feat(wrapper-generator): commit v1.0 wrapper module sources under src… - #3733
Conversation
c1e051b to
c450ffc
Compare
|
The GitOps/AdvancedSecurity check is failing because
To fix this, add an explicit <PackageReference Include="System.Text.Json" Version="10.0.3" /> |
|
Done in f7b83ce - thanks, and 10.0.3 was the right call over what I was about to use. Pinned I had been about to pin 8.0.5, which is the minimum version that patches both advisories (CVE-2024-30105 is fixed in 8.0.4, CVE-2024-43485 in 8.0.5, so 8.0.4 alone is still vulnerable). That would have worked but diverged from the existing convention for no reason. Verified rather than assumed, since the client projects are netstandard2.0:
Diff is 39 files, +117/-0 - the template and the csprojs only, no generated output. |
…e}/wrapper
All 38 modules' Kiota clients and generated cmdlets are committed - 11,719
cmdlet files, 9,051 public names - so a clean checkout builds with only the
.NET SDK. The API version nests under wrapper/ because AutoRest clears
src/{Module}/{version} on regeneration; both projects target netstandard2.0
so one dll path serves Core and Desktop. DirectoryObjects no longer
double-declares publicKeyInfrastructure. Gates and docs re-measured against
this corpus: parity 9,548 of 10,385 joinable, omission oracle 0 failures.
…cation binding Manifests now declare RequiredModules on Microsoft.Graph.Authentication (minimum read from its csproj) and packages no longer embed the Authentication assemblies: a module-local copy at a different version splits the GraphSession static under Windows PowerShell's loader, reporting NoGraphSession while connected. ModuleVersion now equals the package version - the hard-coded placeholder made every versioned-folder install refuse to import. Proven by marker-client probes; package gate passes.
…nsitive Microsoft.Kiota.Bundle 2.0.0 pulls System.Text.Json 8.0.0 transitively, which carries CVE-2024-30105 and CVE-2024-43485 - both high-severity denial of service - and Dependency Review fails the build on it. Pins 10.0.3 explicitly in the client template and in all 38 committed Client.csproj, the version Authentication.Core already pins, so the repository keeps one answer. Verified: a netstandard2.0 restore with Kiota 2.0.0 resolves 10.0.3 rather than 8.0.0, and Mail rebuilds clean.
891013d to
40ac65f
Compare
Addresses #3705 — the committable layout under
src/{Module}/and the target-framework decision.Changes proposed in this pull request
src/{Module}/wrapper/{ApiVersion}/, so a clean checkout builds them with only the .NET SDK — kiota is needed to regenerate, never to compile.wrapper/, not above it. AutoRest owns src/{Module}/{ApiVersion}/and runs withclear-output-folder, so wrapper source placed there is deleted whenever the AutoRest modules regenerate — observed: generating Mail removed its wrapper tree.src/{Module}/` itself is never cleared.netstandard2.0for both projects instead ofnet10.0. The compatibility contract comes from the module every wrapper references — src/Authentication/Authentication/Microsoft.Graph.Authentication.psd1declaresPowerShellVersion 5.1andCompatiblePSEditions Core, Desktop` — and a manifest binds one un-conditioned dll path, so a single framework must satisfy both editions..gitignore. Kiota derives directory names from Graph URL paths, so segments likePublish/,Log/andBackupRestore/collided with the existing Visual Studio rules and silently dropped 174 real source files.kiota-lock.json's spec path relative to its output folder. It was absolute and machine-local, so every clone differed.DirectoryObjectsclaimingdirectory.publicKeyInfrastructureRoot. The mapping gave the family to bothDirectoryObjectsandIdentity.DirectoryManagement, emitting 11 identical public cmdlets from two modules; the published-command inventory assigns it toIdentity.DirectoryManagementalone.Test-BodyBindingCoverage.ps1andCompare-WrapperOperationInventory.ps1at the committed corpus, and replace the inventory's newest-write-time generator stamp with a SHA-256 over the generator's sources, embedded data and project file.docs/WrapperCmdlets-V1.0.csvand-Summary.csvas the reviewable inventory.How to review this
34,443 files, 34,427 of them generated. Read
docs/WrapperCmdlets-V1.0.csv, not the tree — one row per emitted cmdlet with its module, verb, noun and request path, plus per-module totals in the summary. The 16 hand-written files are the whole reviewable surface:.gitignore,config/ModulesMapping.jsonc, the twoopenApiDocs*re-slices, six scripts, twocsproj templates,
Program.cs, and two docs.