Repository navigation
Conversation
…ects (get, create, update, suggest, whoami)
dklawren
requested changes
Oct 7, 2026
…request, shorten method chains, fix test data
dklawren
requested changes
Oct 8, 2026
dklawren
requested changes
Oct 9, 2026
| # This Source Code Form is "Incompatible With Secondary Licenses", as | ||
| # defined by the Mozilla Public License, v. 2.0. | ||
|
|
||
| package Bugzilla::API::V1::Util; |
Collaborator
There was a problem hiding this comment.
Util.pm is in the namespace _load_api_module scans, so ->new fails and logs a warning on every startup. Update _load_api_module In Controller.pm to return early unless $module->can('setup_routes'). I do not want to move Util.pm out of V1 as a future V2 might have different code for Util.pm that behaves differently.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Ports the user object endpoints of the legacy User REST resource to a native Mojo controller,
Bugzilla::API::V1::UserObject, mirroring the pattern already used for Classification, BugUserLastVisit and Product.Part of bug 2071909 (User), itself part of bug 2057358.
Endpoints:
GET /rest/userPOST /rest/userGET /rest/user/<id_or_name>PUT /rest/user/<id_or_name>GET /rest/user/suggestGET /rest/whoamiPOST /rest/user/offer_account_by_emailChanges
Bugzilla/API/V1/UserObject.pmwithget,create,update,suggest,whoamiandoffer_account_by_email. Request parameters and response format are unchanged.offer_account_by_emailis ported here rather than in a separateUserAuthmodule: withlogin,logoutandvalid_loginnot being ported (token support is dropped in favour of API keys), it was the only endpoint left for that module. It stays login exempt, as in the legacy method.typemethod with the same output as the legacy one, because thewebservice_user_gethooks of Review, UserProfile and TagNewUsers call$webservice->type(...). The user autocomplete in the web UI depends on those hooks.whoamireads theX-PHABRICATOR-TOKENheader directly, since native Mojo does not populateBugzilla->input_paramsqa/t/rest_user_suggest_whoami.t: neither endpoint had a test. It covers the same call as the autocomplete injs/field.jst/app-user-whoami.t:whoamiwith a valid, unknown and revoked API key, and with a Phabricator token (Phabricator'suser.whoamiis stubbed), including a disabled accountpermissivetests toqa/t/rest_user_get.tdocs/en/rst/api/core/v1/user.rst:whoamivalidates an API key, not a token or a username and password.Bugzilla::WebService::Userand its REST resource file are not touched here. The native routes take precedence over the ported methods. The legacy module is removed with the last User sub-task, once its remaining endpoints are migrated.Behaviour changes
permissiveonGET /rest/usernow works (bug 1787294): it called->messageon a plain string and died instead of recording a fault.Bugzilla_login/Bugzilla_passwordand login tokens are no longer accepted.whoamistill reportsapi_key_not_valid/api_key_revokedfor an API key that is refused, as the legacy endpoint did;login_requiredis only returned when no key was sent.whoamiwith a Phabricator token now refuses a disabled account (account_disabled), as it does with an API key. The legacy method answered for it.updatedrops the request-level keys (include_fields,exclude_fields,Bugzilla_api_token,api_key,token, etc.) beforeset_all(), as in Group, so a cookie-authenticatedPUT, or one passing?api_key=, no longer fails withunknown_method.include_fields/exclude_fieldsin a JSON body is ignored.updatereturnsidas an integer (as documented).Test plan
qa/t/rest_user_get.t,rest_user_create.t,rest_user_update_protected.tqa/t/rest_user_suggest_whoami.t(new)t/app-user-whoami.t(new)qa/t/rest_user_offer_account_by_email.t: now served by the native routeqa/t/rest_user_login_logout.t: the endpoints still served by the legacy module are unaffected by the new routesGET /rest/whoamiwith anX-PHABRICATOR-TOKENheaderReferences