, and never a runtime import of a route contract object, presenter, or Copilot handler (contract types, schemas, and constants are fine); a surface fact, such as a cursor's route, comes in as input.
76
76
- Copilot is a surface adapter. Use `createCopilotApplicationAdapter` and the domain's registered operation object; never a Copilot-only authorization or business implementation.
77
77
- Protected compound mutations belong in one top-level semantic application operation, never a sequence of independently committing mutations in a route or tool adapter.
78
78
- Never substitute a billing owner, uploader, creator, or API-key owner for the acting principal. Fail fast when the identity model or operation policy cannot express the caller.
0 commit comments