Skip to content

feat(api): POST /api/packages/upload (REST upload path) - #24

Merged
criptogus merged 1 commit into
mainfrom
claude/fix-mcp-oauth-callback-brZDc
May 23, 2026
Merged

criptogus merged 1 commit into
mainfrom
claude/fix-mcp-oauth-callback-brZDc

Conversation

@criptogus

Copy link
Copy Markdown
Owner

Summary

  • /account/tokens advertises a curl + JS snippet against POST /api/packages/upload, but the route didn't exist — the SPA caught it and returned HTML. CI / curl users had no working write path.
  • Adds the route with Authorization: Bearer … auth (accepts both sas_… PATs and OAuth access tokens) on top of the existing processBulkUpload pipeline, so REST and MCP share the same logic, queue, and private-draft semantics.
  • publish: true in the body is accepted for forward-compat but ignored — marketplace listing still requires the explicit submit flow in /account/packages followed by admin review.
  • Extracts verifyBearer + extractBearer into src/lib/auth/bearer.server.ts so /api/mcp and /api/packages/upload validate identically. mcp.ts now imports from the shared util.

Test plan

  • curl -i -X POST $HOST/api/packages/upload -H "Authorization: Bearer $SAS_TOKEN" -H "Content-Type: application/json" -d '{"files":[{"name":"x.md","content":"# hi"}]}' returns 200 with visibility:"private_draft" and a package_id.
  • Same call with no Authorization returns 401 JSON (no SPA HTML).
  • Same call with a revoked/bad token returns 401.
  • More than 1 file → first inline, rest reported under queued.
  • publish:true in the body still results in a private draft (and surfaces publish_ignored hint).
  • MCP upload_packages still works (regression — same verifyBearer now imported, not duplicated).

https://claude.ai/code/session_019gMoupKKTVydpNwiiACQRd


Generated by Claude Code

…packages)

The /account/tokens page advertises a curl/fetch snippet against
POST /api/packages/upload, but the route did not exist — the SPA caught
the unmatched path and returned HTML, leaving curl/CI users without a
working write path.

Adds the route with Bearer auth (sas_… PAT or OAuth access token) that
reuses processBulkUpload, so REST and MCP share the same pipeline,
queue, and private-draft semantics. `publish:true` is accepted in the
body for forward compatibility but ignored — marketplace listing still
requires the /account/packages submit flow + admin review.

Also extracts verifyBearer/extractBearer into src/lib/auth/bearer.server.ts
so /api/mcp and /api/packages/upload validate tokens identically.

https://claude.ai/code/session_019gMoupKKTVydpNwiiACQRd
@criptogus
criptogus marked this pull request as ready for review May 23, 2026 03:35
@criptogus
criptogus merged commit 3bfc186 into main May 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants