Closes the gaps and the one security finding from the second end-to-end
CLI test (E2E_STASH_REPORT.md), plus the H1 boot-regression found while
re-reviewing those fixes.
Security
- S6: reserved-path validation (`check_reserved`) now case-folds before
comparing, so `/API/v2/x`, `/HEALTHZ`, `/Admin/x` are rejected like
their lowercase forms. Request-time matching stays case-sensitive.
- S10: "public route != public data" callout in sdk-shape.md (script_gate
skips authz when the principal is anonymous).
Observability / features
- G1: trigger executions now write `execution_logs`. Migration 0043 adds
a `source` column (CHECK mirrors ExecutionSource/OutboxSourceKind,
DEFAULT 'http' backfills history); a shared `build_execution_log` helper
in executor-core; dispatcher logging for outbox triggers + queue
consumers (skips sync-HTTP rows the orchestrator already logs). `pic
logs` gains a source column + `--source` filter.
- G5: dev-only in-memory email capture under PICLOUD_DEV_MODE with no SMTP
(email::send succeeds locally), readable at GET /api/v1/admin/dev/emails
(Owner/Admin only; route mounted only in capture mode).
- G6: generalized the Rhai in-place-mutation footgun note (trim/replace/
make_upper/make_lower/crop/truncate/pad return ()).
- G2/G3/G4 (CLI): `pic members`, `pic files`, `pic queues`, read-only
`pic kv` (+ new kv_api.rs); `pic deploy --timeout/--memory/--kind/
--sandbox`; first-class `pic triggers create-{docs,files,pubsub,queue,
email}` wrappers. All new client path segments percent-encoded via seg().
H1 regression fix (found in re-review)
- The S6 change also runs in `compile_routes`, which compiles every stored
route at boot and on each route CRUD. A single stored route the new
validation rejects (creatable while the S6 gap existed) made the whole
compile Err and aborted startup. `compile_routes` is now lenient: it
skips an un-compilable row with a warning instead of bricking boot
(route creation still validates separately). Migration 0044 sweeps
pre-existing reserved-path routes on upgrade (WHERE mirrors
check_reserved exactly). Added regression tests for both.
Verified: cargo fmt, clippy --all-targets --all-features -D warnings, the
schema_snapshot test, and the new S6/lenient-compile unit tests all pass;
boot-resilience and G1/G5 confirmed live.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
72 lines
2.3 KiB
Rust
72 lines
2.3 KiB
Rust
//! `pic files ls | get | rm` — operator-facing files inspection (G2).
|
|
//!
|
|
//! Wraps the read-only `/api/v1/admin/apps/{id}/files*` surface. There is
|
|
//! no `set`/`upload` — blob writes go through scripts (`files::create`);
|
|
//! the admin surface is inspect + delete only, matching the dashboard.
|
|
|
|
use std::io::Write;
|
|
use std::path::Path;
|
|
|
|
use anyhow::{Context, Result};
|
|
|
|
use crate::client::Client;
|
|
use crate::config;
|
|
use crate::output::{OutputMode, Table};
|
|
|
|
pub async fn ls(app: &str, collection: &str, limit: u32, mode: OutputMode) -> Result<()> {
|
|
let creds = config::resolve()?;
|
|
let client = Client::from_creds(&creds)?;
|
|
let page = client.files_list(app, collection, limit).await?;
|
|
let mut table = Table::new(["id", "name", "content_type", "size", "updated_at"]);
|
|
for f in page.files {
|
|
table.row([
|
|
f.id,
|
|
f.name,
|
|
f.content_type,
|
|
f.size.to_string(),
|
|
f.updated_at,
|
|
]);
|
|
}
|
|
table.print(mode);
|
|
if page.next_cursor.is_some() {
|
|
let _ = writeln!(
|
|
std::io::stderr(),
|
|
"(more results available — raise --limit to see them)"
|
|
);
|
|
}
|
|
Ok(())
|
|
}
|
|
|
|
/// Download a file's bytes. With `--out <path>` writes to disk; otherwise
|
|
/// streams raw bytes to stdout (pipe to a file or `xxd`).
|
|
pub async fn get(app: &str, collection: &str, file_id: &str, out: Option<&Path>) -> Result<()> {
|
|
let creds = config::resolve()?;
|
|
let client = Client::from_creds(&creds)?;
|
|
let bytes = client.files_get_bytes(app, collection, file_id).await?;
|
|
match out {
|
|
Some(path) => {
|
|
std::fs::write(path, &bytes).with_context(|| format!("writing {}", path.display()))?;
|
|
let _ = writeln!(
|
|
std::io::stderr(),
|
|
"Wrote {} bytes to {}",
|
|
bytes.len(),
|
|
path.display()
|
|
);
|
|
}
|
|
None => {
|
|
std::io::stdout()
|
|
.write_all(&bytes)
|
|
.context("writing bytes to stdout")?;
|
|
}
|
|
}
|
|
Ok(())
|
|
}
|
|
|
|
pub async fn rm(app: &str, collection: &str, file_id: &str) -> Result<()> {
|
|
let creds = config::resolve()?;
|
|
let client = Client::from_creds(&creds)?;
|
|
client.files_delete(app, collection, file_id).await?;
|
|
println!("Deleted file {file_id} from {collection}");
|
|
Ok(())
|
|
}
|