Files
composio-zen[bot] 4b790dc0ce fix(docs): correct toolkit versions and enforce production source (#3837)
## What this fixes

This is a follow-up to #3770, not a second root-cause fix.

#3770 moved the docs data workflow from staging to production,
centralized the production API URL, removed staging hosts from the
committed data, and added the hostname guard. The committed toolkit
catalog still retained staging-derived `version` values, however,
because that PR intentionally did not regenerate the full catalog. After
#3770 merged, the scheduled production regeneration began failing with
`401 Unauthorized`: the repository's existing `COMPOSIO_API_KEY` secret
is staging-scoped.

The customer-visible result was that nearly every toolkit page showed
the internal staging version `20260703_00`; Gmail's production version
was `20260702_01`.

## Changes

- Correct every `version` in `docs/public/data/toolkits.json` from the
production toolkit changelog. Toolkits absent from that changelog
receive `null`, matching the full generator's semantics. No other JSON
field changes.
- Move production changelog fetching and version application into shared
`toolkit-versions.ts` logic used by the full catalog generator.
- Add `bun run generate:toolkit-versions` as the narrow, reproducible
generator for version-only repairs.
- Reject any non-production `COMPOSIO_API_BASE` in the toolkit and
meta-tool generators before a request is made.
- Keep the version-distribution check as a smoke signal for the known
whole-catalog staging-bump pattern, while testing the production source
boundary separately. The distribution heuristic is no longer described
as proof of provenance.
- Fail before writing when the production changelog response is
malformed or contains no versions.

## CI policy compatibility

- Replace the enterprise-blocked mise action with allowlisted tool setup
actions while continuing to resolve exact versions from mise.lock.
Install the existing pinned mise CLI release through a checksum-verified
repository script for lock freshness and preinstall validation.
- Run the existing GitHub Advanced Security alert check locally and
notify Slack through the already-allowlisted Slack action, avoiding the
central workflow dependency rejected by the enterprise action policy.

## Verification

- `bun test tests/static/` — 30 passed.
- Targeted ESLint for every changed script/test — passed.
- `bun run types:check` — passed.
- `bun run build` — passed.
- Explicit staging override of `generate-toolkits.ts` — rejected before
network access.
- Verified the JSON data change remains version-only; toolkit ordering,
tools, triggers, descriptions, and counts are unchanged.

## Remaining deployment action

An administrator still needs to replace `COMPOSIO_API_KEY` with a
production-scoped key. The scheduled `docs-update-data` workflow is
correctly pinned to production and therefore fails loudly with the
current staging credential instead of republishing staging data. Once
the secret is corrected, the normal full-catalog generator remains the
authoritative refresh path.

Triggered by: abhishek@composio.dev | Source: slack
Session: https://zen.corp.composio.io/dashboard/#/chat/zen-3a77f73eb146

---------

Co-authored-by: Zen Agent <zen@composio.dev>
Co-authored-by: abhishek <abhishek@composio.dev>
Co-authored-by: jkomyno <alberto@composio.dev>
2026-07-15 17:16:44 +04:00

78 lines
2.1 KiB
TypeScript

import { fetchWithRetry, type FetchWithRetryOptions } from './fetch-with-retry';
import { PRODUCTION_API_V3_URL } from './production-api.mjs';
interface ToolkitWithVersion {
slug: string;
version: string | null;
}
interface ChangelogEntry {
slug?: string;
versions?: Array<{ version?: string }>;
}
interface ChangelogResponse {
items?: ChangelogEntry[];
}
export type ToolkitVersionFetcher = (
url: string,
options?: FetchWithRetryOptions
) => Promise<Response>;
/** Fetch the authoritative toolkit-version map from the production API. */
export async function fetchProductionToolkitVersions(
apiKey: string,
fetcher: ToolkitVersionFetcher = fetchWithRetry
): Promise<Map<string, string>> {
const response = await fetcher(`${PRODUCTION_API_V3_URL}/toolkits/changelog`, {
headers: {
'Content-Type': 'application/json',
'x-api-key': apiKey,
},
});
if (!response.ok) {
throw new Error(
`Failed to fetch production toolkit changelog: ${response.status} ${response.statusText}`
);
}
const data = (await response.json()) as ChangelogResponse;
if (!Array.isArray(data.items)) {
throw new Error('Production toolkit changelog response is missing an items array');
}
const versionMap = new Map<string, string>();
for (const entry of data.items) {
const slug = entry.slug?.toLowerCase();
const latestVersion = entry.versions?.[0]?.version;
if (slug && latestVersion) {
versionMap.set(slug, latestVersion);
}
}
if (versionMap.size === 0) {
throw new Error('Production toolkit changelog contains no toolkit versions');
}
return versionMap;
}
/** Apply generator semantics: absent production changelog entries become null. */
export function applyToolkitVersions<T extends ToolkitWithVersion>(
toolkits: T[],
versionMap: ReadonlyMap<string, string>
): { matched: number; missing: number } {
let matched = 0;
for (const toolkit of toolkits) {
const version = versionMap.get(toolkit.slug.toLowerCase()) ?? null;
toolkit.version = version;
if (version) matched++;
}
return { matched, missing: toolkits.length - matched };
}