Repository navigation
feat(sdk): add codegen --tenant and --operator-key flags - #729
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details🧰 Additional context used📓 Path-based instructions (5)Source excerpt: Requires Node 22 or newer — the only line this SDK is tested against; Node 18 and 20 are past upstream end-of-life.📄 CodeRabbit inference engine (clients/ts/README.md) Files:
Source excerpt: **Never hand-write `®` or `™` in prose.**📄 CodeRabbit inference engine (AGENTS.md) Files:
Source excerpt: The TypeScript SDK (`@wavehouse/sdk` in `clients/ts/`) is the canonical client and ships from this repo.📄 CodeRabbit inference engine (AGENTS.md) Files:
Source excerpt: **WH001 applies to every tracked Markdown file, with no carve-out** — `AGENTS.md`, `CHANGELOG.md`, `.github/` CI docs and `.claude/` agent prompts included.📄 CodeRabbit inference engine (AGENTS.md) Files:
Source excerpt: **Docs prose**: never hard-wrap Markdown — one paragraph is one line.📄 CodeRabbit inference engine (CONTRIBUTING.md) Files:
🧠 Learnings (1)📓 Common learnings🪛 ast-grep (0.45.3)clients/ts/src/cli/codegen.test.ts[warning] 190-190: Regular expression constructed from variable input detected. This can lead to Regular Expression Denial of Service (ReDoS) attacks if the variable contains malicious patterns. Use libraries like 'recheck' to validate regex safety or use static patterns. (regexp-from-variable) 🪛 LanguageToolCHANGELOG.md[typographical] ~13-~13: Consider using an em dash in dialogues and enumerations. (DASH_RULE) 🔇 Additional comments (4)
📝 SummarySummary by CodeRabbit
WalkthroughThe Codegen CLI adds ChangesCodegen schema access
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature · Severity of issue fixed: Medium Sequence Diagram(s)sequenceDiagram
participant CodegenCLI
participant fetchSchemas
participant OpsSchemaEndpoint
CodegenCLI->>fetchSchemas: Pass tenant and credential options
fetchSchemas->>OpsSchemaEndpoint: GET /v1/ops/schema with tenant query and supplied headers
Suggested reviewers: Merge Risk: 🟡 Moderate · up to Using --operator-key with a remote HTTP endpoint can expose the key in transit. Require encrypted transport for remote credentialed requests before merging. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Server authorization and tenant selection remain intact, and credentialed redirects are blocked. However, the new operator-key option can send a platform-wide credential over an explicitly configured remote HTTP connection. Exploitation requires access to that unencrypted network path; the documented HTTPS example avoids this exposure. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 40.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 2 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 2📝 Generate docstrings 💡
🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
📚 Docs preview is live → https://dab24a05-wavehouse-docs.wave-rf.workers.dev |
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 4
ℹ️ Review info
⚙️ Run configuration
- Configuration used: Organization UI
- Review profile: ASSERTIVE
- Plan: Advanced
- Run ID:
64831913-9dc9-4dbd-aa29-9d54d732deeb
📒 Files selected for processing (5)
CHANGELOG.mdclients/ts/README.mdclients/ts/src/cli/codegen.test.tsclients/ts/src/cli/codegen.tsdocs/src/content/docs/sdk/reference.md
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.
📜 Review details
🧰 Additional context used
📓 Path-based instructions (5)
Source excerpt: Requires Node 22 or newer — the only line this SDK is tested against; Node 18 and 20 are past upstream end-of-life.
📄 CodeRabbit inference engine (clients/ts/README.md)
Files:
docs/src/content/docs/sdk/reference.md
Source excerpt: **Never hand-write `®` or `™` in prose.**
📄 CodeRabbit inference engine (AGENTS.md)
Files:
docs/src/content/docs/sdk/reference.md
Source excerpt: The TypeScript SDK (`@wavehouse/sdk` in `clients/ts/`) is the canonical client and ships from this repo.
📄 CodeRabbit inference engine (AGENTS.md)
Files:
clients/ts/src/cli/codegen.test.tsclients/ts/src/cli/codegen.ts
Source excerpt: **WH001 applies to every tracked Markdown file, with no carve-out** — `AGENTS.md`, `CHANGELOG.md`, `.github/` CI docs and `.claude/` agent prompts included.
📄 CodeRabbit inference engine (AGENTS.md)
Files:
clients/ts/README.mddocs/src/content/docs/sdk/reference.mdCHANGELOG.md
Source excerpt: **Docs prose**: never hard-wrap Markdown — one paragraph is one line.
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Files:
clients/ts/README.mddocs/src/content/docs/sdk/reference.mdCHANGELOG.md
🪛 LanguageTool
CHANGELOG.md
[typographical] ~13-~13: Consider using an em dash in dialogues and enumerations.
Context: - **Codegen reads any tenant of a nested ...
(DASH_RULE)
|
@coderabbitai review |
✅ Action performedReview finished.
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Summary
wavehouse-codegencould not generate types for a tenant of a nested settings directory. It had no way to send the?tenant=parameter thatGET /v1/ops/schemareads, and no way to send the operator key, which is the only credential the nested/v1/ops/*routes admit.--authsends a bearer token, which gets403there.--tenant <id>(-t) is sent as?tenant=. Without it the request names no tenant, so the server reads tenant0. An empty value is refused client-side; any other check is the server's.--operator-key <key>(-k) is sent as theX-Operator-Keyheader. It is a separate header from--auth'sAuthorization: Bearer, so neither replaces the other.--authstays the flat-directory crtenant, and the operator key without--tenantreads tenant0`on either shape.and the
--helptext list both flags.Test plan
clients/ts/src/cli/codegen.test.ts: the URL carries?tenant=only when the flag is setX-Operator-Key, with and without a bearer token, and the bearer header is left in placeparseArgsreads both flags and their aliases, and refuses an empty--tenantmake test-ts, Biome,tsc --noEmit, markdownlint and misspell pass--helpprints the new flags, an empclear messageRelated Issues
Closes #640
Part of #583
Follow-ups
None. #527 and #528 touch the same file and are left out on purpo