import type { Context } from "@wrnexus/core"; import { httpTransport, serviceClient } from "@wrnexus/rpc"; import { auditService, catalogService } from "../lib/contracts.ts"; interface GitHubRepository { full_name?: unknown; stargazers_count?: unknown; } function requestedSku(ctx: Context): string { return new URL(ctx.req.url).searchParams.get("sku")?.trim() || "starter"; } /** GET /api/product-summary?sku=starter */ export async function GET(ctx: Context): Promise { const sku = requestedSku(ctx); const transport = httpTransport(); // Inter-app call #1: query the catalog app. `{ as: ctx }` forwards the // signed subject/tenant context; catalog still authorizes independently. const catalog = serviceClient(catalogService, { app: "catalog", as: ctx, transport }); const product = await catalog.getProduct({ sku }); // External API call: GitHub's public repository endpoint. Do not send the // user's RPC identity token or internal headers to external services. let githubResponse: Response; try { githubResponse = await fetch("https://api.github.com/repos/octocat/Hello-World", { headers: { accept: "application/vnd.github+json", "user-agent": "wrnexus-example" }, signal: ctx.req.signal, }); } catch { return Response.json({ error: "External repository lookup failed." }, { status: 502 }); } if (!githubResponse.ok) { return Response.json({ error: "External repository lookup failed." }, { status: 502 }); } const github = (await githubResponse.json()) as GitHubRepository; if (typeof github.full_name !== "string" || typeof github.stargazers_count !== "number") { return Response.json( { error: "External repository returned an unexpected response." }, { status: 502 }, ); } // Inter-app call #2: record the completed lookup in the audit app. This is // intentionally awaited: callers learn whether the audit record was saved. const audit = serviceClient(auditService, { app: "audit", as: ctx, transport }); const receipt = await audit.recordLookup({ sku: product.sku, repository: github.full_name, stars: github.stargazers_count, }); return Response.json({ product, external: { repository: github.full_name, stars: github.stargazers_count }, audit: receipt, }); }