Skip to content

[api] Fix payloads and routes that Zou rejects or ignores - #3

Merged
frankrousseau merged 19 commits into
cgwire:mainfrom
frankrousseau:audit-fixes
Sep 28, 2026
Merged

frankrousseau merged 19 commits into
cgwire:mainfrom
frankrousseau:audit-fixes

Conversation

@frankrousseau

@frankrousseau frankrousseau commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Problem

  • newEdit, getProjectTaskTypes, createBudgetEntry and buildWorkingFilePath sent keys or methods Zou rejects or drops
  • Several options were silently ignored by Zou: budget fields, reply author, per-person studio filter, nb_elements
  • allOpenTasks took no filter and no pagination, allLastEvents cut after/before to the local day
  • Finished downloads stayed in the in-flight set, leaking memory
  • logIn accepted an answer without access token; timecodes could show frame fps or a fractional frame

Solution

  • Send episode_id, sep and the BudgetEntrySchema fields, read task types from their GET route
  • Drop the ignored options
  • Expose the open tasks filters Kitsu uses with page and limit, send event dates to the second in UTC, expose the name filter
  • Release a download once its body is read or cancelled
  • Reject a tokenless login, clamp timecode frames
  • Add a coverage script, patch dependency updates, document the sibling checkouts the scripts need

frankrousseau and others added 19 commits September 27, 2026 17:35
Zou reads episode_id and drops parent_id, so the edit was created outside
its episode.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
settings/task-types only accepts POST in Zou: getProjectTaskTypes always
failed with a 405.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Zou requires department_id and reads the person, position, seniority,
start date, duration and daily salary: the former body was always
rejected with a 400.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Zou only stores the name and the currency of a new budget: description,
dates and amount were silently dropped.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The working-file-path route of Zou reads sep, unlike the output-file-path
one: the folder was always built with slashes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The output-file-path schema of Zou has no such field: only the creation
of an output file reads it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Zou answers open-tasks with one page of 100 tasks wrapped with their
stats: allOpenTasks returned that dict instead of the tasks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Zou reads a full datetime there: a Date was cut to its local day, so a
sync loop polling with after fetched the whole day again.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Zou and gazu support the name filter, the client did not expose it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Neither the project settings route nor the project template one reads
the bitrates: only the task type and its priority are stored.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Zou only narrows the time spents of a single person by project: the
studio option was silently ignored. The tables keep it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Zou only reads the text of a reply and always credits the current user.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
formatTime rounded the last milliseconds of a second up to frame fps
(00:00:00:25 at 25 fps), and formatToTimecode printed a fractional frame
with a fractional fps.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A raw response left the in-flight set only on abort: every finished
download stayed there, with its listener on the caller signal.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
In bearer mode such an answer stored an empty session and the next
request failed far from its cause.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The spread in reduce copied the entity once per field.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
vitest moves to 5.0.2 along with @vitest/coverage-v8, which pins it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@frankrousseau
frankrousseau merged commit 2e89787 into cgwire:main Sep 28, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant