Repository navigation
feat(api): scope endpoints and live-link groundwork for Files, Links, Storage - #1069
Conversation
…rom repos countPrivateScopeItems probed every key past the first page (up to 2,000), at two or more R2 operations each, which could pass the 1,000-subrequest ceiling and fail /scope with a 503 on busy repos. It now returns null when more than 300 keys need a probe, and probes none of them. listWorkspaceRepos now drops gh.status=promoted shadows like scopeFrom, so a repo holding only shadows does not list and a shadow never sets lastUpdatedAt. docs/ops.md: the backfill dry-run comment now matches the route's output.
|
|
CodeRabbit (@coderabbitai) review |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important Review skippedAuto incremental reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (38)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThis change adds workspace-scoped pull, repository, and file endpoints; PR activity rollups; paginated public feeds with source attribution; and lowercase ChangesWorkspace Scope and PR Activity
Public Feeds
Repository Metadata Backfill
Priority: ⬇️ Low Estimated code review effort: 4 (Complex) | ~60 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Client
participant workspaceScope
participant scopeFilesHandler
participant prScopeQuery
participant Storage
Client->>workspaceScope: Request scoped files
workspaceScope->>scopeFilesHandler: Apply route authentication
scopeFilesHandler->>prScopeQuery: Query files and cursor
prScopeQuery-->>scopeFilesHandler: Return scope page
scopeFilesHandler->>Storage: Hydrate file items
Storage-->>scopeFilesHandler: Return visibility and URLs
scopeFilesHandler-->>Client: Return files and pagination data
Merge Risk: ⚪ Minimal · up to This API-only change adds workspace scope views, paginated public feeds, PR rollups, and a repository-case backfill. No confirmed defect blocks merging. Operators still need to run the documented backfill after deployment so older mixed-case repository files appear in the new views. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Workspace authorization and public-content withholding remain in place. However, the new anonymous item endpoint performs scope-sized database reads and sequential hashing without application-level request limiting, creating a bounded resource-abuse risk. Production traffic controls and deployment sequencing remain unverified. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 54.90% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 102 functions across 31 files. (7 skipped: 7 unsupported.) ✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit pages feeds at dawn, Comment |
✅ Action performedReview finished.
|
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
uploads-api | 7df2056 | Commit Preview URL Branch Preview URL |
Oct 04 2026, 09:47 PM |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
uploads-auth | 7df2056 | Oct 04 2026, 09:47 PM |
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
uploads-web | 7df2056 | Commit Preview URL Branch Preview URL |
Oct 04 2026, 09:47 PM |
API groundwork for the workspace redesign: a Files tab organized by pull request, repo and page; a Links tab for live links and galleries; and a Storage tab for the bucket. In the UI, change feeds become live links. This PR is slice 1 of 5 and ships no UI.
What changes
apps/api/src/pr-scope.ts. It matchesgh.repoand an optionalgh.number, excludes promoted copies, and does not requirepath. It takes an optional file-type filter and pages with a keyset cursor. Live links (findLatestRepoScreenshots) now run through it./v1/workspaces/:ws, session or bearer auth,files:read:GET /pulls: PRs with media, newest first. Defaults to the last 90 days;all=1lifts that. Each row has a title, state and up to 4 thumbnails.GET /repos: repos with media and their open-PR counts.GET /scope/:owner/:repo/files?number=&type=: one PR's or repo's files. The response also carries:privateCount:nullwhen the scope is too large to count.liveLink: the existing live link for this scope, if any.pull: branch, title and state.GET /public/feeds/:idpages with?cursor=, so long feeds no longer stop at 50 items.GET /public/feeds/:id/items/:itemreturns one item with its previous and next neighbours.{updatedAt, itemId}, never an object key.feeds.sourcecolumn recordscomment(GitHub App comment sync) oruser(API). The API ignores anysourcea client sends.number = 0) count toward the cap of 50. PR and issue feeds are uncapped, so PR comments no longer fall back to/f/links once a workspace has 50 PRs.github_pr_activitygainstitleandstate. Thepull_requestwebhook writes them, and/pullsrefreshes them when it reads the rows.gh.repois lowercased on write.POST /admin/file-metadata/backfill-gh-repo-case(supports?dryRun=1) lowercases older rows. It is run by hand; the steps are indocs/ops.md.@uploads/comment-render/scopeholdsfileTypeClassFromKey,isInFeedScopeandfeedItemIdFor. The CLI gets a generated copy.Privacy
github_repo_links). Lookups useresolveTitleswith the member audience from fix(api): keep private PR titles out of other workspaces and public pages #1065.source, linked-repo information, titles looked up for signed-in members, or object keys of private files.Migrations (apply to production on merge)
20261004120000_feeds_source.sql: addsfeeds.source.20261004120100_pr_activity_title_state.sql: addstitleandstate, plus a cursor index.20261004120200_file_metadata_gh_repo_idx.sql: adds a partial index ongh.reporows.All three only add columns or indexes.
After deploy
Run the
gh.repocase backfill once, dry run first. The steps are indocs/ops.md.Testing
pnpm test,pnpm typecheckandpnpm checkpass./pulls,/reposand/scoperoutes, public pagination and the item endpoint, and the backfill.EXPLAIN QUERY PLANtests check that the scope query uses the new index.Summary by CodeRabbit