fix(agentnetwork): require access_log_retention_days on the settings PUT

The settings PUT replaces every mutable field, but retention was optional
in the schema while the other three toggles were required. That was not
merely inconsistent: the handler applies the request to a zero-valued
Settings and UpdateSettings copies each field onto the stored row
unconditionally, so an omitted retention was written as 0 — which the API
documents as "keep indefinitely". A client sending only the required
fields silently switched the account from bounded to unbounded access-log
retention, with no error and no signal.

The nil check in FromAPIRequest looked like it guarded against this but
never did: the receiver is a fresh struct, not the loaded row, so skipping
the assignment preserved nothing.

Marking the field required changes the generated client type from *int to
int, so a generated client can no longer omit it. Nothing validates
OpenAPI required-ness at runtime, so a hand-rolled body without the field
still lands as 0 — the same latitude the three booleans already have, left
consistent rather than special-cased, and now pinned by a test that says
so explicitly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Brad Ison
2026-08-10 16:57:21 +02:00
co-authored by Claude Opus 5
parent 13f9bde30e
commit e60e7c9089
6 changed files with 61 additions and 16 deletions
+1
View File
@@ -6290,6 +6290,7 @@ components:
- enable_log_collection
- enable_prompt_collection
- redact_pii
- access_log_retention_days
AgentNetworkBudgetRule:
type: object
description: Account-level budget rule. A limit-only rule bound to groups and/or users that applies across all policies as a min-wins ceiling. Empty targets means it applies to every caller.
+1 -1
View File
@@ -2414,7 +2414,7 @@ type AgentNetworkSettingsCreateRequest struct {
// AgentNetworkSettingsRequest Account-level Agent Network settings update. The request replaces every mutable field (the collection toggles and retention). The endpoint and proxy address are assigned at bootstrap (POST) and are not part of this schema.
type AgentNetworkSettingsRequest struct {
// AccessLogRetentionDays Days to retain full access-log rows; older rows are swept. 0 or less means keep indefinitely.
AccessLogRetentionDays *int `json:"access_log_retention_days,omitempty"`
AccessLogRetentionDays int `json:"access_log_retention_days"`
// EnableLogCollection Whether per-request access-log entries are collected for this account's agent-network traffic.
EnableLogCollection bool `json:"enable_log_collection"`