Skip to content

docs: regenerate rules from documentation@5cda815 - #77

Open
harper-skills-sync[bot] wants to merge 1 commit into
mainfrom
auto/docs-sync
Open

docs: regenerate rules from documentation@5cda815#77
harper-skills-sync[bot] wants to merge 1 commit into
mainfrom
auto/docs-sync

Conversation

@harper-skills-sync

@harper-skills-sync harper-skills-sync Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Automated regeneration of docs-driven skill rules, now synced to HarperFast/documentation@5cda815.

Why these rules changed

Each rule regenerated because its source content differs from the docs commit it was last synced from. The trigger commit is not necessarily what changed a given rule — drift accumulates across every docs commit since the rule’s recorded baseline (below).

  • schema-design-tooling — last synced from docs@3749d0c
  • automatic-apis — last synced from docs@3749d0c
  • querying-rest-apis — last synced from docs@3749d0c
  • checking-authentication — last synced from docs@b7fbdda
  • programmatic-table-requests — last synced from docs@3749d0c
  • deploying-to-harper-fabric — last synced from docs@6bf676d
  • enabling-mcp — last synced from docs@d7d2ddb
  • custom-mcp-tools — last synced from docs@d7d2ddb

Docs commits since baseline (d7d2ddb..5cda815)

5cda8154	docs(rest): map exported tables to their automatic REST endpoints (#650)
98872e4e	docs: link static plugin implementation as plugin API example (#642)
eb49a16c	docs(http): remove unimplemented deserializeStream handler property (#641)
0841ba68	docs(cli): document the `harper deploy` command (#624)
090ff882	docs(resources): scope static properties schema docs to shipped behavior (#605)
3603b4d8	docs(mcp): custom mcpResources and the harper+rest:// descriptor scheme (#567)
39526f8b	chore: add missing final newlines to config files (#652)
4a7cf94f	ci: deploy on reference/** and historic-redirects.ts changes (#651)
ef9921b6	docs: fix broken anchors and stale HarperDB org URLs (#649)
f0c92c59	docs(components): align package scopes with published npm names (#645)
be934414	docs(cli): object and array-of-object params do work via CLI (#646)
55228e71	style(version-badge): right-align standalone badges onto the heading line (#653)
966c5b88	chore: make Renovate group, automerge, and refresh dependencies (#648)
ca6143ef	Document record-structure dictionary counts and the encoding they measure (#633)
0734027c	Document the built-in agent operations API (#635)
28b62396	Add companion-check workflow: docs PRs auto-merge once their companion code PR lands (#629)
51e315e8	docs: document static loadAsInstance in the v5 Resource API reference (#619)
cd6e102e	docs: replicating the system database with a constrained topology (5.2) (#583)
71bb19e0	docs(analytics): document transaction-commit-time metric (#572)
efa22403	docs: replication.blobGapReconnectMs and bulk-copy cursor flush options (#628)
a455bd46	Document scoped tokens (inline role) for create_authentication_tokens (#627)
fd94430a	docs(storage): document storage.blobRetention (#622)
87f1d209	Document cacheControl directive, identity-floor caching headers, and static plugin cache options (#578)
e52bed3f	docs(security): response-header hardening (app-level controls + #1567 gap) (#560)
c1885b71	docs: clarify that @hidden, @export are not access controls + allowRead trusted-context / filter caveats (#553)
1fd0faa9	docs(agents): verify the tag object before trusting --contains
2dadb894	docs(security): qualify the uniform-rejection claim
9c8a89fa	docs(security): aim the OIDC section at the happy path, add a CLI walkthrough
399338c1	docs: copy edits from review
8a4762f3	docs: OIDC trusted publishing, ops-table anchors, and badge guidance
6bf676d4	docs(deploy): complete the super_user call list for deploy setup
d1f34583	docs: drop a duplicated header and clarify "before it ships"
47d872ad	docs(security): add_ssh_key server-side keygen (v5.2.4)
a74ae3b6	docs(deploy): by-reference deploys and sealed credentials (v5.2.3)
aa74b1cc	Badge node identity change for v5.3.0 and add 5.3 release notes
cca76303	Correct node.hostname docs to match merged rejection behavior
0ca3fbfb	Drop in-doc harper issue/PR links per review
97b3b05f	Document node.hostname config and require a bare hostname
97284557	docs(cli): local authorization applies only when no credential is attached
7b99e1b8	docs(security): give authorizeLocal the facts the CLI page defers to it
05412a63	docs(cli): scope the loopback remediation to a pointer, keep the hazard
964fd165	docs(cli): the socket rule is also the limit of the loopback remediation
9f3b6b03	docs(cli): only authorizeLocal:false closes the loopback exposure, and it needs a restart
c5255853	docs(cli): the loopback case needs configuration, not a result check
4a4b855b	docs(cli): resolve the contradiction the loopback bullet created
c8acc796	docs(cli): loopback targets make a token failure succeed, not fail
e70060ff	docs(cli): point the 403 warning at its tracking issue
a9ecc7eb	docs(cli): state the one-credential-style rule once, up front
43bbafcf	docs(cli): a lost target falls back to the saved login, not straight to local
64a51e58	docs(cli): expiry answers 403 and does not halt the command
86ea5c5e	docs(release-notes): scope the refresh-failure caveat to the CI credential shape
3388ec11	docs(cli): split refresh-failure behavior by credential shape
e6c37f0e	docs(cli): narrow two token-handling claims to what 5.2.4 actually does
030c46ef	docs(cli): a blank token namespace is skipped, not a hard failure
7a9187d8	docs(release-notes): cover CI token credentials in 5.2
7cfed5a8	docs(cli): slot token credentials into the canonical auth precedence
c6838cf2	Document the child_process spawn contract for components (#634)
544f15d1	Separate queue depth coverage and attribution limits
56a9d4e1	Document mixed-engine queue depth undercounting
5ca5352d	Identify the stuck commit log signal
633c0dbd	Clarify raw queue depth alert path
098e548b	Clarify transaction queue depth metric semantics
e70894de	fix(docs): sync maxTransactionQueueTime bypass note and remove stale duplicate wording
dabdad00	fix(analytics): transaction-commit-time is silent on a true wedge, not rising
e0d58b4d	fix(analytics): document transaction-commit-time as the 503 leading indicator
9607b80d	fix(analytics): correct aggregation semantics and doc conventions
1c415a61	fix(analytics): correct transaction queue depth documentation
ab213e59	fix(analytics): satisfy prettier table formatting
ef7d4427	docs(analytics): document transaction queue depth metrics
df4971bc	Fix conflicting storage model in logging.auditLog description
a7ad4a01	Address Codex review: fix LMDB result fields, cross-page log terminology, config default
98b1a99e	Collapse audit-log/transaction-log distinction; fix conflicting messaging
1e9a4d50	Split the scoping notes into bold-led sub-paragraphs
bb794065	Add tool-calling scoping note to the CI-stub section
ebb9e70e	Document operation authorization and explicit row filters (#593)
5cc6c517	Address review round 2: LMDB example gap, WAL clustering row, data-safety admonition, params/results, get_job error example, 5.2 release note
ffe30c44	Address review: job semantics, storage-model consistency, badge placement, type style
f3d66404	Clarify engine scope of the 404 change and document cleanup_deleted_records
22004028	Add Transaction Log Operations section header
71bd2636	Document database-wide-only transaction log deletion on RocksDB
7ddbe0e8	docs(backups): use plain ASCII in blob path notation and shell comments
e93a18d5	docs(http): address review feedback on connectionInfo docs
92719679	docs(http): document request.connectionInfo (forwarded PROXY v2 TLS facts)
f6924587	docs: fastifyRoutes host mount fails to load, not just a warning
f013ba24	docs: note that deploy_component mount options require package
b36d21e7	docs: note what an application mount does not do
d623f458	docs: route applications by host/urlPath in the root config
b2d60531	docs(backups): align with harper#1831 (blobs, verify scope, restore semantics)
a3521397	docs: clarify env var context in CLI auth precedence list
d3631f0a	Document CLI authentication precedence
de314d59	Add missing transaction import to migration example (#606)
a5be7383	chore: migrate to @harperfast/code-guidelines (#615)
8ee6cda7	docs: add Web Application Firewall reference (#603)
a19158fc	docs(schema): correct from+to relationship cardinality to many-to-one (#602)
94a3d5af	docs(backups): clarify engine-specific backup paths and reorder ops
c75d5891	ci: re-enable the pr-preview paths filter (#611)
47b82ca9	feat(ci): deploy docs site to production Harper fabric on main (#610)
024870f6	ci: pin deploy/validate workflow actions to commit SHAs at latest releases (#608)
9a7ae7fc	fix(ci): use admin-scoped token to delete PR preview environments (#607)
dd5fa32b	fix(mcp): correct the exportTypes MCP-gating example (#601)
fcf2c7a5	Document get_deployment_payload / delete_deployment_payload response contracts (#600)
69343c0e	docs(tls): document multi-source cipher/SECLEVEL resolution per listener (#598)
6dff1546	docs(sql): 5.2 SQL engine performance guidance (#588)
aaa7af1b	Document the built-in scheduler component plugin (5.2) (#592)
7eae83cc	docs(models): local-development setup matching production (#597)
03000d39	docs: document middleware host and path routing (#595)
d8d7ba4d	docs(learn): deploying from a CI/CD pipeline into Harper — best practices for private repos and registries (#594)
f0d69516	docs: note cross-database read consistency for sourcedFrom resolvers (#591)
8aba3c31	Document the @expiresAt schema directive (#585)
37dd3476	docs(security): secrets store, secrets operations, and deploy_component registryAuth (#581)
c7e80a74	docs(rest): clarify PATCH is a shallow top-level merge (nested objects replaced, not deep-merged) (#547)
752cdef8	Restructure backup docs into a dedicated Backups reference section
561160bc	Use snake_case response fields for backup operations (backup_id, file_count)
f7211a60	Address docs review: keep_count wording, target_database CLI example
ff392e0d	Document RocksDB backup & restore operations

Produced by .github/workflows/generate.yaml. Review the diff as you would any rule change — the generator reads the docs build output and rewrites mode: generate / imports mode: direct rule bodies, then reassembles AGENTS.md. See docs/plans/docs-driven-skills.md.

🤖 Generated with Claude Code

@harper-skills-sync
harper-skills-sync Bot requested a review from a team as a code owner August 26, 2026 22:27
@harper-skills-sync harper-skills-sync Bot changed the title docs: regenerate rules from documentation@e52bed3 docs: regenerate rules from documentation@28b6239 Aug 26, 2026

@kriszyp kriszyp left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Reviewed with Codex


Proposed inline comments (anchors failed):

  • harper-best-practices/rules/vector-indexing.md:118: The source documentation’s complete example also overrides get(), because rowFilter does not protect a direct primary-key GET. As written, an agent following this “row-level access control” recipe can secure searches and subscriptions while /Reports/<id> still returns another owner’s record. Please retain the source’s get(target) branch—attaching the filter for collection reads and explicitly authorizing loaded single records—or clearly scope this recipe as search/subscription-only. Since this file is generated, please also add direct-GET handling to generation coverage so later syncs cannot regress it.

— KrAIs (GPT-5)

  • harper-best-practices/rules/vector-indexing.md:119: rowFilter cannot evaluate delete tombstones, value-less invalidations, raw events, or published messages when they lack an authoritative row; without an eventFilter, those events are withheld. This recipe therefore silently loses deletes and similar events for otherwise authorized rows. Please preserve the source documentation’s caveat and eventFilter pattern (including its ID-prefix invariant), or explicitly state that this example delivers only full-row events.

— KrAIs (GPT-5)

  • harper-best-practices/rules/v5-upgrade.md:94: saveBeforeCommit belongs in the options passed to Harper’s createBlob() API, as shown in harper-best-practices/rules/using-blob-datatype.md:50-54; it is not a native Blob constructor option. Following this instruction as written can leave the transaction committing while streamed blob data is still being written. Please show the actual replacement, such as createBlob(source, { saveBeforeCommit: true }), and strengthen generation coverage so the API name cannot be lost on later syncs.

— KrAIs (GPT-5)

  • harper-best-practices/rules/v5-upgrade.md:148: This now presents allowedDirectory: any as a standalone migration example while removing the prior warning that production should retain allowedDirectory: app unless external module loading is genuinely required. An agent following the example can unnecessarily widen the component’s module-loading boundary. Please restore that warning next to the example, or omit the example from this general migration recipe.

— KrAIs (GPT-5)

  • harper-best-practices/rules/v5-upgrade.md:39: This generated code block prefixes a tab with spaces; the same issue occurs at line 48 and in the generated aggregate. Consequently, git diff --check origin/main...HEAD fails with four whitespace errors. Please normalize the rule-body indentation and rebuild the aggregate.

— KrAIs (GPT-5)

## How It Works

1. **Import `tables`**: Pull `tables` from the `harper` package. Each property on `tables` corresponds to a table defined in `schema.graphql`.
1. **Import `tables`**: Import from the `harper` package. Each table defined in `schema.graphql` with `@table` is available as a property.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tables contains only tables from the default data database; a schema type declared with @table(database: "analytics"), as this regeneration now demonstrates elsewhere, is available through databases.analytics, not tables. Following this statement makes tables.Event unexpectedly undefined. Please preserve the default-database qualifier and direct readers to databases.<name> for non-default tables, with generation coverage for that distinction.

— KrAIs (GPT-5)

- `@expiresAt` — marks a field as the record's absolute expiration time (Unix epoch ms)
- `@embed(source:, model:)` — computes an embedding vector when the source field is written; field type must be `[Float]`
- `@hidden` — suppresses the field from MCP tool descriptors and OpenAPI document (not an access-control mechanism)
Without `name`, the type name is used as the path segment. Omitting `@export` removes the REST/MQTT route (callers get 404) but does **not** protect the data — the table remains accessible through the Operations API and SQL subject to RBAC.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MQTT does not return HTTP 404 responses, so “returns 404 on REST/MQTT” conflates the REST and MQTT failure behavior. Please state the REST 404 behavior separately and describe MQTT as unavailable/not routed unless the source documentation defines a specific MQTT acknowledgment outcome.

— KrAIs (GPT-5)


```javascript
const record = await Product.update(target.id);
const record = await this.update(target.id);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The source example places this.update(target.id) inside a static resource method where both this and target exist. The generator removed that wrapper, so copying this standalone table-class recipe throws because neither identifier is defined. Please retain the enclosing method or use a self-contained call such as Product.update(productId), then protect the example shape in generation coverage.

— KrAIs (GPT-5)

- Sorting by a bare `@primaryKey` with no conditions raises `HdbError: <attribute> is not indexed and not combined with any other conditions`. Add an open-ended condition or pass `allowFullScan: true`.
- Selecting a relationship field without filtering on it behaves as a **LEFT JOIN**. Adding a condition on a related attribute (e.g. `attribute: ['author', 'name']`) behaves as an **INNER JOIN**.
- `tables` calls run in a trusted server-side context and do **not** automatically apply the target table's role permissions. Enforce authorization in your own application logic.
- Sorting by a non-indexed `attribute` with zero `conditions` throws `HdbError: <attribute> is not indexed and not combined with any other conditions`. Add a condition or pass `allowFullScan: true`.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This regeneration removes every mention of limit, offset, and the sort descriptor’s descending/next properties even though Query Object remains a primary source. An agent using this rule can no longer construct pagination or deterministic tie-breaking. Please retain a concise query-options section and add these core option names to generation coverage so later summaries cannot silently discard them.

— KrAIs (GPT-5)

5. **Implement logout via `context.session.delete`**: Check that `context.session` exists, then call `context.session.delete(context.session.id)` to end the session.

Duration strings follow the `jsonwebtoken` package format (e.g., `1d`, `12h`, `60m`).
6. **Choose the right auth mechanism for the client**: Cookie-based sessions are intended for browser clients. For non-browser clients (CLI tools, mobile apps, service-to-service), use JWT issuance instead.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The supplemental JWT Authentication documentation still provides create_authentication_tokens and refresh_operation_token flows through server.operation(). This regeneration tells non-browser clients to use JWT issuance but removes every API call and example needed to do so, so an agent cannot implement the recommendation. Please restore concise issue/refresh examples and the current-user authorization behavior, and add the operation names to generation coverage so later syncs cannot discard the supplemental source again.

— KrAIs (GPT-5)

```

9. **Use unique database names** in plugins or applications to avoid table naming collisions, since all tables default to the `data` database.
7. **Use unique database names in plugins**: All tables default to the `data` database. Specify a unique `database` argument in `@table` to avoid naming collisions when building plugins or applications.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The selected Schema field-directives source documents @embed, @createdTime, @updatedTime, @expiresAt, and field-level @hidden. This regeneration no longer mentions embeddings or audit timestamps at all and shows @expiresAt without explaining that it takes an absolute Unix-millisecond timestamp. Please restore concise coverage of these directives—including the [Float] and absolute-time constraints—and make their identifiers generation requirements.

— KrAIs (GPT-5)

type Product @table {
id: Long @primaryKey
name: String @indexed
name: String

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This regenerated fence combines spaces before a tab. The same pattern appears in this rule’s other GraphQL examples, in programmatic-table-requests.md, and in their generated AGENTS.md mirrors; git diff --check origin/main...HEAD reports 14 errors. Please normalize both source rules, rebuild the aggregate, and add a diff-check generation guard so another successful sync cannot commit mixed indentation.

— KrAIs (GPT-5)

@harper-skills-sync harper-skills-sync Bot changed the title docs: regenerate rules from documentation@28b6239 docs: regenerate rules from documentation@f0c92c5 Aug 28, 2026
@harper-skills-sync harper-skills-sync Bot changed the title docs: regenerate rules from documentation@f0c92c5 docs: regenerate rules from documentation@ef9921b Aug 28, 2026
@harper-skills-sync
harper-skills-sync Bot force-pushed the auto/docs-sync branch 2 times, most recently from a7dfe1d to 6fc535a Compare August 28, 2026 18:02
@harper-skills-sync harper-skills-sync Bot changed the title docs: regenerate rules from documentation@ef9921b docs: regenerate rules from documentation@090ff88 Aug 28, 2026
@harper-skills-sync harper-skills-sync Bot changed the title docs: regenerate rules from documentation@090ff88 docs: regenerate rules from documentation@0841ba6 Aug 28, 2026
@harper-skills-sync harper-skills-sync Bot changed the title docs: regenerate rules from documentation@0841ba6 docs: regenerate rules from documentation@5cda815 Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant