Repository navigation
Fix hosted API dependency discovery for virtual projects - #3120
Conversation
Hosted API routes load source files through the runtime adapter, but dependency discovery still read package.json from the host filesystem. Remote and preview-backed projects therefore produced an empty user dependency set, leaving externalized imports such as zod bare in the temporary handler module. Constraint: Hosted project sources and package metadata may be adapter-backed while temporary handler files still need host filesystem writes. Rejected: Bundle user dependencies into API handlers | this bypasses the existing external-dependency policy and does not fix other declared npm dependencies. Confidence: high Scope-risk: narrow Directive: Keep source project reads on RuntimeAdapter.fs when projectDir may be virtual; host fs should be reserved for local temp artifacts. Tested: deno test -A src/routing/api/module-loader/loader.test.ts Tested: deno task fmt:check Tested: deno task lint Tested: deno task typecheck Tested: deno test -A src/utils/version.test.ts src/utils/logger/logger.test.ts Tested: deno task test:unit (2687 passed, 0 failed)
There was a problem hiding this comment.
Pull request overview
This PR fixes npm dependency discovery for API route modules when the project source is provided by a runtime adapter (for hosted/preview “virtual” projects), ensuring package.json dependencies are visible during bundling and import rewriting.
Changes:
- Route dependency discovery now reads
package.jsonvia the runtime adapter filesystem instead of only the host filesystem. - Adds a regression test covering a virtual adapter-backed API route that imports
zodvia a project alias. - Bumps the release version to
0.1.1156indeno.jsonand the shared version constant.
Verification (reported by author):
deno test -A src/routing/api/module-loader/loader.test.tsdeno task fmt:checkdeno task lintdeno task typecheckdeno test -A src/utils/version.test.ts src/utils/logger/logger.test.tsdeno task test:unit(2687 passed, 0 failed)- Pre-push hook (fmt, lint, typecheck, unit tests)
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| src/utils/version-constant.ts | Updates shared version constant to 0.1.1156. |
| src/routing/api/module-loader/loader.ts | Reads project dependency metadata through the runtime adapter for virtual projects. |
| src/routing/api/module-loader/loader.test.ts | Adds regression coverage for adapter-backed dependency discovery (zod via alias). |
| deno.json | Bumps package version to 0.1.1156. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Dependency discovery consumes only readTextFile, so its contract now reflects that capability and hosted loading passes an explicit adapter-backed reader. This avoids spreading class-backed host filesystems while preserving host ownership of temporary handler artifacts. Constraint: Hosted project metadata may exist only behind RuntimeAdapter.fs. Rejected: Delegate every FileSystem method through a wrapper | dependency discovery does not need the wider contract. Confidence: high Scope-risk: narrow Directive: Keep project-source reads on the runtime adapter and temp-artifact operations on the host filesystem. Tested: deno fmt --check on changed files; deno test -A src/routing/api/module-loader/loader.test.ts; deno task typecheck
|
@codex review |
|
Codex Review: Didn't find any major issues. What shall we delve into next? Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
Summary
Root cause
Hosted API routes loaded source files through RuntimeAdapter.fs, but dependency discovery still read package.json through the host filesystem. For virtual project directories, package.json was invisible there, so userDeps was empty. The loader externalized zod without adding it to the import map, and Deno failed while loading the generated handler.mjs with
Import "zod" not a dependency and not in import map.Testing