Repository navigation
Conversation
|
Verification footprint for 799 authored additions; 29,488 generated additions; 2 deletions. Generated classifications and destructive regeneration procedure are recorded in the shared API2 receipt and maintainer guide. Generated lines are not a claim of native/runtime proof; both SDK CI and API2's local-native acceptance passed separately. Raw canonical numstat (additions, deletions, path): |
Final source footprint and review receiptThe approved first-party SDK slice is implemented. Existing SDK entrypoints remain intact; the new namespaces are experimental. No SDK release, deployment or merge was performed.
Measured with the canonical text/Myers/no-renames/no-indent-heuristic numstat command from the living document. Generated ownership: API2's generated contract; each SDK's client/manifest/coverage/vectors; Node's existing legacy-package README/package projection. All native transport, tests, documentation and receipt additions count as authored. The conservative historical authored lower bound is now 59,141, not a fully reconciled program total or an additional footprint authorization. The last API2 increment is the targeted cold-artifact test-budget correction and its CI receipt; production and generated SDK bytes are unchanged. All council findings have dispositions and fail-first evidence in API2's All three exact-head CI runs are now green: API2 36161865722, Node 36136692611, and Go 36153479049. The prescribed API2 watcher finished with all checks passed on September 25 at 17:34 UTC. The generator suite passed in 2.8 minutes under coverage and the actual native SDK server canary in 30.5 seconds. API2 changed-line coverage is 93.62% (514/549); the unchanged 80% gate passed. No review threads were open at this final checkpoint. The green API2 run also reports two already nonblocking cloud-image Before landing: API2 main has since advanced by one Slack-workflow/test commit, Producer first, then consumers: |
|
Type-identity acceptance receipt, September 28, 22:24 UTC.
This closes exact-head Node CI monitoring, not the workflow-readiness merge gate. The PR remains https://github.com/transloadit/api2/pull/9252 |
Wait/cancel acceptance receipt (2026-09-29)Candidate:
API2's full remote CI and the last Go review are separate outstanding gates, not implied green by this Node receipt. No new blind-reader test, release, deployment or merge is claimed. Tus/upload/resume remains a later slice; existing coverage is retained until its replacement exists. Producer: https://github.com/transloadit/api2/pull/9252. Go companion: transloadit/go-sdk#47. |
Upload/resume acceptance receipt, September 29This closes the upload/resume slice's historical pending review/check items in the canonical living
Local acceptance
Main API2 attempt 1 stopped in the Core suite before the API2 suites: 161/162 Core suites passed and The final API2 report records 1,821 passed suites, 19 passing suites already marked flaky, one GitHub tested merge Review dispositionThe last API2 council found no issues. All accepted native council findings are reproduced and Independent consumer evidence and limitsBoth fresh Opus 5.5 readers completed all five tasks, with successful compiles and actual new-process Those readers tested Node Reader-driven example/transport clarification is included. Follow-ups, not implemented here: Companions: https://github.com/transloadit/api2/pull/9252 · #517 · transloadit/go-sdk#47. |
|
Exact-head CI receipt: |
Immutable native verification receiptFrozen Node head:
These immutable receipts supersede historical pending boxes in the pre-push checklist. The timed Companions: https://github.com/transloadit/api2/pull/9252 · transloadit/go-sdk#47. |
October 6 immutable reader-slice verification receiptThis closes the forward-compatible Assembly reader slice, not the experimental SDK release. Frozen sources and generation
Behavior and fail-first review repairs
Final verification
The completion receipt supersedes the pre-push pending boxes in the canonical living document Next slice and release boundaryPublic OAuth The user explicitly chose to defer this authentication slice. All three PRs remain experimental https://github.com/transloadit/api2/pull/9252 · #517 · transloadit/go-sdk#47 |
October 6 completion receipt: bounded native grant authenticationThis completes the final two acceptance gates in the canonical living document's October 6 Frozen revisions and CI
API2 build, test job and patch-coverage gate pass: 95.02% (956/1,006) changed lines covered The old producer runs at Local acceptance and review
BoundariesForm-selected account authentication and explicit credentialless configuration are implemented. The existing living document is updated; this immutable receipt closes its pre-push CI checkbox. Companions: https://github.com/transloadit/api2/pull/9252 · |
Why
Provide an experimental contract-generated API and useful native workflows alongside the existing
Node SDK. Blind-reader feedback motivated navigable types; runtime canaries motivated safe uploader
routing and genuinely resumable uploads. Keep API facts in API2, not in a second SDK inventory.
October 6 bounded grant-authentication correction
through one shared lowering function; neither native transport owns an endpoint/grant list.
authentication: { kind: 'none' }and Go
NoAccountCredentials: true. Missing, malformed or contradictory credentials andprotected calls without account authentication fail locally.
client. Their grant proof is still required. Basic client-credentials issuance is unchanged.
Authentication uses the same validated form snapshot that is serialized on the wire.
cookie isolation, redirect rejection, single-attempt errors and preserved response data.
yarn checkruns pass, as do 93 focused Node tests, both strict packedNode consumers and Go native/example/offline race, vet and build checks. Current pinned-source
generation/shared/actual API2-tusd acceptance passes in 2.4 minutes with no failures/flakes.
Generated Node/Go files match check-mode output byte for byte.
and a prototype-named selector have fail-first fixes; the last redirect-test assertion issue is
repaired. A separate envelope-key concern is disproved by the installed strict validator and
retained as a negative regression. There are no outstanding actionable council findings.
canary. Complete OAuth onboarding is not automatically a release blocker. Registration,
discovery/revocation and producer-owned OAuth error-code identity remain separate follow-ups.
7cad7b7db43f405c88114145f14c81ce805c3499,Node
56f455944f5652226b59055a291b47652ce48ac6,Go
d152a4105ebe51aa63ad02d2beed0d13adc0060a.The Node immutable implementation pin remains
71196f2: all four pinned files are byte-identicalat the final head, whose only extra change fixes the unit-test harness.
and Go CI are green.
API2 CI is also green,
including the 95.02% changed-line coverage gate. Final acceptance receipt
closes the pre-push living-document checkpoint, with all review/test evidence and flaky-test details.
Contract SHA-256:
6a90b6e2cc6d24e5be3c0a94588583fcf7294f3abc73adca63bdd9ab88f761f1.All three PRs remain experimental drafts, unmerged. No deployment or Content repin.
Scope
Transloadit.contract()and package/contractentrypoints for 37 ordinary operations andthree bounded tus bindings. This is a package export, not a server discovery endpoint.
transport and orchestration in this SDK. Neither workflow calls legacy SDK methods.
admitted destinations, exact metadata bytes, file digest and actual server offsets/receipts.
Never forward account credentials to returned uploader capabilities.
creation or cancellation. Reconcile ambiguous PATCH acknowledgements before sending more bytes.
REQUEST_ABORTEDas a finite, unsuccessful wait result. Explicit cancel still contactsthe owner once; active/aborted confirmation never conceals a failed DELETE. Neither completion
nor cancellation promises stopped workers or billing.
TypeErrorbefore headers. Retain receivedHTTP status/backoff for request-owned timeouts and both failed DELETE/GET attempts in ordered
AggregateErrordiagnostics. Default messages never include capability URLs or response bodies.remains a local helper with shared exact-byte vectors.
Existing-API behavior change
The legacy polling fix makes the configured deadline effective: it aborts in-flight reads/backoff,
rejects late success and does no new poll after an exhausted budget. This affects completion waiting
from
createAssemblyandresumeAssemblyUploadsas well asawaitAssemblyCompletion. Public APIshapes remain compatible; the changeset explicitly describes the intentional behavior change.
October 6 reader compatibility
Known codes remain autocomplete hints. Malformed errors and unknown success/progress codes
remain rejected; the public reader and current runtime emitter are tested separately.
Preserve the exact error as data, without interpolating it into diagnostic messages.
observations exercise 16 cases through 10 native modes per SDK (320 observations total),
including failed-cancellation confirmation, partial resume and completed-upload receipts.
permanent Node fetch failures being retried, and examples/canaries losing cleanup ownership.
Go's experimental
OnSessioncallback now receives the derived upload context; all callersand the README are updated so persistence can honor the shorter upload deadline.
unsupported literal/union/intersection combinations fail generation instead of silently widening
codecs or emitting invalid Go. Current generated clients stay byte-identical after these repairs.
These codecs are not complete JSON Schema validators.
b646c529fb0bf0e3aa4295c1a3208cdd028dd681.Native pins: Node
d63d6ccce4cf0f43464d8e351eb96f493de52155,Go
5362ca695cbf16f1f5060f48626ddd3eb9dbcf3c.Generated bytes remain those from producer
f8947685ba; contract SHA-2564c71aa3a66cf20aebfaea7b6f87ee8b8f3bc5c91ff4894ce115d978b2accc6b4.plus the other workspace suites; both fresh packed package names pass strict root/subpath/example
compilation. Go contract/shared/example race tests, vet and build pass.
zero failures or flakes, 2.1 minutes. All ten generated files match byte-for-byte.
Generated client sizes remain 5,012,654 bytes (TypeScript) and 7,581,401 bytes (Go), under 6/8 MB.
explicitly deferred OAuth blocker below. The same required checks pass again after review.
and all five Go versions.
The final producer run is API2 CI;
its final status is recorded in the immutable completion receipt below.
The authentication limitation described in this historical reader receipt is addressed by the
bounded correction above. Its former blanket OAuth release-blocker wording is superseded by the
user-approved narrower scope. Earlier CI receipts do not certify the new candidate.
Historical October 4 acceptance
c4c3f41f4954c348f94206863c297b30d0d04345.0b4c13d7de0674077ddcfa390d72e676bfe50b20;contract SHA-256
4246893330e3fa724407e19fa3d8d49501f87132b7aff9665f850a2f10fd8c53.Generated client bytes are unchanged by the final native transport repair and verify exactly.
yarn checkpasses: 1,180 Node tests, one existing skip, plus remaining monorepo suites.All 287 focused native/shared cases pass, including 32 source-owned metadata/receipt observations.
Four pre-header abort tests fail before the fix and pass afterward.
/contractand their shipped example,with exact optional properties, unchecked indexed access and declaration checks enabled.
is green: all 11 checks, including Node 20/22/24 and the Supabase Edge fixture.
shared suites: zero failures/flakes, 3.0 minutes. Complete earlier councils are triaged; the fresh
source-access-verified final combined council reports No issues found. Full
yarn checkpasses again after review, with the frozen native source and generated wrapper still clean.
reaches the request timeout and retain the failed DELETE when confirmation inspection fails.
Seventeen new failures reproduce the defects; nine POST/HEAD/PATCH × 403/429/503 cases and
caller/deadline controls pass afterward. No extra cancellation write or wider URL admission.
The historical timed Opus reader completed all five live tasks on
50b659d5ac, including a processrestart and offset-confirmed resume. That receipt does not test later fixes. No additional live
credentialed tests were run; this iteration uses synthetic/native and local API2/tusd acceptance.
Boundaries
Fixed-size replayable Blobs and simple upload IDs only. Deferred lengths, concatenation and streams
remain outside this helper. Session URLs are secrets. Additional uploader origins are configured,
not inferred; proxy receipt rewriting must be consistent. Overall upload deadlines include hashing,
persistence and transfer. Types describe the wire contract, not complete response validation.
Template-content typing, deterministic multipart ordering and SSE/Webhook
receivers remain separate work. Tus identity/receipt policy lowering is completed, not an open
native inventory or adapter-side replacement feature.
All three SDK PRs remain experimental drafts: do not merge, release or deploy.
Canonical record: API2
docs/prompts/2026-07-09-handover-sdks-branch-restructure.md.Native pre-push checklist:
docs/prompts/2026-09-29-contract-finality.md; subsequent immutablereview/CI receipts here supersede its historical pending boxes without restarting CI for copy.
Companions: https://github.com/transloadit/api2/pull/9252 · transloadit/go-sdk#47.