Skip to content

N8: openApiTools(document, options): an OpenAPI document becomes tools - #283

Merged
LinuxDevil merged 4 commits into
mainfrom
lou-n8-openapi-tools
Oct 2, 2026
Merged

LinuxDevil merged 4 commits into
mainfrom
lou-n8-openapi-tools

Conversation

@LinuxDevil

Copy link
Copy Markdown
Owner

N8: openApiTools(document, options)

An OpenAPI 3.0 / 3.1 document (object, JSON or YAML string, https URL) becomes one typed tool per operation. GET, HEAD and OPTIONS run; other methods ask for approval by default. See the new page docs/openapi-tools.md.

  • src/tools/openapi/ (openApiTools.ts, operations.ts), exported from src/tools/index.ts (root and ./tools); no new subpath, no new dependency.
  • jsonSchemaToZod(schema, root?) takes an optional root for $ref resolution; existing call sites unchanged.
  • Security: https base URL (http only for loopback), no credentials in URLs, headers and tokens never in the schema, events or transcript, manual redirects limited to the base origin (3 hops), path values encoded (. / .. refused, because URL parsing resolves even %2E%2E).
  • Not done on purpose: the shared pinned-DNS / SSRF helper from N13a had not merged when this was made (origin/main has no such helper), so requests use plain fetch against the developer-configured base URL, as the ticket says. The docs say so under "Security rules". A follow-up can route requests through the helper once it exists.

For the docs site (G9): new page openapi-tools; edited pages tools (one table row, no heading change); README docs table has one new row.

Verification (on the branch after merging latest origin/main)

  • npx tsc --noEmit, npm run lint (zero warnings), npm run build, npm run build --workspace=packages/create-lousho-agent, npm run test:types: pass
  • npm run docs:verify-snippets -- --skip-build: 203 snippets type-check, 8 run
  • npm run docs:llms:check: pass (regenerated)
  • npm run test:coverage: 216 files, 3020 passed, 2 skipped. (Earlier runs had the known flakes: cloudflare / guardrails timeouts, a Docker-daemon sandbox test, http.test.ts self-signed TLS; they passed on re-run, src/deploy passes alone.)
  • npm run fallow: exit 0 (0 above threshold). My first version exceeded complexity limits and was split.
  • Agent Forge: typecheck, typecheck:server, test (122 passed), test:server: pass
  • npm run pack-smoke: all checks passed

Live test spend: none (no model calls).

Closes #220

🤖 Generated with Claude Code

LinuxDevil and others added 4 commits October 2, 2026 14:50
@LinuxDevil
LinuxDevil merged commit c3de073 into main Oct 2, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[N8] openApiTools(document, { include, approval }): an OpenAPI document becomes tools

1 participant