Skip to content

feat(sds): add com.sds.repo.uploadBlob lexicon with repo param - #19

Merged
aspiers merged 1 commit into
devfrom
uploadBlob
Jan 28, 2026
Merged

aspiers merged 1 commit into
devfrom
uploadBlob

Conversation

@aspiers

@aspiers aspiers commented Jan 28, 2026 •

Copy link
Copy Markdown
Collaborator

Add SDS-specific blob upload lexicon that requires a repo parameter,
enabling explicit targeting of shared repositories for blob uploads.
The handler already supports this via req.query.repo access.


Note

Medium Risk
Changes a write-path API surface and its authorization flow for blob uploads in SDS; mistakes could allow unintended repo targeting or break existing clients expecting the previous optional behavior.

Overview
Adds a new SDS XRPC procedure, com.sds.repo.uploadBlob, whose lexicon requires a repo parameter so clients can explicitly target a shared repository for blob uploads.

Updates the SDS upload handler to register this new endpoint (instead of com.atproto.repo.uploadBlob) and to always resolve/authorize the target repo via findAccountWithSharedAccess(repo, userDid, 'create') before writing the blob, removing the prior optional req.query.repo behavior. Generated lexicon bindings are updated to expose the new method.

Written by Cursor Bugbot for commit 53d8c9c. This will update automatically on new commits. Configure here.

Copilot AI review requested due to automatic review settings January 28, 2026 11:48
@vercel

vercel Bot commented Jan 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
sds-demo Ready Ready Preview, Comment Jan 28, 2026 7:10pm

Request Review

@railway-app

railway-app Bot commented Jan 28, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the atproto-pr-19 environment in hypercerts

Service Status Web Updated (UTC)
sds-eu-west4 ✅ Success (View Logs) Web Jan 28, 2026 at 7:10 pm
PDS entryway ✅ Success (View Logs) Web Jan 28, 2026 at 7:10 pm
pds-eu-west4 ✅ Success (View Logs) Web Jan 28, 2026 at 7:10 pm

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a new SDS-specific blob upload lexicon (com.sds.repo.uploadBlob) that requires a repo parameter, enabling explicit targeting of shared repositories for blob uploads. This differs from the standard AT Protocol com.atproto.repo.uploadBlob endpoint which always uploads to the authenticated user's repository.

Changes:

  • Added new lexicon definition with required repo query parameter for targeting specific repositories
  • Generated TypeScript types for the new lexicon with proper QueryParams interface
  • Updated the handler registration to use the new com.sds.repo.uploadBlob endpoint instead of com.atproto.repo.uploadBlob

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
lexicons/com/sds/repo/uploadBlob.json New lexicon definition with repo parameter and error types
packages/sds/src/lexicon/types/com/sds/repo/uploadBlob.ts Generated TypeScript types including QueryParams with repo field
packages/sds/src/lexicon/lexicons.ts Schema dictionary and ID registry entries for the new lexicon
packages/sds/src/lexicon/index.ts Import and method definition for the uploadBlob handler
packages/sds/src/api/com/sds/repo/uploadBlob.ts Handler registration updated to use SDS-specific endpoint

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +7 to +8
// Register the SDS-specific uploadBlob endpoint that requires a repo parameter
server.com.sds.repo.uploadBlob({

Copilot AI Jan 28, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The comment states that the endpoint "requires a repo parameter", but the handler implementation below (line 23 onwards) still accesses the repo parameter via req.query.repo which is not the correct pattern for lexicon-defined QueryParams. The handler should be updated to use params.repo instead. See getPermissions.ts and listCollaborators.ts for the correct pattern. The handler signature should include params and access params.repo directly.

Copilot uses AI. Check for mistakes.
*/
import stream from 'node:stream'
import { type ValidationResult, BlobRef } from '@atproto/lexicon'
import { CID } from 'multiformats/cid'

Copilot AI Jan 28, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unused import CID.

Suggested change
import { CID } from 'multiformats/cid'

Copilot uses AI. Check for mistakes.
Comment on lines +10 to +15
is$typed as _is$typed,
type OmitKey,
} from '../../../../util'

const is$typed = _is$typed,
validate = _validate

Copilot AI Jan 28, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unused variable is$typed.

Suggested change
is$typed as _is$typed,
type OmitKey,
} from '../../../../util'
const is$typed = _is$typed,
validate = _validate
type OmitKey,
} from '../../../../util'
const validate = _validate

Copilot uses AI. Check for mistakes.
Comment on lines +14 to +15
const is$typed = _is$typed,
validate = _validate

Copilot AI Jan 28, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unused variable validate.

Suggested change
const is$typed = _is$typed,
validate = _validate
const is$typed = _is$typed

Copilot uses AI. Check for mistakes.

const is$typed = _is$typed,
validate = _validate
const id = 'com.sds.repo.uploadBlob'

Copilot AI Jan 28, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unused variable id.

Suggested change
const id = 'com.sds.repo.uploadBlob'

Copilot uses AI. Check for mistakes.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

This is the final PR Bugbot will review for you during this billing cycle

Your free Bugbot reviews will reset on February 19

Details

You are on the Bugbot Free tier. On this plan, Bugbot will review limited PRs each billing cycle.

To receive Bugbot reviews on all of your PRs, visit the Cursor dashboard to activate Pro and start your 14-day free trial.

Comment thread packages/sds/src/api/com/sds/repo/uploadBlob.ts
Add SDS-specific blob upload lexicon that requires a repo parameter,
enabling explicit targeting of shared repositories for blob uploads.
The handler already supports this via req.query.repo access.
@railway-app
railway-app Bot temporarily deployed to hypercerts / atproto-pr-19 January 28, 2026 19:08 Destroyed
@aspiers
aspiers merged commit 955c0a5 into dev Jan 28, 2026
16 checks passed
@aspiers
aspiers deleted the uploadBlob branch January 28, 2026 19:16

This branch was successfully deployed

1 active deployment
Preview — 53d8c9c4 Deployed Jan 28, 2026 by vercel[bot]
hypercerts / atproto-pr-19 — 53d8c9c4 Deployed Jan 28, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants