Skip to content

History / REST API

Revisions

  • Fix double-bracket JSON/SQL example arrays Two example payloads in code fences were wrapped in [[ ]] (which renders literally) instead of single-bracket JSON/SQL arrays. Correct to [ ]. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
  • Wiki-wide: fix cross-page and same-page section links Same mis-placed-anchor pattern as the Cookbook fix, swept across the whole wiki: 19 links across 8 pages carried the #anchor on the display side of the [[...]] pipe (or as a bare [[Section Title]]), so they landed on the page top instead of the section. Convert each to a markdown link that honors the fragment, e.g. [[Architecture: Advanced#high-availability-activestandby|active/standby]] -> [active/standby](Architecture-Advanced#high-availability-activestandby) and same-page ones to [text](#anchor). One swapped plain link ([[Configuration: Basics|setting values]]) corrected to [[setting values|Configuration-Basics]]. Every target anchor verified against a real heading. Not touched: two double-bracket JSON/SQL examples inside code fences (a separate typo, flagged for review). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
  • Split Security into Security: Basics + Advanced; add Config Tokens/SSO Concepts: - Rename Security -> Security: Basics (operational surfaces unchanged). - New Security: Advanced - the mechanisms behind the surfaces: the token model (two kinds, fingerprint storage, the two-question check with cache TTL + write-bypass, admin bootstrap), the machine door (two doors, private-network listener, shared-secret vs mutual certs), and single sign-on (SAML contract, login/refresh flow, offline token validation, pasted-URL browsing), plus ironclad defaults + audit. Configuration: Advanced - two operator sections: - Tokens: store on the primary's /app/data, first-boot bootstrap secret, expiry / switch-off tunables, deployment-choice vs -cfg-<tag> bake. - Single sign-on: resources/ drop, entityID / IdP-cert / role settings, gateway signing-cert + allowed-origins. Sidebar + cross-refs re-pointed: SSO-specific links -> Advanced; scope/delegation/network links -> Basics. Sourced from com.metafluent.rest/docs/design.md; property keys deferred to Configuration: Reference pending the shipped implementation. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
  • Split Security & Entitlements into Access Control + Security Separate the combined Concepts page into two: - Access Control (Architect) - client authentication, entitlements (authorization), and transitive entitlement for derived content. New lead. Placed after Architecture: Basics in the sidebar. - Security (Architect, Operator) - the operational surfaces: REST/admin access, cluster-internal traffic, transport, and deployment secrets. Keeps the original "Elastic MDS's security..." lead, adapted. Placed after Architecture: Advanced. Drops the "security surfaces" list; re-points all cross-references (Glossary, Entitlements-Context, Configuration-Advanced, How-to-Read to Access Control; Deployment-Advanced, API-Token-Administration, REST-API to Security). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj

    @amacgaffey amacgaffey committed Jul 28, 2026
  • Stop codifying REST as "not a content-access interface" Drop the "not a content-access interface" remark from the REST API page - it overstated an early assumption. Remove the redundant word "surface" from the Security cross-link and reword the How to Read pointer to "the control-plane to use". Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 18, 2026
  • Wiki-wide: replace the AI-tell "shape" with topology/arrangement/etc. "deployment shape(s)" -> "topology"/"arrangement"; "two shapes of API" -> "kinds"; "the shape your script expects" -> "structure"; "canonical shape of a subscriber" -> "form"; "production-shaped" -> "production-grade". Spans Architecture: Advanced, Deployment: Advanced/Basics/Without-Docker, Glossary, REST API, and the SimpleSubscriber example. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 17, 2026
  • Security & Entitlements: rework entitlements + authn frameworks; tokens as shipped Entitlements section rewritten as the access-control (authorization) framework, not the JMS entitlements-context (removes the circular reference): DACS/alternative behind a pluggable entitlements service abstraction that content adapters bind to independently (per-table binding as a footnote); framework capabilities - row-level read AND write, transitive access through the derived-content framework, live refresh of access. Client authentication: add the authn framework capabilities - refreshable, independent of authz, multiple principals (Subjects). Admin/REST access: write API tokens in present tense (shipping soon); gloss the administration + SSO login UI and link to a new API Token Administration page (in preparation). REST API: authentication note now present-tense. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 17, 2026
  • Security & Entitlements: author first pass; ground the API-token roadmap in the agreed design Cross-cutting security page: the security surfaces map; client authentication (none / DACS, grounded in the session-authn mode); an entitlements pointer to the Entitlements Context page; and the admin/REST access section - open today (network-secured), with roadmap placeholders. The API-token placeholder now reflects the preliminary architecture agreed under IssueTracking#472 (Bearer mft_ token, guest/full *:read and *:* scopes leading with fine-grained <api>.<object>:<action> as advanced, operator-issued and shown once, per-cluster, TTL revocation), plus SAML2 SSO as the planned self-service token-login path. All clearly marked planned/preliminary. REST API: add a short Authentication note pointing here. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 16, 2026
  • REST API: revise per review - Split the topology-neutral point into its own section, after read-mostly. - Add a "Singletons and per-container APIs" section up front; the distinction now drives how instances are addressed. - Reframe discovery positively ("the gateway describes itself"). - Addressing: note id can be UUID or name; use a <your-instance-id> placeholder instead of a misleading abbreviated id; name each predicate explicitly; add the ~ (like) substring operator. - Collections: lead with nested collections (real orchestration session -> statements -> results -> shards example in natural language); make every example copy-paste-ready via wildcards/predicates instead of abbreviated ids. - Drop the "genuinely filters" phrasing. All examples verified live against a running gateway. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 16, 2026
  • REST API: author the reference (discovery, addressing, projection, predicates) Turns the stub into the query-grammar home the Operations pages link to: gateway host + DNS prerequisite; discover via catalog + apidoc; instance addressing (wildcard / id / attribute predicate); collection element selection incl. the literal-match operator for names with grammar chars; projection (single / CSV / dot-path token, shallow vs deep); the one mutating call (log-level PATCH); an end-to-end worked example; and a quick-reference table. Every form verified live against a running gateway. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L52U3EycDjN8uLAYL79HJ9

    @amacgaffey amacgaffey committed Jul 16, 2026
  • Correct REST framing: not a content interface. Move REST out of Developing Applications to Reference (REST API control-plane); fix Home tagline/persona/v5 note

    @amacgaffey amacgaffey committed Jul 14, 2026