Pre-launch — Gluecron is in final validation. Public signups and git hosting for non-owner users open after launch review.
CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
claude/adoring-hopper-5x74bqclaude/affectionate-feynman-ykrf1hclaude/architecture-audit-design-wxprenclaude/build-status-update-3MXsfclaude/charming-meitner-mllb5rclaude/compare-gate-gluecron-s4mFQclaude/confident-faraday-tikcwbclaude/continue-work-XMTlIclaude/crontech-gluecron-deploy-7MIECclaude/crontech-platform-setup-SeKfwclaude/design-2026claude/ecstatic-ptolemy-jMdigclaude/enhance-github-integration-QNHdGclaude/fix-aa-loop-issue-PonMQclaude/fix-actions-and-processclaude/fix-desktop-errors-XqoW8claude/fix-red-workflowsclaude/fix-website-access-6FKJNclaude/gatetest-integration-hardeningclaude/github-audit-improvements-bDFr9claude/gluecron-launch-status-FoMRlclaude/hopeful-lamport-olfCTclaude/issue-to-pr-and-protectionsclaude/jolly-heisenberg-2sg1Qclaude/launch-preparation-QmTb6claude/new-session-xk1l7claude/plan-platform-architecture-kkN4yclaude/platform-analysis-roadmap-1nUGLclaude/platform-launch-assessment-8dWV8claude/polish-platform-release-AeDrUclaude/resume-previous-work-KzyLwclaude/review-crontech-handoff-qYEVqclaude/review-project-completeness-lHhS2claude/review-readme-docs-ulqPKclaude/serene-edison-rj87weclaude/setup-multi-repo-dev-BCwNQclaude/ship-fixes-and-tests-Jvz1cclaude/site-audit-competitive-pctlwgclaude/site-migration-vercel-XstpKclaude/standalone-product-repos-XHFTDcopilot/feat-smart-empty-states-keyboard-first-enhancementcopilot/feat-smart-morning-digest-review-context-restorecopilot/fix-and-process-workflowscopilot/update-ai-powered-code-reviewfeat/debt-mapfeat/push-policy-codeowners-hardeningfeat/smart-digest-contextfeat/stage-impactfeat/t1-secret-migrationfeat/u-polishfeat/w-self-hostfeat/w2-claude-configfix/agent-journey-orphan-sweepgatetest/auto-fix-1776586424172gatetest/auto-fix-1776586534814gatetest/auto-fix-1776590685143gatetest/auto-fix-1776590808199mainops/redeploy-retriggerstyle/dxt-cta-themeworktree-agent-a3377aad30d55da26worktree-agent-a7ef607b7ee1d6c74
commit-statuses.ts4.6 KB · 149 lines
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
/**
 * Block J8 — Commit status API (GitHub-parity).
 *
 * External CI / automation systems POST statuses against a (repo, sha, context)
 * triple. Reads are public for public repos (softAuth visibility check) and
 * writes require repo-owner auth (session / OAuth / PAT accepted by
 * requireAuth).
 *
 *   POST /api/v1/repos/:owner/:repo/statuses/:sha
 *     body: { state, context?, description?, target_url? }
 *     200: { ok: true, status }
 *     400: invalid state / sha
 *     401/403: auth / permission
 *
 *   GET  /api/v1/repos/:owner/:repo/commits/:sha/statuses
 *     200: { total, statuses: [...] }
 *
 *   GET  /api/v1/repos/:owner/:repo/commits/:sha/status
 *     200: { state, total, counts, contexts }
 */

import { Hono } from "hono";
import { and, eq } from "drizzle-orm";
import { db } from "../db";
import { repositories, users } from "../db/schema";
import { softAuth, requireAuth } from "../middleware/auth";
import type { AuthEnv } from "../middleware/auth";
import {
  combinedStatus,
  isValidSha,
  isValidState,
  listStatuses,
  setStatus,
} from "../lib/commit-statuses";

const statuses = new Hono<AuthEnv>();

async function resolveRepo(ownerName: string, repoName: string) {
  const [owner] = await db
    .select()
    .from(users)
    .where(eq(users.username, ownerName))
    .limit(1);
  if (!owner) return null;
  const [repo] = await db
    .select()
    .from(repositories)
    .where(
      and(eq(repositories.ownerId, owner.id), eq(repositories.name, repoName))
    )
    .limit(1);
  if (!repo) return null;
  return { owner, repo };
}

// ---------------------------------------------------------------------------
// POST status
// ---------------------------------------------------------------------------
statuses.post(
  "/api/v1/repos/:owner/:repo/statuses/:sha",
  softAuth,
  requireAuth,
  async (c) => {
    const { owner: ownerName, repo: repoName, sha } = c.req.param();
    const user = c.get("user")!;
    if (!isValidSha(sha)) {
      return c.json({ error: "Invalid sha" }, 400);
    }
    const resolved = await resolveRepo(ownerName, repoName);
    if (!resolved) return c.json({ error: "Repository not found" }, 404);
    if (resolved.owner.id !== user.id) {
      return c.json({ error: "Forbidden" }, 403);
    }

    let body: any = {};
    try {
      body = await c.req.json();
    } catch {
      body = {};
    }

    const state = body.state;
    if (!isValidState(state)) {
      return c.json(
        {
          error:
            "Invalid state; must be one of pending, success, failure, error",
        },
        400
      );
    }

    const row = await setStatus({
      repositoryId: resolved.repo.id,
      commitSha: sha,
      state,
      context: body.context ?? body.Context ?? "default",
      description: body.description ?? null,
      targetUrl: body.target_url ?? body.targetUrl ?? null,
      creatorId: user.id,
    });

    if (!row) return c.json({ error: "Could not save status" }, 500);

    return c.json({ ok: true, status: row });
  }
);

// ---------------------------------------------------------------------------
// GET statuses list
// ---------------------------------------------------------------------------
statuses.get(
  "/api/v1/repos/:owner/:repo/commits/:sha/statuses",
  softAuth,
  async (c) => {
    const { owner: ownerName, repo: repoName, sha } = c.req.param();
    if (!isValidSha(sha)) return c.json({ error: "Invalid sha" }, 400);
    const resolved = await resolveRepo(ownerName, repoName);
    if (!resolved) return c.json({ error: "Repository not found" }, 404);
    const user = c.get("user");
    if (resolved.repo.isPrivate && (!user || user.id !== resolved.owner.id)) {
      return c.json({ error: "Forbidden" }, 403);
    }
    const rows = await listStatuses(resolved.repo.id, sha);
    return c.json({ total: rows.length, statuses: rows });
  }
);

// ---------------------------------------------------------------------------
// GET combined status
// ---------------------------------------------------------------------------
statuses.get(
  "/api/v1/repos/:owner/:repo/commits/:sha/status",
  softAuth,
  async (c) => {
    const { owner: ownerName, repo: repoName, sha } = c.req.param();
    if (!isValidSha(sha)) return c.json({ error: "Invalid sha" }, 400);
    const resolved = await resolveRepo(ownerName, repoName);
    if (!resolved) return c.json({ error: "Repository not found" }, 404);
    const user = c.get("user");
    if (resolved.repo.isPrivate && (!user || user.id !== resolved.owner.id)) {
      return c.json({ error: "Forbidden" }, 403);
    }
    const combined = await combinedStatus(resolved.repo.id, sha);
    return c.json(combined);
  }
);

export default statuses;