Commit Graph
3 Commits
Author SHA1 Message Date
thethreemagi 752fb08d73 API.md: every admin route tested over HTTP and approved
123 checks across all 48 routes plus /api/docs, driven on a throwaway
copy of the live database with anonymous, member, leader, admin and
owner access; 0 failures. Calendar checks used 2036 probes against the
real store and left it at 32 objects. API.md records, per route, the
capability and what each request actually returned. tests/api_drive.py
is the harness and tests/api_doc.py regenerates the document from its
results, so the next approval run is a rerun, not a rewrite.
2026-09-04 20:27:19 -04:00
thethreemagi d1dfa6df90 API.md ships in the image; GET /api/docs/approved serves it behind api:docs
Moved to app/API.md so the build context carries it. The console renders
it at /leaders/api. tests/smoke_admin.py 162 -> 164.
2026-09-04 20:26:45 -04:00
thethreemagi 38bedaea88 API.md: every admin route driven over HTTP and approved; tests/http_drive.py
48 routes plus /api/docs, 123 checks over real HTTP against a throwaway
site on a copy of the live database, as anonymous, a member, a pack
leader, an admin (the claude account), the owner, and the break-glass
token from the LAN and from outside. Every refusal path the routes
promise was exercised: 401, 403 by capability and by unit scope, 404,
409 state conflicts, 422 validation, and 502 when the publisher refuses
a bad signature. Calendar probes went to the real Radicale store dated
2036 and were deleted; the store ended with 32 objects and none in the
site namespace. API.md is generated from the router registry plus those
results, one entry per route with its own description and what was
tried. No route failed; all 48 approved.
2026-09-04 20:24:31 -04:00