Skip to content

chore(routes): Remove unused private routes - #1215

Merged
vprashrex merged 2 commits into
mainfrom
chore/derigster-unused-route
Sep 30, 2026
Merged

vprashrex merged 2 commits into
mainfrom
chore/derigster-unused-route

Conversation

@vprashrex

@vprashrex vprashrex commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Issue

Closes #1216

Summary

  • Before: app/api/routes/private.py was registered unconditionally on api_router (the env-gated include was commented out) and none of its routes declared an auth dependency. POST /private/users could create an arbitrary user and POST /private/migrate/tts-base64-to-s3 could trigger a data migration — both reachable by any caller, not just superusers. These routes were also no longer used by anything.
  • Now: private.py and its router registration are removed, so the endpoints no longer exist.
  • Also removed the unused POST /utils/test-email route and its imports (generate_test_email / send_email); /utils/health is untouched.

Checklist

Before submitting a pull request, please ensure that you mark these task.

  • Ran fastapi run --reload app/main.py or docker compose up in the repository root and test.
  • If you've fixed a bug or added code that is tested and has test cases.

Notes

Removed the private routes because they exposed private API endpoints with no permission dependency, making them accessible to non-superusers.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 8 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: ProjectTech4DevAI/kaapi-backend/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: cb4c59e4-522c-476c-a17a-6779b7b5df68

📥 Commits

Reviewing files that changed from the base of the PR and between 2353a34 and 305700a.

📒 Files selected for processing (2)
  • backend/app/tests/api/routes/test_private.py
  • docs/wiki/modules/tenancy.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: ProjectTech4DevAI/kaapi-backend/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 202899ce-12a1-4c3b-8e52-a068716c91e7

📥 Commits

Reviewing files that changed from the base of the PR and between 2143d25 and 2353a34.

📒 Files selected for processing (3)
  • backend/app/api/main.py
  • backend/app/api/routes/private.py
  • backend/app/api/routes/utils.py
💤 Files with no reviewable changes (2)
  • backend/app/api/main.py
  • backend/app/api/routes/private.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The API no longer imports or mounts the private router. The private module and its TTS migration and user-creation endpoints were deleted. The /utils/test-email endpoint and its related imports were removed; the /utils router remains.

Changes

API route cleanup

Layer / File(s) Summary
Remove private routes and registration
backend/app/api/routes/private.py, backend/app/api/main.py
The private routes module, its TTS migration and user-creation endpoints, and its import and router mount were removed.
Remove test-email endpoint
backend/app/api/routes/utils.py
The /utils/test-email endpoint and its related imports were removed. The /utils router and health-check endpoint remain.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 2353a

This PR removes unused private routes and the test-email endpoint as the linked issue requests. The remaining utils routes stay mounted, and no concrete merge-blocking risk was found. Confirm that no internal tooling still calls the removed endpoints.

Architecture Summary

Architecture risk: 🔵 Low · up to 2353a

The change affects 1 system.

Changed systems: backend

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — backend (api) was modified; 3 changed files map to changed impact.

Before / after behavior

  • observed — Modified behavior in backend/app/api/main.py: Removed the private routes import.
  • observed — Modified behavior in backend/app/api/main.py: Removed the unconditional private.router mount from api_router. The commented development/testing mount remains.
  • observed — Modified behavior in backend/app/api/routes/private.py: The entire private routes module was removed, including the router and its hidden endpoints. The TTS migration had selected non-deleted text-to-audio calls, skipped rows without base64 content, uploaded decoded audio to S3, replaced content with a URI, and committed successful updates in batches of 50; it returned processing counts and up to 50 errors. The user-creation endpoint hashed the supplied password, created the user, and committed it.
  • observed — Modified behavior in backend/app/api/routes/utils.py: The /utils/test-email route was removed. It previously required SUPERUSER permission, generated and sent a test email to the supplied address, and returned a Message; its related imports were also removed. The /utils router remains.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Issue #1216 requires removal of the private route and the utils test route. The PR deletes backend/app/api/routes/private.py, removes its router import and mount from backend/app/api/main.py, and …
Out of Scope Changes check ✅ Passed The deleted private router contents are part of the private route. The removed TTS migration and user-creation endpoint therefore fall within removal of that route. The deleted email endpoint is the u…
Description check ✅ Passed The description clearly explains the removal of the unused private routes and the /utils/test-email route. It also states the security reason and testing status.
Title check ✅ Passed The title accurately and concisely summarizes the main change: removal of unused private routes.
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot changed the title chore: remove unused private routes and test email functionality chore(routes): Remove unused private routes Sep 30, 2026
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

OpenAPI changes   ⚪ No API surface changes

Note

This PR does not modify the API contract.

main ↔ fa07af00 · generated by oasdiff

@vprashrex
vprashrex requested review from AkhileshNegi, Ayush8923 and Prajna1999 and removed request for AkhileshNegi September 30, 2026 10:22
@vprashrex vprashrex self-assigned this Sep 30, 2026
@vprashrex vprashrex added bug Something isn't working ready-for-review labels Sep 30, 2026
@vprashrex
vprashrex enabled auto-merge (squash) September 30, 2026 11:16
@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@vprashrex
vprashrex merged commit cff0dcc into main Sep 30, 2026
6 checks passed
@vprashrex
vprashrex deleted the chore/derigster-unused-route branch September 30, 2026 11:31
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 1.7.1-main.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants