Skip to content

Fix hosted API dependency discovery for virtual projects - #3120

Merged
kwakayama merged 2 commits into
mainfrom
fix/api-route-npm-deps
Jul 27, 2026
Merged

kwakayama merged 2 commits into
mainfrom
fix/api-route-npm-deps

Conversation

@kojiwakayama

Copy link
Copy Markdown
Contributor

Summary

  • read API route project dependencies through the runtime adapter so hosted/preview virtual projects can discover their package.json dependencies
  • keep temp handler filesystem behavior on the host filesystem
  • add a regression test for a virtual adapter-backed API route importing zod through a project alias
  • bump deno.json and the shared version constant to 0.1.1156 for the next release

Root cause

Hosted API routes loaded source files through RuntimeAdapter.fs, but dependency discovery still read package.json through the host filesystem. For virtual project directories, package.json was invisible there, so userDeps was empty. The loader externalized zod without adding it to the import map, and Deno failed while loading the generated handler.mjs with Import "zod" not a dependency and not in import map.

Testing

  • deno test -A src/routing/api/module-loader/loader.test.ts
  • deno task fmt:check
  • deno task lint
  • deno task typecheck
  • deno test -A src/utils/version.test.ts src/utils/logger/logger.test.ts
  • deno task test:unit (2687 passed, 0 failed)
  • pre-push hook (fmt, lint, typecheck, unit tests: 2687 passed, 0 failed)

Hosted API routes load source files through the runtime adapter, but dependency discovery still read package.json from the host filesystem. Remote and preview-backed projects therefore produced an empty user dependency set, leaving externalized imports such as zod bare in the temporary handler module.

Constraint: Hosted project sources and package metadata may be adapter-backed while temporary handler files still need host filesystem writes.

Rejected: Bundle user dependencies into API handlers | this bypasses the existing external-dependency policy and does not fix other declared npm dependencies.

Confidence: high

Scope-risk: narrow

Directive: Keep source project reads on RuntimeAdapter.fs when projectDir may be virtual; host fs should be reserved for local temp artifacts.

Tested: deno test -A src/routing/api/module-loader/loader.test.ts

Tested: deno task fmt:check

Tested: deno task lint

Tested: deno task typecheck

Tested: deno test -A src/utils/version.test.ts src/utils/logger/logger.test.ts

Tested: deno task test:unit (2687 passed, 0 failed)
@kojiwakayama
kojiwakayama requested a review from kwakayama as a code owner July 26, 2026 18:12
Copilot AI review requested due to automatic review settings July 26, 2026 18:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes npm dependency discovery for API route modules when the project source is provided by a runtime adapter (for hosted/preview “virtual” projects), ensuring package.json dependencies are visible during bundling and import rewriting.

Changes:

  • Route dependency discovery now reads package.json via the runtime adapter filesystem instead of only the host filesystem.
  • Adds a regression test covering a virtual adapter-backed API route that imports zod via a project alias.
  • Bumps the release version to 0.1.1156 in deno.json and the shared version constant.

Verification (reported by author):

  • deno test -A src/routing/api/module-loader/loader.test.ts
  • deno task fmt:check
  • deno task lint
  • deno task typecheck
  • deno test -A src/utils/version.test.ts src/utils/logger/logger.test.ts
  • deno task test:unit (2687 passed, 0 failed)
  • Pre-push hook (fmt, lint, typecheck, unit tests)

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
src/utils/version-constant.ts Updates shared version constant to 0.1.1156.
src/routing/api/module-loader/loader.ts Reads project dependency metadata through the runtime adapter for virtual projects.
src/routing/api/module-loader/loader.test.ts Adds regression coverage for adapter-backed dependency discovery (zod via alias).
deno.json Bumps package version to 0.1.1156.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/routing/api/module-loader/loader.ts Outdated
Dependency discovery consumes only readTextFile, so its contract now reflects that capability and hosted loading passes an explicit adapter-backed reader. This avoids spreading class-backed host filesystems while preserving host ownership of temporary handler artifacts.

Constraint: Hosted project metadata may exist only behind RuntimeAdapter.fs.

Rejected: Delegate every FileSystem method through a wrapper | dependency discovery does not need the wider contract.

Confidence: high

Scope-risk: narrow

Directive: Keep project-source reads on the runtime adapter and temp-artifact operations on the host filesystem.

Tested: deno fmt --check on changed files; deno test -A src/routing/api/module-loader/loader.test.ts; deno task typecheck
Copilot AI review requested due to automatic review settings July 27, 2026 05:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 1 comment.

Comment thread src/routing/api/module-loader/loader.test.ts
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

Reviewed commit: a5948bcadd

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

@kwakayama
kwakayama added this pull request to the merge queue Jul 27, 2026
Merged via the queue into main with commit 0618803 Jul 27, 2026
31 checks passed
@kwakayama
kwakayama deleted the fix/api-route-npm-deps branch July 27, 2026 10:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants