chore(routes): Remove unused private routes - #1215
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedNext included review available in 8 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: ProjectTech4DevAI/kaapi-backend/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: ProjectTech4DevAI/kaapi-backend/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
💤 Files with no reviewable changes (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe API no longer imports or mounts the private router. The private module and its TTS migration and user-creation endpoints were deleted. The ChangesAPI route cleanup
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Other Merge Risk: ⚪ Minimal · up to This PR removes unused private routes and the test-email endpoint as the linked issue requests. The remaining utils routes stay mounted, and no concrete merge-blocking risk was found. Confirm that no internal tooling still calls the removed endpoints. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 2📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
🛠️ Fix failing CI checks 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
OpenAPI changes ⚪ No API surface changesNote This PR does not modify the API contract.
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
🎉 This PR is included in version 1.7.1-main.1 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
Issue
Closes #1216
Summary
app/api/routes/private.pywas registered unconditionally onapi_router(the env-gated include was commented out) and none of its routes declared an auth dependency.POST /private/userscould create an arbitrary user andPOST /private/migrate/tts-base64-to-s3could trigger a data migration — both reachable by any caller, not just superusers. These routes were also no longer used by anything.private.pyand its router registration are removed, so the endpoints no longer exist.POST /utils/test-emailroute and its imports (generate_test_email/send_email);/utils/healthis untouched.Checklist
Before submitting a pull request, please ensure that you mark these task.
fastapi run --reload app/main.pyordocker compose upin the repository root and test.Notes
Removed the private routes because they exposed private API endpoints with no permission dependency, making them accessible to non-superusers.