mirror of
https://github.com/ComposioHQ/composio.git
synced 2026-09-22 11:46:35 +08:00
16fa3d963a
## Summary - upgrades `fumadocs-openapi` 10 → 11, `fumadocs-mdx` 14 → 15, and `fumadocs-core` / `fumadocs-ui` 16.4 → 16.13 - migrates the Fumadocs OpenAPI API while preserving the custom schema renderer - restores local `$ref` resolution in both the visible API schema UI and generated LLM markdown - reduces API-reference client payloads by slicing the bundled OpenAPI document to each page's reachable operations and components - restores required badges for GET parameters - normalizes the OpenAPI `no_auth` sentinel so explicitly public endpoints render without authentication - moves to `getOpenAPIPageProps()` / `OpenAPIPageProps` and removes obsolete CSS overrides ## Correctness fixes Fumadocs 11 changed the page contract from a server-resolved document id to a client-side bundled document. That exposed several silent regressions: - **Reference resolution:** bundled documents retain local `$ref`s. The LLM renderer now dereferences them, including alias chains and cycles, while the custom schema renderer uses Fumadocs' resolver and retains raw reference identity for stable deduplication. - **Dereference reuse:** repeated LLM-page requests reuse the dereferenced copy for each cached bundled document instead of walking the complete spec per page. - **Client payload size:** each API page now receives only its selected operations and transitively reachable components. The slicer falls back to the complete document for non-component pointers, deep component pointers, missing operations, or dangling references. - **Required badges:** `readOnly` cannot distinguish GET inputs from responses. The renderer now uses the page hook's client name to identify responses. - **Recursive rendering:** schema markdown rendering now caps both structural recursion and nested array type rendering. - **No-auth normalization:** the undeclared `no_auth` sentinel is removed without discarding any real security alternatives that may accompany it. - **Contract drift:** code consuming `getSchema()` now treats `bundled` as required, matching the upstream type. Review follow-up also replaces the new OpenAPI `any` types with typed Fumadocs page props and a narrow recursive schema model. Historical Fumadocs 10/11 migration explanations live here in the PR, not as version-specific source comments; source comments retain only durable invariants. ## Payload impact | | before | after | | --- | --- | --- | | bundled document | 451 KB | 7.7 KB avg / 30 KB worst | | served page HTML | 693 KB | 198 KB | | 10-page sample | 6.55 MB | 2.02 MB (69% smaller) | ## Verification - `bun install --frozen-lockfile` - `bun run test` — 89 pass - `bun run lint:links` — 0 errors - `bun run lint` — 0 errors (77 existing warnings) - `bun run types:check` - `bun run build` - production server + `bun run test:integration` — 74 pass, including v3.1/v3 API pages, redirects, search, and LLM endpoints The production build has one existing Turbopack NFT tracing warning from `next.config.mjs`; it does not fail the build. ## Production vs preview checks A live sample comparison between [production](https://docs.composio.dev) and the [PR preview](https://docs-git-chore-docs-fumadocs-11.preview.composio.dev) found no docs regression: - all 14 representative routes returned 200 with matching titles, headings, canonical production URLs, and key content - redirects for `/`, `/api-reference`, `/tools`, and `/docs/welcome` matched exactly - the sampled pages exposed the same 1,137 internal-link targets; a balanced sample of 29 links resolved successfully on both deployments - sampled v3 and v3.1 OpenAPI pages retained endpoint paths, required fields, response schemas, and legacy indicators - the generated OpenAPI LLM page was byte-for-byte identical - selecting TypeScript in a hydrated browser rendered both inactive-tab examples and synchronized the language tab groups - `llms.txt` retained the same 139 unique lines in a different order - `/docs/quickstart.md` only added an explicit `[#next]` heading anchor The sampled OpenAPI HTML was roughly 35–42% smaller in the preview, consistent with document slicing rather than missing rendered content.
28 lines
711 B
TypeScript
28 lines
711 B
TypeScript
import { describe, expect, test } from 'bun:test';
|
|
|
|
import { normalizeNoAuthSecurity } from '../../lib/openapi';
|
|
|
|
describe('normalizeNoAuthSecurity', () => {
|
|
test('removes the no_auth sentinel without discarding real alternatives', () => {
|
|
const document = {
|
|
paths: {
|
|
'/public': {
|
|
get: {
|
|
security: [{ no_auth: [] }],
|
|
},
|
|
},
|
|
'/mixed': {
|
|
post: {
|
|
security: [{ no_auth: [] }, { bearer: [] }],
|
|
},
|
|
},
|
|
},
|
|
};
|
|
|
|
normalizeNoAuthSecurity(document);
|
|
|
|
expect(document.paths['/public'].get.security).toEqual([]);
|
|
expect(document.paths['/mixed'].post.security).toEqual([{ bearer: [] }]);
|
|
});
|
|
});
|