feat(api): Stage I views, selected DELETE routes, and stateless Responses - #382
Conversation
🧭 IronLoop Run · ReviewThis comment updates in place as the Run moves through its stages. 🟩 Final result · Completed
Automatic trigger · attempt 1 of 3 · completed in 1m 2s IronLoop completed the review and posted it to GitHub. 🔗 Result |
Review:
|
There was a problem hiding this comment.
🔍 IronLoop review
The stateless proxy mostly implements the retirement boundary, but it unnecessarily removes stateless function calling.
Findings: 🟠 Medium 1
🟠 Medium · Allow client-managed function calling
Inline on crates/api/src/routes/api.rs:428. See the inline comment for details.
Validation
- ✅ Stateless boundary inspection — Traced request validation and normalization through the Responses proxy and confirmed that function definitions and their client-managed outputs are rejected before reaching Cloud API.
Review details
- Run:
c7095235-fe44-429d-92ac-9750953d2312 - Workflow: Review
- Attempts: 1
|
Follow-up fixes are in 34e9024.
Validation: |
|
Fixed the failed CI fixture in 7a15469: the test now establishes an active subscription before asserting the handler’s local 400 response. Production authentication and subscription middleware ordering are unchanged. |
Stage I clarification — owner-only viewsThe Stage I read window retains only authenticated owner Conversation and File views. Sharing is not an export dependency: the entire sharing namespace, including its GET routes, and optional-auth/public shared Conversation reads are This PR therefore preserves the three Conversation and three File owner views, blocks all writes and sharing routes, and keeps Responses stateless without author injection or local tracking. Client-managed custom Final removal of the remaining owner views and wiring is deliberately deferred to Stage III. |
|
Update: final head |
Correction to the earlier Stage I clarificationStage I retains four existing session-authenticated DELETE routes:
All other stateful mutations—including both pin/unpin and archive/unarchive—and every sharing operation other than the two sharing DELETE routes remain |
|
@ironloopai review |
Review · Status🟩 CompletedIronLoop completed the review and posted it to GitHub. ResultRun detailsManual command by think-in-universe · attempt 1 of 3 · completed in 6m 35s |
There was a problem hiding this comment.
Review · Summary
One low-severity routing contract issue was found.
Findings: 🟡 Low 1
Code-specific findings are attached to the diff.
Validation
- ✅ Captured PR checks — The captured Test Suite, CodeQL, and cargo deny checks are passing.
Review details
- Run:
81705f8f-8034-4d0b-8f4a-fd2035cd7daf - Attempts: 1
Superseding Stage I read-surface clarificationLeadership has clarified that Stage I retains every existing read endpoint in the Conversation, File, and sharing namespaces.
The four existing DELETE routes remain available. Only stateful writes and unsupported/unknown legacy paths are retired with This supersedes the earlier owner-only and sharing-read retirement clarifications in this thread. |
Closes #386
Closes #387
Closes #388
Closes #389
Summary
This PR implements the Stage I Private Chat contract in #385. It retains all
existing Conversation, File, and sharing read endpoints, preserves four
established session-authenticated DELETE routes, retires stateful writes, and
makes the Responses proxy stateless.
Stage I API contract
This table covers the Private Chat stateful surface only. Other inference APIs
remain outside this migration scope.
POST /v1/responsesCache-Control: no-store. A non-empty body must be an identity-encoded JSON object. Chat rejectsstore: true, non-nullconversation, non-nullprevious_response_id, andbackground: true; it normalizes valid JSON requests tostore: false. It does not inject author metadata, perform Conversation ACL/tracking, execute tools, or run an agent loop.tools: [{type:"function"}]and replayedinputitems/v1/responses400for unsupported capabilities. This does not affect the separate root MCP proxy below.GET /v1/conversationsGET /v1/conversations/{conversation_id}GET /v1/conversations/{conversation_id}/itemsCache-Control: no-store.GET /v1/conversations/{conversation_id}/sharesGET /v1/share-groupsGET /v1/shared-with-meCache-Control: no-store.GET /v1/filesGET /v1/files/{file_id}GET /v1/files/{file_id}/contentCache-Control: no-store.DELETE /v1/conversations/{conversation_id}DELETE /v1/files/{file_id}DELETE /v1/conversations/{conversation_id}/shares/{share_id}DELETE /v1/share-groups/{group_id}Cache-Control: no-store.POST/DELETEpin,POST/DELETEarchive, and clone/copy410 GonewithCache-Control: no-store; they do not mutate local state or forward a Cloud mutation. Unsupported methods and unknown descendants remain retired.DELETE /v1/users/meDELETE /v1/conversations/{id}andDELETE /v1/files/{id}, before local finalization. This lifecycle is separate from the four session-proxy DELETE routes above.POST /mcp/v1/chat/completions,/v1/images/*, model/signature routesOut of scope
No schema/migration/data cleanup, no new export API, and no removal of
temporary view wiring. #380 tracks account-deletion compatibility; final
route/runtime removal remains Stage III work under #377 and #390–#392.
Validation
cargo fmt --all -- --checkgit diff --checkcargo test -p api documents_stage_one_views_and_retained_delete_operations --libcargo test -p api --test conversations_tests --test files_tests --features test -- --test-threads=1(10 passed)