Skip to content

feat: add account_id param to PATCH /api/sandboxes for Org API keys - #199

Merged
sweetmantech merged 1 commit into
testfrom
sweetmantech/myc-4132-api-filetree-patch-apisandboxessnapshot-accept-account_id
Feb 4, 2026
Merged

feat: add account_id param to PATCH /api/sandboxes for Org API keys#199
sweetmantech merged 1 commit into
testfrom
sweetmantech/myc-4132-api-filetree-patch-apisandboxessnapshot-accept-account_id

Conversation

@sweetmantech

@sweetmantechsweetmantech commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Added optional account_id parameter to PATCH /api/sandboxes endpoint
  • Organization API keys can now update snapshots for any account within their organization
  • Personal API keys cannot use this parameter (returns 403 if attempted)

Changes

  • Updated validateSnapshotPatchBody.ts:
    • Added account_id (UUID) to request body schema
    • Pass account_id to validateAuthContext for authorization

Reference

Test plan

  • Org API key can update snapshot for member account using account_id
  • Personal API key updating own account (no account_id) works
  • Personal API key using account_id returns 403
  • Org API key using account_id for non-member account returns 403

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Snapshot patch requests now support an optional account ID parameter in the request body, enabling flexible account targeting for patch operations.
  • Improvements

    • Enhanced validation and error handling for snapshot operations, including refined error messaging and improved validation processing order for better user feedback.

Add optional account_id parameter to UpdateSnapshotRequest, allowing
organization API keys to update snapshots for any account within their
organization. Personal API keys cannot use this parameter.
The account_id is passed to validateAuthContext which handles:
- Self-access (always allowed)
- Org key access to member accounts
- 403 for unauthorized access attempts
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@vercel

vercelBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
recoup-apiReadyReadyPreviewFeb 4, 2026 2:09pm

@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown

Braintrust eval report

Catalog Opportunity Analysis Evaluation (HEAD-1770214139)

ScoreAverageImprovementsRegressions
Catalog_availability0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration45.73s (+44.43s)-5 🔴

Catalog Songs Count Evaluation (HEAD-1770214139)

ScoreAverageImprovementsRegressions
Llm_calls4 (+0)--
Tool_calls0 (+0)--
Errors3 (+3)-3 🔴
Llm_errors1 (+1)-3 🔴
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration18.08s (+16.86s)-3 🔴

First Week Album Sales Evaluation (HEAD-1770214139)

ScoreAverageImprovementsRegressions
Llm_calls1 (+0)--
Tool_calls0 (+0)--
Errors1 (+1)-4 🔴
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration17.08s (+15.85s)-4 🔴

Memory & Storage Tools Evaluation (HEAD-1770214139)

ScoreAverageImprovementsRegressions
Tools_called0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration16s (+14.91s)-1 🔴

Monthly Listeners Tracking Evaluation (HEAD-1770214139)

ScoreAverageImprovementsRegressions
Llm_calls2--
Tool_calls0--
Errors2--
Llm_errors1--
Tool_errors0--
Prompt_tokens0tok--
Prompt_cached_tokens0tok--
Prompt_cache_creation_tokens0tok--
Completion_tokens0tok--
Completion_reasoning_tokens0tok--
Total_tokens0tok--
Duration14.67s--

Search Web Tool Evaluation (HEAD-1770214139)

ScoreAverageImprovementsRegressions
Llm_calls3 (+0)--
Tool_calls0 (+0)--
Errors2 (+2)-11 🔴
Llm_errors1 (+1)-11 🔴
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration25.12s (+23.88s)-11 🔴

Social Scraping Evaluation (HEAD-1770214139)

ScoreAverageImprovementsRegressions
Tools_called0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration29.51s (+28.37s)-6 🔴

Spotify Followers Evaluation (HEAD-1770214139)

ScoreAverageImprovementsRegressions
Llm_calls3 (+0)--
Tool_calls0 (+0)--
Errors3 (+1)-5 🔴
Llm_errors2 (+1)-5 🔴
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration15.88s (+14.87s)-5 🔴

Spotify Tools Evaluation (HEAD-1770214139)

ScoreAverageImprovementsRegressions
Tools_called0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration35.05s (+33.76s)-2 🔴

TikTok Analytics Questions Evaluation (HEAD-1770214139)

ScoreAverageImprovementsRegressions
Question_answered5% (+5pp)1 🟢-
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration14.33s (+13s)-2 🔴

@coderabbitai

coderabbitaiBot commented Feb 4, 2026

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

This PR refactors the snapshot patch validation logic by introducing an optional account_id field to the request body schema, restructuring the SnapshotPatchBody type to exclude authentication context, and deferring authentication validation until after body validation completes.

Changes

Cohort / File(s)Summary
Snapshot Patch Validation
lib/sandbox/validateSnapshotPatchBody.ts
Added optional account_id UUID field to schema; changed SnapshotPatchBody type from intersection with AuthContext to standalone object with accountId and snapshotId; reordered validation flow to process body before auth; removed AuthContext import and updated response composition logic.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • Recoupable-com/Recoup-API#198 — Modifies the same validateSnapshotPatchBody function, directly conflicting with or superseding prior implementation of the same validation logic.

Poem

🔄 Validation dances a new rhythm,

Body first, then auth follows suit,

Account IDs flow both ways—

Where context and override meet, clean and bright! ✨

🚥 Pre-merge checks | ❌ 1
❌ Failed checks (1 warning)
Check nameStatusExplanationResolution
Solid & Clean Code⚠️ WarningThe PR implements a well-structured validator but perpetuates DRY and OCP violations by duplicating the validation pattern across multiple validators instead of extracting shared logic.Extract the common validation pattern into a reusable factory function that accepts a schema and returns a configured validator, eliminating code duplication and enabling composition.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch sweetmantech/myc-4132-api-filetree-patch-apisandboxessnapshot-accept-account_id

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@sweetmantech
sweetmantech merged commit 158ff85 into testFeb 4, 2026
4 of 5 checks passed
sweetmantech added a commit that referenced this pull request Feb 4, 2026
sweetmantech added a commit that referenced this pull request Feb 4, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@sweetmantech