Catalog audit: fix the #642 adapters against the vendors' real APIs - #833
Merged
Merged
Conversation
The 63 adapters added in #642 were written from memory and never run. Each was checked against the vendor's OpenAPI spec or official docs, and paths on fixed hosts were probed without credentials (401 = route exists, 404 = wrong path). 28 of 56 still unfixed REST adapters had broken tools. Fixed (broken for every or most calls): otto-market (scope, v5/v3 paths), aruba-fatturazione (auth host, findByUsername/getByIdSdi), clockodo (routes retired May 2026), quipu (vendor Accept header, scope), zalando-zds (merchants host, real filters), papershift (range_start/end, required location), paperless-ngx (Accept version=9), docuware (Identity Service token, cookie logon is 410), timetac (api host, client credentials, v4 read routes), matrix42 (token exchange, paging, data definitions), jtl-wawi (Wawi auth, /stocks, /deliveryNotes, paging), propstack (/units), afas-profit (standard connectors, operator codes). Fixed (some tools): sellsy (sort/embed enums, filter keys and date-times: the 400s a user hit), ebay-sell (disputes on apiz host, bulk price update), fatture-in-cloud (filter is q), sevdesk (categoryId 3 = customer: creating a customer made a supplier), axonaut (page is a header), zabbix (probe works with a token; selectHostGroups), dynamics-nav, mautic, synology, exact-online, d-velop, pennylane, topdesk, teamleader, zammad, znuny, bexio, visma, erpnext, e-conomic, holded, checkmk (POST live state), kimai, fhir (next page), youtrack, moneybird, openproject, glpi. New: odoo-jsonrpc, Odoo 14-18 over /jsonrpc (same tool names as the JSON-2 adapter), verified on a live Odoo including a create/write/activity/unlink cycle. Unlisted: teamsystem, sage-100, elo, cas-genesisworld, haufe-x360 and zucchetti describe APIs that do not exist and could not be verified. A new `unlisted` flag keeps them out of the listing, the install endpoint and the advertised count; they stay resolvable by slug. None is installed. Counts: 261 adapters (with Splunk from #830). The keyless count also ignored credentials passed as variables (bluesky, telegram-bot, odds-api, ...): 15, not 21.
keysersoft
force-pushed
the
keysersoft/adapter-audit-installed
branch
from
October 3, 2026 09:03
efa43ae to
3c855d8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The 63 adapters from #642 were written from memory and never run. After Odoo (#822) and BuchhaltungsButler (#829) broke for paying users, every one was checked against the vendor's OpenAPI spec or official docs, and paths on fixed hosts were probed without credentials (401 = route exists, 404 = wrong path, 405 = wrong method). Result before this PR: 28 of the 56 remaining REST adapters had broken tools, 18 were risky, 9 were fine, 1 unverifiable.
Installed in production and fixed here (affected workspaces get a catalog re-sync after deploy):
order/embedclosed lists, filter keysid/updated_at, full date-times. These are exactly the 400s logged for the one Sellsy workspace.categoryId3 = customer, 2 = supplier (was inverted: "create a customer" created a supplier); status texts;depthas string;isBooked.apiz.ebay.com; price update viabulk_update_price_quantity;offsetis a page index.apiinfo.versionrefuses any call with a token; it is nowhostgroup.getcountOutput.selectHostGroupsfor 7.2+.pageis a header (spec:in: header), company name filter issearch.findByUsername/getByIdSdi/getByInvoiceFilename.Broken for all calls, fixed: otto-market, clockodo, quipu, zalando-zds, papershift, paperless-ngx (v3), docuware, timetac, matrix42, jtl-wawi, propstack, afas-profit.
Broken in some tools / risky, fixed: fatture-in-cloud, dynamics-nav, mautic, synology, exact-online, d-velop, pennylane, topdesk, teamleader, zammad, znuny, visma, erpnext, e-conomic, holded, checkmk, kimai, fhir, youtrack, moneybird, openproject, glpi.
New adapter
odoo-jsonrpc(Odoo 14-18,/jsonrpcexecute_kw, API key + user id): same tool names as the JSON-2odooadapter. Verified through the engine against a live Odoo: all 11 tools, plus create → write → activity_schedule → unlink.Unlisted (new
unlistedflag: out of the listing, the install endpoint and the advertised count, still resolvable by slug): teamsystem (API hosts are NXDOMAIN), sage-100 (real API is SData + Sage ID), elo, cas-genesisworld, haufe-x360, zucchetti. None is installed anywhere.Counts: 261 adapters (incl. Splunk from #830).
keylessnow also excludes adapters that require a key/token/secret/password variable (bluesky, telegram-bot, odds-api, plaid, kashflow, less-annoying-crm counted as "no API key" before): 15.Lexware Office is left to #831 (it edits the same file); its remaining fixes follow after that merges.
Engine notes found during the audit (not changed here): JSON-RPC errors arrive as HTTP 200 and are logged as SUCCESS; nested parameter schemas are flattened before reaching the model; OAuth2 client_credentials cannot send
audience.Tests: full backend suite 6479 passed; validate-adapters 266/266; adapter-count --check OK; each changed adapter's static spec pins the corrected paths/params.