mirror of
https://github.com/appwrite/appwrite.git
synced 2026-05-26 13:51:13 +00:00
Insights are produced by internal Appwrite services (edge, executor, background analyzers) — never by user clients. Move the ingestion endpoint accordingly. - Move Http/Insights/Create.php → Http/Manager/Insights/Create.php. - Path: /v1/insights → /v1/manager/insights. SDK Method marked `hide: true` and namespaced under `manager` so generated SDKs don't expose it. Auth narrowed from [ADMIN, KEY] to [KEY] only. - New scope `insights.manager`. Not granted by any user role (app/config/roles.php) — Cloud/edge teams configure their internal key issuance to grant it. `insights.write` description trimmed to the user-facing surface (update/dismiss/delete) since create is now manager-only. - Reports, ListInsights, GetInsight, UpdateInsight, DeleteInsight remain at /v1/insights/*. Existing scopes unchanged. - Reports `categories` switched from JSON-encoded string to a native array<string> column (size 64 per entry, up to 32 entries via the endpoint validator). MySQL JSON-array indexes are weak and we never query individual entries — read+rewrite only. - E2E test API key in tests/e2e/Scopes/ProjectCustom.php gains insights.read/write/manager + reports.read/write so the manager endpoint is reachable from the test harness. - E2E InsightsBase.createInsight() helper now POSTs /manager/insights. - New testCreateRequiresManagerScope verifies a key with insights.read/write but no insights.manager is rejected with 401. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>