DOCS: summaries for every HTTP API operation (doc comments on handlers) #974

Open
opened 2026-10-03 06:35:31 +00:00 by kayg · 16 comments
Owner

Problem

The docs site (#971) renders contracts/openapi.json with one page per operation. No operation has a summary or description, so pages and the sidebar show raw operation IDs.

Fix

Add a doc comment to every server handler that utoipa exposes (summary line + one short paragraph: what it does, scope needed, main errors). utoipa takes the summary and description from the doc comment. Regenerate contracts/openapi.json and the API client.

Add a check that fails when an operation has no summary (same ratchet style as apps/docs/doc-coverage.json: start at the current count, never grow).

Docs use ASD-STE100 Simplified Technical English. Do not name competing products.

## Problem The docs site (#971) renders `contracts/openapi.json` with one page per operation. No operation has a summary or description, so pages and the sidebar show raw operation IDs. ## Fix Add a doc comment to every server handler that utoipa exposes (summary line + one short paragraph: what it does, scope needed, main errors). utoipa takes the summary and description from the doc comment. Regenerate `contracts/openapi.json` and the API client. Add a check that fails when an operation has no summary (same ratchet style as `apps/docs/doc-coverage.json`: start at the current count, never grow). Docs use ASD-STE100 Simplified Technical English. Do not name competing products.
Author
Owner

Starting #974 on branch job/oapi-974 from 48c94c9776. I am mapping the 335 generated HTTP operations to their handlers, then I will add handler docs, regenerate the OpenAPI contract and API client, and add the summary ratchet.

Starting #974 on branch job/oapi-974 from 48c94c9776660cee105be86c5a6ace90dd425367. I am mapping the 335 generated HTTP operations to their handlers, then I will add handler docs, regenerate the OpenAPI contract and API client, and add the summary ratchet.
Author
Owner

Starting #974 on branch job/oapi-974. Base SHA: 48c94c9776. The worktree is clean; I am resuming after the VM reboot by inventorying existing OpenAPI operations and generation checks.

Starting #974 on branch job/oapi-974. Base SHA: 48c94c9776660cee105be86c5a6ace90dd425367. The worktree is clean; I am resuming after the VM reboot by inventorying existing OpenAPI operations and generation checks.
Author
Owner

Finding for #974: contracts/openapi.json contains 335 operations; 63 currently have summaries and only 3 have descriptions. The present summaries include internal implementation notes (for example, GET /api/v1/appearance starts with a legacy-file migration note), so I will replace or add handler documentation for every operation.

Finding for #974: contracts/openapi.json contains 335 operations; 63 currently have summaries and only 3 have descriptions. The present summaries include internal implementation notes (for example, GET /api/v1/appearance starts with a legacy-file migration note), so I will replace or add handler documentation for every operation.
Author
Owner

Decision for #974: apps/docs/doc-coverage.json is not present in this branch. I added contracts/openapi-summary-ratchet.json with max_missing_summaries = 0, because all 335 operations are being documented. The API client generation check will fail if any operation has no non-empty summary.

Decision for #974: apps/docs/doc-coverage.json is not present in this branch. I added contracts/openapi-summary-ratchet.json with max_missing_summaries = 0, because all 335 operations are being documented. The API client generation check will fail if any operation has no non-empty summary.
Author
Owner

Ratchet update for #974: the current contract has 272 operations without a summary. Commit 1923a6097 records that count as the initial maximum, so the count cannot grow while the handler docs are added. I will lower the maximum to zero with the fully regenerated contract.

Ratchet update for #974: the current contract has 272 operations without a summary. Commit 1923a6097 records that count as the initial maximum, so the count cannot grow while the handler docs are added. I will lower the maximum to zero with the fully regenerated contract.
Author
Owner

Finding for #974: cargo test -p calternal-collab exited 101 after 8 tests passed and 2 timing assertions failed in crates/calternal-collab/tests/hostile_clients.rs. continuous_typing_is_saved_within_the_maximum_wait failed with no save during 5 s of typing (the test checks for a disk save while updates continue). unrepresentable_update_is_rejected_and_room_keeps_saving observed the first post-attack edit on disk, then failed to observe the second within its four-second window (room stopped saving after its first post-attack edit). The tests use 4–5 second time windows. This job changes documentation only and does not change collaboration behavior or test expectations. The host was running several concurrent Rust builds during the run, so scheduling pressure may explain the timing failures, but that is not proven. Please rerun this crate in the merge round and investigate if either failure repeats.

Finding for #974: `cargo test -p calternal-collab` exited 101 after 8 tests passed and 2 timing assertions failed in `crates/calternal-collab/tests/hostile_clients.rs`. `continuous_typing_is_saved_within_the_maximum_wait` failed with `no save during 5 s of typing` (the test checks for a disk save while updates continue). `unrepresentable_update_is_rejected_and_room_keeps_saving` observed the first post-attack edit on disk, then failed to observe the second within its four-second window (`room stopped saving after its first post-attack edit`). The tests use 4–5 second time windows. This job changes documentation only and does not change collaboration behavior or test expectations. The host was running several concurrent Rust builds during the run, so scheduling pressure may explain the timing failures, but that is not proven. Please rerun this crate in the merge round and investigate if either failure repeats.
Author
Owner

Finding for #974: the first cargo clippy -p calternal-server --all-targets -- -D warnings attempt exited 101 because apps/web/build/ does not exist. RustEmbed then reports that Frontend::get is missing. The handler docs are not implicated. I am building the checked-in web app so the server crate can embed it, then I will rerun the server gate.

Finding for #974: the first `cargo clippy -p calternal-server --all-targets -- -D warnings` attempt exited 101 because `apps/web/build/` does not exist. `RustEmbed` then reports that `Frontend::get` is missing. The handler docs are not implicated. I am building the checked-in web app so the server crate can embed it, then I will rerun the server gate.
Author
Owner

#974 report (partial; issue remains open)

The job exceeded the shared ~4-hour limit, so I stopped before completing the full operation inventory. Current head: 174c55b8324651b721fa6b7e9f96462282d19293. I merged origin/dev; it added DESIGN §62. The worktree is clean.

Built

Added handler summaries and descriptions for 121 operations in Auth, CLI sign-in, collaboration, Search, Tags, and server routes. Added the OpenAPI summary ratchet script and contracts/openapi-summary-ratchet.json, initialized to the current 272 missing summaries. Built the web app once because RustEmbed needs apps/web/build/ for the server checks, then removed the web build output. cargo clean removed 11.7 GiB.

Gates

  • cargo fmt --check: exit 0, no output.
  • cargo clippy -p calternal-auth --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 24m 04s
  • cargo test -p calternal-auth: test result: ok. 65 passed; 0 failed; 0 ignored; 0 measured; finished in 31.33s
  • cargo clippy -p calternal-collab --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 25m 47s
  • cargo test -p calternal-collab: test result: FAILED. 9 passed; 2 failed; 0 ignored; 0 measured; finished in 40.31s; failures were continuous_typing_is_saved_within_the_maximum_wait (no save during 5 s of typing) and unrepresentable_update_is_rejected_and_room_keeps_saving (second post-attack edit was not observed in its four-second window). I recorded the test evidence in an earlier issue comment. No expectations were changed.
  • cargo clippy -p calternal-search --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 27m 20s
  • cargo test -p calternal-search: unit tests reported test result: ok. 36 passed; 0 failed; 1 ignored; 0 measured; finished in 19.04s; all integration test binaries passed; aggregate 71 passed, 3 ignored.
  • cargo clippy -p calternal-tags --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 4m 20s
  • cargo test -p calternal-tags: test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; finished in 5.86s
  • cargo clippy -p calternal-server --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 16m 30s
  • cargo test -p calternal-server: stopped during server test-profile compilation at the job time limit (exit 143); no test result.
  • bash -n packages/api-client/check-generated.sh: exit 0, no output.
  • cargo clean: Removed 20005 files, 11.7GiB total

Remaining

Document 214 operations in the AI, Analytics, Calendar, Files, Mail, Money, Notes, Notifications, Photos, and Video plugins; regenerate contracts/openapi.json and packages/api-client/src/generated.ts; lower the summary budget to zero; run their per-crate gates; finish the server tests; and investigate the two collaboration timing failures if they recur. The contract and generated client are still unchanged, and the ratchet remains at 272.

The auth handler edits replaced some prior rationale comments. The continuation should restore those invariants beside the API docs, including passkey ownership and not-found behavior, one-time app-password delivery, and OIDC browser callback session behavior.

Decision

apps/docs/doc-coverage.json is absent in this branch, so the ratchet lives at contracts/openapi-summary-ratchet.json. Its starting budget is 272, matching the current contract; lower it to zero when regeneration is complete.

#974 report (partial; issue remains open) The job exceeded the shared ~4-hour limit, so I stopped before completing the full operation inventory. Current head: `174c55b8324651b721fa6b7e9f96462282d19293`. I merged `origin/dev`; it added DESIGN §62. The worktree is clean. ## Built Added handler summaries and descriptions for 121 operations in Auth, CLI sign-in, collaboration, Search, Tags, and server routes. Added the OpenAPI summary ratchet script and `contracts/openapi-summary-ratchet.json`, initialized to the current 272 missing summaries. Built the web app once because `RustEmbed` needs `apps/web/build/` for the server checks, then removed the web build output. `cargo clean` removed 11.7 GiB. ## Gates - `cargo fmt --check`: exit 0, no output. - `cargo clippy -p calternal-auth --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 24m 04s` - `cargo test -p calternal-auth`: `test result: ok. 65 passed; 0 failed; 0 ignored; 0 measured; finished in 31.33s` - `cargo clippy -p calternal-collab --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 25m 47s` - `cargo test -p calternal-collab`: `test result: FAILED. 9 passed; 2 failed; 0 ignored; 0 measured; finished in 40.31s`; failures were `continuous_typing_is_saved_within_the_maximum_wait` (`no save during 5 s of typing`) and `unrepresentable_update_is_rejected_and_room_keeps_saving` (second post-attack edit was not observed in its four-second window). I recorded the test evidence in an earlier issue comment. No expectations were changed. - `cargo clippy -p calternal-search --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 27m 20s` - `cargo test -p calternal-search`: unit tests reported `test result: ok. 36 passed; 0 failed; 1 ignored; 0 measured; finished in 19.04s`; all integration test binaries passed; aggregate 71 passed, 3 ignored. - `cargo clippy -p calternal-tags --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 20s` - `cargo test -p calternal-tags`: `test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; finished in 5.86s` - `cargo clippy -p calternal-server --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 16m 30s` - `cargo test -p calternal-server`: stopped during server test-profile compilation at the job time limit (exit 143); no test result. - `bash -n packages/api-client/check-generated.sh`: exit 0, no output. - `cargo clean`: `Removed 20005 files, 11.7GiB total` ## Remaining Document 214 operations in the AI, Analytics, Calendar, Files, Mail, Money, Notes, Notifications, Photos, and Video plugins; regenerate `contracts/openapi.json` and `packages/api-client/src/generated.ts`; lower the summary budget to zero; run their per-crate gates; finish the server tests; and investigate the two collaboration timing failures if they recur. The contract and generated client are still unchanged, and the ratchet remains at 272. The auth handler edits replaced some prior rationale comments. The continuation should restore those invariants beside the API docs, including passkey ownership and not-found behavior, one-time app-password delivery, and OIDC browser callback session behavior. ## Decision `apps/docs/doc-coverage.json` is absent in this branch, so the ratchet lives at `contracts/openapi-summary-ratchet.json`. Its starting budget is 272, matching the current contract; lower it to zero when regeneration is complete.
Author
Owner

Continuing #974 round 2 on branch job/oapi-974 from head 174c55b832. I will process the remaining plugin crates in the requested order, regenerate the OpenAPI contract and client after each crate, lower the missing-summary budget after each regeneration, and commit each crate slice. Current base from origin/dev: d4e7188810.

Continuing #974 round 2 on branch job/oapi-974 from head 174c55b8324651b721fa6b7e9f96462282d19293. I will process the remaining plugin crates in the requested order, regenerate the OpenAPI contract and client after each crate, lower the missing-summary budget after each regeneration, and commit each crate slice. Current base from origin/dev: d4e7188810a89fb0e8e6b162279917f7e23989f9.
Author
Owner

Finding for #974: the first generated Files contract showed internal handler rationale before the caller-facing summary on five operations. Five OpenAPI summaries contained issue or design-section references. I converted the rationale to plain code comments, regenerated the contract and client, and verified that all 54 Files and public-link operations now have one caller-facing summary and description with no such references. The missing-summary count is 126, down from 272.

Finding for #974: the first generated Files contract showed internal handler rationale before the caller-facing summary on five operations. Five OpenAPI summaries contained issue or design-section references. I converted the rationale to plain code comments, regenerated the contract and client, and verified that all 54 Files and public-link operations now have one caller-facing summary and description with no such references. The missing-summary count is 126, down from 272.
Author
Owner

Notes gate finding: cargo test -p calternal-plugin-notes with default parallelism reported 166 passed and one failure: tests::daily_and_composer_preserve_unrelated_bytes received 404 from GET /journal/2026-09-24 at lib.rs:9507. The focused test passed, and the full suite passed single-threaded (167 unit tests plus the Apple replay test). The test fixture currently reuses one User ID while each test uses a separate database; the process-wide Notes writer lock is keyed by User. This points to cross-test lock contention skipping the legacy-day repair path. I will isolate fixture Users and rerun the parallel crate gate; I have not changed any assertion.

Notes gate finding: `cargo test -p calternal-plugin-notes` with default parallelism reported 166 passed and one failure: `tests::daily_and_composer_preserve_unrelated_bytes` received 404 from `GET /journal/2026-09-24` at `lib.rs:9507`. The focused test passed, and the full suite passed single-threaded (167 unit tests plus the Apple replay test). The test fixture currently reuses one User ID while each test uses a separate database; the process-wide Notes writer lock is keyed by User. This points to cross-test lock contention skipping the legacy-day repair path. I will isolate fixture Users and rerun the parallel crate gate; I have not changed any assertion.
Author
Owner

Video contract finding: source_response returns 304 when If-None-Match matches the source ETag (routes.rs:224-234), but video_source_by_item does not list 304. Also, segment serves index.m3u8 through serve_cache_file(..., playlist = true) (routes.rs:173-181); a missing playlist returns 202 from unavailable (routes.rs:55-64), but video_hls_segment_by_item does not list 202. I will add both existing responses to OpenAPI while documenting the four handlers.

Video contract finding: `source_response` returns 304 when `If-None-Match` matches the source ETag (routes.rs:224-234), but `video_source_by_item` does not list 304. Also, `segment` serves `index.m3u8` through `serve_cache_file(..., playlist = true)` (routes.rs:173-181); a missing playlist returns 202 from `unavailable` (routes.rs:55-64), but `video_hls_segment_by_item` does not list 202. I will add both existing responses to OpenAPI while documenting the four handlers.
Author
Owner

DAV-related App Password contract finding: create_app_password declares only its 200 response in crates/calternal-auth/src/api.rs, but the handler calls AppPasswordOptions::validated (400), requires an account session and fresh assertion (401/403), and can hit the auth rate limit (429). The profile creation and revoke handlers also omit 403 even though their account-scope and fresh-assertion guards can return it. I will document these existing errors with the revised operation paragraphs.

DAV-related App Password contract finding: `create_app_password` declares only its 200 response in `crates/calternal-auth/src/api.rs`, but the handler calls `AppPasswordOptions::validated` (400), requires an account session and fresh assertion (401/403), and can hit the auth rate limit (429). The profile creation and revoke handlers also omit 403 even though their account-scope and fresh-assertion guards can return it. I will document these existing errors with the revised operation paragraphs.
Author
Owner

Post-merge auth gate finding: cargo test -p calternal-auth had one failure in store::tests::app_password_revoke_rejects_queued_verification. The follower unwrap received AuthError::Unavailable at store.rs:4055. The focused test passes when run alone. The verification path returns Unavailable when a request starts during an active cache change; the test spawned its follower but did not confirm that it had joined the shared verification lock before revocation began. I will synchronize the test on that state and keep its existing assertion.

Post-merge auth gate finding: `cargo test -p calternal-auth` had one failure in `store::tests::app_password_revoke_rejects_queued_verification`. The follower unwrap received `AuthError::Unavailable` at `store.rs:4055`. The focused test passes when run alone. The verification path returns Unavailable when a request starts during an active cache change; the test spawned its follower but did not confirm that it had joined the shared verification lock before revocation began. I will synchronize the test on that state and keep its existing assertion.
Author
Owner

oapi-974 final report

Head: 2462709d2fc3788dfa5f94646901555f30b78ebe

What was built

  • Added caller-facing summaries and short descriptions for the remaining Files, Notes, Mail, Calendar, Photos, Money, AI, Analytics, Location, Notifications, Video, and DAV/Auth operations. The final contract has 342 operations, with no missing summaries or descriptions and no issue or design references in caller-facing operation text. The ratchet budget is 0.
  • Regenerated contracts/openapi.json and packages/api-client/src/generated.ts after each crate. After merging origin/dev, also documented its Connected Accounts and MCP Events operations and regenerated both files.
  • Added the Photos upload 429 response and Video 304/202 response details to match handler behavior.
  • Made the queued App Password verification test wait until its follower joined the in-flight request. The existing assertion stays unchanged.

Files

  • Contract and generated client: contracts/openapi-summary-ratchet.json, contracts/openapi.json, packages/api-client/src/generated.ts.
  • Auth and server: crates/calternal-auth/src/api.rs, crates/calternal-auth/src/store.rs; crates/calternal-server/src/appearance.rs, integrations.rs, location.rs, mcp_events.rs, wire.rs.
  • Files: crates/plugins/files/src/{archive.rs,lib.rs,lookup.rs,pins.rs,preferences.rs,public.rs,shares.rs,thumbnails.rs,uploads.rs}.
  • Notes: crates/plugins/notes/src/{bookmarks.rs,composer_api.rs,lib.rs,reminders_api.rs,tasks_api.rs,wikilinks.rs}.
  • Other Plugin routes: crates/plugins/ai/src/routes.rs, analytics/src/routes.rs, calendar/src/{feeds/publication.rs,feeds/subscriptions.rs,items.rs,routes.rs,view.rs}, mail/src/routes.rs, money/src/routes.rs, notifications/src/routes.rs, photos/src/routes.rs, and video/src/routes.rs.

Gates

cargo fmt --check passed with no output. Contract scan output:

operations=342 missing_summaries_or_descriptions=0 issue_or_design_refs=0

Each Clippy command exited 0. Its final output was:

calternal-server: Finished `dev` profile [unoptimized + debuginfo] target(s) in 49.76s
calternal-auth: Finished `dev` profile [unoptimized + debuginfo] target(s) in 23.71s
calternal-plugin-files: Finished `dev` profile [unoptimized + debuginfo] target(s) in 28.91s
calternal-plugin-notes: Finished `dev` profile [unoptimized + debuginfo] target(s) in 25.26s
calternal-plugin-mail: Finished `dev` profile [unoptimized + debuginfo] target(s) in 14.79s
calternal-plugin-ai: Finished `dev` profile [unoptimized + debuginfo] target(s) in 19.19s
calternal-plugin-calendar: Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.43s
calternal-plugin-photos: Finished `dev` profile [unoptimized + debuginfo] target(s) in 5.18s
calternal-plugin-money: Finished `dev` profile [unoptimized + debuginfo] target(s) in 7.04s
calternal-plugin-analytics: Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.54s
calternal-plugin-notifications: Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.23s
calternal-plugin-video: Finished `dev` profile [unoptimized + debuginfo] target(s) in 1.39s

Cargo test results:

calternal-server: test result: ok. 162 passed; 0 failed; 5 ignored; 0 measured; 0 filtered out in 23.30s
calternal-auth: test result: ok. 88 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out in 95.21s
calternal-plugin-files: test result: ok. 158 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out in 204.67s
calternal-plugin-notes: test result: ok. 187 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out in 196.62s
calternal-plugin-mail: test result: ok. 46 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out
calternal-plugin-ai: test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 0.27s
calternal-plugin-calendar: test result: ok. 88 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out in 4.64s
calternal-plugin-calendar cache integration: test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 0.08s
calternal-plugin-calendar protocol integration: test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 0.04s
calternal-plugin-photos: test result: ok. 46 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out in 2.47s
calternal-plugin-money: test result: ok. 24 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 3.65s
calternal-plugin-analytics: test result: ok. 31 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 3.17s
calternal-plugin-notifications: test result: ok. 24 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 0.62s
calternal-plugin-video: test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 0.05s

The Notes apple_replay integration test passed. Doc-tests passed for each crate. cargo clean removed 26,090 files (21.6 GiB); apps/web/build was removed.

Decisions

  • Where DESIGN did not set wording, each description states the caller-visible effect, relevant input, and response or side effect in direct language. Response statuses follow the handlers.
  • The merge added Connected Accounts and MCP Events routes. Their descriptions follow the current handler scopes, validation, and results.
  • The App Password fix only synchronizes the test with the existing in-flight verification behavior. It does not change the assertion or runtime behavior.

Known gaps and UX gaps

  • No OpenAPI summary or description gaps remain. This work did not change UI, so UX gaps are not applicable.
  • Full web tests, the complete E2E set, and the adversarial matrices were not run in this job under the verification policy.

For the merge round

  • bun run --cwd apps/web check and bun run --cwd apps/web test: verify web integration with the regenerated client and run the full web unit suite.
  • bash tests/adversarial/run.sh: run the XUser, authorization, hostile-input, and concurrency probes against the local server.
  • Run the full registered test:e2e:* scenarios with the shared server and the merge-round worker limit. apps/web has no aggregate full-E2E script; its test:e2e script runs only the shell scenario.
# oapi-974 final report Head: `2462709d2fc3788dfa5f94646901555f30b78ebe` ## What was built - Added caller-facing summaries and short descriptions for the remaining Files, Notes, Mail, Calendar, Photos, Money, AI, Analytics, Location, Notifications, Video, and DAV/Auth operations. The final contract has 342 operations, with no missing summaries or descriptions and no issue or design references in caller-facing operation text. The ratchet budget is 0. - Regenerated `contracts/openapi.json` and `packages/api-client/src/generated.ts` after each crate. After merging `origin/dev`, also documented its Connected Accounts and MCP Events operations and regenerated both files. - Added the Photos upload 429 response and Video 304/202 response details to match handler behavior. - Made the queued App Password verification test wait until its follower joined the in-flight request. The existing assertion stays unchanged. ## Files - Contract and generated client: `contracts/openapi-summary-ratchet.json`, `contracts/openapi.json`, `packages/api-client/src/generated.ts`. - Auth and server: `crates/calternal-auth/src/api.rs`, `crates/calternal-auth/src/store.rs`; `crates/calternal-server/src/appearance.rs`, `integrations.rs`, `location.rs`, `mcp_events.rs`, `wire.rs`. - Files: `crates/plugins/files/src/{archive.rs,lib.rs,lookup.rs,pins.rs,preferences.rs,public.rs,shares.rs,thumbnails.rs,uploads.rs}`. - Notes: `crates/plugins/notes/src/{bookmarks.rs,composer_api.rs,lib.rs,reminders_api.rs,tasks_api.rs,wikilinks.rs}`. - Other Plugin routes: `crates/plugins/ai/src/routes.rs`, `analytics/src/routes.rs`, `calendar/src/{feeds/publication.rs,feeds/subscriptions.rs,items.rs,routes.rs,view.rs}`, `mail/src/routes.rs`, `money/src/routes.rs`, `notifications/src/routes.rs`, `photos/src/routes.rs`, and `video/src/routes.rs`. ## Gates `cargo fmt --check` passed with no output. Contract scan output: ```text operations=342 missing_summaries_or_descriptions=0 issue_or_design_refs=0 ``` Each Clippy command exited 0. Its final output was: ```text calternal-server: Finished `dev` profile [unoptimized + debuginfo] target(s) in 49.76s calternal-auth: Finished `dev` profile [unoptimized + debuginfo] target(s) in 23.71s calternal-plugin-files: Finished `dev` profile [unoptimized + debuginfo] target(s) in 28.91s calternal-plugin-notes: Finished `dev` profile [unoptimized + debuginfo] target(s) in 25.26s calternal-plugin-mail: Finished `dev` profile [unoptimized + debuginfo] target(s) in 14.79s calternal-plugin-ai: Finished `dev` profile [unoptimized + debuginfo] target(s) in 19.19s calternal-plugin-calendar: Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.43s calternal-plugin-photos: Finished `dev` profile [unoptimized + debuginfo] target(s) in 5.18s calternal-plugin-money: Finished `dev` profile [unoptimized + debuginfo] target(s) in 7.04s calternal-plugin-analytics: Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.54s calternal-plugin-notifications: Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.23s calternal-plugin-video: Finished `dev` profile [unoptimized + debuginfo] target(s) in 1.39s ``` Cargo test results: ```text calternal-server: test result: ok. 162 passed; 0 failed; 5 ignored; 0 measured; 0 filtered out in 23.30s calternal-auth: test result: ok. 88 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out in 95.21s calternal-plugin-files: test result: ok. 158 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out in 204.67s calternal-plugin-notes: test result: ok. 187 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out in 196.62s calternal-plugin-mail: test result: ok. 46 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out calternal-plugin-ai: test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 0.27s calternal-plugin-calendar: test result: ok. 88 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out in 4.64s calternal-plugin-calendar cache integration: test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 0.08s calternal-plugin-calendar protocol integration: test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 0.04s calternal-plugin-photos: test result: ok. 46 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out in 2.47s calternal-plugin-money: test result: ok. 24 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 3.65s calternal-plugin-analytics: test result: ok. 31 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 3.17s calternal-plugin-notifications: test result: ok. 24 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 0.62s calternal-plugin-video: test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out in 0.05s ``` The Notes `apple_replay` integration test passed. Doc-tests passed for each crate. `cargo clean` removed 26,090 files (21.6 GiB); `apps/web/build` was removed. ## Decisions - Where DESIGN did not set wording, each description states the caller-visible effect, relevant input, and response or side effect in direct language. Response statuses follow the handlers. - The merge added Connected Accounts and MCP Events routes. Their descriptions follow the current handler scopes, validation, and results. - The App Password fix only synchronizes the test with the existing in-flight verification behavior. It does not change the assertion or runtime behavior. ## Known gaps and UX gaps - No OpenAPI summary or description gaps remain. This work did not change UI, so UX gaps are not applicable. - Full web tests, the complete E2E set, and the adversarial matrices were not run in this job under the verification policy. ## For the merge round - `bun run --cwd apps/web check` and `bun run --cwd apps/web test`: verify web integration with the regenerated client and run the full web unit suite. - `bash tests/adversarial/run.sh`: run the XUser, authorization, hostile-input, and concurrency probes against the local server. - Run the full registered `test:e2e:*` scenarios with the shared server and the merge-round worker limit. `apps/web` has no aggregate full-E2E script; its `test:e2e` script runs only the shell scenario.
Author
Owner

Gate-output addendum for the report above. These are the raw final output lines, without crate labels:

Finished `dev` profile [unoptimized + debuginfo] target(s) in 49.76s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 23.71s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 28.91s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 25.26s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 14.79s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 19.19s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.43s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 5.18s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 7.04s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.54s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.23s
Finished `dev` profile [unoptimized + debuginfo] target(s) in 1.39s

The per-crate cargo test result lines are in the preceding report. cargo fmt --check exited 0 and wrote no output.

Gate-output addendum for the report above. These are the raw final output lines, without crate labels: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 49.76s Finished `dev` profile [unoptimized + debuginfo] target(s) in 23.71s Finished `dev` profile [unoptimized + debuginfo] target(s) in 28.91s Finished `dev` profile [unoptimized + debuginfo] target(s) in 25.26s Finished `dev` profile [unoptimized + debuginfo] target(s) in 14.79s Finished `dev` profile [unoptimized + debuginfo] target(s) in 19.19s Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.43s Finished `dev` profile [unoptimized + debuginfo] target(s) in 5.18s Finished `dev` profile [unoptimized + debuginfo] target(s) in 7.04s Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.54s Finished `dev` profile [unoptimized + debuginfo] target(s) in 21.23s Finished `dev` profile [unoptimized + debuginfo] target(s) in 1.39s ``` The per-crate `cargo test` result lines are in the preceding report. `cargo fmt --check` exited 0 and wrote no output.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#974
No description provided.