Commit 3ca2b9e
Sideloading support: API for Output Sets (#46)
* add external API endpoints for output sets
GET /v1/output-sets lists output file sets from completed runs with
filters for partner, tenant, schoolYear, sentToOds, createdAfter, and
bundle. POST /v1/output-sets/:setUid/download-links returns presigned
S3 download URLs for all files in a set.
New scopes: read:jobs (list metadata) and read:jobs:output-files
(download content). Partner isolation enforced via token scopes.
Query params validated — sentToOds accepts only true/false, createdAfter
must be a parseable date, schoolYear must be a 4-digit end year.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* align output-set API response and JSON typing
return the output-set list as the flat array shape exercised by the PR 6 tests and serialize it through the shared DTO helper.
annotate run_output_file_set.files with a PrismaJson type so the generated client exposes string[] directly and the controller no longer needs an ad hoc cast.
Co-authored-by: Codex <noreply@openai.com>
* document external API output-set endpoints
add the read-only output-set workflow to the external API README, including the new scopes, endpoint table entries, polling step, and request/response examples for listing output sets and fetching download links.
Co-authored-by: Codex <noreply@openai.com>
* update external API docs and local scopes
Document the output retrieval flow and keep the local Keycloak client scopes aligned with the external API README.
Co-authored-by: Codex <noreply@openai.com>
* update external API docs: say "successful runs" not "completed runs"
The output-set list endpoint filters to run.status = 'success', so
"completed runs" was misleading — it could imply failed runs are
included. Updated four occurrences in the README to say "successful
runs" for accuracy.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* improve output-set tests and docs after review
Tests: restructure GET /output-sets tests into "with invalid token" and
"with valid token" groups so auth tests are separate from param validation.
Add listOutputSets helper to make filter tests read as the single query
param they're varying. Remove redundant per-test token creation.
Docs: add 404 to error table, clarify presigned URL expiry (AWS session
rotation vs TTL), remove PR-scoped language from token/verify limitation.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* clean up output-set integration tests
- Add seedOutputSet factory to eliminate repeated job+output-set creation
boilerplate. Each filter test now reads as just the dimension it varies.
- Add listOutputSets helper for the request side (same idea).
- Restructure GET /output-sets into "with invalid token" / "with valid token"
/ "filters" groups. Valid-token tests share a single token via beforeAll.
- Apply same "with valid token" structure to download-links tests.
- Remove unnecessary client_id from output-set test tokens.
- Rename "with seeded output file sets" to "filters".
- Tighten response shape test: exact length, no ordering claim.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* tighten output-set filter test assertions
Each filter test now: seeds a counterexample, makes an unfiltered request
proving both sets are visible (resAll, length 2), then makes a filtered
request asserting exactly one result with the correct field value.
Also: remove unnecessary non-null assertions on seedJob().runs, reorder
helpers before beforeEach, use exact toHaveLength over toBeGreaterThanOrEqual.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* address review feedback on output-set tests
- Lift seedOutputSet to Output Sets V1 describe, removing duplicates
from GET and POST blocks.
- Narrow token scopes to minimum required: GET uses read:jobs only,
POST uses read:jobs:output-files only.
- Tighten successful-runs and partner-isolation tests to assert exact
length and UID instead of toContain/every.
- Fix ordering test: use explicit timestamps and assert exact UID order
instead of relying on incidental insertion order.
- Restore missing 200 status assertions on two tests.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* validate createdAfter with class-validator isISO8601
Replace permissive new Date() parsing with isISO8601 from class-validator
using strict and strictSeparator options. This accepts any valid ISO 8601
precision (year, date, full timestamp) but rejects locale formats like
"03/15/2024" and space-separated datetimes like "2024-03-15 00:00:00Z".
Tests cover garbage strings, locale formats, and space separator.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* return 400 for unknown school year instead of empty array
A nonexistent school year is more likely a caller typo than "no data
yet." Return a clear error so callers can fix their input. Tenant and
bundle don't get this validation yet — they return [] for unknown
values, which is a reasonable v1 default.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Codex <noreply@openai.com>1 parent 283d27e commit 3ca2b9e
9 files changed
Lines changed: 671 additions & 23 deletions
File tree
- app
- api
- integration/tests
- keycloak
- src
- external-api
- auth
- v1
- types
- models/src/dtos
- external-api
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
7 | | - | |
8 | | - | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
9 | 9 | | |
10 | | - | |
| 10 | + | |
| 11 | + | |
11 | 12 | | |
12 | 13 | | |
13 | 14 | | |
| |||
17 | 18 | | |
18 | 19 | | |
19 | 20 | | |
| 21 | + | |
20 | 22 | | |
21 | 23 | | |
22 | 24 | | |
| |||
777 | 779 | | |
778 | 780 | | |
779 | 781 | | |
| 782 | + | |
| 783 | + | |
| 784 | + | |
| 785 | + | |
| 786 | + | |
| 787 | + | |
| 788 | + | |
| 789 | + | |
| 790 | + | |
| 791 | + | |
| 792 | + | |
| 793 | + | |
| 794 | + | |
| 795 | + | |
| 796 | + | |
| 797 | + | |
| 798 | + | |
| 799 | + | |
| 800 | + | |
| 801 | + | |
| 802 | + | |
| 803 | + | |
| 804 | + | |
| 805 | + | |
| 806 | + | |
| 807 | + | |
| 808 | + | |
| 809 | + | |
| 810 | + | |
| 811 | + | |
| 812 | + | |
| 813 | + | |
| 814 | + | |
| 815 | + | |
| 816 | + | |
| 817 | + | |
| 818 | + | |
| 819 | + | |
| 820 | + | |
| 821 | + | |
| 822 | + | |
| 823 | + | |
| 824 | + | |
| 825 | + | |
| 826 | + | |
| 827 | + | |
| 828 | + | |
| 829 | + | |
| 830 | + | |
| 831 | + | |
| 832 | + | |
| 833 | + | |
| 834 | + | |
| 835 | + | |
| 836 | + | |
| 837 | + | |
| 838 | + | |
| 839 | + | |
| 840 | + | |
| 841 | + | |
| 842 | + | |
| 843 | + | |
| 844 | + | |
| 845 | + | |
| 846 | + | |
| 847 | + | |
| 848 | + | |
| 849 | + | |
| 850 | + | |
| 851 | + | |
| 852 | + | |
| 853 | + | |
| 854 | + | |
| 855 | + | |
| 856 | + | |
| 857 | + | |
| 858 | + | |
| 859 | + | |
| 860 | + | |
| 861 | + | |
| 862 | + | |
| 863 | + | |
| 864 | + | |
| 865 | + | |
| 866 | + | |
| 867 | + | |
| 868 | + | |
| 869 | + | |
| 870 | + | |
| 871 | + | |
| 872 | + | |
| 873 | + | |
| 874 | + | |
| 875 | + | |
| 876 | + | |
| 877 | + | |
| 878 | + | |
| 879 | + | |
| 880 | + | |
| 881 | + | |
| 882 | + | |
| 883 | + | |
| 884 | + | |
| 885 | + | |
| 886 | + | |
| 887 | + | |
| 888 | + | |
| 889 | + | |
| 890 | + | |
| 891 | + | |
| 892 | + | |
| 893 | + | |
| 894 | + | |
| 895 | + | |
| 896 | + | |
| 897 | + | |
| 898 | + | |
| 899 | + | |
| 900 | + | |
| 901 | + | |
| 902 | + | |
| 903 | + | |
| 904 | + | |
| 905 | + | |
| 906 | + | |
| 907 | + | |
| 908 | + | |
| 909 | + | |
| 910 | + | |
| 911 | + | |
| 912 | + | |
| 913 | + | |
| 914 | + | |
| 915 | + | |
| 916 | + | |
| 917 | + | |
| 918 | + | |
| 919 | + | |
| 920 | + | |
| 921 | + | |
| 922 | + | |
| 923 | + | |
| 924 | + | |
| 925 | + | |
| 926 | + | |
| 927 | + | |
| 928 | + | |
| 929 | + | |
| 930 | + | |
| 931 | + | |
| 932 | + | |
| 933 | + | |
| 934 | + | |
| 935 | + | |
| 936 | + | |
| 937 | + | |
| 938 | + | |
| 939 | + | |
| 940 | + | |
| 941 | + | |
| 942 | + | |
| 943 | + | |
| 944 | + | |
| 945 | + | |
| 946 | + | |
| 947 | + | |
| 948 | + | |
| 949 | + | |
| 950 | + | |
| 951 | + | |
| 952 | + | |
| 953 | + | |
| 954 | + | |
| 955 | + | |
| 956 | + | |
| 957 | + | |
| 958 | + | |
| 959 | + | |
| 960 | + | |
| 961 | + | |
| 962 | + | |
| 963 | + | |
| 964 | + | |
| 965 | + | |
| 966 | + | |
| 967 | + | |
| 968 | + | |
| 969 | + | |
| 970 | + | |
| 971 | + | |
| 972 | + | |
| 973 | + | |
| 974 | + | |
| 975 | + | |
| 976 | + | |
| 977 | + | |
| 978 | + | |
| 979 | + | |
| 980 | + | |
| 981 | + | |
| 982 | + | |
| 983 | + | |
| 984 | + | |
| 985 | + | |
| 986 | + | |
| 987 | + | |
| 988 | + | |
| 989 | + | |
| 990 | + | |
| 991 | + | |
| 992 | + | |
| 993 | + | |
| 994 | + | |
| 995 | + | |
| 996 | + | |
| 997 | + | |
| 998 | + | |
| 999 | + | |
| 1000 | + | |
| 1001 | + | |
| 1002 | + | |
| 1003 | + | |
| 1004 | + | |
| 1005 | + | |
| 1006 | + | |
| 1007 | + | |
| 1008 | + | |
| 1009 | + | |
| 1010 | + | |
| 1011 | + | |
| 1012 | + | |
| 1013 | + | |
| 1014 | + | |
| 1015 | + | |
| 1016 | + | |
| 1017 | + | |
| 1018 | + | |
| 1019 | + | |
| 1020 | + | |
| 1021 | + | |
| 1022 | + | |
| 1023 | + | |
| 1024 | + | |
| 1025 | + | |
| 1026 | + | |
| 1027 | + | |
| 1028 | + | |
| 1029 | + | |
| 1030 | + | |
| 1031 | + | |
| 1032 | + | |
| 1033 | + | |
| 1034 | + | |
| 1035 | + | |
| 1036 | + | |
| 1037 | + | |
| 1038 | + | |
| 1039 | + | |
| 1040 | + | |
| 1041 | + | |
| 1042 | + | |
| 1043 | + | |
| 1044 | + | |
| 1045 | + | |
| 1046 | + | |
| 1047 | + | |
| 1048 | + | |
| 1049 | + | |
| 1050 | + | |
| 1051 | + | |
| 1052 | + | |
| 1053 | + | |
| 1054 | + | |
| 1055 | + | |
| 1056 | + | |
| 1057 | + | |
| 1058 | + | |
| 1059 | + | |
| 1060 | + | |
| 1061 | + | |
| 1062 | + | |
| 1063 | + | |
| 1064 | + | |
| 1065 | + | |
| 1066 | + | |
| 1067 | + | |
| 1068 | + | |
| 1069 | + | |
| 1070 | + | |
| 1071 | + | |
| 1072 | + | |
| 1073 | + | |
| 1074 | + | |
| 1075 | + | |
| 1076 | + | |
| 1077 | + | |
| 1078 | + | |
| 1079 | + | |
| 1080 | + | |
| 1081 | + | |
| 1082 | + | |
| 1083 | + | |
| 1084 | + | |
| 1085 | + | |
| 1086 | + | |
| 1087 | + | |
| 1088 | + | |
| 1089 | + | |
| 1090 | + | |
| 1091 | + | |
| 1092 | + | |
| 1093 | + | |
| 1094 | + | |
| 1095 | + | |
| 1096 | + | |
| 1097 | + | |
| 1098 | + | |
| 1099 | + | |
| 1100 | + | |
| 1101 | + | |
| 1102 | + | |
| 1103 | + | |
| 1104 | + | |
| 1105 | + | |
| 1106 | + | |
| 1107 | + | |
| 1108 | + | |
| 1109 | + | |
| 1110 | + | |
| 1111 | + | |
| 1112 | + | |
| 1113 | + | |
| 1114 | + | |
| 1115 | + | |
| 1116 | + | |
780 | 1117 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
18 | 26 | | |
19 | 27 | | |
20 | 28 | | |
| |||
90 | 98 | | |
91 | 99 | | |
92 | 100 | | |
| 101 | + | |
| 102 | + | |
93 | 103 | | |
94 | 104 | | |
95 | 105 | | |
| |||
0 commit comments