fix(codegen/vercel): deployments sync works after adopt, get and create; lookup filters on list item fields (swamp-club #2843) #450
Loading…
Reference in a new issue
No description provided.
Delete branch "2843"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes swamp-club #2843.
Problem
syncon@swamp/vercel/deployments/deploymentsalways failed withStored state has no uid - cannot syncfor state written byadopt,getorcreate. Those calls read/v13/deployments, which returns the deployment'sid; only the/v7/deploymentslist used bylookupreturnsuid. The Vercel pipeline mapped the{idOrUrl}path param touid.lookupwithproject: prj_xxxalso never matched, because list items exposeprojectId, notproject.Fix (codegen/vercel, regenerated)
Identifier:
idOrUrlnow maps toid. The pipeline records the list-item identifier separately (listIdentifyingField,uidfor deployments). When the two differ, the generatedsyncandupdateuseexisting.id ?? existing.uid, so state written bycreate,get,adoptorlookupcan all be synced. Models with a single identifier generate the same code as before.Lookup filters: when the list item schema is known,
lookupfilters only on fields items carry.projectis compared againstprojectId, and the readidagainst the listuid. Create-only arguments that items never carry stop being filters, since a set value made every lookup fail. When the item schema can't be identified, all filters stay. A remapped filter's no-match error names the argument that was set:project="my-app" (matched against projectId).Sensitive fields: top-level request-body fields are emitted with
.meta({ sensitive: true })and never used as lookup filters if any of these hold:writeOnlyorformat: password;importKey, a KMS PEM private key).This marks
deployments.gitAccessTokenandkms issuers.importKey.Regenerated services, each with one CalVer bump:
gitAccessToken.importKey, and drops lookup filters list items lack.model/matches generator output.Design doc updated:
codegen/designs/vercel.mdsection 8.⚠️ Breaking change: gitAccessToken / importKey must come from a vault
swamp core refuses literal values for sensitive arguments. A definition that sets
gitAccessToken(deployments) orimportKey(kms issuers) as a plain value fails every method after upgrading:To migrate, find the affected definitions, store the value in a vault, and reference it:
Previously the plain token sat in the definition YAML, was written into every run's method-summary report, and was printed in lookup's no-match error. All three were confirmed against the published 2026.10.01.1.
Testing
Unit tests: pipeline tests cover identifier mapping, list-item extraction and sensitive detection. Generator tests cover the fallback, filter remapping and sensitive meta.
Integration test:
codegen/vercel/deployments_identifier_integration_test.tsuses a mock server. It coversadopt/create/lookup→sync, a not_foundsync, and that the no-match error omits the secret. It fails on the old keying with the issue's exact error.End to end: run on the vercel-labs/emulate Vercel emulator in a temporary swamp repo, with the branch added via
swamp extension source add:* The emulator returns both
idanduidfrom get/create, unlike real Vercel, so it cannot reproduce the original sync failure; the unit and integration tests cover that.Regeneration: idempotent (the second run produces no diff). The full codegen suite passes, 434 tests.
Known gaps
delivery.secret. This is documented in the design doc.Verified on
1f0df5241(verify-build 14/14, verify-reviews pass); attestation posted.🤖 Generated with Claude Code