Skip to main content

umbral_openapi/
lib.rs

1//! umbral-openapi — auto-generated OpenAPI 3.0 schema + Swagger UI.
2//!
3//! Register [`OpenApiPlugin`] on `App::builder()` alongside
4//! `RestPlugin`. The plugin walks the migration registry, drops the
5//! tables umbral-rest hides by default, and emits an OpenAPI 3.0
6//! document describing every remaining model's REST surface.
7//!
8//! Default mount point is `/openapi/`:
9//!
10//! - `GET /openapi/openapi.json` — the JSON spec
11//! - `GET /openapi/`             — Swagger UI loaded from unpkg
12//!
13//! Override via `OpenApiPlugin::new().at("/api/docs")` to put the UI
14//! under `/api/docs/` and the JSON under `/api/docs/openapi.json`.
15//!
16//! ## Scope
17//!
18//! v1 only describes umbral-rest's auto-generated endpoints. Hand-
19//! written routes the user added on the builder are not in scope.
20//! The spec emits a `components.securitySchemes` block populated from
21//! the REST layer's registered auth schemes (via
22//! `umbral_rest::registered_security_schemes()`). List endpoints
23//! include the pagination query parameters that match the configured
24//! backend — `page`/`page_size` for [`umbral_rest::PageNumberPagination`],
25//! `limit`/`offset` for [`umbral_rest::LimitOffsetPagination`], none for
26//! [`umbral_rest::NoPagination`] (the default).
27
28use std::sync::OnceLock;
29
30pub mod client_gen;
31
32use serde_json::{Map, Value, json};
33use umbral::migrate::{Column, ModelMeta};
34use umbral::orm::SqlType;
35use umbral::prelude::*;
36use umbral::web::{Html, IntoResponse, Json, Response, StatusCode, header};
37use umbral_casing::pascal_case_from_ident;
38
39const SWAGGER_UI_HTML: &str = include_str!("../templates/swagger_ui.html");
40
41/// The OpenAPI plugin.
42#[derive(Debug, Clone)]
43pub struct OpenApiPlugin {
44    base_path: String,
45    title: String,
46    version: String,
47    description: Option<String>,
48    extra_exclude: Vec<String>,
49    /// Whether to mount the spec + Swagger UI under `Environment::Prod`.
50    /// Default `false` (audit_2 plugin-observability #1): the schema exposes
51    /// the entire API surface (every model, field, filter, FK graph) to
52    /// unauthenticated callers — recon for attacking the live API. Opt in with
53    /// [`Self::allow_in_prod`].
54    allow_in_prod: bool,
55    /// Base URL the Swagger UI CSS/JS assets load from (audit_2
56    /// plugin-observability #9). Defaults to a **pinned exact** version on a
57    /// public CDN ([`DEFAULT_SWAGGER_ASSET_BASE`]) — pinned so a resolved
58    /// version can't drift under you. Point it at a self-hosted / vendored copy
59    /// (e.g. served from your own static files) for an air-gapped or
60    /// CSP-strict deployment that must not fetch third-party JS. Set via
61    /// [`Self::swagger_asset_base`].
62    swagger_asset_base: String,
63}
64
65/// Default Swagger UI asset base: an **exact** pinned version (not `@5`, which
66/// silently resolves to whatever the CDN serves for the major). audit_2
67/// plugin-observability #9.
68pub const DEFAULT_SWAGGER_ASSET_BASE: &str = "https://unpkg.com/swagger-ui-dist@5.17.14";
69
70/// Subresource-Integrity (SHA-384) hashes for the two Swagger UI assets at the
71/// pinned [`DEFAULT_SWAGGER_ASSET_BASE`] version (audit_2 plugin-observability
72/// #9). The browser refuses an asset whose bytes don't match, so a compromised
73/// or MITM'd CDN response can't inject script. These are version-specific: they
74/// are only emitted when the asset base is the default. If an operator points
75/// `swagger_asset_base` at a self-hosted / different-version copy, integrity is
76/// omitted (we can't know their bytes) — and same-origin self-hosting doesn't
77/// need it. Bump these whenever the pinned version changes.
78const SWAGGER_CSS_SRI: &str =
79    "sha384-wxLW6kwyHktdDGr6Pv1zgm/VGJh99lfUbzSn6HNHBENZlCN7W602k9VkGdxuFvPn";
80const SWAGGER_JS_SRI: &str =
81    "sha384-wmyclcVGX/WhUkdkATwhaK1X1JtiNrr2EoYJ+diV3vj4v6OC5yCeSu+yW13SYJep";
82
83impl Default for OpenApiPlugin {
84    fn default() -> Self {
85        Self::new()
86    }
87}
88
89impl OpenApiPlugin {
90    pub fn new() -> Self {
91        Self {
92            base_path: "/openapi".to_string(),
93            title: "umbral API".to_string(),
94            version: "0.0.1".to_string(),
95            description: None,
96            extra_exclude: Vec::new(),
97            allow_in_prod: false,
98            swagger_asset_base: DEFAULT_SWAGGER_ASSET_BASE.to_string(),
99        }
100    }
101
102    /// Override where the Swagger UI CSS/JS load from (audit_2
103    /// plugin-observability #9). Point it at a self-hosted / vendored copy to
104    /// avoid a third-party CDN entirely (air-gapped, CSP-strict). The base is
105    /// used as `<base>/swagger-ui.css` and `<base>/swagger-ui-bundle.js`.
106    pub fn swagger_asset_base(mut self, base: impl Into<String>) -> Self {
107        self.swagger_asset_base = base.into();
108        self
109    }
110
111    /// Mount the OpenAPI spec + Swagger UI even in `Environment::Prod`. Off by
112    /// default — the spec is a full unauthenticated map of your API. Only opt
113    /// in if `/openapi/*` is firewalled or auth-proxied to internal callers.
114    pub fn allow_in_prod(mut self) -> Self {
115        self.allow_in_prod = true;
116        self
117    }
118
119    /// Mount the JSON + UI under a different base. Trailing slashes
120    /// are normalised so both `.at("/api/docs")` and `.at("/api/docs/")`
121    /// register the same routes.
122    pub fn at(mut self, path: &str) -> Self {
123        let trimmed = path.trim_end_matches('/');
124        self.base_path = if trimmed.is_empty() {
125            "/".to_string()
126        } else {
127            trimmed.to_string()
128        };
129        self
130    }
131
132    /// Override `info.title` in the emitted spec.
133    pub fn title(mut self, s: impl Into<String>) -> Self {
134        self.title = s.into();
135        self
136    }
137
138    /// Override `info.version` in the emitted spec.
139    pub fn version(mut self, s: impl Into<String>) -> Self {
140        self.version = s.into();
141        self
142    }
143
144    /// Set `info.description` in the emitted spec. Optional —
145    /// omitted from the JSON when unset. Markdown is permitted (per
146    /// OpenAPI 3.0.3); Swagger UI renders it above the operations
147    /// list, so this is the place to document API-wide auth, rate
148    /// limiting, conventions, etc.
149    pub fn description(mut self, s: impl Into<String>) -> Self {
150        self.description = Some(s.into());
151        self
152    }
153
154    /// Add tables to the block-list. The umbral-rest defaults still
155    /// apply.
156    pub fn exclude<I, S>(mut self, tables: I) -> Self
157    where
158        I: IntoIterator<Item = S>,
159        S: Into<String>,
160    {
161        for t in tables {
162            self.extra_exclude.push(t.into());
163        }
164        self
165    }
166
167    fn is_exposed(&self, table: &str) -> bool {
168        // The default block-list lives in umbral-rest and is consulted
169        // via `umbral_rest::is_exposed(table)` at spec-build time, so
170        // we don't duplicate it here. Our own opt-out is purely the
171        // `extra_exclude` list — for cases like "served by REST but
172        // I don't want it in the public spec."
173        !self.extra_exclude.iter().any(|t| t == table)
174    }
175
176    fn spec_url(&self) -> String {
177        if self.base_path == "/" {
178            "/openapi.json".to_string()
179        } else {
180            format!("{}/openapi.json", self.base_path)
181        }
182    }
183
184    fn ui_route(&self) -> String {
185        if self.base_path == "/" {
186            "/".to_string()
187        } else {
188            format!("{}/", self.base_path)
189        }
190    }
191}
192
193// Configured plugin lives in a OnceLock so the static handlers, which
194// can't capture per-instance state through axum, can read the title /
195// version / block-list at request time.
196static CONFIG: OnceLock<OpenApiPlugin> = OnceLock::new();
197
198/// Public read of the configured spec URL — the path the JSON
199/// document is served at after `App::build()` runs. Returns
200/// `None` when OpenApiPlugin isn't installed (the OnceLock
201/// hasn't been populated by `Plugin::routes()` yet); returns
202/// `Some("/openapi/openapi.json")` for the default mount and
203/// `Some("/api/docs/openapi.json")` when the user calls
204/// `OpenApiPlugin::default().at("/api/docs")`.
205///
206/// The playground plugin reads this at HTML-render time to inject
207/// the URL into the shell page as a JS global, so a re-mounted
208/// spec is auto-discovered by the SPA without the user having to
209/// also configure the playground.
210pub fn spec_url() -> Option<String> {
211    CONFIG.get().map(|cfg| cfg.spec_url())
212}
213
214impl Plugin for OpenApiPlugin {
215    fn name(&self) -> &'static str {
216        "openapi"
217    }
218
219    fn dependencies(&self) -> &'static [&'static str] {
220        &["rest"]
221    }
222
223    fn commands(&self) -> Vec<Box<dyn umbral::cli::PluginCommand>> {
224        vec![Box::new(GenClientCommand)]
225    }
226
227    fn routes(&self) -> Router {
228        // audit_2 #1: don't expose the full API schema in production unless the
229        // operator explicitly opted in. `get_opt` never panics pre-settings.
230        let is_prod = matches!(
231            umbral::settings::get_opt().map(|s| &s.environment),
232            Some(umbral::Environment::Prod)
233        );
234        if is_prod && !self.allow_in_prod {
235            tracing::warn!(
236                "umbral-openapi: not mounting in Environment::Prod (the OpenAPI spec maps your \
237                 entire API surface for unauthenticated callers). Call \
238                 OpenApiPlugin::new().allow_in_prod() to override, ideally behind a firewall.",
239            );
240            return Router::new();
241        }
242        let _ = CONFIG.set(self.clone());
243        // Publish the spec URL to the core registry so cross-plugin
244        // consumers (umbral-playground's SPA fetches it from the
245        // browser) can discover the configured mount without
246        // hardcoding `/openapi/openapi.json`.
247        umbral::routes::init_openapi_spec_url(self.spec_url());
248        let mut router = Router::new()
249            .route(&self.spec_url(), get(spec_handler))
250            .route(&self.ui_route(), get(swagger_ui_handler));
251        // Also register the slash-less form (`/openapi` alongside
252        // `/openapi/`) so the trailing-slash gotcha doesn't bite users
253        // who haven't opted into the framework-wide
254        // `App::builder().slash_redirect(SlashRedirect::Append)`
255        // policy. Cheap: same handler, no extra state. Skipped when
256        // the base path is `/` (the ui_route is already just `/`,
257        // no alternate form to register).
258        if self.base_path != "/" {
259            router = router.route(&self.base_path, get(swagger_ui_handler));
260        }
261        router
262    }
263}
264
265// =========================================================================
266// Handlers.
267// =========================================================================
268
269async fn spec_handler() -> Response {
270    let cfg = CONFIG.get().expect("OpenApiPlugin::routes was called");
271    let spec = build_spec(cfg);
272    // Json's IntoResponse already sets application/json, but be
273    // explicit so a future swap to a String body doesn't drop it.
274    (
275        StatusCode::OK,
276        [(header::CONTENT_TYPE, "application/json")],
277        Json(spec),
278    )
279        .into_response()
280}
281
282async fn swagger_ui_handler() -> Response {
283    let cfg = CONFIG.get().expect("OpenApiPlugin::routes was called");
284    // Only emit SRI when serving the known, pinned default assets — the hashes
285    // are version-specific and would BREAK a self-hosted / re-versioned base
286    // (audit_2 plugin-observability #9).
287    let is_default = cfg.swagger_asset_base == DEFAULT_SWAGGER_ASSET_BASE;
288    let (css_integrity, js_integrity) = if is_default {
289        (
290            format!(" integrity=\"{SWAGGER_CSS_SRI}\""),
291            format!(" integrity=\"{SWAGGER_JS_SRI}\""),
292        )
293    } else {
294        (String::new(), String::new())
295    };
296    let body = SWAGGER_UI_HTML
297        .replace("{ASSET_BASE}", &cfg.swagger_asset_base)
298        .replace("{CSS_INTEGRITY}", &css_integrity)
299        .replace("{JS_INTEGRITY}", &js_integrity)
300        .replace("{SPEC_URL}", &cfg.spec_url());
301    Html(body).into_response()
302}
303
304// =========================================================================
305// Spec generation. Walk the registry, dispatch each SqlType to an
306// OpenAPI type/format, and emit one schema + six operations per
307// exposed model.
308// =========================================================================
309
310fn build_spec(cfg: &OpenApiPlugin) -> Value {
311    let mut schemas = Map::new();
312    let mut paths = Map::new();
313
314    // Playground-openapi-gaps #2: precompute every (table →
315    // schema_name) mapping so FK columns can emit
316    // `x-umbral-fk-ref` pointing at the target schema's JSON
317    // pointer. The pointer shape `#/components/schemas/<Target>`
318    // is what generated clients follow to navigate from `Post.author`
319    // to the `User` schema. Done in a separate walk first so the
320    // map is complete by the time column_schema runs on FK fields.
321    let mut table_to_schema: std::collections::HashMap<String, String> =
322        std::collections::HashMap::new();
323    for plugin in umbral::migrate::registered_plugins() {
324        for model in umbral::migrate::models_for_plugin(&plugin) {
325            table_to_schema.insert(model.table.clone(), pascal_case_from_ident(&model.name));
326        }
327    }
328
329    // Read the REST base path once before the model loop. This is what
330    // the real mounted routes use, so the documented paths mirror the live
331    // routes exactly. E.g. `.at("/v2")` → paths under `/v2/`, not `/api/`.
332    let rest_base = umbral_rest::registered_base_path().to_owned();
333
334    for plugin in umbral::migrate::registered_plugins() {
335        for model in umbral::migrate::models_for_plugin(&plugin) {
336            // The spec describes what REST actually serves, so defer
337            // to RestPlugin's allow/block decision first. This means
338            // `RestPlugin::default().include_only(["article"])`
339            // automatically restricts the spec to `article` without
340            // the user having to repeat the configuration on
341            // OpenApiPlugin. The OpenAPI plugin's own `.exclude(...)`
342            // list still applies AFTER as an additional filter for
343            // tables the user wants served-but-not-documented.
344            if !umbral_rest::is_exposed(&model.table) {
345                continue;
346            }
347            if !cfg.is_exposed(&model.table) {
348                continue;
349            }
350            let schema_name = pascal_case_from_ident(&model.name);
351            schemas.insert(schema_name.clone(), model_schema(&model, &table_to_schema));
352            // Advertise every filterable column × lookup AND the
353            // `?search=` free-text parameter (when enabled) as
354            // discoverable query parameters on the GET list
355            // operation. The playground (and any spec consumer) can
356            // then drive a real filter UI off the spec instead of
357            // guessing.
358            let mut list_params = Vec::new();
359            // Emit the pagination query params that match the configured
360            // backend. PageNumber → page/page_size; LimitOffset →
361            // limit/offset; NoPagination and unknown custom → nothing.
362            list_params.extend(pagination_parameters_for_style(
363                umbral_rest::registered_pagination_style(),
364            ));
365            if umbral_rest::search_enabled_for(&model.table) {
366                list_params.push(search_parameter());
367            }
368            // `?fields=` sparse fieldset (BUG-81) is always
369            // available — independent of search / filter opt-out.
370            list_params.push(fields_parameter(&model));
371            // `?include=fk1,fk2` — only emit when the model actually
372            // has FK columns; otherwise the param has nothing to
373            // expand and the playground multi-select would render
374            // empty.
375            if model.fields.iter().any(|c| c.fk_target.is_some()) {
376                list_params.push(include_parameter(&model));
377            }
378            if umbral_rest::filters_enabled_for(&model.table) {
379                list_params.extend(filter_parameters(&model));
380            }
381            // Skip the collection path entirely when `.views(...)` scoped
382            // out both List and Create — an OpenAPI path item with no
383            // operations is meaningless (and clutters Swagger UI).
384            let collection = collection_paths(&model.table, &schema_name, &list_params);
385            if has_operations(&collection) {
386                paths.insert(format!("{}/{}/", rest_base, model.table), collection);
387            }
388            // Retrieve respects both `?fields=` and `?include=` — same
389            // shape as list. Build the params slice dynamically so the
390            // FK-less models don't get a vestigial `?include=` entry.
391            let mut item_params = vec![fields_parameter(&model)];
392            if model.fields.iter().any(|c| c.fk_target.is_some()) {
393                item_params.push(include_parameter(&model));
394            }
395            // Same guard for the detail path: `views([List])` leaves the
396            // item URL with no operations (only the `id` parameter), so
397            // it's omitted from the spec.
398            let item = item_paths(&model.table, &schema_name, &item_params);
399            if has_operations(&item) {
400                paths.insert(format!("{}/{}/{{id}}", rest_base, model.table), item);
401            }
402        }
403    }
404
405    // BUG-20: every plugin's `Plugin::openapi_paths()` contribution
406    // gets merged into the spec. Auto-CRUD paths above land first
407    // (so a plugin can shadow a model's path with a custom Path Item
408    // if it wants); plugin contributions land on top, last-write-
409    // wins for duplicate URLs.
410    if let Some(entries) = umbral::routes::registered_openapi_paths() {
411        for (path, item) in entries {
412            paths.insert(path.clone(), item.clone());
413        }
414    }
415
416    // Every custom `@action` endpoint gets its own path item so it shows up
417    // in the spec + playground. Declared request/response schemas (feature
418    // #60) are inlined; a schemaless action (e.g. `get_price_at`) still
419    // appears, with a generic 200 response.
420    for action in umbral_rest::registered_action_schemas() {
421        let path = if action.detail {
422            format!(
423                "{}/{}/{{id}}/{}/",
424                action.base_path, action.table, action.name
425            )
426        } else {
427            format!("{}/{}/{}/", action.base_path, action.table, action.name)
428        };
429        paths.insert(path, action_path_item(&action));
430    }
431
432    let mut info = Map::new();
433    info.insert("title".into(), Value::String(cfg.title.clone()));
434    info.insert("version".into(), Value::String(cfg.version.clone()));
435    if let Some(desc) = &cfg.description {
436        info.insert("description".into(), Value::String(desc.clone()));
437    }
438
439    // Playground-openapi-gaps #4: read the configured auth chain's
440    // securitySchemes and emit a `components.securitySchemes` block
441    // + a global `security` array referencing each. The global
442    // security is an OR (any one scheme satisfies the request),
443    // matching `ChainAuthentication([Session, Bearer])`'s actual
444    // runtime behaviour.
445    let mut security_schemes = Map::new();
446    let mut security: Vec<Value> = Vec::new();
447    for (name, scheme) in umbral_rest::registered_security_schemes() {
448        security.push(json!({ name.clone(): [] }));
449        security_schemes.insert(name, scheme);
450    }
451    let mut components = Map::new();
452    components.insert("schemas".into(), Value::Object(schemas));
453    if !security_schemes.is_empty() {
454        components.insert("securitySchemes".into(), Value::Object(security_schemes));
455    }
456
457    let mut document = Map::new();
458    document.insert("openapi".into(), Value::String("3.0.3".into()));
459    document.insert("info".into(), Value::Object(info));
460    document.insert("paths".into(), Value::Object(paths));
461    document.insert("components".into(), Value::Object(components));
462    if !security.is_empty() {
463        document.insert("security".into(), Value::Array(security));
464    }
465    Value::Object(document)
466}
467
468/// Path Item for a custom `@action` (feature #60): the declared HTTP
469/// method with the request/response schemas inlined, plus the `{id}` path
470/// param for detail-scope actions.
471fn action_path_item(a: &umbral_rest::ActionSchema) -> Value {
472    let mut op = Map::new();
473    op.insert(
474        "operationId".into(),
475        Value::String(format!("{}_{}", a.table, a.name)),
476    );
477    op.insert("tags".into(), json!([a.table]));
478    op.insert(
479        "summary".into(),
480        Value::String(format!("`{}` action on {}", a.name, a.table)),
481    );
482    if a.detail {
483        op.insert(
484            "parameters".into(),
485            json!([{
486                "name": "id", "in": "path", "required": true,
487                "schema": { "type": "string" },
488                "description": "Primary key of the target row"
489            }]),
490        );
491    }
492    if let Some(input) = &a.input_schema {
493        op.insert(
494            "requestBody".into(),
495            json!({ "required": true, "content": { "application/json": { "schema": input } } }),
496        );
497    }
498    let mut ok = Map::new();
499    ok.insert("description".into(), Value::String("Action result".into()));
500    if let Some(output) = &a.output_schema {
501        ok.insert(
502            "content".into(),
503            json!({ "application/json": { "schema": output } }),
504        );
505    }
506    op.insert("responses".into(), json!({ "200": Value::Object(ok) }));
507
508    let mut item = Map::new();
509    item.insert(a.method.to_lowercase(), Value::Object(op));
510    Value::Object(item)
511}
512
513fn model_schema(
514    model: &ModelMeta,
515    table_to_schema: &std::collections::HashMap<String, String>,
516) -> Value {
517    let mut properties = Map::new();
518    let mut required: Vec<Value> = Vec::new();
519    for col in &model.fields {
520        // A column the REST plugin hides (`ResourceConfig::hide` /
521        // `RestPlugin::hide_model`) is stripped from every response
522        // body, so it must not appear in the schema either — otherwise
523        // the spec advertises (and Swagger UI shows) a field like
524        // `password_hash` the API will never return: an info leak +
525        // confusing docs. Skip it for both `properties` and `required`.
526        if umbral_rest::is_hidden(&model.table, &col.name) {
527            continue;
528        }
529        properties.insert(
530            col.name.clone(),
531            column_schema_with_refs(col, table_to_schema),
532        );
533        // PK is auto-generated by SQLite on POST.
534        // Non-nullable non-PK columns are what the client MUST
535        // supply — except when the framework supplies a default
536        // itself. `auto_now` / `auto_now_add` stamp `Utc::now()`
537        // when the body omits the value, and `noform` columns
538        // are stripped from the body before write. None of
539        // those should appear in `required`; making them so
540        // would force clients to ship server-managed timestamps
541        // and password hashes on every POST.
542        if !col.nullable && !col.primary_key && !col.auto_now && !col.auto_now_add && !col.noform {
543            required.push(Value::String(col.name.clone()));
544        }
545    }
546    // M2M relations live on the parent's `m2m_relations` channel
547    // (not on `fields`, because they have no column on the parent
548    // table). Surface them as `array of integer` with a vendor
549    // extension naming the child schema so playground / generated
550    // clients can render a tag-picker. Not marked required —
551    // M2M slots are always optional on write.
552    for rel in &model.m2m_relations {
553        let target_schema = table_to_schema
554            .get(&rel.target_table)
555            .cloned()
556            .unwrap_or_else(|| pascal_case_from_ident(&rel.target_name));
557        let mut prop = serde_json::Map::new();
558        prop.insert("type".into(), Value::String("array".into()));
559        // Items are the child model's PK type, not always int64 (review #4):
560        // a M2M to a String/Uuid-PK child sends an array of slugs/uuids.
561        let (item_ty, item_fmt) = umbral::migrate::pk_meta_for_table(&rel.target_table)
562            .map(|(_, pk_ty)| openapi_type(pk_ty))
563            .unwrap_or(("integer", Some("int64")));
564        let items = match item_fmt {
565            Some(f) => json!({ "type": item_ty, "format": f }),
566            None => json!({ "type": item_ty }),
567        };
568        prop.insert("items".into(), items);
569        prop.insert(
570            "description".into(),
571            Value::String(format!(
572                "Many-to-many relation to {}. Send an array of child ids on \
573                 create / update; the framework writes the junction table.",
574                target_schema,
575            )),
576        );
577        // Vendor extensions: aware clients (playground) can render
578        // a multi-select chip picker pointed at the child schema.
579        prop.insert("x-umbral-m2m".into(), Value::Bool(true));
580        prop.insert(
581            "x-umbral-m2m-target".into(),
582            Value::String(target_schema.clone()),
583        );
584        prop.insert(
585            "x-umbral-m2m-target-table".into(),
586            Value::String(rel.target_table.clone()),
587        );
588        if table_to_schema.contains_key(&rel.target_table) {
589            prop.insert(
590                "x-umbral-m2m-target-ref".into(),
591                Value::String(format!("#/components/schemas/{target_schema}")),
592            );
593        }
594        properties.insert(rel.field_name.clone(), Value::Object(prop));
595    }
596    let mut obj = Map::new();
597    obj.insert("type".into(), Value::String("object".into()));
598    obj.insert("properties".into(), Value::Object(properties));
599    if !required.is_empty() {
600        obj.insert("required".into(), Value::Array(required));
601    }
602    Value::Object(obj)
603}
604
605/// Wrap [`column_schema`] with the schema-name-aware FK ref. The
606/// inner function stays backwards-compatible (no map arg) for the
607/// test cases that exercise `column_schema(&col)` directly.
608fn column_schema_with_refs(
609    col: &Column,
610    table_to_schema: &std::collections::HashMap<String, String>,
611) -> Value {
612    let mut value = column_schema(col);
613    // Playground-openapi-gaps #2: emit `x-umbral-fk-ref` as a JSON
614    // pointer to the target schema. Generated clients that follow
615    // vendor extensions can navigate from a `Post.author` (integer)
616    // to the `User` schema. OpenAPI 3.0's strict `$ref` rule
617    // ("siblings of $ref must be ignored") rules out putting this on
618    // the value as a real `$ref`, which is why this lives as a
619    // vendor extension. The Swagger UI playground already special-
620    // cases umbral's `x-umbral-*` extensions; openapi-generator
621    // / orval can do the same.
622    if let Some(target_table) = &col.fk_target {
623        if let Some(schema_name) = table_to_schema.get(target_table) {
624            if let Some(obj) = value.as_object_mut() {
625                obj.insert(
626                    "x-umbral-fk-ref".into(),
627                    Value::String(format!("#/components/schemas/{schema_name}")),
628                );
629            }
630        }
631    }
632    value
633}
634
635fn column_schema(col: &Column) -> Value {
636    let (ty, format) = openapi_type(umbral::migrate::fk_effective_type(col));
637    let mut obj = Map::new();
638    obj.insert("type".into(), Value::String(ty.into()));
639    if let Some(f) = format {
640        obj.insert("format".into(), Value::String(f.into()));
641    }
642    if col.nullable {
643        obj.insert("nullable".into(), Value::Bool(true));
644    }
645    // `#[umbral(help = "...")]` lands as the OpenAPI standard
646    // `description` so Swagger UI / generated clients pick it up.
647    // Closes playground-openapi-gaps item 5.
648    if !col.help.is_empty() {
649        obj.insert("description".into(), Value::String(col.help.clone()));
650    }
651    // `#[umbral(example = "...")]` lands as the OpenAPI standard
652    // `example` so Swagger UI pre-fills request bodies with a
653    // useful sample. Closes playground-openapi-gaps item 6.
654    if !col.example.is_empty() {
655        obj.insert("example".into(), Value::String(col.example.clone()));
656    }
657    // IMP-3: `#[umbral(min = N)]` / `#[umbral(max = N)]` →
658    // OpenAPI `minimum` / `maximum`. Both are standard 3.0 keys.
659    if let Some(min) = col.min {
660        obj.insert(
661            "minimum".into(),
662            Value::Number(serde_json::Number::from(min)),
663        );
664    }
665    if let Some(max) = col.max {
666        obj.insert(
667            "maximum".into(),
668            Value::Number(serde_json::Number::from(max)),
669        );
670    }
671    // BUG-11/12/13: `Slug` / `Email` / `Url` wrappers lower to
672    // standard OpenAPI markers so generated clients and Swagger UI
673    // render the right widget.
674    if let Some(fmt) = col.text_format.as_deref() {
675        match fmt {
676            "email" => {
677                obj.insert("format".into(), Value::String("email".into()));
678            }
679            "url" => {
680                obj.insert("format".into(), Value::String("uri".into()));
681            }
682            "slug" => {
683                // No built-in OpenAPI format for slug; use the
684                // `pattern` keyword (standard 3.0) to constrain
685                // accepted values. Mirrors the macro-side regex.
686                obj.insert("pattern".into(), Value::String("^[A-Za-z0-9_-]+$".into()));
687            }
688            _ => {}
689        }
690    }
691    // Standard OpenAPI: closed-set values become `enum`. Skipped for
692    // multichoice (a CSV-encoded subset) because each request value is
693    // a comma-separated string of the choices, not one choice — clients
694    // need richer guidance than a flat enum can provide. We still emit
695    // the underlying choices via `x-umbral-choices` below.
696    if !col.choices.is_empty() && !col.is_multichoice {
697        obj.insert(
698            "enum".into(),
699            Value::Array(col.choices.iter().cloned().map(Value::String).collect()),
700        );
701    }
702    if col.max_length > 0 {
703        obj.insert(
704            "maxLength".into(),
705            Value::Number(serde_json::Number::from(col.max_length)),
706        );
707    }
708    if !col.default.is_empty() {
709        // OpenAPI `default` is typed as the property's type, but the
710        // Column carries it as a string (it's a SQL literal). Emitting
711        // as a string is the conservative choice — Swagger UI shows it
712        // as a hint, and clients that care can re-parse.
713        obj.insert("default".into(), Value::String(col.default.clone()));
714    }
715    if col.is_multichoice {
716        obj.insert("x-umbral-multichoice".into(), Value::Bool(true));
717        obj.insert(
718            "x-umbral-choices".into(),
719            Value::Array(col.choices.iter().cloned().map(Value::String).collect()),
720        );
721    }
722    if !col.choice_labels.is_empty() {
723        obj.insert(
724            "x-umbral-choice-labels".into(),
725            Value::Array(
726                col.choice_labels
727                    .iter()
728                    .cloned()
729                    .map(Value::String)
730                    .collect(),
731            ),
732        );
733    }
734    if let Some(target) = &col.fk_target {
735        obj.insert("x-umbral-fk-target".into(), Value::String(target.clone()));
736    }
737    // Playground-openapi-gaps #2: the schema-pointer flavour of
738    // `x-umbral-fk-target` lives on the wrapper `column_schema_with_refs`
739    // because it needs the table→schema name map.
740    if col.is_string_repr {
741        obj.insert("x-umbral-string-repr".into(), Value::Bool(true));
742    }
743    // `noedit` is intentionally NOT mapped to `readOnly`. The two
744    // concepts are different: `noedit` is an admin EDIT-form hint
745    // ("show this field disabled when the user clicks the row"),
746    // while OpenAPI's `readOnly` means "never accept this field in
747    // ANY request body" — including POST. The conflation hid
748    // required `noedit` fields from the playground autofill on
749    // CREATE, which is exactly the wrong direction.
750    //
751    // The real "API never accepts" semantic is `noform` (the field
752    // is never shown on any admin form AND the REST plugin drops
753    // it from request bodies before write). That maps cleanly to
754    // OpenAPI `readOnly`.
755    // `auto_now` / `auto_now_add` are server-populated: the ORM
756    // stamps `Utc::now()` when the body omits the value. Surface
757    // them as vendor extensions so an aware client (the playground)
758    // can show a "the server fills this in" hint and skip the
759    // field on autofill / form prefill. Not mapped to `readOnly`
760    // because the client CAN still send an explicit value — the
761    // framework respects it. `required` is already dropped at
762    // `model_schema`'s pass for the same reason.
763    if col.auto_now_add {
764        obj.insert("x-umbral-auto-now-add".into(), Value::Bool(true));
765    }
766    if col.auto_now {
767        obj.insert("x-umbral-auto-now".into(), Value::Bool(true));
768    }
769    if col.noform {
770        obj.insert("readOnly".into(), Value::Bool(true));
771        // Vendor extension so clients aware of the umbral surface
772        // (the playground in particular) can distinguish "API
773        // doesn't accept this" from "admin won't let you edit it"
774        // without having to re-derive the rule from the column
775        // metadata.
776        obj.insert("x-umbral-noform".into(), Value::Bool(true));
777    }
778    // `noedit` becomes a pure vendor extension. Aware clients can
779    // surface it in their edit UI (the playground could, e.g.,
780    // grey the field on PUT/PATCH but not POST) without it
781    // contaminating the request-body contract.
782    if col.noedit {
783        obj.insert("x-umbral-noedit".into(), Value::Bool(true));
784    }
785    Value::Object(obj)
786}
787
788fn openapi_type(ty: SqlType) -> (&'static str, Option<&'static str>) {
789    match ty {
790        SqlType::SmallInt => ("integer", Some("int32")),
791        SqlType::Integer => ("integer", Some("int32")),
792        SqlType::BigInt => ("integer", Some("int64")),
793        SqlType::Real => ("number", Some("float")),
794        SqlType::Double => ("number", Some("double")),
795        SqlType::Boolean => ("boolean", None),
796        SqlType::Text => ("string", None),
797        SqlType::Date => ("string", Some("date")),
798        SqlType::Time => ("string", Some("time")),
799        SqlType::Timestamptz => ("string", Some("date-time")),
800        SqlType::Uuid => ("string", Some("uuid")),
801        // OpenAPI represents JSON columns as the catch-all "object". A
802        // tighter schema would use `oneOf: [object, array]` to model the
803        // full JSON value space, but `object` is the conservative and
804        // most-tooling-friendly mapping for a first iteration.
805        SqlType::Json => ("object", None),
806        // Arrays render as `type: array` with an inferred item type in
807        // OpenAPI. The v1 mapping flattens the element to the same
808        // "type" string (no nested `items.format`) — enough for tools
809        // to validate the request shape, but not the full structural
810        // detail. A future pass can recurse into the element type via
811        // openapi_type for proper `items: { type, format }` nesting.
812        SqlType::Array(_) => ("array", None),
813        // Phase 4.4 network address types. INET and CIDR render as
814        // OpenAPI `ipv4`/`ipv6` strings (we use the generic "string"
815        // shape since umbral doesn't distinguish v4 vs v6 at the type
816        // level). MACADDR likewise renders as a string.
817        SqlType::Inet | SqlType::Cidr | SqlType::MacAddr => ("string", None),
818        // Phase 4.3 tsvector — opaque text lexeme vector. Render as
819        // plain string in the OpenAPI schema.
820        SqlType::FullText => ("string", None),
821        // gaps2 #70: text-backed Postgres types (XML / LTREE / BIT
822        // VARYING) carry their value as a plain string on the wire.
823        SqlType::Xml | SqlType::Ltree | SqlType::Bit => ("string", None),
824        // ForeignKey columns expose as integer (i64) in the REST/OpenAPI
825        // schema — the raw PK value, not a nested object.
826        SqlType::ForeignKey => ("integer", Some("int64")),
827        // BLOB / BYTEA. OpenAPI's `string` + `format: byte` means
828        // base64-encoded on the wire by convention, but umbral-rest's
829        // current wire format is a JSON array of u8. Render as
830        // `array` + `format: byte` to keep the schema honest about
831        // the shape; clients that need base64 can handle the encoding
832        // boundary themselves.
833        SqlType::Bytes => ("array", Some("byte")),
834        // BUG-10: NUMERIC. OpenAPI represents arbitrary-precision
835        // decimals as `string` with `format: decimal` per the
836        // 3.1 spec convention; clients that round-trip through
837        // f64 lose precision, so the canonical wire shape is the
838        // string representation.
839        SqlType::Decimal => ("string", Some("decimal")),
840    }
841}
842
843/// Build the OpenAPI `?search=` parameter object. One slot shared
844/// across every searchable column on the resource — the REST list
845/// handler ORs `icontains` predicates on Text columns and `eq`
846/// predicates on numeric / FK / Boolean columns whose type matches
847/// the parsed term shape.
848///
849/// Vendor extension `x-umbral-search: true` flags this parameter for
850/// aware clients (the playground in particular surfaces it as a
851/// dedicated search box rather than treating it as a generic filter
852/// chip).
853fn search_parameter() -> Value {
854    json!({
855        "name": "search",
856        "in": "query",
857        "required": false,
858        "description": "Free-text search across every searchable column. \
859                        Text columns match via case-insensitive substring; \
860                        numeric / FK / Boolean columns match exactly when \
861                        the term parses as that type. Multiple matches are \
862                        ORed.",
863        "schema": { "type": "string" },
864        "x-umbral-search": true,
865    })
866}
867
868/// BUG-81: the `?fields=col1,col2` sparse-fieldset parameter. Lives
869/// on every list AND retrieve endpoint — when set, the response row
870/// drops every key not in the requested list. Unknown column names
871/// are silently ignored; an empty value falls back to the full row.
872///
873/// The `x-umbral-fields` vendor extension lists every column the
874/// model exposes so the playground can render a multi-select
875/// instead of a plain text box. Generated clients that ignore the
876/// extension still see a `string` parameter with a clear
877/// description.
878fn fields_parameter(model: &ModelMeta) -> Value {
879    // Drop REST-hidden columns: the `?fields=` picker shouldn't offer a
880    // field you can never get back (hide always wins in the response).
881    let columns: Vec<Value> = model
882        .fields
883        .iter()
884        .filter(|c| !umbral_rest::is_hidden(&model.table, &c.name))
885        .map(|c| Value::String(c.name.clone()))
886        .collect();
887    json!({
888        "name": "fields",
889        "in": "query",
890        "required": false,
891        "description": "Comma-separated list of column names to include in the \
892                        response. Unknown names are silently dropped; an empty \
893                        value falls back to the full row (BUG-81). Composes \
894                        with hide / transform / computed — hide always wins, \
895                        the rest are returned iff in the list.",
896        "schema": { "type": "string" },
897        "x-umbral-fields": true,
898        "x-umbral-fields-columns": Value::Array(columns),
899    })
900}
901
902/// `?include=fk1,fk2` — expand the named FK columns into their full
903/// related-row objects via the REST plugin's select_related-backed
904/// path. Only FK columns are valid (anything else 400s); the
905/// playground reads `x-umbral-include-fks` to render a multi-select
906/// of the candidate FK names. Mirrors the `fields_parameter` shape
907/// so the same UI machinery can drive both.
908fn include_parameter(model: &ModelMeta) -> Value {
909    // A hidden FK column is stripped from responses, so expanding it via
910    // `?include=` could never surface anything — drop it from the
911    // includable list for consistency with the schema + fields picker.
912    let fks: Vec<Value> = model
913        .fields
914        .iter()
915        .filter(|c| c.fk_target.is_some())
916        .filter(|c| !umbral_rest::is_hidden(&model.table, &c.name))
917        .map(|c| Value::String(c.name.clone()))
918        .collect();
919    json!({
920        "name": "include",
921        "in": "query",
922        "required": false,
923        "description": "Comma-separated list of foreign-key columns to expand \
924                        in the response. Each named FK gets replaced with the \
925                        full related-row JSON object (one batched IN(...) query \
926                        per FK — no N+1). Unknown or non-FK names return a 400. \
927                        Example: `?include=user,billing_address`.",
928        "schema": { "type": "string" },
929        "x-umbral-include": true,
930        "x-umbral-include-fks": Value::Array(fks),
931    })
932}
933
934/// Playground-openapi-gaps #3 / gaps2 #79: emit the pagination query
935/// parameters that match the configured backend, not a hardcoded
936/// `page`/`page_size` pair.
937///
938/// - [`PaginationStyle::PageNumber`] → `page` + `page_size` (the common default)
939/// - [`PaginationStyle::LimitOffset`] → `limit` + `offset` (REST classic)
940/// - [`PaginationStyle::None`] / [`PaginationStyle::Custom`] → empty Vec
941///   (NoPagination has no URL params; unknown custom backends are opaque)
942fn pagination_parameters_for_style(style: umbral_rest::PaginationStyle) -> Vec<Value> {
943    match style {
944        umbral_rest::PaginationStyle::PageNumber => vec![
945            json!({
946                "name": "page",
947                "in": "query",
948                "required": false,
949                "description": "1-indexed page number. Defaults to 1 when omitted.",
950                "schema": { "type": "integer", "format": "int32", "minimum": 1, "default": 1 },
951                "x-umbral-pagination": "page",
952            }),
953            json!({
954                "name": "page_size",
955                "in": "query",
956                "required": false,
957                "description": "Rows per page. Capped at 100. Default 20.",
958                "schema": {
959                    "type": "integer", "format": "int32",
960                    "minimum": 1, "maximum": 100, "default": 20,
961                },
962                "x-umbral-pagination": "page_size",
963            }),
964        ],
965        umbral_rest::PaginationStyle::LimitOffset => vec![
966            json!({
967                "name": "limit",
968                "in": "query",
969                "required": false,
970                "description": "Maximum rows to return. Defaults to the configured page size.",
971                "schema": { "type": "integer", "format": "int32", "minimum": 1 },
972                "x-umbral-pagination": "limit",
973            }),
974            json!({
975                "name": "offset",
976                "in": "query",
977                "required": false,
978                "description": "Number of rows to skip from the start of the result set. Defaults to 0.",
979                "schema": { "type": "integer", "format": "int32", "minimum": 0, "default": 0 },
980                "x-umbral-pagination": "offset",
981            }),
982        ],
983        umbral_rest::PaginationStyle::None | umbral_rest::PaginationStyle::Custom => vec![],
984    }
985}
986
987/// Build the OpenAPI `parameters` entries that document the
988/// query-string filters on a list endpoint.
989/// One entry per (column, lookup) pair.
990///
991/// Skips the primary key (filtering on `id` adds no value over the
992/// detail URL `/api/<table>/{id}`) and the columns whose type the
993/// filter parser can't model (none today, but the helper takes the
994/// stance so future opt-outs are a one-line change).
995fn filter_parameters(model: &ModelMeta) -> Vec<Value> {
996    let mut out: Vec<Value> = Vec::new();
997    for col in &model.fields {
998        if col.primary_key {
999            continue;
1000        }
1001        let lookups = umbral_rest::filtering::applicable_lookups(col);
1002        for lookup in lookups {
1003            let name = if lookup == "eq" {
1004                col.name.clone()
1005            } else {
1006                format!("{}__{}", col.name, lookup)
1007            };
1008            out.push(filter_parameter(col, lookup, &name));
1009        }
1010    }
1011    out
1012}
1013
1014/// One OpenAPI parameter object for a single (column, lookup) pair.
1015///
1016/// - `__in` takes a CSV string: schema `type: string` with a
1017///   description spelling out the format. (A proper `style: form` +
1018///   `explode: false` array would be more correct OpenAPI but
1019///   complicates client code.)
1020/// - `__isnull` takes a boolean.
1021/// - `__contains` / `__icontains` / `__startswith` take a string
1022///   regardless of column type.
1023/// - Range / equality lookups inherit the column's own type.
1024fn filter_parameter(col: &Column, lookup: &str, name: &str) -> Value {
1025    let (schema, description) = match lookup {
1026        "in" => (
1027            json!({ "type": "string" }),
1028            format!(
1029                "Comma-separated `{}` values; matches rows where the column is in the set.",
1030                col.name,
1031            ),
1032        ),
1033        "isnull" => (
1034            json!({ "type": "boolean" }),
1035            format!(
1036                "`true` matches rows where `{}` IS NULL; `false` matches IS NOT NULL.",
1037                col.name,
1038            ),
1039        ),
1040        "contains" | "icontains" | "startswith" => {
1041            let phrase = match lookup {
1042                "contains" => "case-sensitive substring",
1043                "icontains" => "case-insensitive substring",
1044                "startswith" => "case-sensitive prefix",
1045                _ => unreachable!(),
1046            };
1047            (
1048                json!({ "type": "string" }),
1049                format!(
1050                    "Matches rows where `{}` contains the given {phrase}.",
1051                    col.name
1052                ),
1053            )
1054        }
1055        // eq, ne, gte, lte, gt, lt — type-aligned with the column.
1056        _ => {
1057            let (ty, format) = openapi_type(umbral::migrate::fk_effective_type(col));
1058            let mut schema_obj = Map::new();
1059            schema_obj.insert("type".into(), Value::String(ty.into()));
1060            if let Some(f) = format {
1061                schema_obj.insert("format".into(), Value::String(f.into()));
1062            }
1063            let phrase = match lookup {
1064                "eq" => "equals the value",
1065                "ne" => "does not equal the value",
1066                "gte" => "is greater than or equal to the value",
1067                "lte" => "is less than or equal to the value",
1068                "gt" => "is greater than the value",
1069                "lt" => "is less than the value",
1070                _ => "matches the value",
1071            };
1072            (
1073                Value::Object(schema_obj),
1074                format!("Matches rows where `{}` {phrase}.", col.name),
1075            )
1076        }
1077    };
1078
1079    json!({
1080        "name": name,
1081        "in": "query",
1082        "required": false,
1083        "description": description,
1084        "schema": schema,
1085        "x-umbral-filter-field": col.name,
1086        "x-umbral-filter-lookup": lookup,
1087    })
1088}
1089
1090fn collection_paths(table: &str, schema_name: &str, filter_params: &[Value]) -> Value {
1091    use umbral_rest::Action;
1092    let mut item = Map::new();
1093
1094    // `get` (list) — only when the resource exposes List. The list
1095    // operation's `parameters` array is omitted entirely when there are
1096    // no filters (matches the pre-fix spec shape and keeps Swagger UI
1097    // from rendering an empty Parameters section).
1098    if umbral_rest::action_exposed(table, &Action::List) {
1099        let mut get_op = Map::new();
1100        get_op.insert(
1101            "operationId".into(),
1102            Value::String(format!("list_{}", table)),
1103        );
1104        get_op.insert("tags".into(), json!([table]));
1105        if !filter_params.is_empty() {
1106            get_op.insert("parameters".into(), Value::Array(filter_params.to_vec()));
1107        }
1108        get_op.insert(
1109            "responses".into(),
1110            json!({
1111                "200": {
1112                    "description": "List of rows",
1113                    "content": {
1114                        "application/json": {
1115                            "schema": list_envelope(schema_name)
1116                        }
1117                    }
1118                }
1119            }),
1120        );
1121        item.insert("get".into(), Value::Object(get_op));
1122    }
1123
1124    // `post` (create) — only when the resource exposes Create. A
1125    // `views([List, Retrieve])` resource omits it entirely.
1126    if umbral_rest::action_exposed(table, &Action::Create) {
1127        item.insert(
1128            "post".into(),
1129            json!({
1130                "operationId": format!("create_{}", table),
1131                "tags": [table],
1132                "requestBody": {
1133                    "required": true,
1134                    "content": {
1135                        "application/json": {
1136                            "schema": schema_ref(schema_name)
1137                        }
1138                    }
1139                },
1140                "responses": {
1141                    "201": {
1142                        "description": "Row created",
1143                        "content": {
1144                            "application/json": {
1145                                "schema": schema_ref(schema_name)
1146                            }
1147                        }
1148                    },
1149                    "400": { "description": "Invalid input" }
1150                }
1151            }),
1152        );
1153    }
1154
1155    Value::Object(item)
1156}
1157
1158fn item_paths(table: &str, schema_name: &str, retrieve_query_params: &[Value]) -> Value {
1159    use umbral_rest::Action;
1160    let id_param = json!({
1161        "name": "id",
1162        "in": "path",
1163        "required": true,
1164        "schema": { "type": "string" }
1165    });
1166    let mut item = Map::new();
1167    item.insert("parameters".into(), json!([id_param]));
1168
1169    // `get` (retrieve) — only when exposed. Build the GET op separately
1170    // so its query params can be listed alongside the path-level
1171    // `id_param`. Path-level `parameters` apply to every method on the
1172    // item URL, so GET-only knobs (like `?fields=`) land on the
1173    // operation itself instead.
1174    if umbral_rest::action_exposed(table, &Action::Retrieve) {
1175        let mut get_op = Map::new();
1176        get_op.insert(
1177            "operationId".into(),
1178            Value::String(format!("retrieve_{}", table)),
1179        );
1180        get_op.insert("tags".into(), json!([table]));
1181        if !retrieve_query_params.is_empty() {
1182            get_op.insert(
1183                "parameters".into(),
1184                Value::Array(retrieve_query_params.to_vec()),
1185            );
1186        }
1187        get_op.insert(
1188            "responses".into(),
1189            json!({
1190                "200": {
1191                    "description": "Row found",
1192                    "content": {
1193                        "application/json": {
1194                            "schema": schema_ref(schema_name)
1195                        }
1196                    }
1197                },
1198                "404": { "description": "Not found" }
1199            }),
1200        );
1201        item.insert("get".into(), Value::Object(get_op));
1202    }
1203
1204    // `put` + `patch` (update) — gated together on the Update action.
1205    if umbral_rest::action_exposed(table, &Action::Update) {
1206        item.insert(
1207            "put".into(),
1208            json!({
1209                "operationId": format!("update_{}", table),
1210                "tags": [table],
1211                "requestBody": {
1212                    "required": true,
1213                    "content": {
1214                        "application/json": {
1215                            "schema": schema_ref(schema_name)
1216                        }
1217                    }
1218                },
1219                "responses": {
1220                    "200": {
1221                        "description": "Row updated",
1222                        "content": {
1223                            "application/json": {
1224                                "schema": schema_ref(schema_name)
1225                            }
1226                        }
1227                    },
1228                    "404": { "description": "Not found" }
1229                }
1230            }),
1231        );
1232        item.insert(
1233            "patch".into(),
1234            json!({
1235                "operationId": format!("partial_update_{}", table),
1236                "tags": [table],
1237                "requestBody": {
1238                    "required": true,
1239                    "content": {
1240                        "application/json": {
1241                            "schema": schema_ref(schema_name)
1242                        }
1243                    }
1244                },
1245                "responses": {
1246                    "200": {
1247                        "description": "Row partially updated",
1248                        "content": {
1249                            "application/json": {
1250                                "schema": schema_ref(schema_name)
1251                            }
1252                        }
1253                    },
1254                    "404": { "description": "Not found" }
1255                }
1256            }),
1257        );
1258    }
1259
1260    // `delete` (destroy) — only when exposed.
1261    if umbral_rest::action_exposed(table, &Action::Delete) {
1262        item.insert(
1263            "delete".into(),
1264            json!({
1265                "operationId": format!("destroy_{}", table),
1266                "tags": [table],
1267                "responses": {
1268                    "204": { "description": "Row deleted" },
1269                    "404": { "description": "Not found" }
1270                }
1271            }),
1272        );
1273    }
1274
1275    Value::Object(item)
1276}
1277
1278fn schema_ref(name: &str) -> Value {
1279    json!({ "$ref": format!("#/components/schemas/{}", name) })
1280}
1281
1282/// True when an OpenAPI Path Item carries at least one HTTP operation.
1283/// A path item that only has `parameters` (no `get`/`post`/… keys) is
1284/// dropped from the spec — that happens when `.views(...)` scopes out
1285/// every verb the URI would otherwise serve.
1286fn has_operations(path_item: &Value) -> bool {
1287    const METHODS: [&str; 7] = ["get", "post", "put", "patch", "delete", "head", "options"];
1288    path_item
1289        .as_object()
1290        .is_some_and(|m| METHODS.iter().any(|verb| m.contains_key(*verb)))
1291}
1292
1293fn list_envelope(schema_name: &str) -> Value {
1294    json!({
1295        "type": "object",
1296        "properties": {
1297            "results": {
1298                "type": "array",
1299                "items": schema_ref(schema_name)
1300            },
1301            "count": { "type": "integer" }
1302        },
1303        "required": ["results", "count"]
1304    })
1305}
1306
1307// Test hooks: expose the URL helpers so the integration test can
1308// assert that `.at("/api/docs")` flows through to the right path
1309// strings without booting a second App.
1310#[doc(hidden)]
1311pub fn test_spec_url(p: &OpenApiPlugin) -> String {
1312    p.spec_url()
1313}
1314
1315#[doc(hidden)]
1316pub fn test_ui_route(p: &OpenApiPlugin) -> String {
1317    p.ui_route()
1318}
1319
1320// `pascal_case` replaced by `umbral_casing::pascal_case_from_ident` (imported
1321// above) in the gaps2 #77 consolidation refactor.
1322
1323/// `umbral gen-client` — write the typed TypeScript client (gaps3 #38).
1324///
1325/// Emits `client.js` (the single-file ES-module runtime) + `client.d.ts` (every
1326/// type) into `--out <dir>`. Offline: reads the model registry + the REST config
1327/// that `routes()` already published at build time, so it needs no database and
1328/// no running server. `--check` writes nothing and exits non-zero when the files
1329/// on disk have drifted from the current registry — the CI gate.
1330#[derive(Debug, Default)]
1331struct GenClientCommand;
1332
1333#[async_trait::async_trait]
1334impl umbral::cli::PluginCommand for GenClientCommand {
1335    fn command(&self) -> clap::Command {
1336        clap::Command::new("gen-client")
1337            .about("Generate a typed client (client.js + client.d.ts) for the REST API")
1338            .arg(
1339                clap::Arg::new("out")
1340                    .long("out")
1341                    .value_name("DIR")
1342                    .required(true)
1343                    .help("Directory to write client.js and client.d.ts into"),
1344            )
1345            .arg(
1346                clap::Arg::new("lang")
1347                    .long("lang")
1348                    .value_name("LANG")
1349                    .default_value("ts")
1350                    .help("Target language (only `ts` is supported)"),
1351            )
1352            .arg(
1353                clap::Arg::new("check")
1354                    .long("check")
1355                    .action(clap::ArgAction::SetTrue)
1356                    .help("Write nothing; exit non-zero if the files have drifted from the models"),
1357            )
1358    }
1359
1360    async fn run(&self, matches: &clap::ArgMatches) -> Result<(), umbral::cli::CliError> {
1361        let lang = matches
1362            .get_one::<String>("lang")
1363            .map(String::as_str)
1364            .unwrap_or("ts");
1365        if lang != "ts" {
1366            return Err(format!("gen-client: unsupported --lang `{lang}` (only `ts`)").into());
1367        }
1368        let dir = std::path::PathBuf::from(
1369            matches
1370                .get_one::<String>("out")
1371                .expect("--out is required by clap"),
1372        );
1373        let check = matches.get_flag("check");
1374
1375        let generated = client_gen::generate();
1376        let files = [("client.js", generated.js), ("client.d.ts", generated.dts)];
1377
1378        if check {
1379            let mut stale = Vec::new();
1380            for (name, want) in &files {
1381                let path = dir.join(name);
1382                // A missing file is drift, not an error to decode.
1383                let have = std::fs::read_to_string(&path).unwrap_or_default();
1384                if &have != want {
1385                    stale.push(path.display().to_string());
1386                }
1387            }
1388            if stale.is_empty() {
1389                println!("{} is up to date.", dir.display());
1390                return Ok(());
1391            }
1392            return Err(format!(
1393                "gen-client: out of date with the models: {}. Regenerate:\n    \
1394                 cargo run -- gen-client --out {}",
1395                stale.join(", "),
1396                dir.display(),
1397            )
1398            .into());
1399        }
1400
1401        std::fs::create_dir_all(&dir)?;
1402        for (name, contents) in &files {
1403            std::fs::write(dir.join(name), contents)?;
1404        }
1405        println!(
1406            "Wrote {} and {}.",
1407            dir.join("client.js").display(),
1408            dir.join("client.d.ts").display(),
1409        );
1410        Ok(())
1411    }
1412}
1413
1414#[cfg(test)]
1415mod tests {
1416    use super::*;
1417    use umbral::migrate::Column;
1418    use umbral::orm::SqlType;
1419
1420    // audit_2 plugin-observability #9: the Swagger UI asset base is pinned to an
1421    // EXACT version (not a drifting major) and configurable for self-hosting.
1422    #[test]
1423    fn swagger_asset_base_is_pinned_and_configurable() {
1424        // Default is an exact pin, not a bare `@5` major.
1425        assert!(
1426            DEFAULT_SWAGGER_ASSET_BASE.contains("@5.17"),
1427            "default asset base must pin an exact version, got {DEFAULT_SWAGGER_ASSET_BASE}"
1428        );
1429        assert!(!SWAGGER_UI_HTML.contains("unpkg.com/swagger-ui-dist@5/"));
1430        assert!(SWAGGER_UI_HTML.contains("{ASSET_BASE}"));
1431        assert!(SWAGGER_UI_HTML.contains("crossorigin=\"anonymous\""));
1432
1433        // A custom (self-hosted) base flows through the render substitution.
1434        let p = OpenApiPlugin::new().swagger_asset_base("/static/swagger");
1435        let rendered = SWAGGER_UI_HTML
1436            .replace("{ASSET_BASE}", &p.swagger_asset_base)
1437            .replace("{SPEC_URL}", "/openapi/openapi.json");
1438        assert!(rendered.contains("/static/swagger/swagger-ui-bundle.js"));
1439        assert!(!rendered.contains("{ASSET_BASE}"));
1440    }
1441
1442    fn base_col(name: &str, ty: SqlType) -> Column {
1443        Column {
1444            name: name.into(),
1445            ty,
1446            primary_key: false,
1447            nullable: false,
1448            fk_target: None,
1449            noform: false,
1450            privileged: false,
1451            db_constraint: true,
1452            noedit: false,
1453            auto_user_add: false,
1454            auto_user: false,
1455            is_string_repr: false,
1456            max_length: 0,
1457            choices: Vec::new(),
1458            choice_labels: Vec::new(),
1459            default: String::new(),
1460            is_multichoice: false,
1461            unique: false,
1462            on_delete: ::umbral::orm::FkAction::NoAction,
1463            on_update: ::umbral::orm::FkAction::NoAction,
1464            index: false,
1465            auto_now_add: false,
1466            auto_now: false,
1467            trim: false,
1468            lowercase: false,
1469            case_insensitive: false,
1470            help: String::new(),
1471            example: String::new(),
1472            widget: None,
1473            supported_backends: Vec::new(),
1474            min: None,
1475            max: None,
1476            text_format: ::core::option::Option::None,
1477            slug_from: ::core::option::Option::None,
1478        }
1479    }
1480
1481    #[test]
1482    fn choices_render_as_openapi_enum_with_labels_extension() {
1483        let mut col = base_col("status", SqlType::Text);
1484        col.choices = vec!["draft".into(), "published".into(), "archived".into()];
1485        col.choice_labels = vec!["Draft".into(), "Published".into(), "Archived".into()];
1486        let schema = column_schema(&col);
1487        assert_eq!(schema["type"], "string");
1488        assert_eq!(
1489            schema["enum"],
1490            serde_json::json!(["draft", "published", "archived"])
1491        );
1492        assert_eq!(
1493            schema["x-umbral-choice-labels"],
1494            serde_json::json!(["Draft", "Published", "Archived"])
1495        );
1496    }
1497
1498    #[test]
1499    fn multichoice_skips_enum_and_uses_vendor_extension() {
1500        let mut col = base_col("tags", SqlType::Text);
1501        col.choices = vec!["rust".into(), "python".into()];
1502        col.is_multichoice = true;
1503        let schema = column_schema(&col);
1504        assert!(
1505            schema.get("enum").is_none(),
1506            "multichoice columns should not declare a flat enum (value is a CSV subset)"
1507        );
1508        assert_eq!(schema["x-umbral-multichoice"], true);
1509        assert_eq!(
1510            schema["x-umbral-choices"],
1511            serde_json::json!(["rust", "python"])
1512        );
1513    }
1514
1515    #[test]
1516    fn max_length_and_default_surface_as_standard_openapi_keys() {
1517        let mut col = base_col("title", SqlType::Text);
1518        col.max_length = 50;
1519        col.default = "untitled".into();
1520        let schema = column_schema(&col);
1521        assert_eq!(schema["maxLength"], 50);
1522        assert_eq!(schema["default"], "untitled");
1523    }
1524
1525    #[test]
1526    fn fk_target_emits_vendor_extension_for_playground_navigation() {
1527        let mut col = base_col("author_id", SqlType::ForeignKey);
1528        col.fk_target = Some("auth_user".into());
1529        let schema = column_schema(&col);
1530        assert_eq!(schema["type"], "integer");
1531        assert_eq!(schema["format"], "int64");
1532        assert_eq!(schema["x-umbral-fk-target"], "auth_user");
1533    }
1534
1535    #[test]
1536    fn noform_renders_as_read_only_and_carries_vendor_extension() {
1537        // `noform` is the API-readOnly semantic — never accepted in
1538        // any request body, server fills it in. Maps to OpenAPI
1539        // `readOnly: true` so Swagger / generated clients honour it
1540        // on POST and PUT/PATCH alike.
1541        let mut col = base_col("internal_token", SqlType::Text);
1542        col.noform = true;
1543        let schema = column_schema(&col);
1544        assert_eq!(schema["readOnly"], true);
1545        assert_eq!(schema["x-umbral-noform"], true);
1546    }
1547
1548    #[test]
1549    fn noedit_does_NOT_render_as_read_only() {
1550        // Decoupled from API contract: `noedit` is purely an admin
1551        // EDIT-form hint. The field stays writable in the spec so a
1552        // required `noedit` field (e.g. `email` you can set at
1553        // signup but not change later) still gets autofilled on POST
1554        // by the playground and accepted by the REST plugin on CREATE.
1555        let mut col = base_col("email", SqlType::Text);
1556        col.noedit = true;
1557        let schema = column_schema(&col);
1558        assert!(
1559            schema.get("readOnly").is_none(),
1560            "noedit must NOT contaminate the API request-body contract; \
1561             got readOnly in schema: {schema:?}"
1562        );
1563        // Surface it as a vendor extension so aware clients can
1564        // still grey the field on PUT/PATCH if they want.
1565        assert_eq!(schema["x-umbral-noedit"], true);
1566    }
1567
1568    #[test]
1569    fn plain_column_keeps_minimal_schema_no_extensions() {
1570        let col = base_col("body", SqlType::Text);
1571        let schema = column_schema(&col);
1572        let obj = schema.as_object().expect("object");
1573        assert_eq!(
1574            obj.len(),
1575            1,
1576            "plain column should only have `type`: {obj:?}"
1577        );
1578        assert_eq!(schema["type"], "string");
1579    }
1580
1581    /// Playground-openapi-gaps item 5: `#[umbral(help = "...")]`
1582    /// emits as the standard OpenAPI `description` so Swagger UI
1583    /// and any generated client picks it up. Empty help leaves the
1584    /// key absent.
1585    #[test]
1586    fn help_attribute_flows_to_openapi_description() {
1587        let mut col = base_col("status", SqlType::Text);
1588        col.help = "Workflow step. Set by editors on Save.".to_string();
1589        let schema = column_schema(&col);
1590        assert_eq!(
1591            schema["description"], "Workflow step. Set by editors on Save.",
1592            "help should round-trip to OpenAPI description; got: {schema:?}",
1593        );
1594    }
1595
1596    #[test]
1597    fn empty_help_omits_description() {
1598        let col = base_col("body", SqlType::Text);
1599        let schema = column_schema(&col);
1600        assert!(
1601            schema.get("description").is_none(),
1602            "empty help should omit description; got: {schema:?}",
1603        );
1604    }
1605
1606    /// Playground-openapi-gaps item 6: `#[umbral(example = "...")]`
1607    /// emits as OpenAPI `example` on the property schema. Empty
1608    /// leaves the key absent.
1609    #[test]
1610    fn example_attribute_flows_to_openapi_example() {
1611        let mut col = base_col("status", SqlType::Text);
1612        col.example = "published".to_string();
1613        let schema = column_schema(&col);
1614        assert_eq!(
1615            schema["example"], "published",
1616            "example should round-trip; got: {schema:?}",
1617        );
1618    }
1619
1620    #[test]
1621    fn empty_example_omits_example() {
1622        let col = base_col("body", SqlType::Text);
1623        let schema = column_schema(&col);
1624        assert!(
1625            schema.get("example").is_none(),
1626            "empty example should omit example key; got: {schema:?}",
1627        );
1628    }
1629
1630    // ----------------------------------------------------------------- //
1631    // Filter parameter emission                                          //
1632    // ----------------------------------------------------------------- //
1633
1634    fn note_model() -> ModelMeta {
1635        let mut id = base_col("id", SqlType::BigInt);
1636        id.primary_key = true;
1637        let mut published_at = base_col("published_at", SqlType::Timestamptz);
1638        published_at.nullable = true;
1639        ModelMeta {
1640            view: None,
1641            materialized: false,
1642            name: "Note".to_string(),
1643            table: "note".to_string(),
1644            fields: vec![
1645                id,
1646                base_col("title", SqlType::Text),
1647                base_col("views", SqlType::Integer),
1648                published_at,
1649            ],
1650            display: "Note".to_string(),
1651            icon: "database".to_string(),
1652            database: None,
1653            singleton: false,
1654            unique_together: Vec::new(),
1655            indexes: Vec::new(),
1656            ordering: Vec::new(),
1657            m2m_relations: Vec::new(),
1658            soft_delete: false,
1659            audited: false,
1660            app_label: "app".to_string(),
1661        }
1662    }
1663
1664    #[test]
1665    fn filter_parameters_skips_primary_key() {
1666        let params = filter_parameters(&note_model());
1667        let names: Vec<&str> = params.iter().map(|p| p["name"].as_str().unwrap()).collect();
1668        assert!(
1669            !names.iter().any(|n| *n == "id" || n.starts_with("id__")),
1670            "PK column should be skipped; got {names:?}",
1671        );
1672    }
1673
1674    #[test]
1675    fn filter_parameters_eq_uses_bare_column_name_no_suffix() {
1676        let params = filter_parameters(&note_model());
1677        let bare_title = params
1678            .iter()
1679            .find(|p| p["name"] == "title")
1680            .expect("title eq parameter should be present");
1681        assert_eq!(bare_title["x-umbral-filter-lookup"], "eq");
1682        assert_eq!(bare_title["x-umbral-filter-field"], "title");
1683        assert_eq!(bare_title["schema"]["type"], "string");
1684    }
1685
1686    #[test]
1687    fn filter_parameters_in_is_string_typed_with_csv_description() {
1688        let params = filter_parameters(&note_model());
1689        let title_in = params
1690            .iter()
1691            .find(|p| p["name"] == "title__in")
1692            .expect("title__in parameter should be present");
1693        assert_eq!(title_in["schema"]["type"], "string");
1694        assert!(
1695            title_in["description"]
1696                .as_str()
1697                .unwrap()
1698                .to_lowercase()
1699                .contains("comma"),
1700            "__in description should mention the comma-separated format",
1701        );
1702    }
1703
1704    #[test]
1705    fn filter_parameters_isnull_only_on_nullable_columns() {
1706        let params = filter_parameters(&note_model());
1707        let isnull_params: Vec<&str> = params
1708            .iter()
1709            .filter_map(|p| p["name"].as_str())
1710            .filter(|n| n.ends_with("__isnull"))
1711            .collect();
1712        assert_eq!(
1713            isnull_params,
1714            vec!["published_at__isnull"],
1715            "isnull lookup should only appear for nullable columns; got {isnull_params:?}",
1716        );
1717    }
1718
1719    #[test]
1720    fn filter_parameters_range_lookups_only_on_numeric_or_temporal() {
1721        let params = filter_parameters(&note_model());
1722        let has_gte = |field: &str| params.iter().any(|p| p["name"] == format!("{field}__gte"));
1723        assert!(has_gte("views"), "integer column gets gte");
1724        assert!(has_gte("published_at"), "timestamp column gets gte");
1725        assert!(
1726            !has_gte("title"),
1727            "text column must NOT get gte; got {params:?}",
1728        );
1729    }
1730
1731    #[test]
1732    fn filter_parameters_string_lookups_only_on_text() {
1733        let params = filter_parameters(&note_model());
1734        let has_contains = |field: &str| {
1735            params
1736                .iter()
1737                .any(|p| p["name"] == format!("{field}__contains"))
1738        };
1739        assert!(has_contains("title"), "text column gets contains");
1740        assert!(
1741            !has_contains("views"),
1742            "integer column must NOT get contains; got {params:?}",
1743        );
1744    }
1745
1746    #[test]
1747    fn collection_paths_omits_parameters_array_when_no_filters() {
1748        let value = collection_paths("note", "Note", &[]);
1749        let get_op = &value["get"];
1750        assert!(
1751            get_op.get("parameters").is_none(),
1752            "no filters → no parameters key; got {get_op:?}",
1753        );
1754    }
1755
1756    #[test]
1757    fn collection_paths_includes_parameters_when_filters_present() {
1758        let filter_params = filter_parameters(&note_model());
1759        let value = collection_paths("note", "Note", &filter_params);
1760        let params = value["get"]["parameters"]
1761            .as_array()
1762            .expect("parameters array should be present when filters land");
1763        assert!(!params.is_empty());
1764        assert!(
1765            params.iter().all(|p| p["in"] == "query"),
1766            "every filter parameter is in: query",
1767        );
1768    }
1769
1770    /// BUG-81: the `?fields=` sparse-fieldset parameter is built
1771    /// with the model's columns listed under the
1772    /// `x-umbral-fields-columns` vendor extension so the playground
1773    /// can render a multi-select.
1774    #[test]
1775    fn fields_parameter_lists_model_columns() {
1776        let param = fields_parameter(&note_model());
1777        assert_eq!(param["name"], "fields");
1778        assert_eq!(param["in"], "query");
1779        assert_eq!(param["x-umbral-fields"], true);
1780        let cols = param["x-umbral-fields-columns"]
1781            .as_array()
1782            .expect("x-umbral-fields-columns should be a list");
1783        let names: Vec<&str> = cols.iter().filter_map(|v| v.as_str()).collect();
1784        assert!(names.contains(&"title"));
1785        assert!(names.contains(&"views"));
1786        assert!(
1787            !names.is_empty(),
1788            "every column should land in the enum so the playground can offer it",
1789        );
1790    }
1791
1792    /// The retrieve op also documents `?fields=` so the playground
1793    /// renders the same param on GET /resource/{id}.
1794    #[test]
1795    fn item_paths_advertises_fields_query_param_on_retrieve() {
1796        let value = item_paths("note", "Note", &[fields_parameter(&note_model())]);
1797        let get_params = value["get"]["parameters"]
1798            .as_array()
1799            .expect("retrieve op should carry its query parameters");
1800        assert!(
1801            get_params.iter().any(|p| p["name"] == "fields"),
1802            "fields parameter should be on the retrieve op; got {get_params:?}",
1803        );
1804    }
1805
1806    /// Playground-openapi-gaps #2: FK columns gain an
1807    /// `x-umbral-fk-ref` JSON pointer when the target schema is
1808    /// known. Generated clients that follow vendor extensions can
1809    /// navigate Post.author → User.
1810    #[test]
1811    fn fk_column_emits_schema_ref_when_target_known() {
1812        let mut col = base_col("author", SqlType::ForeignKey);
1813        col.fk_target = Some("auth_user".into());
1814        let mut map = std::collections::HashMap::new();
1815        map.insert("auth_user".to_string(), "AuthUser".to_string());
1816        let schema = column_schema_with_refs(&col, &map);
1817        assert_eq!(
1818            schema["x-umbral-fk-target"], "auth_user",
1819            "the table-name vendor extension stays for backward compat",
1820        );
1821        assert_eq!(
1822            schema["x-umbral-fk-ref"], "#/components/schemas/AuthUser",
1823            "the JSON pointer to the target schema should be emitted",
1824        );
1825    }
1826
1827    #[test]
1828    fn fk_column_without_known_target_omits_schema_ref() {
1829        let mut col = base_col("author", SqlType::ForeignKey);
1830        col.fk_target = Some("unknown_table".into());
1831        let map = std::collections::HashMap::new();
1832        let schema = column_schema_with_refs(&col, &map);
1833        assert!(
1834            schema.get("x-umbral-fk-ref").is_none(),
1835            "unknown FK target → no ref emitted; got: {schema:?}",
1836        );
1837    }
1838
1839    /// M2M relations get a property entry on the model schema
1840    /// (`array of integer` ids) plus vendor extensions naming the
1841    /// target schema. Without this the playground / generated
1842    /// clients have no way to know the model has a many-to-many
1843    /// slot.
1844    #[test]
1845    fn m2m_relation_lands_in_model_schema_with_target_extension() {
1846        let mut model = note_model();
1847        model.m2m_relations.push(umbral::migrate::M2MRelation {
1848            field_name: "tags".to_string(),
1849            target_table: "tag".to_string(),
1850            target_name: "Tag".to_string(),
1851        });
1852        // table_to_schema mirrors what `model_schemas` builds at
1853        // spec-emit time; pre-seed with the M2M target so the
1854        // vendor `x-umbral-m2m-target-ref` JSON pointer is set.
1855        let mut tts = std::collections::HashMap::new();
1856        tts.insert("tag".to_string(), "Tag".to_string());
1857        let schema = model_schema(&model, &tts);
1858        let tags_prop = &schema["properties"]["tags"];
1859        assert_eq!(tags_prop["type"], "array");
1860        assert_eq!(tags_prop["items"]["type"], "integer");
1861        assert_eq!(tags_prop["x-umbral-m2m"], true);
1862        assert_eq!(tags_prop["x-umbral-m2m-target"], "Tag");
1863        assert_eq!(tags_prop["x-umbral-m2m-target-table"], "tag");
1864        assert_eq!(
1865            tags_prop["x-umbral-m2m-target-ref"],
1866            "#/components/schemas/Tag",
1867        );
1868        // Not in `required` — M2M slots are always optional.
1869        let required = schema["required"].as_array();
1870        if let Some(req) = required {
1871            assert!(!req.iter().any(|v| v == "tags"));
1872        }
1873    }
1874
1875    /// `auto_now_add` (created_at) and `auto_now` (updated_at)
1876    /// fields are server-populated — the framework stamps
1877    /// `Utc::now()` when the body omits them. The OpenAPI
1878    /// schema must reflect that: the columns drop out of the
1879    /// `required` array AND gain vendor extensions so the
1880    /// playground can render them as "server fills this in"
1881    /// instead of marking them as missing inputs.
1882    #[test]
1883    fn auto_now_columns_are_optional_in_the_request_schema() {
1884        let mut model = note_model();
1885        let mut created = base_col("created_at", SqlType::Timestamptz);
1886        created.auto_now_add = true;
1887        let mut updated = base_col("updated_at", SqlType::Timestamptz);
1888        updated.auto_now = true;
1889        model.fields.push(created);
1890        model.fields.push(updated);
1891
1892        let schema = model_schema(&model, &std::collections::HashMap::new());
1893
1894        // Vendor extensions: aware clients flag these as
1895        // server-populated. Both extensions present, keyed
1896        // under the right column.
1897        assert_eq!(
1898            schema["properties"]["created_at"]["x-umbral-auto-now-add"],
1899            true
1900        );
1901        assert_eq!(
1902            schema["properties"]["updated_at"]["x-umbral-auto-now"],
1903            true
1904        );
1905
1906        // NOT marked `readOnly` — the client can still send an
1907        // explicit timestamp if they want. `readOnly` is reserved
1908        // for `noform` columns the framework drops from bodies.
1909        assert!(
1910            schema["properties"]["created_at"].get("readOnly").is_none(),
1911            "auto_now_add must not be readOnly; got {}",
1912            schema["properties"]["created_at"],
1913        );
1914        assert!(
1915            schema["properties"]["updated_at"].get("readOnly").is_none(),
1916            "auto_now must not be readOnly; got {}",
1917            schema["properties"]["updated_at"],
1918        );
1919
1920        // And dropped from `required` so a POST that omits them
1921        // doesn't 400 with "this field is required."
1922        let required = schema["required"].as_array().expect("required array");
1923        let names: Vec<&str> = required.iter().filter_map(|v| v.as_str()).collect();
1924        assert!(
1925            !names.contains(&"created_at"),
1926            "auto_now_add should drop out of required; got {names:?}",
1927        );
1928        assert!(
1929            !names.contains(&"updated_at"),
1930            "auto_now should drop out of required; got {names:?}",
1931        );
1932    }
1933
1934    /// gaps2 #79: pagination_parameters_for_style emits the correct
1935    /// params per pagination class, not always `page`/`page_size`.
1936    #[test]
1937    fn pagination_parameters_per_style() {
1938        use umbral_rest::PaginationStyle;
1939
1940        // NoPagination → no params.
1941        let none_params = pagination_parameters_for_style(PaginationStyle::None);
1942        assert!(
1943            none_params.is_empty(),
1944            "NoPagination should emit no pagination params; got {none_params:?}"
1945        );
1946
1947        // Custom → no params (opaque).
1948        let custom_params = pagination_parameters_for_style(PaginationStyle::Custom);
1949        assert!(
1950            custom_params.is_empty(),
1951            "Custom pagination should emit no params; got {custom_params:?}"
1952        );
1953
1954        // PageNumber → page + page_size.
1955        let page_params = pagination_parameters_for_style(PaginationStyle::PageNumber);
1956        assert_eq!(page_params.len(), 2, "PageNumber should emit 2 params");
1957        assert_eq!(page_params[0]["name"], "page");
1958        assert_eq!(page_params[0]["in"], "query");
1959        assert_eq!(page_params[0]["schema"]["type"], "integer");
1960        assert_eq!(page_params[0]["schema"]["minimum"], 1);
1961        assert_eq!(page_params[0]["schema"]["default"], 1);
1962        assert_eq!(page_params[0]["x-umbral-pagination"], "page");
1963        assert_eq!(page_params[1]["name"], "page_size");
1964        assert_eq!(page_params[1]["schema"]["maximum"], 100);
1965        assert_eq!(page_params[1]["x-umbral-pagination"], "page_size");
1966
1967        // LimitOffset → limit + offset.
1968        let lo_params = pagination_parameters_for_style(PaginationStyle::LimitOffset);
1969        assert_eq!(lo_params.len(), 2, "LimitOffset should emit 2 params");
1970        assert_eq!(lo_params[0]["name"], "limit");
1971        assert_eq!(lo_params[0]["x-umbral-pagination"], "limit");
1972        assert_eq!(lo_params[1]["name"], "offset");
1973        assert_eq!(lo_params[1]["x-umbral-pagination"], "offset");
1974        assert_eq!(lo_params[1]["schema"]["minimum"], 0);
1975    }
1976}