Repository navigation
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #47 +/- ##
==========================================
- Coverage 82.60% 5.39% -77.22%
==========================================
Files 6 10 +4
Lines 345 32493 +32148
==========================================
+ Hits 285 1754 +1469
- Misses 32 30497 +30465
- Partials 28 242 +214 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Verification footprint for 1,040 authored additions; 55,282 generated additions; 1 deletion. Generated classifications and destructive regeneration procedure are recorded in the shared API2 receipt and maintainer guide. Generated lines are not a claim of native/runtime proof; both SDK CI and API2's local-native acceptance passed separately. Raw canonical numstat (additions, deletions, path): |
Final source footprint and review receiptThe approved first-party SDK slice is implemented. Existing SDK entrypoints remain intact; the new namespaces are experimental. No SDK release, deployment or merge was performed.
Measured with the canonical text/Myers/no-renames/no-indent-heuristic numstat command from the living document. Generated ownership: API2's generated contract; each SDK's client/manifest/coverage/vectors; Node's existing legacy-package README/package projection. All native transport, tests, documentation and receipt additions count as authored. The conservative historical authored lower bound is now 59,141, not a fully reconciled program total or an additional footprint authorization. The last API2 increment is the targeted cold-artifact test-budget correction and its CI receipt; production and generated SDK bytes are unchanged. All council findings have dispositions and fail-first evidence in API2's All three exact-head CI runs are now green: API2 36161865722, Node 36136692611, and Go 36153479049. The prescribed API2 watcher finished with all checks passed on September 25 at 17:34 UTC. The generator suite passed in 2.8 minutes under coverage and the actual native SDK server canary in 30.5 seconds. API2 changed-line coverage is 93.62% (514/549); the unchanged 80% gate passed. No review threads were open at this final checkpoint. The green API2 run also reports two already nonblocking cloud-image Before landing: API2 main has since advanced by one Slack-workflow/test commit, Producer first, then consumers: |
|
Type-identity acceptance receipt, September 28, 22:24 UTC.
The type-identity cleanup is accepted locally and in CI. This does not establish generated-client https://github.com/transloadit/api2/pull/9252 |
Upload/resume acceptance receipt, September 29This closes the upload/resume slice's historical pending review/check items in the canonical living
Local acceptance
Main API2 attempt 1 stopped in the Core suite before the API2 suites: 161/162 Core suites passed and The final API2 report records 1,821 passed suites, 19 passing suites already marked flaky, one GitHub tested merge Review dispositionThe last API2 council found no issues. All accepted native council findings are reproduced and Independent consumer evidence and limitsBoth fresh Opus 5.5 readers completed all five tasks, with successful compiles and actual new-process Those readers tested Node Reader-driven example/transport clarification is included. Follow-ups, not implemented here: Companions: https://github.com/transloadit/api2/pull/9252 · transloadit/node-sdk#517 · #47. |
|
Exact-head CI receipt: |
Immutable native verification receiptFrozen Go head:
These immutable receipts supersede historical pending boxes in the pre-push checklist. The timed Companions: https://github.com/transloadit/api2/pull/9252 · transloadit/node-sdk#517. |
October 6 immutable reader-slice verification receiptThis closes the forward-compatible Assembly reader slice, not the experimental SDK release. Frozen sources and generation
Behavior and fail-first review repairs
Final verification
The completion receipt supersedes the pre-push pending boxes in the canonical living document Next slice and release boundaryPublic OAuth The user explicitly chose to defer this authentication slice. All three PRs remain experimental https://github.com/transloadit/api2/pull/9252 · transloadit/node-sdk#517 · #47 |
October 6 completion receipt: bounded native grant authenticationThis completes the final two acceptance gates in the canonical living document's October 6 Frozen revisions and CI
API2 build, test job and patch-coverage gate pass: 95.02% (956/1,006) changed lines covered The old producer runs at Local acceptance and review
BoundariesForm-selected account authentication and explicit credentialless configuration are implemented. The existing living document is updated; this immutable receipt closes its pre-push CI checkbox. Companions: https://github.com/transloadit/api2/pull/9252 · |
Why
Prove canonical-contract generation in a second native language and deliver real workflows through
that new opt-in surface, without implementing the scenarios through legacy SDK adapters.
October 6 bounded grant-authentication correction
through one shared lowering function; neither native transport owns an endpoint/grant list.
authentication: { kind: 'none' }and Go
NoAccountCredentials: true. Missing, malformed or contradictory credentials andprotected calls without account authentication fail locally.
client. Their grant proof is still required. Basic client-credentials issuance is unchanged.
Authentication uses the same validated form snapshot that is serialized on the wire.
cookie isolation, redirect rejection, single-attempt errors and preserved response data.
yarn checkruns pass, as do 93 focused Node tests, both strict packedNode consumers and Go native/example/offline race, vet and build checks. Current pinned-source
generation/shared/actual API2-tusd acceptance passes in 2.4 minutes with no failures/flakes.
Generated Node/Go files match check-mode output byte for byte.
and a prototype-named selector have fail-first fixes; the last redirect-test assertion issue is
repaired. A separate envelope-key concern is disproved by the installed strict validator and
retained as a negative regression. There are no outstanding actionable council findings.
canary. Complete OAuth onboarding is not automatically a release blocker. Registration,
discovery/revocation and producer-owned OAuth error-code identity remain separate follow-ups.
7cad7b7db43f405c88114145f14c81ce805c3499,Node
56f455944f5652226b59055a291b47652ce48ac6,Go
d152a4105ebe51aa63ad02d2beed0d13adc0060a.The Node immutable implementation pin remains
71196f2: all four pinned files are byte-identicalat the final head, whose only extra change fixes the unit-test harness.
and Go CI are green.
API2 CI is also green,
including the 95.02% changed-line coverage gate. Final acceptance receipt
closes the pre-push living-document checkpoint, with all review/test evidence and flaky-test details.
Contract SHA-256:
6a90b6e2cc6d24e5be3c0a94588583fcf7294f3abc73adca63bdd9ab88f761f1.All three PRs remain experimental drafts, unmerged. No deployment or Content repin.
Scope
contractpackage for 37 ordinary operations and three bounded tus bindings, with stabledomain types, semantic unions, exact integers and omission/null distinctions.
Validate admitted uploaders, exact metadata bytes, file digest, offsets and transferred receipts.
Keep request buffers owned until HTTP body closure; never forward credentials to capabilities.
endpoint/receipt inventory. Empty/binary unrelated metadata is supported and tested.
Ordinary Assembly discovery does not retry HTTP 409. Lost PATCH replies reconcile accepted bytes.
REQUEST_ABORTEDas a finite, unsuccessful wait result. Explicit cancellation reachesits uploader once; a later active/aborted status cannot conceal a failed DELETE or prove cleanup.
AssemblyCancellationConfirmationError, includingerrors.Is/errors.Aswith cancellation-firstmatching and direct access to both errors. Preserve caller context/deadline precedence and Go 1.15.
Shared upload/resume acceptance invokes the delivered contract workflow, never an adapter fallback.
Existing-API behavior changes
CreateSignedSmartCDNUrlfollows canonical shared signing vectors: path escaping, UTF-16 key orderand millisecond expiration can change generated strings/signatures. Callers caching/comparing old
output need to account for the correction. Legacy
WaitForAssemblypreserves cancellation/deadlineidentity and keeps polling
ASSEMBLY_REPLAYING. API shapes remain compatible, but these intentionaltested behavior changes are documented, not described as unchanged behavior.
October 6 reader compatibility
Known codes remain autocomplete hints. Malformed errors and unknown success/progress codes
remain rejected; the public reader and current runtime emitter are tested separately.
Preserve the exact error as data, without interpolating it into diagnostic messages.
observations exercise 16 cases through 10 native modes per SDK (320 observations total),
including failed-cancellation confirmation, partial resume and completed-upload receipts.
permanent Node fetch failures being retried, and examples/canaries losing cleanup ownership.
Go's experimental
OnSessioncallback now receives the derived upload context; all callersand the README are updated so persistence can honor the shorter upload deadline.
unsupported literal/union/intersection combinations fail generation instead of silently widening
codecs or emitting invalid Go. Current generated clients stay byte-identical after these repairs.
These codecs are not complete JSON Schema validators.
b646c529fb0bf0e3aa4295c1a3208cdd028dd681.Native pins: Node
d63d6ccce4cf0f43464d8e351eb96f493de52155,Go
5362ca695cbf16f1f5060f48626ddd3eb9dbcf3c.Generated bytes remain those from producer
f8947685ba; contract SHA-2564c71aa3a66cf20aebfaea7b6f87ee8b8f3bc5c91ff4894ce115d978b2accc6b4.plus the other workspace suites; both fresh packed package names pass strict root/subpath/example
compilation. Go contract/shared/example race tests, vet and build pass.
zero failures or flakes, 2.1 minutes. All ten generated files match byte-for-byte.
Generated client sizes remain 5,012,654 bytes (TypeScript) and 7,581,401 bytes (Go), under 6/8 MB.
explicitly deferred OAuth blocker below. The same required checks pass again after review.
and all five Go versions.
The final producer run is API2 CI;
its final status is recorded in the immutable completion receipt below.
The authentication limitation described in this historical reader receipt is addressed by the
bounded correction above. Its former blanket OAuth release-blocker wording is superseded by the
user-approved narrower scope. Earlier CI receipts do not certify the new candidate.
Historical October 4 acceptance
93dedeb94a67166fad12fa80f1d5a27a9110afaa.0b4c13d7de0674077ddcfa390d72e676bfe50b20;contract SHA-256
4246893330e3fa724407e19fa3d8d49501f87132b7aff9665f850a2f10fd8c53.Its generation check-mode output matches the committed Go client exactly.
go vetand the workflow example build pass. Compound-errorregressions retain both causes, including failures with identical concrete types.
passes Go 1.15, 1.20, 1.24, 1.25 and 1.26.
acceptance with immutable source/hash pins passes all four producer/model/shared/native suites:
zero failures/flakes, 3.0 minutes. Complete earlier councils are triaged; the fresh source-access-
verified final combined council reports No issues found. Contract/shared race, vet and
example-build checks pass again after review; the frozen native source remains clean.
the original DELETE diagnostic. Caller/deadline precedence, validation and one DELETE stay intact.
The historical timed Opus reader completed all five live tasks on
a35909efb8, including a processrestart and HEAD-confirmed resume. It did not test later fixes. This iteration adds no live
credentialed tests or customer writes.
Boundaries
Fixed-size ReaderAt inputs and simple upload IDs only; no deferred lengths, concatenation or
non-seekable streams. Caller-owned readers/callbacks must return promptly. Session URLs are private;
local failure does not prove remote cleanup. Trusted origins are additive, proxy receipt rewriting
must be consistent, and the complete deadline includes hashing, persistence and transfer.
Types/decoders preserve modeled wire semantics, not every server schema constraint.
Template-content typing, deterministic multipart ordering and SSE/Webhook
receivers remain separate work. Unrelated empty tus metadata and generated receipt-policy lowering
are now completed and verified, not unresolved interoperability placeholders.
All three SDK PRs remain experimental drafts: do not merge, release or deploy.
Canonical record: API2
docs/prompts/2026-07-09-handover-sdks-branch-restructure.md.Native checklist:
docs/prompts/2026-09-29-contract-finality.md; these immutable receipts supersedeits historical pre-push boxes without a copy-only CI restart.
Companions: https://github.com/transloadit/api2/pull/9252 · transloadit/node-sdk#517.