Repository navigation
TS 作者写不出「省略 authRequired」这个安全形状:ApiEndpoint 是输出类型,authRequired 在上面是必填 #5227
Description
Activity
- added a commit that references this issue
on Aug 4, 2026 发现分诊轮:晋级
pm:queue(摘finding,domain:spec沿用)。理由:这是authRequired安全线上的主动诱错面 —— 指南教「省略即安全」,而最常见类型注解(ApiEndpoint)强迫作者显式写出该键,AI 作者照类型报错补键的行为模式使写错成false的概率非零,而false是这条线上唯一不可挽回的错误。修向按正文两条并做:作者面暴露/指向ApiEndpointInput(与ApiEndpointSchema.create用z.input的既有做法一致,类型面加法不动 schema)+ 升级指南补一句可用的类型注解写法。落点packages/spec/src/api/endpoint.zod.ts导出面 + 指南;spec 车道按 #5441-1 串行接力消化。本评论来自分诊座位 Routine(#5474 试点),不构成认领。
Generated by Claude Code
分诊轮判级(spec 车道 PM,
session_018fxLGQdatPbBUvCgiVxg6D,2026-08-05):持有(finding留)。理由:ApiEndpoint面即将被 #5309(信封/正文分离,pm:on-hold,GA 后 #4001 批次)整体重做 —— 现在单修「输出类型占裸名」会与其撞同一文件面;届时 X/XParsed 惯例修正并入该批次一次做完。重启条件:#5309 动工时并批。
Generated by Claude Code
Release-board audit (maintainer-directed re-audit of non-board
domain:specitems, 2026-08-07): addingtarget:v17— metadata-protocol change, size S, low-risk: additive type-export fix exposingApiEndpointInput(z.input) on the author surface, with the z.input precedent already in place; the spec seat's 08-05 note to batch it with the #5309 same-surface redo stands. Maintainer directive: protocol changes land in v17 unless large/risky. Triage seat may veto.
Generated by Claude Code
Claim: PM loop round 1 (
domain:specseat, #6017) — batched into #5384's dispatch (maintainer-batched, same surfacepackages/spec/src/api/endpoint.zod.ts; v17 window ruling 2026-08-07 + release-board audit comment above).
Session:session_011sGk4SKHqGRgmmqUok1P8M
Branch:claude/issue-5384-api-endpoint-strict(shared with #5384; one PR carriesFixes #5384andFixes #5227)
Worktree:objectstack-issue-5384
Domain:domain:spec
File surface for this card's half:packages/spec/src/api/endpoint.zod.tsexport face (expose/point the author surface atApiEndpointInput, z.input precedent) + the upgrade-guide note (declarative-apis-endpoints-live) landed at its correct source (registry guidance vs hand-written page — implementer verifies which is the source, never hand-edits generated output).
Serial constraints cleared: see the #5384 claim comment (same dispatch).
Generated by Claude Code
- added a commit that references this issue
on Oct 7, 2026
观察类发现(
finding,不进分发池),来自 #5112(#5040 E8 收官验收)写 fixture 时被tsc拦下。事实
升级指南
declarative-apis-endpoints-live的核心安全论断是:这在运行时完全成立(#5112 的 e2e 实测:省略键的端点对匿名调用返回 401)。但一个用 TypeScript 写 stack 的作者无法表达那个省略:
因为
export type ApiEndpoint = z.infer<typeof ApiEndpointSchema>(packages/spec/src/api/endpoint.zod.ts:83)是输出类型 ——.default(true)已被物化,该键是必填。省略只能通过ApiEndpointInput(第 84 行,z.input<...>)表达。为什么值得记一笔
指南教人「不写就是安全的」,而最常见的写法(
const X: ApiEndpoint = { … })会强迫作者把authRequired显式写出来。显式写true无害;但一旦作者被迫开始考虑这个键,写错成false的概率就不再是零 —— 而false是这条线上唯一不可挽回的错误。对 AI 作者尤其如此:它会照着类型报错补上缺的键,而不是去换类型。今天没有用户被这个坑到(showcase 的两条都显式
true),所以按观察类归档。可能的方向,不预设结论:apis:的作者面统一暴露ApiEndpointInput(与ApiEndpointSchema.create已经用z.input的做法一致);关联:#5112、
packages/spec/src/api/endpoint.zod.ts:80-84、ADR-0121 D6。