mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-10 03:30:59 +00:00
parent
9e80a76798
commit
3e0fc4249d
5 changed files with 175 additions and 7 deletions
|
|
@ -1,29 +1,35 @@
|
|||
{
|
||||
"timestamp": "2026-03-19T15:05:19.277221Z",
|
||||
"current_node": "preflight_lint",
|
||||
"timestamp": "2026-03-19T15:08:46.450812Z",
|
||||
"current_node": "implement",
|
||||
"completed_nodes": [
|
||||
"start",
|
||||
"toolchain",
|
||||
"preflight_compile",
|
||||
"preflight_lint"
|
||||
"preflight_lint",
|
||||
"implement"
|
||||
],
|
||||
"node_retries": {
|
||||
"preflight_lint": 1,
|
||||
"toolchain": 1,
|
||||
"preflight_compile": 1,
|
||||
"implement": 1,
|
||||
"start": 1
|
||||
},
|
||||
"context_values": {
|
||||
"internal.node_visit_count": 1,
|
||||
"current.preamble": "Goal: # Detect GitHub App visibility mismatch during `repo init`\n\n## Context\n\nWhen `fabro repo init` detects the GitHub App is not installed for a repo, it shows a generic \"install at\" URL. But if the repo owner differs from the app owner, the app must be **public** to be installable. Users currently get no guidance about this, leading to confusion when the install link doesn't work.\n\n## Changes\n\n### 1. Add `get_authenticated_app()` to fabro-github\n\n**File:** `lib/crates/fabro-github/src/lib.rs`\n\nAdd two public structs near the existing response types (around line 40):\n\n```rust\npub struct AppOwner {\n pub login: String,\n}\n\npub struct AppInfo {\n pub slug: String,\n pub owner: AppOwner,\n}\n```\n\nAdd function after `check_app_installed` (after line 525):\n\n- `pub async fn get_authenticated_app(client, jwt, base_url) -> Result<AppInfo, String>`\n- Calls `GET {base_url}/app` with Bearer JWT auth\n- Returns `AppInfo` on 200, errors on 401/other\n\n### 2. Add `is_app_public()` to fabro-github\n\n**File:** `lib/crates/fabro-github/src/lib.rs`\n\nAdd function after `get_authenticated_app`:\n\n- `pub async fn is_app_public(client, slug, base_url) -> Result<bool, String>`\n- Calls `GET {base_url}/apps/{slug}` **without** auth (public apps are visible to unauthenticated requests)\n- Returns `Ok(true)` on 200, `Ok(false)` on 404, error on other status\n\n### 3. Update `check_github_app_installation` in init.rs\n\n**File:** `lib/crates/fabro-cli/src/init.rs`\n\nIn the `Ok(false)` branch (line 250), before showing the install URL:\n\n1. Call `get_authenticated_app()` to get the app's owner\n2. Compare `app_info.owner.login` with the repo `owner` (case-insensitive)\n3. If they differ, call `is_app_public()` to check visibility\n4. If the app is private and owners differ, show a targeted warning:\n\n```\n ! GitHub App \"{slug}\" is private but this repo belongs to a different owner ({repo_owner}).\n The app must be made public before it can be installed outside {app_owner}.\n Update visibility at: https://github.com/settings/apps/{slug}\n```\n\nAll new checks are best-effort — failures are silently ignored (the existing generic warning still shows).\n\n### 4. Tests\n\n**File:** `lib/crates/fabro-github/src/lib.rs` (test module)\n\nAdd tests using existing `mockito` patterns:\n\n- `get_authenticated_app_success` — 200 returns parsed `AppInfo`\n- `get_authenticated_app_auth_failure` — 401 returns error\n- `is_app_public_returns_true_on_200` — public app\n- `is_app_public_returns_false_on_404` — private app\n- `is_app_public_no_auth_header` — verify no Authorization header is sent\n\n## Verification\n\n1. `cargo test -p fabro-github` — new unit tests pass\n2. `cargo build --workspace` — compiles cleanly\n3. `cargo clippy --workspace -- -D warnings` — no warnings\n4. Manual: run `fabro repo init` in a repo owned by a different org than the app to verify the warning appears\n\n\n## Completed stages\n- **toolchain**: success\n - Script: `command -v cargo >/dev/null || { curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && sudo ln -sf $HOME/.cargo/bin/* /usr/local/bin/; }; cargo --version 2>&1`\n - Stdout:\n ```\n cargo 1.94.0 (85eff7c80 2026-01-15)\n ```\n - Stderr: (empty)\n- **preflight_compile**: success\n - Script: `cargo check -q --workspace 2>&1`\n - Stdout: (empty)\n - Stderr: (empty)\n",
|
||||
"current.preamble": "Goal: # Detect GitHub App visibility mismatch during `repo init`\n\n## Context\n\nWhen `fabro repo init` detects the GitHub App is not installed for a repo, it shows a generic \"install at\" URL. But if the repo owner differs from the app owner, the app must be **public** to be installable. Users currently get no guidance about this, leading to confusion when the install link doesn't work.\n\n## Changes\n\n### 1. Add `get_authenticated_app()` to fabro-github\n\n**File:** `lib/crates/fabro-github/src/lib.rs`\n\nAdd two public structs near the existing response types (around line 40):\n\n```rust\npub struct AppOwner {\n pub login: String,\n}\n\npub struct AppInfo {\n pub slug: String,\n pub owner: AppOwner,\n}\n```\n\nAdd function after `check_app_installed` (after line 525):\n\n- `pub async fn get_authenticated_app(client, jwt, base_url) -> Result<AppInfo, String>`\n- Calls `GET {base_url}/app` with Bearer JWT auth\n- Returns `AppInfo` on 200, errors on 401/other\n\n### 2. Add `is_app_public()` to fabro-github\n\n**File:** `lib/crates/fabro-github/src/lib.rs`\n\nAdd function after `get_authenticated_app`:\n\n- `pub async fn is_app_public(client, slug, base_url) -> Result<bool, String>`\n- Calls `GET {base_url}/apps/{slug}` **without** auth (public apps are visible to unauthenticated requests)\n- Returns `Ok(true)` on 200, `Ok(false)` on 404, error on other status\n\n### 3. Update `check_github_app_installation` in init.rs\n\n**File:** `lib/crates/fabro-cli/src/init.rs`\n\nIn the `Ok(false)` branch (line 250), before showing the install URL:\n\n1. Call `get_authenticated_app()` to get the app's owner\n2. Compare `app_info.owner.login` with the repo `owner` (case-insensitive)\n3. If they differ, call `is_app_public()` to check visibility\n4. If the app is private and owners differ, show a targeted warning:\n\n```\n ! GitHub App \"{slug}\" is private but this repo belongs to a different owner ({repo_owner}).\n The app must be made public before it can be installed outside {app_owner}.\n Update visibility at: https://github.com/settings/apps/{slug}\n```\n\nAll new checks are best-effort — failures are silently ignored (the existing generic warning still shows).\n\n### 4. Tests\n\n**File:** `lib/crates/fabro-github/src/lib.rs` (test module)\n\nAdd tests using existing `mockito` patterns:\n\n- `get_authenticated_app_success` — 200 returns parsed `AppInfo`\n- `get_authenticated_app_auth_failure` — 401 returns error\n- `is_app_public_returns_true_on_200` — public app\n- `is_app_public_returns_false_on_404` — private app\n- `is_app_public_no_auth_header` — verify no Authorization header is sent\n\n## Verification\n\n1. `cargo test -p fabro-github` — new unit tests pass\n2. `cargo build --workspace` — compiles cleanly\n3. `cargo clippy --workspace -- -D warnings` — no warnings\n4. Manual: run `fabro repo init` in a repo owned by a different org than the app to verify the warning appears\n\n\n## Completed stages\n- **toolchain**: success\n - Script: `command -v cargo >/dev/null || { curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && sudo ln -sf $HOME/.cargo/bin/* /usr/local/bin/; }; cargo --version 2>&1`\n - Stdout:\n ```\n cargo 1.94.0 (85eff7c80 2026-01-15)\n ```\n - Stderr: (empty)\n- **preflight_compile**: success\n - Script: `cargo check -q --workspace 2>&1`\n - Stdout: (empty)\n - Stderr: (empty)\n- **preflight_lint**: success\n - Script: `cargo clippy -q --workspace -- -D warnings 2>&1`\n - Stdout: (empty)\n - Stderr: (empty)\n",
|
||||
"response.implement": "All 55 tests pass. Here's a summary of all changes made:\n\n### Changes Summary\n\n**1. `lib/crates/fabro-github/src/lib.rs`** — Added two structs and two functions:\n\n- **`AppOwner`** struct — holds the `login` field for the app's owner\n- **`AppInfo`** struct — holds `slug` and `owner` (an `AppOwner`), both derived from `Deserialize`\n- **`get_authenticated_app(client, jwt, base_url)`** — calls `GET {base_url}/app` with Bearer JWT auth, returns `AppInfo` on 200, error on 401/other\n- **`is_app_public(client, slug, base_url)`** — calls `GET {base_url}/apps/{slug}` **without** auth, returns `Ok(true)` on 200, `Ok(false)` on 404, error on other\n\n**5 new tests** added to the test module:\n- `get_authenticated_app_success` — verifies 200 response is parsed into `AppInfo`\n- `get_authenticated_app_auth_failure` — verifies 401 returns authentication error\n- `is_app_public_returns_true_on_200` — public app returns true\n- `is_app_public_returns_false_on_404` — private app returns false\n- `is_app_public_no_auth_header` — verifies no `Authorization` header is sent (using `Matcher::Missing`)\n\n**2. `lib/crates/fabro-cli/src/init.rs`** — Updated `check_github_app_installation`:\n\nIn the `Ok(false)` branch (app not installed), before showing the install URL, added best-effort checks:\n1. Calls `get_authenticated_app()` to get the app's owner\n2. Compares `app_info.owner.login` with the repo `owner` (case-insensitive via `eq_ignore_ascii_case`)\n3. If they differ, calls `is_app_public()` to check visibility\n4. If the app is private and owners differ, shows a targeted warning about making the app public\n\nAll checks are best-effort — failures at any step are silently ignored and the existing generic warning still shows.",
|
||||
"internal.retry_count.toolchain": 1,
|
||||
"last_response": "All 55 tests pass. Here's a summary of all changes made:\n\n### Changes Summary\n\n**1. `lib/crates/fabro-github/src/lib.rs`** — Added two structs and two functions:\n\n- **`AppOwner`** struct — holds t",
|
||||
"failure_signature": "",
|
||||
"internal.retry_count.preflight_lint": 1,
|
||||
"internal.thread_id": "preflight_compile",
|
||||
"current_node": "preflight_lint",
|
||||
"internal.retry_count.implement": 1,
|
||||
"internal.thread_id": "preflight_lint",
|
||||
"current_node": "implement",
|
||||
"internal.retry_count.start": 1,
|
||||
"graph.rankdir": "LR",
|
||||
"internal.run_id": "01KM39Z9DVCBB36GZMYAA6P0FJ",
|
||||
"thread.preflight_lint.current_node": "implement",
|
||||
"outcome": "success",
|
||||
"graph.model_stylesheet": "\n * { backend: api; model: claude-opus-4-6;}\n ",
|
||||
"failure_class": "",
|
||||
|
|
@ -34,6 +40,7 @@
|
|||
"command.stderr": "",
|
||||
"internal.retry_count.preflight_compile": 1,
|
||||
"thread.toolchain.current_node": "preflight_compile",
|
||||
"last_stage": "implement",
|
||||
"command.output": ""
|
||||
},
|
||||
"logs": [],
|
||||
|
|
@ -56,6 +63,29 @@
|
|||
"notes": "Script completed: cargo clippy -q --workspace -- -D warnings 2>&1",
|
||||
"duration_ms": 13770
|
||||
},
|
||||
"implement": {
|
||||
"status": "success",
|
||||
"context_updates": {
|
||||
"last_response": "All 55 tests pass. Here's a summary of all changes made:\n\n### Changes Summary\n\n**1. `lib/crates/fabro-github/src/lib.rs`** — Added two structs and two functions:\n\n- **`AppOwner`** struct — holds t",
|
||||
"last_stage": "implement",
|
||||
"response.implement": "All 55 tests pass. Here's a summary of all changes made:\n\n### Changes Summary\n\n**1. `lib/crates/fabro-github/src/lib.rs`** — Added two structs and two functions:\n\n- **`AppOwner`** struct — holds the `login` field for the app's owner\n- **`AppInfo`** struct — holds `slug` and `owner` (an `AppOwner`), both derived from `Deserialize`\n- **`get_authenticated_app(client, jwt, base_url)`** — calls `GET {base_url}/app` with Bearer JWT auth, returns `AppInfo` on 200, error on 401/other\n- **`is_app_public(client, slug, base_url)`** — calls `GET {base_url}/apps/{slug}` **without** auth, returns `Ok(true)` on 200, `Ok(false)` on 404, error on other\n\n**5 new tests** added to the test module:\n- `get_authenticated_app_success` — verifies 200 response is parsed into `AppInfo`\n- `get_authenticated_app_auth_failure` — verifies 401 returns authentication error\n- `is_app_public_returns_true_on_200` — public app returns true\n- `is_app_public_returns_false_on_404` — private app returns false\n- `is_app_public_no_auth_header` — verifies no `Authorization` header is sent (using `Matcher::Missing`)\n\n**2. `lib/crates/fabro-cli/src/init.rs`** — Updated `check_github_app_installation`:\n\nIn the `Ok(false)` branch (app not installed), before showing the install URL, added best-effort checks:\n1. Calls `get_authenticated_app()` to get the app's owner\n2. Compares `app_info.owner.login` with the repo `owner` (case-insensitive via `eq_ignore_ascii_case`)\n3. If they differ, calls `is_app_public()` to check visibility\n4. If the app is private and owners differ, shows a targeted warning about making the app public\n\nAll checks are best-effort — failures at any step are silently ignored and the existing generic warning still shows."
|
||||
},
|
||||
"notes": "Stage completed: implement",
|
||||
"usage": {
|
||||
"model": "claude-opus-4-6",
|
||||
"input_tokens": 38264,
|
||||
"output_tokens": 4938,
|
||||
"cache_read_tokens": 401866,
|
||||
"cache_write_tokens": 43204,
|
||||
"reasoning_tokens": 126,
|
||||
"cost": 0.94431
|
||||
},
|
||||
"files_touched": [
|
||||
"/home/daytona/workspace/lib/crates/fabro-cli/src/init.rs",
|
||||
"/home/daytona/workspace/lib/crates/fabro-github/src/lib.rs"
|
||||
],
|
||||
"duration_ms": 203786
|
||||
},
|
||||
"toolchain": {
|
||||
"status": "success",
|
||||
"context_updates": {
|
||||
|
|
@ -70,8 +100,9 @@
|
|||
"duration_ms": 0
|
||||
}
|
||||
},
|
||||
"next_node_id": "implement",
|
||||
"next_node_id": "simplify_opus",
|
||||
"node_visits": {
|
||||
"implement": 1,
|
||||
"preflight_lint": 1,
|
||||
"preflight_compile": 1,
|
||||
"start": 1,
|
||||
|
|
|
|||
99
nodes/implement/prompt.md
Normal file
99
nodes/implement/prompt.md
Normal file
|
|
@ -0,0 +1,99 @@
|
|||
Goal: # Detect GitHub App visibility mismatch during `repo init`
|
||||
|
||||
## Context
|
||||
|
||||
When `fabro repo init` detects the GitHub App is not installed for a repo, it shows a generic "install at" URL. But if the repo owner differs from the app owner, the app must be **public** to be installable. Users currently get no guidance about this, leading to confusion when the install link doesn't work.
|
||||
|
||||
## Changes
|
||||
|
||||
### 1. Add `get_authenticated_app()` to fabro-github
|
||||
|
||||
**File:** `lib/crates/fabro-github/src/lib.rs`
|
||||
|
||||
Add two public structs near the existing response types (around line 40):
|
||||
|
||||
```rust
|
||||
pub struct AppOwner {
|
||||
pub login: String,
|
||||
}
|
||||
|
||||
pub struct AppInfo {
|
||||
pub slug: String,
|
||||
pub owner: AppOwner,
|
||||
}
|
||||
```
|
||||
|
||||
Add function after `check_app_installed` (after line 525):
|
||||
|
||||
- `pub async fn get_authenticated_app(client, jwt, base_url) -> Result<AppInfo, String>`
|
||||
- Calls `GET {base_url}/app` with Bearer JWT auth
|
||||
- Returns `AppInfo` on 200, errors on 401/other
|
||||
|
||||
### 2. Add `is_app_public()` to fabro-github
|
||||
|
||||
**File:** `lib/crates/fabro-github/src/lib.rs`
|
||||
|
||||
Add function after `get_authenticated_app`:
|
||||
|
||||
- `pub async fn is_app_public(client, slug, base_url) -> Result<bool, String>`
|
||||
- Calls `GET {base_url}/apps/{slug}` **without** auth (public apps are visible to unauthenticated requests)
|
||||
- Returns `Ok(true)` on 200, `Ok(false)` on 404, error on other status
|
||||
|
||||
### 3. Update `check_github_app_installation` in init.rs
|
||||
|
||||
**File:** `lib/crates/fabro-cli/src/init.rs`
|
||||
|
||||
In the `Ok(false)` branch (line 250), before showing the install URL:
|
||||
|
||||
1. Call `get_authenticated_app()` to get the app's owner
|
||||
2. Compare `app_info.owner.login` with the repo `owner` (case-insensitive)
|
||||
3. If they differ, call `is_app_public()` to check visibility
|
||||
4. If the app is private and owners differ, show a targeted warning:
|
||||
|
||||
```
|
||||
! GitHub App "{slug}" is private but this repo belongs to a different owner ({repo_owner}).
|
||||
The app must be made public before it can be installed outside {app_owner}.
|
||||
Update visibility at: https://github.com/settings/apps/{slug}
|
||||
```
|
||||
|
||||
All new checks are best-effort — failures are silently ignored (the existing generic warning still shows).
|
||||
|
||||
### 4. Tests
|
||||
|
||||
**File:** `lib/crates/fabro-github/src/lib.rs` (test module)
|
||||
|
||||
Add tests using existing `mockito` patterns:
|
||||
|
||||
- `get_authenticated_app_success` — 200 returns parsed `AppInfo`
|
||||
- `get_authenticated_app_auth_failure` — 401 returns error
|
||||
- `is_app_public_returns_true_on_200` — public app
|
||||
- `is_app_public_returns_false_on_404` — private app
|
||||
- `is_app_public_no_auth_header` — verify no Authorization header is sent
|
||||
|
||||
## Verification
|
||||
|
||||
1. `cargo test -p fabro-github` — new unit tests pass
|
||||
2. `cargo build --workspace` — compiles cleanly
|
||||
3. `cargo clippy --workspace -- -D warnings` — no warnings
|
||||
4. Manual: run `fabro repo init` in a repo owned by a different org than the app to verify the warning appears
|
||||
|
||||
|
||||
## Completed stages
|
||||
- **toolchain**: success
|
||||
- Script: `command -v cargo >/dev/null || { curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && sudo ln -sf $HOME/.cargo/bin/* /usr/local/bin/; }; cargo --version 2>&1`
|
||||
- Stdout:
|
||||
```
|
||||
cargo 1.94.0 (85eff7c80 2026-01-15)
|
||||
```
|
||||
- Stderr: (empty)
|
||||
- **preflight_compile**: success
|
||||
- Script: `cargo check -q --workspace 2>&1`
|
||||
- Stdout: (empty)
|
||||
- Stderr: (empty)
|
||||
- **preflight_lint**: success
|
||||
- Script: `cargo clippy -q --workspace -- -D warnings 2>&1`
|
||||
- Stdout: (empty)
|
||||
- Stderr: (empty)
|
||||
|
||||
|
||||
Read the plan file referenced in the goal and implement every step. Make all the code changes described in the plan. Use red/green TDD.
|
||||
5
nodes/implement/provider_used.json
Normal file
5
nodes/implement/provider_used.json
Normal file
|
|
@ -0,0 +1,5 @@
|
|||
{
|
||||
"mode": "agent",
|
||||
"provider": "anthropic",
|
||||
"model": "claude-opus-4-6"
|
||||
}
|
||||
27
nodes/implement/response.md
Normal file
27
nodes/implement/response.md
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
All 55 tests pass. Here's a summary of all changes made:
|
||||
|
||||
### Changes Summary
|
||||
|
||||
**1. `lib/crates/fabro-github/src/lib.rs`** — Added two structs and two functions:
|
||||
|
||||
- **`AppOwner`** struct — holds the `login` field for the app's owner
|
||||
- **`AppInfo`** struct — holds `slug` and `owner` (an `AppOwner`), both derived from `Deserialize`
|
||||
- **`get_authenticated_app(client, jwt, base_url)`** — calls `GET {base_url}/app` with Bearer JWT auth, returns `AppInfo` on 200, error on 401/other
|
||||
- **`is_app_public(client, slug, base_url)`** — calls `GET {base_url}/apps/{slug}` **without** auth, returns `Ok(true)` on 200, `Ok(false)` on 404, error on other
|
||||
|
||||
**5 new tests** added to the test module:
|
||||
- `get_authenticated_app_success` — verifies 200 response is parsed into `AppInfo`
|
||||
- `get_authenticated_app_auth_failure` — verifies 401 returns authentication error
|
||||
- `is_app_public_returns_true_on_200` — public app returns true
|
||||
- `is_app_public_returns_false_on_404` — private app returns false
|
||||
- `is_app_public_no_auth_header` — verifies no `Authorization` header is sent (using `Matcher::Missing`)
|
||||
|
||||
**2. `lib/crates/fabro-cli/src/init.rs`** — Updated `check_github_app_installation`:
|
||||
|
||||
In the `Ok(false)` branch (app not installed), before showing the install URL, added best-effort checks:
|
||||
1. Calls `get_authenticated_app()` to get the app's owner
|
||||
2. Compares `app_info.owner.login` with the repo `owner` (case-insensitive via `eq_ignore_ascii_case`)
|
||||
3. If they differ, calls `is_app_public()` to check visibility
|
||||
4. If the app is private and owners differ, shows a targeted warning about making the app public
|
||||
|
||||
All checks are best-effort — failures at any step are silently ignored and the existing generic warning still shows.
|
||||
6
nodes/implement/status.json
Normal file
6
nodes/implement/status.json
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{
|
||||
"status": "success",
|
||||
"notes": "Stage completed: implement",
|
||||
"failure_reason": null,
|
||||
"timestamp": "2026-03-19T15:08:46.450407+00:00"
|
||||
}
|
||||
Loading…
Add table
Reference in a new issue