diff options
| author | Christian Cleberg <[email protected]> | 2026-07-16 01:29:06 -0500 |
|---|---|---|
| committer | GitHub <[email protected]> | 2026-07-16 01:29:06 -0500 |
| commit | 8e585a709d8979d493fef3ed4015db93687f48e8 (patch) | |
| tree | faebe598a4c6f7a5f3db92d465ed693aab594252 /SCOPE.md | |
| parent | f100206cc6d6784563d8eb905c9feb15c58bcc1e (diff) | |
| parent | 21be03e6ca54c1a15607faab905b119eda9a548f (diff) | |
| download | hutch-8e585a709d8979d493fef3ed4015db93687f48e8.tar.gz hutch-8e585a709d8979d493fef3ed4015db93687f48e8.tar.bz2 hutch-8e585a709d8979d493fef3ed4015db93687f48e8.zip | |
Merge pull request #6 from zerolabsco/phase-3-api-features
Phase 3: API features
Diffstat (limited to 'SCOPE.md')
| -rw-r--r-- | SCOPE.md | 36 |
1 files changed, 36 insertions, 0 deletions
@@ -7,3 +7,39 @@ - Explore / search (hub.sr.ht) (no public discovery API) - Pronouns on profile (not in GraphQL schema) - Revoke personal access tokens (`@internal` in schema, inaccessible) +- Archive a message to a list (`archiveMessage` is `@internal`, inaccessible) +- Ticket activity feed (todo.sr.ht's root `events` query is broken upstream and + returns an empty list for every user). `event.participant_id` references + `participant(id)`, but the resolver joins it against `participant.user_id`: + + ```sql + FROM event ev + JOIN participant p ON p.user_id = ev.participant_id -- id space vs user id space + WHERE p.user_id = <viewer> + ``` + + The rows exist — the writer inserts `participant.ID` for the submitter and for + every subscriber — but that join cannot find them. `Ticket.events` is + unaffected because it filters on `ev.ticket_id`, which is why ticket timelines + work. Nothing a client can do fixes this; revisit only if sr.ht changes the + resolver. +- Subscribe to a mailing list (`mailingListSubscribe` exists, but `MailingList` + has no `subscription` field and sr.ht has no discovery API, so there is no way + to find a list you are not already subscribed to — see hub.sr.ht above) +- Submitting patches (a `git send-email` flow, not a GraphQL mutation; Hutch + reviews patchsets but cannot send them) + +## Declined rather than blocked + +These are reachable in the API. They are left out on judgement, not capability. + +- **Webhook management** (24 fields across five services). A webhook needs an + HTTPS endpoint you control to receive POSTs. Without the relay above, this + only serves someone already running their own endpoint, and that person is not + managing it from a phone. Reconsider if `hutch-notify` ever ships. +- **`shareSecret`.** Shares a build secret — an SSH key or PAT — with another + user. A mistap grants someone else a credential, and nothing in the app can + take it back. That belongs on the web behind a full-size confirmation. The + read-only `secrets` list would be fine on its own. +- **Build groups** (`createGroup`, `startGroup`). Multi-job pipelines are + authored in `.build.yml`, not composed on a phone. |
