Skip to content

Add transactional REST retry protection and typed client support - #462

Merged
valthon merged 1 commit into
codex/durable-realtime-replayfrom
codex/rest-idempotency
Sep 19, 2026
Merged

valthon merged 1 commit into
codex/durable-realtime-replayfrom
codex/rest-idempotency

Conversation

@valthon

@valthon valthon commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Authenticated JSON record mutations can now carry Idempotency-Key, so a lost response can be retried after a restart without repeating the database write. The opt-in REST adapter stores the result and mutation atomically, rechecks current authorization on replay, binds receipts to principal/account/schema/body, and refuses requests before mutation when its bounded receipt namespace is full.

The TypeScript client and generated typed client expose explicit idempotencyKey options for create/update/delete. With durable realtime enabled, record, receipt and journal entry commit together; replay produces no duplicate invalidation. This also corrects PostgreSQL parameter binding in tenant membership resolution, with a transaction/rollback regression test.

This first adapter supports allowlisted base collections with JSON-only requests and no record hooks, TTL, files, hidden or encrypted fields. Predicate-constrained deletes are refused. External side effects remain outside its transaction guarantee. Documentation and backlog describe these boundaries.

Validation:

  • Full combined PostgreSQL/resource-admission/replay/retry suite: 2,379 passed, 31 skipped.
  • Live SQLite/PostgreSQL restart and retry tests plus combined replay/tenant tests: 7 passed; disabled-feature case skipped in this enabled-only run and verified separately.
  • TypeScript client: 315 tests passed; type checking passed.
  • Documentation and skill parity: 67 passed; allocation contracts, formatting, strict site checks and browser navigation passed.
  • Independent source review and final integration review; clean detached-commit gate.

Stacked on #461; this PR adds REST retry protection and typed client support.

@valthon
valthon added this pull request to stack #463 September 19, 2026 03:58
@valthon
valthon force-pushed the codex/rest-idempotency branch from 1de4f39 to f96234d Compare September 19, 2026 11:22
Copilot AI lite review requested due to automatic review settings September 19, 2026 11:22

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved critical and moderate findings remain in schema locking, request handling, generated outputs, and PostgreSQL CI coverage.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

This PR adds opt-in transactional REST retry protection and typed TypeScript client support for idempotent record mutations.

Changes:

  • Adds bounded transactional receipts, replay authorization, and durable journal integration.
  • Exposes idempotencyKey across TypeScript clients and generated APIs.
  • Fixes PostgreSQL tenancy binding and updates tests, fixtures, documentation, and CI.
File Reviewed change
tests/​admin/​test_rest_retry_integration.py Durable replay, restart, and tenancy integration tests
tests/​admin/​test_rest_idempotency.py REST receipt and mutation behavior tests
src/​tenancy/​tenancy.zig PostgreSQL tenant membership parameter fix
src/​rest_idempotency.zig Transactional REST adapter and replay handling; open critical and moderate findings remain
src/​idempotency.zig Replay authorization support
src/​framework.zig Idempotency configuration wiring
src/​codegen/​emit.zig Generated client mutation signatures; generated fixture regeneration remains needed
src/​app.zig Application idempotency state wiring
src/​api/​records.zig Idempotency request routing
site/​sources/​docs/​overview.md Feature overview documentation
scripts/​check-rest-idempotency-gating.sh REST idempotency symbol gating
fixtures/​rest-idempotency/​main.zig Enabled feature fixture
fixtures/​rest-idempotency/​invalid.zig Invalid configuration fixture
examples/​golfsim/​clients/​typescript/​zbase.gen.ts Updated generated TypeScript client
docs/​typescript-sdk.md TypeScript retry documentation
docs/​framework.md Framework documentation; schema eligibility exception needs clarification
clients/​typescript/​test/​typed/​service.test.ts Typed client retry tests
clients/​typescript/​test/​records.test.ts SDK idempotency key tests
clients/​typescript/​test/​codegen/​dating/​zbase.runtime.gen.ts Runtime generated client fixture
clients/​typescript/​test/​codegen/​dating/​zbase.gen.ts Generated client fixture
clients/​typescript/​src/​typed/​service.ts Typed mutation option forwarding
clients/​typescript/​src/​typed/​index.ts Typed API exports
clients/​typescript/​src/​records.ts Mutation option types
clients/​typescript/​src/​index.ts Public SDK exports
clients/​typescript/​src/​collection.ts Idempotency header transport
changelog.d/​rest-idempotency.md Release notes
build.zig Build flags and fixture steps
BACKLOG.md Feature scope update
.github/​workflows/​ci.yml CI integration; PostgreSQL REST coverage remains unexercised

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/rest_idempotency.zig
Copilot AI review requested due to automatic review settings September 19, 2026 18:16
@valthon
valthon force-pushed the codex/rest-idempotency branch from f96234d to 90ede6d Compare September 19, 2026 18:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Address the replay race and test mismatch, regenerate the stale typed-client fixture, and clarify SDK retry documentation.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 High severity

Open (2)
Resolved since last review (1)

Comment thread src/rest_idempotency.zig
Comment thread tests/admin/test_rest_idempotency.py Outdated
Copilot AI review requested due to automatic review settings September 19, 2026 18:39
@valthon
valthon force-pushed the codex/rest-idempotency branch from 90ede6d to 72080be Compare September 19, 2026 18:39
@valthon

valthon commented Sep 19, 2026

Copy link
Copy Markdown
Owner Author

Also addressed the summary items: updated the hand-authored blog typed-client fixture to expose idempotencyKey and delete options, added mutation forwarding coverage, and clarified that supplying a key does not add network/conflict retries while existing 429/overload/session-refresh behavior still applies. SDK: 316 tests and type checking passed. Final restacked REST/PostgreSQL/replay/docs run: 78 passed, one disabled-feature skip. Updated head: 72080be; native stack retained.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Three unresolved critical issues remain in transaction recovery, validation-error cleanup, and replay authorization.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 3 High severity

Open (3)
Resolved since last review (2)

Comment thread src/rest_idempotency.zig Outdated
Comment thread src/rest_idempotency.zig Outdated
Comment thread src/rest_idempotency.zig
Copilot AI review requested due to automatic review settings September 19, 2026 19:12
@valthon
valthon force-pushed the codex/rest-idempotency branch from 72080be to 6040a4d Compare September 19, 2026 19:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Two unresolved critical findings affect replay correctness and PostgreSQL lock safety.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 High severity

Open (2)
Resolved since last review (3)

Comment thread src/rest_idempotency.zig
Comment thread src/rest_idempotency.zig
Copilot AI review requested due to automatic review settings September 19, 2026 19:35
@valthon
valthon force-pushed the codex/rest-idempotency branch from 6040a4d to 6c389a8 Compare September 19, 2026 19:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Unresolved critical replay-authorization and moderate DELETE-body validation findings require fixes and human review.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (2)

Comment thread src/rest_idempotency.zig
Copilot AI review requested due to automatic review settings September 19, 2026 19:57
@valthon
valthon force-pushed the codex/rest-idempotency branch from 6c389a8 to 4b83911 Compare September 19, 2026 19:57
@valthon

valthon commented Sep 19, 2026

Copy link
Copy Markdown
Owner Author

Also addressed the DELETE-body concern from the review summary: keyed DELETE now explicitly requires an empty body, while keyed POST/PATCH accept JSON objects. Valid-JSON and malformed nonempty DELETE bodies both return 400 before record mutation or receipt creation. Tests verify the record remains and the same key can subsequently complete and replay a bodyless delete; both fail against the old binary and pass with the fix. Documentation updated accordingly.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The PostgreSQL CI job uses the wrong test binary, and a replay integration assertion conflicts with the adapter’s 401 behavior.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Comment thread .github/workflows/ci.yml
@valthon
valthon merged commit 59ac830 into main Sep 19, 2026
31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants