ssh-keys NonRepo routes lack /api-browser/v1 twins required by 07 §3 lane note #339

Closed
opened 2026-09-11 17:22:38 +00:00 by crueber · 3 comments
Owner

Child of #331 (audit finding 3230, commit 70d29dd). docs/go/07_api.md lane note says Non-repo endpoints have /api/v1 and /api-browser/v1 twins, but GET/POST/DELETE /api/v1/ssh-keys (internal/api/routes.go:42-44) have no /api-browser/v1 twin. Mitigating: 17_ssh.md:89 and 11_config_cli.md:66 name only the /api/v1 routes and the UI uses the token lane directly (Keys.jsx). Fix: amend the 07 section 3 lane note to carve out self-service ssh-keys as token-lane-only (or add the twins). Doc-clarity gap, not a functional bug.

Child of #331 (audit finding 3230, commit 70d29dd). docs/go/07_api.md lane note says Non-repo endpoints have /api/v1 and /api-browser/v1 twins, but GET/POST/DELETE /api/v1/ssh-keys (internal/api/routes.go:42-44) have no /api-browser/v1 twin. Mitigating: 17_ssh.md:89 and 11_config_cli.md:66 name only the /api/v1 routes and the UI uses the token lane directly (Keys.jsx). Fix: amend the 07 section 3 lane note to carve out self-service ssh-keys as token-lane-only (or add the twins). Doc-clarity gap, not a functional bug.
Author
Owner

Fix up at #351 (docs-only carve-out of ssh-keys as token-lane-only in 07 §3 + Decisions entry). Chose the carve-out rail: no consumer for browser twins exists (Keys.jsx uses /api/v1 directly). Not merging — needs review.

Fix up at #351 (docs-only carve-out of ssh-keys as token-lane-only in 07 §3 + Decisions entry). Chose the carve-out rail: no consumer for browser twins exists (Keys.jsx uses /api/v1 directly). Not merging — needs review.
Author
Owner

Review of PR #351 (fix/issue-339, docs-only):

Scope: docs/go/07_api.md only (11+/1-, git diff name-only confirms). No code changed. Matches expected shape: §3 lane-note carve-out + Decisions entry.

Verification (main checkout, read-only):

  • routes.go:42-44: GET/POST /api/v1/ssh-keys + DELETE /api/v1/ssh-keys/{fp}, all NonRepo:true, zero /api-browser/v1/ssh-keys rows. Carve-out factually true.
  • Twins spot-check: every other NonRepo endpoint has its twin — /me (L41→L45), /owners, /owners/detailed, /owners/{owner}/repos, .../detailed, profile GET+PUT (each /api/v1→/api-browser/v1, plus /services/api twins for owners per the lane note); /services/api/instance is the documented services-only exception. ssh-keys is the sole carve-out.
  • Repo-wide grep for 'api-browser/v1/ssh-keys': zero hits. Nothing to un-break.
  • Keys.jsx (L4, L23, L43, L68): fetches /api/v1/ssh-keys directly (same-origin), no browser-lane consumer. True.
  • 17_ssh.md §3 (L89) and 11_config_cli.md (L66, L351) name only /api/v1/ssh-keys. True.
  • Decisions entry records the carve-out-over-twins rationale explicitly (no consumer; twins would widen the browser-lane cookie surface for nothing; no wire/behavior change). Law 12 satisfied: code/doc disagreement fixed doc-side in the same change, decision appended not silently overridden.
  • Nit (non-blocking): internal/api/routes.go L39-40 header comment still reads as blanket '/api/v1 + /api-browser/v1' twins; it was already approximate (instance is services-only). Left alone to keep this change docs-only.

MERGE RECOMMENDATION: ready to merge.

Review of PR #351 (fix/issue-339, docs-only): Scope: docs/go/07_api.md only (11+/1-, git diff name-only confirms). No code changed. Matches expected shape: §3 lane-note carve-out + Decisions entry. Verification (main checkout, read-only): - routes.go:42-44: GET/POST /api/v1/ssh-keys + DELETE /api/v1/ssh-keys/{fp}, all NonRepo:true, zero /api-browser/v1/ssh-keys rows. Carve-out factually true. - Twins spot-check: every other NonRepo endpoint has its twin — /me (L41→L45), /owners, /owners/detailed, /owners/{owner}/repos, .../detailed, profile GET+PUT (each /api/v1→/api-browser/v1, plus /services/api twins for owners per the lane note); /services/api/instance is the documented services-only exception. ssh-keys is the sole carve-out. - Repo-wide grep for 'api-browser/v1/ssh-keys': zero hits. Nothing to un-break. - Keys.jsx (L4, L23, L43, L68): fetches /api/v1/ssh-keys directly (same-origin), no browser-lane consumer. True. - 17_ssh.md §3 (L89) and 11_config_cli.md (L66, L351) name only /api/v1/ssh-keys. True. - Decisions entry records the carve-out-over-twins rationale explicitly (no consumer; twins would widen the browser-lane cookie surface for nothing; no wire/behavior change). Law 12 satisfied: code/doc disagreement fixed doc-side in the same change, decision appended not silently overridden. - Nit (non-blocking): internal/api/routes.go L39-40 header comment still reads as blanket '/api/v1 + /api-browser/v1' twins; it was already approximate (instance is services-only). Left alone to keep this change docs-only. MERGE RECOMMENDATION: ready to merge.
Author
Owner

Fixed by PR #351 (review clean; carve-out verified true, sole exception, no consumers of twins; law 12 satisfied), merged. Closing.

Fixed by PR #351 (review clean; carve-out verified true, sole exception, no consumers of twins; law 12 satisfied), merged. Closing.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
crueber/walhub#339
No description provided.