Repository navigation
feat(sds): add com.sds.repo.uploadBlob lexicon with repo param - #19
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
🚅 Deployed to the atproto-pr-19 environment in hypercerts
|
There was a problem hiding this comment.
Pull request overview
This PR adds a new SDS-specific blob upload lexicon (com.sds.repo.uploadBlob) that requires a repo parameter, enabling explicit targeting of shared repositories for blob uploads. This differs from the standard AT Protocol com.atproto.repo.uploadBlob endpoint which always uploads to the authenticated user's repository.
Changes:
- Added new lexicon definition with required
repoquery parameter for targeting specific repositories - Generated TypeScript types for the new lexicon with proper QueryParams interface
- Updated the handler registration to use the new
com.sds.repo.uploadBlobendpoint instead ofcom.atproto.repo.uploadBlob
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 5 comments.
Show a summary per file
| File | Description |
|---|---|
| lexicons/com/sds/repo/uploadBlob.json | New lexicon definition with repo parameter and error types |
| packages/sds/src/lexicon/types/com/sds/repo/uploadBlob.ts | Generated TypeScript types including QueryParams with repo field |
| packages/sds/src/lexicon/lexicons.ts | Schema dictionary and ID registry entries for the new lexicon |
| packages/sds/src/lexicon/index.ts | Import and method definition for the uploadBlob handler |
| packages/sds/src/api/com/sds/repo/uploadBlob.ts | Handler registration updated to use SDS-specific endpoint |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| // Register the SDS-specific uploadBlob endpoint that requires a repo parameter | ||
| server.com.sds.repo.uploadBlob({ |
There was a problem hiding this comment.
The comment states that the endpoint "requires a repo parameter", but the handler implementation below (line 23 onwards) still accesses the repo parameter via req.query.repo which is not the correct pattern for lexicon-defined QueryParams. The handler should be updated to use params.repo instead. See getPermissions.ts and listCollaborators.ts for the correct pattern. The handler signature should include params and access params.repo directly.
| */ | ||
| import stream from 'node:stream' | ||
| import { type ValidationResult, BlobRef } from '@atproto/lexicon' | ||
| import { CID } from 'multiformats/cid' |
There was a problem hiding this comment.
Unused import CID.
| import { CID } from 'multiformats/cid' |
| is$typed as _is$typed, | ||
| type OmitKey, | ||
| } from '../../../../util' | ||
|
|
||
| const is$typed = _is$typed, | ||
| validate = _validate |
There was a problem hiding this comment.
Unused variable is$typed.
| is$typed as _is$typed, | |
| type OmitKey, | |
| } from '../../../../util' | |
| const is$typed = _is$typed, | |
| validate = _validate | |
| type OmitKey, | |
| } from '../../../../util' | |
| const validate = _validate |
| const is$typed = _is$typed, | ||
| validate = _validate |
There was a problem hiding this comment.
Unused variable validate.
| const is$typed = _is$typed, | |
| validate = _validate | |
| const is$typed = _is$typed |
|
|
||
| const is$typed = _is$typed, | ||
| validate = _validate | ||
| const id = 'com.sds.repo.uploadBlob' |
There was a problem hiding this comment.
Unused variable id.
| const id = 'com.sds.repo.uploadBlob' |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.
This is the final PR Bugbot will review for you during this billing cycle
Your free Bugbot reviews will reset on February 19
Details
You are on the Bugbot Free tier. On this plan, Bugbot will review limited PRs each billing cycle.
To receive Bugbot reviews on all of your PRs, visit the Cursor dashboard to activate Pro and start your 14-day free trial.
Add SDS-specific blob upload lexicon that requires a repo parameter, enabling explicit targeting of shared repositories for blob uploads. The handler already supports this via req.query.repo access.
Add SDS-specific blob upload lexicon that requires a repo parameter,
enabling explicit targeting of shared repositories for blob uploads.
The handler already supports this via req.query.repo access.
Note
Medium Risk
Changes a write-path API surface and its authorization flow for blob uploads in SDS; mistakes could allow unintended repo targeting or break existing clients expecting the previous optional behavior.
Overview
Adds a new SDS XRPC procedure,
com.sds.repo.uploadBlob, whose lexicon requires arepoparameter so clients can explicitly target a shared repository for blob uploads.Updates the SDS upload handler to register this new endpoint (instead of
com.atproto.repo.uploadBlob) and to always resolve/authorize the target repo viafindAccountWithSharedAccess(repo, userDid, 'create')before writing the blob, removing the prior optionalreq.query.repobehavior. Generated lexicon bindings are updated to expose the new method.Written by Cursor Bugbot for commit 53d8c9c. This will update automatically on new commits. Configure here.