Skip to content

Type the Run User invite and forced password change fields - #71

Merged
FabianoEger merged 4 commits into
mainfrom
feat/run-user-invite-fields
Sep 28, 2026
Merged

FabianoEger merged 4 commits into
mainfrom
feat/run-user-invite-fields

Conversation

@FabianoEger

@FabianoEger FabianoEger commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Summary

Types the Run User invite fields that tago-io/server#1799 adds, and adds userResendInvite for POST /run/users/:id/invite. userCreate accepts generate_password and send_email (with password now optional), userEdit accepts force_password_change and logout_sessions through a new UserEditInfo that matches the server update schema, and UserInfo carries force_password_change. Bumps the package to 5.1.7 and documents the new fields and method in the Run docs.

Test plan

  • uv run pytest tests/: 222 passed, including new tests for userResendInvite (path, method, body with and without invite_template) and userCreate with generate_password
  • uv run ruff check src: clean
  • uv run ruff format --check src: changed lines are clean; the 21 files it flags fail the same way on main (existing code is wrapped at 120 columns against the configured 88) and are left untouched
  • Sphinx build of docs/source: no warnings in the Run pages
  • pyproject.toml and the tagoio-sdk entry in uv.lock read 5.1.7

Handoff

  • Publish 5.1.7 only after tago-io/server#1799 is deployed to production. Until then, userResendInvite returns 404 and userCreate with generate_password and no password fails validation.

Risk (CIA)

Likelihood: 🟢 Low | Impact: 🟢 Low | Exposure: 🟢 Low

Related

tago-io/server#1799

@FabianoEger

Copy link
Copy Markdown
Member Author

Block
Create types still require a password key the new call has to omit.

Description alignment

Gaps

  • PR description > Handoff: userResendInvite targets POST /run/users/:id/invite from tago-io/server#1799, which is still open. Publishing 5.1.7 before that API is deployed makes the new method 404, and generate_password without password fails validation on the current API.

Rewrite the PR description with /tagoio:pr-and-issue-descriptions.

In this PR

Blockers

  • src/tagoio_sdk/modules/Resources/Run_Type.py:212: password: Optional[str] on a total TypedDict still requires the key. None is sent as JSON null, and the server rejects null on its own (z.string()) and together with generate_password (password !== undefined). The docstring says to omit the key. Use NotRequired[str] so the key can be absent. requires-python is >=3.11, so NotRequired is in typing.

Questions

  • PR description > Handoff: add a Handoff that this package is published only after tago-io/server#1799 is deployed.

Improvements

  • src/tagoio_sdk/modules/Resources/Run_Type.py:222: generate_password and send_email use the same total-TypedDict Optional pattern, so a type checker requires those keys on every userCreate. Prefer NotRequired for both.
  • src/tagoio_sdk/modules/Resources/Run_Type.py:233: UserEditInfo lists email, which zRunUserUpdateAdmin omits and strips, and it leaves out options, newsletter, and custom_preferences, which that schema accepts. userEdit is Union[UserEditInfo, Dict] at Run.py:193, so any mapping is accepted. Align the fields with the update schema and drop the Dict arm.
  • src/tagoio_sdk/modules/Resources/Run.py:222: userResendInvite takes Optional[Dict]. A small TypedDict with invite_template: NotRequired[str] matches the server body.
  • docs/source/Resources/Run/index.rst:157: the hand-written Run docs have a section per method and none for userResendInvite. Add that section, and mention generate_password, send_email, force_password_change, and logout_sessions on the create and edit sections, before the docs site is rebuilt.

Praise

  • test_run.py checks the create body (generate_password, template name, no password key) and both invite calls (empty object and invite_template).

Risk (CIA)

Likelihood: 🟢 Low | Impact: 🟢 Low | Exposure: 🟢 Low.
Confirmed.

@FabianoEger

Copy link
Copy Markdown
Member Author

Approve
The create key can be omitted, the edit type matches the update schema, and the docs cover the new method.

Thread consolidation

Resolved

  • src/tagoio_sdk/modules/Resources/Run_Type.py:213: prior Blocker. password is NotRequired[str], so the key can be absent. Verified.
  • src/tagoio_sdk/modules/Resources/Run_Type.py:223: generate_password and send_email are NotRequired. Verified.
  • src/tagoio_sdk/modules/Resources/Run_Type.py:236: UserEditInfo no longer lists email, and it includes options, newsletter, and custom_preferences. Verified against zRunUserUpdateAdmin.
  • src/tagoio_sdk/modules/Resources/Run.py:226: userResendInvite takes Optional[UserInviteInfo], and invite_template is NotRequired[str] at Run_Type.py:277. Verified.
  • docs/source/Resources/Run/index.rst: userResendInvite has a section, and the create and edit sections mention the new fields. Verified.
  • PR description > Handoff: publish 5.1.7 only after tago-io/server#1799 is deployed. Verified in the body.

Prior leads

  • Prior review improvement to drop the Dict arm: userEdit is still Union[UserEditInfo, Dict] at Run.py:196. The field list matches the update schema, and the Dict arm keeps existing callers valid. Not carried.

Praise

  • testRunMethodUserCreateGeneratePassword sends generate_password with no password key, and NotRequired makes that call valid. The resend tests still check the empty body and invite_template.

Risk (CIA)

Likelihood: 🟢 Low | Impact: 🟢 Low | Exposure: 🟢 Low.
Confirmed. Client types and docs only. Publish stays behind the server deploy named in Handoff.

@FabianoEger
FabianoEger merged commit 7522098 into main Sep 28, 2026
6 checks passed
@FabianoEger
FabianoEger deleted the feat/run-user-invite-fields branch September 28, 2026 18:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants