fix(graphql-costing): account for aliased expensive mutations — enforce query-cost limits against resolver multiplication - #774
Closed
unohee wants to merge 13 commits into
Conversation
added 13 commits
September 10, 2026 02:18
This was referenced Sep 27, 2026
unohee
added a commit
that referenced
this pull request
Sep 28, 2026
…d CLI/provider validation (#788) Salvages the boundary work from draft PRs #764, #774 and #778 onto current main. From #764: - support/outboundUrl: resolvePublicHttpUrl returns the validated addresses, createPinnedPublicLookup answers the connect hook from that same set (no second DNS round-trip), and publicFetch installs a per-request pinned dispatcher instead of a shared unpinned agent. - issues/graphql/server: GRAPHQL_MAX_DEPTH/FIELD_COUNT/ALIAS_COUNT/COST plus createGraphQLCostRule, and exact-path '/graphql' matching. - mcp/mcpClient: MAX_INPUT_SCHEMA_BYTES/PROPERTIES with countSchemaProperties. - auth/oauthPkce: isLoopbackRemote guard on the callback server (+ re-export). - verify/runner: buildVerifyToolchainPath replaces the inherited sandbox PATH. - adapters/webTools: cancel the redirect body before the next hop. From #774: - issues/graphql/costAnalysis: registry CRUD costs (registerEntity 100, updateEntity/removeEntity 80, addEntityRelation/removeEntityRelation 60). - issues/graphql/server: applyCors returns early without an Origin header. - bulkRegisterEntities alias/fragment-multiplication tests. From #778: - adapters/rateLimitError: parseRetryAfterSeconds handles HTTP-date Retry-After; classifyLimitResponse falls back to the codex reset epoch. - cli/mcpCommand: preset/url/command validation before persisting the registry. - cli/prCreate: fail closed on a dirty tree or a branch with no upstream. - adapters/webTools: refuse non-http(s) redirect destinations. Kept main's newer clone-timeout/resource-budget code in verify/runner and its onValidate cost plugin; dropped the already-in-main #774 files and all scratch probe files.
Collaborator
Author
|
Closing: superseded — the salvageable work in this draft was rebased onto current main, verified, and re-published as a reviewed PR: absorbed into #788. Closing the stale draft instead of merging it, because it was 170-250 commits behind, carried scratch files, and (in several cases) reverted main's later hardening. |
unohee
deleted the
swarm/AGT-3473-fix-graphql-costing-account-for-aliased-
branch
September 28, 2026 07:03
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Published because this run stopped and needs a human: autonomous execution failed 4 times
It has not been reviewed and is very likely incomplete — this PR is a draft on purpose. It exists so the work is reviewable instead of sitting on a branch that was never pushed.
Change shape
429 file(s): 211 source · 185 test · 9 docs · 24 other
Base freshness
Branch base is 175 commit(s) behind
mainat publication.⚠ Conflicts with
mainin:CHANGELOG.md,package-lock.json,package.json,src/automation/runnerExecution.ts,src/issues/graphql/costAnalysis.ts,src/issues/graphql/server.test.tsGitHub runs no
pull_requestworkflows on a PR it cannot merge, so any green checks here are not the verification gate. Opened as a draft; rebase before review.This branch changes files that other open PRs / active branches also touch. Coordinate before merging to avoid divergent parallel edits (INT-2388 #3):
package-lock.json,package.jsonpackage-lock.jsonpackage-lock.json,package.jsonsrc/memory/memoryCore.tspackage-lock.jsonsrc/issues/graphql/server.test.ts,src/issues/graphql/server.tspackage-lock.jsoncursor-hooks.json,hooks.json,package-lock.jsonpackage-lock.json,package.jsonpackage-lock.jsonpackage-lock.jsonpackage-lock.json,package.json,src/issues/graphql/server.tspackage-lock.json,package.jsonpackage-lock.jsonsrc/issues/graphql/costAnalysis.ts,src/issues/graphql/server.test.ts,src/issues/graphql/server.tshooks.json,package-lock.json,package.json,src/memory/memoryCore.tspackage-lock.json,src/memory/memoryCore.tshooks.json,lspackage-lock.json,package.jsonpackage-lock.jsonpackage-lock.jsonpackage-lock.jsonpackage-lock.json,package.jsonpackage-lock.jsonCHANGELOG.mdpackage-lock.json,src/coordination/coordinationTools.test.tspackage-lock.jsonpackage-lock.json,package.jsonsrc/coordination/coordinationTools.test.tsCHANGELOG.mdsrc/coordination/coordinationTools.test.tsCHANGELOG.md,package-lock.json,package.jsonCHANGELOG.md,package-lock.json,package.jsonCHANGELOG.md,package-lock.json,package.jsonLinear
Closes AGT-3473
🤖 Generated with OpenSwarm