feat(apps): show owner-site quota usage and structured quota errors - #8
Open
nandiheath wants to merge 1 commit into
Open
nandiheath wants to merge 1 commit into
nandiheath wants to merge 1 commit into
Conversation
nandiheath
marked this pull request as ready for review
September 25, 2026 23:55
jonwinton
reviewed
Sep 25, 2026
jonwinton
left a comment
There was a problem hiding this comment.
redact_json_value sanitizes successful responses as well as errors (authorized_json_request, delete_app), so the change at src/bl/apps.rs:1533 affects every successful Apps Platform response, not only the error recovery fields:
- String values now go through
terminal_safe_text, which rewrites newlines, tabs, and other control characters as literal Rust-style escapes (\nbecomes the two characters\n, ESC becomes\u{1b}).print_jsonalready emits valid JSON with bidi controls escaped, so--jsonconsumers only lose data. For example, multi-line pod logs frombl apps debug --jsonnow arrive as a single line with literal\nsequences. The updated contract process test (nested.messageexpecting\\u{1b}[31m) reflects this change on the success path. - The stricter key check at line 1541 also applies to successful responses. A key containing any control or bidi character now fails the whole command. For
delete, that surfaces as "delete outcome unknown" after a request that may have succeeded.
Consider applying terminal-safe escaping and the unsafe-key rejection only inside sanitize_field (error details and next_action), and leaving redact_json_value as credential redaction for successful responses.
Separately, the DCO check is failing; the commit needs a Signed-off-by trailer.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
bl appsis ready for Compose owner-site quotas:owner_site_limit_reached,owner_site_quota_maintenance,tier_resolution_unavailable,owner_site_quota_unavailable,owner_site_quota_misconfigured) now carry the server'serror.detailsandnext_action(string or structured) into the CLI failure output, not just the error code. Both are credential-redacted and made terminal-safe. Raw bodies and backend messages are still never echoed. Object keys that contain the credential or terminal control characters are rejected.bl apps list --scope ownedreturns the server's owner quota metadata (accounting_enabled,enforcement_enabled,tier_status,current_count,max_sites,remaining,over_limit) unchanged. The help text explains that the list count is visible apps, not quota usage; that accounting-only limits are informational; and that an unavailable tier does not block listing.owner_site_limit_reached: inspect owned apps, don't auto-retry during maintenance or a tier outage, and note that existing apps stay manageable. Delete help explains that logical deletion releases quota even if cleanup fails, and how to check before retrying creation.Servers without quota support return no quota metadata or codes, and output is unchanged.
Verification
cargo fmt --all -- --checkcargo clippy --locked --workspace --all-targets --all-features -- -D warningscargo test --locked --workspace --all-features: all suites pass. That includes CLI process tests against a local HTTP fixture:next_action, with no mutation retry.next_action/details values have credentials and escape sequences removed.package-smokewas not run locally (needs the internal packaging build).