queueserver: PARITY.md ancestry map; require read:resources on /api/plans/existing - #117
Merged
Anubhuti Sinha (anubhutisinha04) merged 2 commits intoAug 7, 2026
Conversation
Upstream bluesky-httpserver leaves this endpoint unauthenticated while devices/existing requires read:resources; the fork inherited the asymmetry. Align the scopes and regenerate the OpenAPI schema.
Anubhuti Sinha (anubhutisinha04)
approved these changes
Aug 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two related changes from a full-surface parity audit of queueserver_service against its upstream ancestors (bluesky-queueserver v0.0.25, bluesky-httpserver @ PR #81):
PARITY.md in backend/queueserver_service/ — a short technical record of what the service was forked from, what is preserved (all 50 0MQ methods, all REST endpoints and WebSockets, all 9 CLI entry points, the carried upstream test suites), what the restructure changed (merge into one package, composition/DI seams, unified-process mode), the fork-local additions, and the deliberate divergences.
Auth asymmetry fix: upstream leaves GET /api/plans/existing unauthenticated while devices/existing requires read:resources. The fork inherited that asymmetry; this aligns the two and regenerates the checked-in OpenAPI schema. Authenticated clients (including bluesky-queueserver-api in single-user or token mode) are unaffected; only anonymous access to that one endpoint tightens.