canned-prompts/workplans
tegwick 5f47da8036 CANP-WP-0006 T03: read API
Search, versions, manifests, archives and the index, over HTTP.

The route shape is the decision worth recording. Package ids contain `/`, so
the obvious /packages/{id}/{version} is ambiguous under a greedy path
parameter. Rather than invent an HTTP-specific identifier, the routes speak the
format's own <registry>:<id>@<version> syntax and parse it — `:` and `@` are
both legal in a path segment, and each route keeps a distinct prefix so
greediness cannot swallow a neighbouring one. The API therefore exercises
section 3.2's reference notation instead of working around it.

A bare id present in more than one registry returns 409 with the candidates,
never a guess. 409 rather than 300 because the request is answerable once the
caller says which registry they meant. Omitting a version applies section
17.1's selector rules, so a prerelease is never chosen implicitly.

Validation is delegated to reference/, installed into the service environment
rather than reimplemented. One validator means the service and the CLI cannot
disagree about what a valid package is; a service accepting something the CLI
rejects would be the divergence this project exists to prevent. Importing it is
not changing it — reference/ stays the dependency-light conformance witness.

Storage keeps the format's distinctions: an immutable package version, its
files as content rather than parsed rows, and an index entry recording arrival.
Only reserved paths and manifest-referenced files are stored (section 2), and a
re-publish of identical content is accepted while different content under the
same id@version is a conflict (section 17).

Handles a real test-vs-production difference: SQLite autoincrements INTEGER
PRIMARY KEY only, never BIGINT, so the SQLite-backed tests could not insert a
row. BigInteger().with_variant(Integer, "sqlite") keeps BIGINT on PostgreSQL
while letting the tests exercise the same models and migration.

Verified live against a seeded store holding this repo's examples and four
helix-forge prompt packages. Service tests 11 -> 22.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 388925@bnt-lap001
Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-06 20:23:25 +02:00
..
ADHOC-2026-09-06.md chore(consistency): regenerate WORK-RECORDS.md 2026-09-06 14:48:27 +02:00
CANP-WP-0001-statehub-bootstrap.md Add repo classification and record workplan review context 2026-09-06 00:47:23 +02:00
CANP-WP-0002-format-open-questions.md CANP-WP-0002 T06: revision v0.2, and section 23 rewritten 2026-09-06 14:22:45 +02:00
CANP-WP-0003-registry-naming-residual.md CANP-WP-0003: name the default registry default 2026-09-06 19:32:30 +02:00
CANP-WP-0004-prompt-index.md chore(consistency): regenerate WORK-RECORDS.md 2026-09-06 17:14:49 +02:00
CANP-WP-0005-inclusion-diamond.md CANP-WP-0005: document and detect inclusion diamonds 2026-09-06 19:23:16 +02:00
CANP-WP-0006-hosted-registry-service.md CANP-WP-0006 T03: read API 2026-09-06 20:23:25 +02:00