From e1a458793d6f66c798006744321ca4a10405fc9d Mon Sep 17 00:00:00 2001 From: Fabro Date: Thu, 19 Mar 2026 11:05:02 -0400 Subject: [PATCH] checkpoint MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ⚒️ Generated with [Fabro](https://fabro.sh) --- checkpoint.json | 30 ++++++++++++++----- .../preflight_compile/script_invocation.json | 5 ++++ nodes/preflight_compile/script_timing.json | 5 ++++ nodes/preflight_compile/status.json | 6 ++++ 4 files changed, 38 insertions(+), 8 deletions(-) create mode 100644 nodes/preflight_compile/script_invocation.json create mode 100644 nodes/preflight_compile/script_timing.json create mode 100644 nodes/preflight_compile/status.json diff --git a/checkpoint.json b/checkpoint.json index 4d163be6f..4cc344bf7 100644 --- a/checkpoint.json +++ b/checkpoint.json @@ -1,21 +1,23 @@ { - "timestamp": "2026-03-19T15:03:46.386424Z", - "current_node": "toolchain", + "timestamp": "2026-03-19T15:05:02.687355Z", + "current_node": "preflight_compile", "completed_nodes": [ "start", - "toolchain" + "toolchain", + "preflight_compile" ], "node_retries": { "toolchain": 1, + "preflight_compile": 1, "start": 1 }, "context_values": { "internal.node_visit_count": 1, - "current.preamble": "Goal: # Detect GitHub App visibility mismatch during `repo init`\n\n## Context\n\nWhen `fabro repo init` detects the GitHub App is not installed for a repo, it shows a generic \"install at\" URL. But if the repo owner differs from the app owner, the app must be **public** to be installable. Users currently get no guidance about this, leading to confusion when the install link doesn't work.\n\n## Changes\n\n### 1. Add `get_authenticated_app()` to fabro-github\n\n**File:** `lib/crates/fabro-github/src/lib.rs`\n\nAdd two public structs near the existing response types (around line 40):\n\n```rust\npub struct AppOwner {\n pub login: String,\n}\n\npub struct AppInfo {\n pub slug: String,\n pub owner: AppOwner,\n}\n```\n\nAdd function after `check_app_installed` (after line 525):\n\n- `pub async fn get_authenticated_app(client, jwt, base_url) -> Result`\n- Calls `GET {base_url}/app` with Bearer JWT auth\n- Returns `AppInfo` on 200, errors on 401/other\n\n### 2. Add `is_app_public()` to fabro-github\n\n**File:** `lib/crates/fabro-github/src/lib.rs`\n\nAdd function after `get_authenticated_app`:\n\n- `pub async fn is_app_public(client, slug, base_url) -> Result`\n- Calls `GET {base_url}/apps/{slug}` **without** auth (public apps are visible to unauthenticated requests)\n- Returns `Ok(true)` on 200, `Ok(false)` on 404, error on other status\n\n### 3. Update `check_github_app_installation` in init.rs\n\n**File:** `lib/crates/fabro-cli/src/init.rs`\n\nIn the `Ok(false)` branch (line 250), before showing the install URL:\n\n1. Call `get_authenticated_app()` to get the app's owner\n2. Compare `app_info.owner.login` with the repo `owner` (case-insensitive)\n3. If they differ, call `is_app_public()` to check visibility\n4. If the app is private and owners differ, show a targeted warning:\n\n```\n ! GitHub App \"{slug}\" is private but this repo belongs to a different owner ({repo_owner}).\n The app must be made public before it can be installed outside {app_owner}.\n Update visibility at: https://github.com/settings/apps/{slug}\n```\n\nAll new checks are best-effort — failures are silently ignored (the existing generic warning still shows).\n\n### 4. Tests\n\n**File:** `lib/crates/fabro-github/src/lib.rs` (test module)\n\nAdd tests using existing `mockito` patterns:\n\n- `get_authenticated_app_success` — 200 returns parsed `AppInfo`\n- `get_authenticated_app_auth_failure` — 401 returns error\n- `is_app_public_returns_true_on_200` — public app\n- `is_app_public_returns_false_on_404` — private app\n- `is_app_public_no_auth_header` — verify no Authorization header is sent\n\n## Verification\n\n1. `cargo test -p fabro-github` — new unit tests pass\n2. `cargo build --workspace` — compiles cleanly\n3. `cargo clippy --workspace -- -D warnings` — no warnings\n4. Manual: run `fabro repo init` in a repo owned by a different org than the app to verify the warning appears\n\n", + "current.preamble": "Goal: # Detect GitHub App visibility mismatch during `repo init`\n\n## Context\n\nWhen `fabro repo init` detects the GitHub App is not installed for a repo, it shows a generic \"install at\" URL. But if the repo owner differs from the app owner, the app must be **public** to be installable. Users currently get no guidance about this, leading to confusion when the install link doesn't work.\n\n## Changes\n\n### 1. Add `get_authenticated_app()` to fabro-github\n\n**File:** `lib/crates/fabro-github/src/lib.rs`\n\nAdd two public structs near the existing response types (around line 40):\n\n```rust\npub struct AppOwner {\n pub login: String,\n}\n\npub struct AppInfo {\n pub slug: String,\n pub owner: AppOwner,\n}\n```\n\nAdd function after `check_app_installed` (after line 525):\n\n- `pub async fn get_authenticated_app(client, jwt, base_url) -> Result`\n- Calls `GET {base_url}/app` with Bearer JWT auth\n- Returns `AppInfo` on 200, errors on 401/other\n\n### 2. Add `is_app_public()` to fabro-github\n\n**File:** `lib/crates/fabro-github/src/lib.rs`\n\nAdd function after `get_authenticated_app`:\n\n- `pub async fn is_app_public(client, slug, base_url) -> Result`\n- Calls `GET {base_url}/apps/{slug}` **without** auth (public apps are visible to unauthenticated requests)\n- Returns `Ok(true)` on 200, `Ok(false)` on 404, error on other status\n\n### 3. Update `check_github_app_installation` in init.rs\n\n**File:** `lib/crates/fabro-cli/src/init.rs`\n\nIn the `Ok(false)` branch (line 250), before showing the install URL:\n\n1. Call `get_authenticated_app()` to get the app's owner\n2. Compare `app_info.owner.login` with the repo `owner` (case-insensitive)\n3. If they differ, call `is_app_public()` to check visibility\n4. If the app is private and owners differ, show a targeted warning:\n\n```\n ! GitHub App \"{slug}\" is private but this repo belongs to a different owner ({repo_owner}).\n The app must be made public before it can be installed outside {app_owner}.\n Update visibility at: https://github.com/settings/apps/{slug}\n```\n\nAll new checks are best-effort — failures are silently ignored (the existing generic warning still shows).\n\n### 4. Tests\n\n**File:** `lib/crates/fabro-github/src/lib.rs` (test module)\n\nAdd tests using existing `mockito` patterns:\n\n- `get_authenticated_app_success` — 200 returns parsed `AppInfo`\n- `get_authenticated_app_auth_failure` — 401 returns error\n- `is_app_public_returns_true_on_200` — public app\n- `is_app_public_returns_false_on_404` — private app\n- `is_app_public_no_auth_header` — verify no Authorization header is sent\n\n## Verification\n\n1. `cargo test -p fabro-github` — new unit tests pass\n2. `cargo build --workspace` — compiles cleanly\n3. `cargo clippy --workspace -- -D warnings` — no warnings\n4. Manual: run `fabro repo init` in a repo owned by a different org than the app to verify the warning appears\n\n\n## Completed stages\n- **toolchain**: success\n - Script: `command -v cargo >/dev/null || { curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && sudo ln -sf $HOME/.cargo/bin/* /usr/local/bin/; }; cargo --version 2>&1`\n - Stdout:\n ```\n cargo 1.94.0 (85eff7c80 2026-01-15)\n ```\n - Stderr: (empty)\n", "internal.retry_count.toolchain": 1, "failure_signature": "", - "internal.thread_id": "start", - "current_node": "toolchain", + "internal.thread_id": "toolchain", + "current_node": "preflight_compile", "internal.retry_count.start": 1, "graph.rankdir": "LR", "internal.run_id": "01KM39Z9DVCBB36GZMYAA6P0FJ", @@ -26,7 +28,9 @@ "internal.fidelity": "compact", "thread.start.current_node": "toolchain", "command.stderr": "", - "command.output": "cargo 1.94.0 (85eff7c80 2026-01-15)\n" + "internal.retry_count.preflight_compile": 1, + "thread.toolchain.current_node": "preflight_compile", + "command.output": "" }, "logs": [], "node_outcomes": { @@ -39,13 +43,23 @@ "notes": "Script completed: command -v cargo >/dev/null || { curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && sudo ln -sf $HOME/.cargo/bin/* /usr/local/bin/; }; cargo --version 2>&1", "duration_ms": 72 }, + "preflight_compile": { + "status": "success", + "context_updates": { + "command.output": "", + "command.stderr": "" + }, + "notes": "Script completed: cargo check -q --workspace 2>&1", + "duration_ms": 73470 + }, "start": { "status": "success", "duration_ms": 0 } }, - "next_node_id": "preflight_compile", + "next_node_id": "preflight_lint", "node_visits": { + "preflight_compile": 1, "start": 1, "toolchain": 1 } diff --git a/nodes/preflight_compile/script_invocation.json b/nodes/preflight_compile/script_invocation.json new file mode 100644 index 000000000..ccbef36c7 --- /dev/null +++ b/nodes/preflight_compile/script_invocation.json @@ -0,0 +1,5 @@ +{ + "command": "cargo check -q --workspace 2>&1", + "language": "shell", + "timeout_ms": null +} \ No newline at end of file diff --git a/nodes/preflight_compile/script_timing.json b/nodes/preflight_compile/script_timing.json new file mode 100644 index 000000000..b66895b99 --- /dev/null +++ b/nodes/preflight_compile/script_timing.json @@ -0,0 +1,5 @@ +{ + "duration_ms": 73469, + "exit_code": 0, + "timed_out": false +} \ No newline at end of file diff --git a/nodes/preflight_compile/status.json b/nodes/preflight_compile/status.json new file mode 100644 index 000000000..2f5aeebe5 --- /dev/null +++ b/nodes/preflight_compile/status.json @@ -0,0 +1,6 @@ +{ + "status": "success", + "notes": "Script completed: cargo check -q --workspace 2>&1", + "failure_reason": null, + "timestamp": "2026-03-19T15:05:02.686836+00:00" +} \ No newline at end of file