Skip to content

Catalog audit: fix the #642 adapters against the vendors' real APIs - #833

Merged
keysersoft merged 2 commits into
mainfrom
keysersoft/adapter-audit-installed
Oct 3, 2026
Merged

keysersoft merged 2 commits into
mainfrom
keysersoft/adapter-audit-installed

Conversation

@keysersoft

@keysersoft keysersoft commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

The 63 adapters from #642 were written from memory and never run. After Odoo (#822) and BuchhaltungsButler (#829) broke for paying users, every one was checked against the vendor's OpenAPI spec or official docs, and paths on fixed hosts were probed without credentials (401 = route exists, 404 = wrong path, 405 = wrong method). Result before this PR: 28 of the 56 remaining REST adapters had broken tools, 18 were risky, 9 were fine, 1 unverifiable.

Installed in production and fixed here (affected workspaces get a catalog re-sync after deploy):

  • sellsy: order/embed closed lists, filter keys id/updated_at, full date-times. These are exactly the 400s logged for the one Sellsy workspace.
  • sevdesk: categoryId 3 = customer, 2 = supplier (was inverted: "create a customer" created a supplier); status texts; depth as string; isBooked.
  • ebay-sell: payment disputes on apiz.ebay.com; price update via bulk_update_price_quantity; offset is a page index.
  • zabbix: the probe apiinfo.version refuses any call with a token; it is now hostgroup.get countOutput. selectHostGroups for 7.2+.
  • axonaut: page is a header (spec: in: header), company name filter is search.
  • aruba-fatturazione: login on the auth host (form body, 30 min token), findByUsername / getByIdSdi / getByInvoiceFilename.
  • bexio: instructions (PAT, 60 days, 403 = bexio user rights), address fields.

Broken for all calls, fixed: otto-market, clockodo, quipu, zalando-zds, papershift, paperless-ngx (v3), docuware, timetac, matrix42, jtl-wawi, propstack, afas-profit.
Broken in some tools / risky, fixed: fatture-in-cloud, dynamics-nav, mautic, synology, exact-online, d-velop, pennylane, topdesk, teamleader, zammad, znuny, visma, erpnext, e-conomic, holded, checkmk, kimai, fhir, youtrack, moneybird, openproject, glpi.

New adapter odoo-jsonrpc (Odoo 14-18, /jsonrpc execute_kw, API key + user id): same tool names as the JSON-2 odoo adapter. Verified through the engine against a live Odoo: all 11 tools, plus create → write → activity_schedule → unlink.

Unlisted (new unlisted flag: out of the listing, the install endpoint and the advertised count, still resolvable by slug): teamsystem (API hosts are NXDOMAIN), sage-100 (real API is SData + Sage ID), elo, cas-genesisworld, haufe-x360, zucchetti. None is installed anywhere.

Counts: 261 adapters (incl. Splunk from #830). keyless now also excludes adapters that require a key/token/secret/password variable (bluesky, telegram-bot, odds-api, plaid, kashflow, less-annoying-crm counted as "no API key" before): 15.

Lexware Office is left to #831 (it edits the same file); its remaining fixes follow after that merges.

Engine notes found during the audit (not changed here): JSON-RPC errors arrive as HTTP 200 and are logged as SUCCESS; nested parameter schemas are flattened before reaching the model; OAuth2 client_credentials cannot send audience.

Tests: full backend suite 6479 passed; validate-adapters 266/266; adapter-count --check OK; each changed adapter's static spec pins the corrected paths/params.

@keysersoft
keysersoft requested a review from D3nisty as a code owner October 3, 2026 08:51
The 63 adapters added in #642 were written from memory and never run. Each
was checked against the vendor's OpenAPI spec or official docs, and paths
on fixed hosts were probed without credentials (401 = route exists, 404 =
wrong path). 28 of 56 still unfixed REST adapters had broken tools.

Fixed (broken for every or most calls): otto-market (scope, v5/v3 paths),
aruba-fatturazione (auth host, findByUsername/getByIdSdi), clockodo (routes
retired May 2026), quipu (vendor Accept header, scope), zalando-zds
(merchants host, real filters), papershift (range_start/end, required
location), paperless-ngx (Accept version=9), docuware (Identity Service
token, cookie logon is 410), timetac (api host, client credentials, v4
read routes), matrix42 (token exchange, paging, data definitions),
jtl-wawi (Wawi auth, /stocks, /deliveryNotes, paging), propstack (/units),
afas-profit (standard connectors, operator codes).

Fixed (some tools): sellsy (sort/embed enums, filter keys and date-times:
the 400s a user hit), ebay-sell (disputes on apiz host, bulk price update),
fatture-in-cloud (filter is q), sevdesk (categoryId 3 = customer: creating
a customer made a supplier), axonaut (page is a header), zabbix (probe
works with a token; selectHostGroups), dynamics-nav, mautic, synology,
exact-online, d-velop, pennylane, topdesk, teamleader, zammad, znuny,
bexio, visma, erpnext, e-conomic, holded, checkmk (POST live state),
kimai, fhir (next page), youtrack, moneybird, openproject, glpi.

New: odoo-jsonrpc, Odoo 14-18 over /jsonrpc (same tool names as the JSON-2
adapter), verified on a live Odoo including a create/write/activity/unlink
cycle.

Unlisted: teamsystem, sage-100, elo, cas-genesisworld, haufe-x360 and
zucchetti describe APIs that do not exist and could not be verified. A new
`unlisted` flag keeps them out of the listing, the install endpoint and
the advertised count; they stay resolvable by slug. None is installed.

Counts: 261 adapters (with Splunk from #830). The keyless count also ignored credentials passed as
variables (bluesky, telegram-bot, odds-api, ...): 15, not 21.
@keysersoft
keysersoft force-pushed the keysersoft/adapter-audit-installed branch from efa43ae to 3c855d8 Compare October 3, 2026 09:03
@keysersoft
keysersoft merged commit aec34f4 into main Oct 3, 2026
13 checks passed
@keysersoft
keysersoft deleted the keysersoft/adapter-audit-installed branch October 3, 2026 09:13
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 3, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant