Repository navigation
Add transactional REST retry protection and typed client support - #462
Conversation
1de4f39 to
f96234d
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved critical and moderate findings remain in schema locking, request handling, generated outputs, and PostgreSQL CI coverage.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
What changed in this PR
This PR adds opt-in transactional REST retry protection and typed TypeScript client support for idempotent record mutations.
Changes:
- Adds bounded transactional receipts, replay authorization, and durable journal integration.
- Exposes
idempotencyKeyacross TypeScript clients and generated APIs. - Fixes PostgreSQL tenancy binding and updates tests, fixtures, documentation, and CI.
| File | Reviewed change |
|---|---|
tests/admin/test_rest_retry_integration.py |
Durable replay, restart, and tenancy integration tests |
tests/admin/test_rest_idempotency.py |
REST receipt and mutation behavior tests |
src/tenancy/tenancy.zig |
PostgreSQL tenant membership parameter fix |
src/rest_idempotency.zig |
Transactional REST adapter and replay handling; open critical and moderate findings remain |
src/idempotency.zig |
Replay authorization support |
src/framework.zig |
Idempotency configuration wiring |
src/codegen/emit.zig |
Generated client mutation signatures; generated fixture regeneration remains needed |
src/app.zig |
Application idempotency state wiring |
src/api/records.zig |
Idempotency request routing |
site/sources/docs/overview.md |
Feature overview documentation |
scripts/check-rest-idempotency-gating.sh |
REST idempotency symbol gating |
fixtures/rest-idempotency/main.zig |
Enabled feature fixture |
fixtures/rest-idempotency/invalid.zig |
Invalid configuration fixture |
examples/golfsim/clients/typescript/zbase.gen.ts |
Updated generated TypeScript client |
docs/typescript-sdk.md |
TypeScript retry documentation |
docs/framework.md |
Framework documentation; schema eligibility exception needs clarification |
clients/typescript/test/typed/service.test.ts |
Typed client retry tests |
clients/typescript/test/records.test.ts |
SDK idempotency key tests |
clients/typescript/test/codegen/dating/zbase.runtime.gen.ts |
Runtime generated client fixture |
clients/typescript/test/codegen/dating/zbase.gen.ts |
Generated client fixture |
clients/typescript/src/typed/service.ts |
Typed mutation option forwarding |
clients/typescript/src/typed/index.ts |
Typed API exports |
clients/typescript/src/records.ts |
Mutation option types |
clients/typescript/src/index.ts |
Public SDK exports |
clients/typescript/src/collection.ts |
Idempotency header transport |
changelog.d/rest-idempotency.md |
Release notes |
build.zig |
Build flags and fixture steps |
BACKLOG.md |
Feature scope update |
.github/workflows/ci.yml |
CI integration; PostgreSQL REST coverage remains unexercised |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
f96234d to
90ede6d
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Address the replay race and test mismatch, regenerate the stale typed-client fixture, and clarify SDK retry documentation.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 2
Open (2)
Resolved since last review (1)
90ede6d to
72080be
Compare
|
Also addressed the summary items: updated the hand-authored blog typed-client fixture to expose idempotencyKey and delete options, added mutation forwarding coverage, and clarified that supplying a key does not add network/conflict retries while existing 429/overload/session-refresh behavior still applies. SDK: 316 tests and type checking passed. Final restacked REST/PostgreSQL/replay/docs run: 78 passed, one disabled-feature skip. Updated head: 72080be; native stack retained. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Three unresolved critical issues remain in transaction recovery, validation-error cleanup, and replay authorization.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 3
Open (3)
Resolved since last review (2)
72080be to
6040a4d
Compare
6040a4d to
6c389a8
Compare
6c389a8 to
4b83911
Compare
|
Also addressed the DELETE-body concern from the review summary: keyed DELETE now explicitly requires an empty body, while keyed POST/PATCH accept JSON objects. Valid-JSON and malformed nonempty DELETE bodies both return 400 before record mutation or receipt creation. Tests verify the record remains and the same key can subsequently complete and replay a bodyless delete; both fail against the old binary and pass with the fix. Documentation updated accordingly. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The PostgreSQL CI job uses the wrong test binary, and a replay integration assertion conflicts with the adapter’s 401 behavior.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1

Authenticated JSON record mutations can now carry
Idempotency-Key, so a lost response can be retried after a restart without repeating the database write. The opt-in REST adapter stores the result and mutation atomically, rechecks current authorization on replay, binds receipts to principal/account/schema/body, and refuses requests before mutation when its bounded receipt namespace is full.The TypeScript client and generated typed client expose explicit
idempotencyKeyoptions for create/update/delete. With durable realtime enabled, record, receipt and journal entry commit together; replay produces no duplicate invalidation. This also corrects PostgreSQL parameter binding in tenant membership resolution, with a transaction/rollback regression test.This first adapter supports allowlisted base collections with JSON-only requests and no record hooks, TTL, files, hidden or encrypted fields. Predicate-constrained deletes are refused. External side effects remain outside its transaction guarantee. Documentation and backlog describe these boundaries.
Validation:
Stacked on #461; this PR adds REST retry protection and typed client support.