Add a Connect RPC¶
- Add the request, response, validation rules, and service method under
proto/scribe/v1. - Add the protobuf
scribe.v1.options.v1.authzmethod option. This is the runtime and generated OpenAPI source of truth. Useallow_anonymousonly for intentionally public operations andsession_onlyfor browser account or workspace administration that must reject API keys and external JWTs. - Assign any operation larger than the 4 MiB default to an explicit request
class in
internal/server/request_limits.goand add a boundary test. - Run
make generate; never hand-edit generated clients or handlers. - Implement an application use case rather than embedding orchestration in the transport handler.
- Normalize errors to Connect codes and avoid leaking provider/database text.
- Add handler, policy, and generated-client tests. Generation fails if the RPC is absent from OpenAPI or its authorization descriptor is missing.
- Update the API guide.
docs/api/scribe.openapi.yamlis generated by Buf.
No new REST business endpoint should be added. Public IIIF resources and OAuth callbacks remain HTTP representations where that protocol requires them.