Commit Graph

3 Commits

Author SHA1 Message Date
Alberto Schiabel 09f76b1c9f refactor(cli): eliminate raw environment access (#4134)
This PR:
- routes Composio-prefixed runtime configuration through `APP_CONFIG`
and normalizes unprefixed host values through `HOST_CONFIG` in
`app-config.ts`
- removes `loadOptionalAppConfig`-style fallback loading so optional
strings, booleans, and CLI flag precedence resolve at the configuration
boundary
- removes every executable `process.env` reference from CLI source;
child commands inherit the ambient environment through
`@effect/platform` and receive explicit normalized overrides
- preserves arbitrary `CODEX_*`, `CLAUDE_*`, and `OPENCLAW_*` detection
through Effect config enumeration without exposing the raw environment
map
- propagates telemetry debug state through worker arguments instead of
mutating the process environment
- replaces removable filesystem, OS, subprocess, and error-handling
exceptions with Effect services and typed control flow
- documents supported and internal CLI environment variables, including
their `user_data.json` and `config.json` mappings
- reduces registered CLI lint boundaries from 45 to 4; the retained
entries are the detached-spawn, Node OS, synchronous preload filesystem,
and MD5 checksum implementations
- verifies the result with 1,201 passing CLI tests (1 skipped), strict
Oxlint, boundary validation, root typechecking across 19 packages, the
CLI build, and real `composio run` child-process checks
2026-08-18 12:54:26 +02:00
Alberto Schiabel 1503786358 refactor(core): forbid explicit any and type JSON Schema recursively (#3968)
This PR:

- is refreshed directly onto the current next branch now that #3966 and
#3967 have merged; the PR contains only its intended type-safety work
- enforces no explicit any through the standard .oxlintrc.json, pnpm
lint, and plain oxlint --fix in lint-staged; docs remain covered by
their nested configuration
- replaces the loose JSONSchemaProperty in @composio/core with a
concrete recursive interface, removing explicit any reachable through
Tool.inputParameters and Tool.outputParameters
- includes a minor changeset documenting the type narrowing for
properties, default, and enum consumers
- adds a compile-only public-contract test for recursive schemas,
known-key validation, extension keywords, and Tool reachability
- removes explicit any from FileToolModifier, ts-builders, core and CLI
tests, provider tests, and json-schema-to-zod tests
- keeps TypeScript ESLint-parity rules enabled and closes the
tool-router example lint/typecheck gap
- makes no lockfile changes and no runtime behavior changes

## Context

Final PR from the original #3958 split. The migration foundations are
already on next via #3966 and #3967, so this branch no longer carries a
stacked base commit.
2026-08-03 22:24:57 +05:30
Alberto Schiabel f233e46937 chore(repo): migrate eslint to oxlint and typecheck to TypeScript 7 (#3966)
This PR:

- replaces ESLint with oxlint across the pnpm workspace and the
Bun-based docs site, porting the rules to `.oxlintrc.json` /
`docs/.oxlintrc.json` with behavior parity (restricted-syntax selectors
kept via `oxlint-plugin-eslint`)
- migrates typecheck to TypeScript 7 (`typescript@^7.0.2` catalog) and
keeps a TS6 pin for JS compiler API consumers via a named `ts6` pnpm
catalog (`ts/scripts/validate-examples.ts`, the `@composio/cli` generate
pipeline). The CLI's `typescript` dependency rebinds only the
compiler-API import — its typecheck still runs the root TS7 `tsc`, since
the alias package only ships a `tsc6` bin (documented in
`ts/packages/cli/AGENTS.md`)
- removes the `paths` mappings that pointed `@composio/core` (and, in
`experimental`, `@composio/json-schema-to-zod` plus core-internal
`#`-imports) at sibling `src` directories: under TS7, tsdown's
tsgo-based dts step emitted stray `.d.ts` files next to those
out-of-root sources on every dependent package build. Workspace deps now
resolve through their built dist types, which turbo's `dependsOn:
^build` already guarantees exist — and which the deep-path exports
(`@composio/core/*`) always used anyway
- renames the cli boundary tooling `eslint-boundaries*` →
`lint-boundaries*` and hardens the scanner to reject `oxlint-disable`
spellings so the disable manifest cannot be bypassed
- rewrites inline `eslint-disable` comments to oxlint rule names
(comment-only; no runtime changes), and adds **one new** declared
boundary: `tool-file-uploads.ts` needs `no-restricted-imports` disabled
for `node:crypto` (MD5 for the presigned-upload checksum is not in Web
Crypto), because oxlint also catches dynamic `await import()` where
ESLint did not. The manifest grows 46 → 47 deliberately
- updates CI path filters, `turbo.jsonc` lint inputs, and the docs
typescript-check workflow (renamed to "Docs - Lint and TypeScript
Validation" since it now lints too); drops `eslint`,
`typescript-eslint`, `eslint-config-next`, and `globals` from the
dependency graphs
- ships no changeset: I built `@composio/core` and `@composio/anthropic`
on this branch and on the pre-migration base and diffed the emitted
`dist/**/*.d.mts`. The provider output is byte-identical. Core's output
is **semantically identical but not byte-identical**: TS7 changes quote
style (`"x"` → `'x'`), object-property and union-member ordering in
inferred types, and picks equivalent shorter re-export alias paths for
five signatures (e.g. `OpenAI.Beta.Threads.Runs.Run` →
`OpenAI.Beta.Threads.Run` — verified both names alias the same type in
the shipped typings). Chunk-name hashes shift as a consequence. No type
gains, losses, or shape changes; `attw` and `publint` pass on the TS7
build

## Context

First of a three-PR split of #3958. The type-safety refactors are
stacked on this branch and merge after it:

- docs: https://github.com/ComposioHQ/composio/pull/3967
- `@composio/core`: https://github.com/ComposioHQ/composio/pull/3968
2026-07-28 19:16:57 +05:30