Correct access control docs and widen the docs review rule - #2346
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Follow-up to #2343, from a review that ran after it merged.
Access control docs
/explorersegment is matched case-sensitively. The proxy matches API paths case-insensitively, but the UI finds/explorerin its own URL with a case-sensitive match, so a layer that changes that segment's casing breaks the UI. The path matching paragraph implied casing never mattered.graph-db-connection-url. The 400 body names the missing header, which is the clue a layer operator needs.[!IMPORTANT]for the getting started notice, matching the same prohibition in the four deployment guides. It was a[!NOTE].[!IMPORTANT]blocks stay, since both appear in every deployment guide.Review and doc conventions
REVIEW.md: widen the docs bullet. It only covered docs contradicting code, and still namedCONTEXT.md, which is nowGLOSSARY.md. It now covers docs contradicting each other, names what counts as Important, and drops the file list. It was the only bullet that applied to a docs-only change.REVIEW.md: scope "Writing comments" to the reviewer's own comments. A reviewer applied those rules to the docs under review.docs/agents/documentation.md: one marker per claim. Alert markers had no consistency rule, which caused most of the nits in that review.docs/agents/documentation.md: record which docs mirror code. The reference section copies the proxy server's routes, headers, and limits by hand, and nothing told an agent to update it alongside the code.How to read
docs/references/security.md— the two content correctionsREVIEW.md— the review rule changesdocs/agents/documentation.md— the marker rule and the docs that mirror codeThe rest are one-line edits.
Validation
pnpm checkspasses.RequestValidationErrorinpackages/graph-explorer-proxy-server/src/errors.ts, which carries the prettified Zod error naming the field./explorermatch was checked againstresolveApiRootinpackages/graph-explorer/src/connector/utils/apiUrl.ts.Related Issues
Check List
pnpm checkspasses with no errors.pnpm testpasses with no failures.