Skip to content

feat(docs): add settings.embedding.allowed-origins to docs.yml - #17773

Merged
willkendall01 merged 9 commits into
mainfrom
devin/1789663742-docs-embedding-allowed-origins
Sep 18, 2026
Merged

willkendall01 merged 9 commits into
mainfrom
devin/1789663742-docs-embedding-allowed-origins

Conversation

@willkendall01

@willkendall01 willkendall01 commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Description

Linear ticket: Refs

Adds settings.embedding.allowed-origins to docs.yml so customers can whitelist third-party origins that may embed their docs site in an iframe. The CLI passes the list through to FDR as docsConfig.embedding.allowedOrigins; the platform appends each origin to the frame-ancestors CSP directive (platform-side change is separate).

settings:
  embedding:
    allowed-origins:
      - https://app.example.com
      - https://*.example.com

Changes Made

  • fern/apis/docs-yml/definition/docs.yml + regenerated docs-yml.schema.json (root and workspace/loader): new EmbeddingConfig { allowed-origins: list<string> }, exposed as DocsSettingsConfig.embedding
  • @fern-api/configuration: zod EmbeddingConfig schema, generated SDK api/serialization types, ParsedDocsSettingsConfig.embedding
  • @fern-api/configuration-loader: convertSettingsConfig passes settings.embedding through
  • @fern-api/docs-resolver: DocsDefinitionResolver emits embedding: { allowedOrigins } on the written DocsConfig (typed via the existing local shim until @fern-api/fdr-sdk publishes the field)
  • remote-workspace-runner/mapDocsConfigToLedgerConfig: forwards embedding into the ledger config (same shim)
  • Changelog: packages/cli/cli/changes/unreleased/add-docs-embedding-allowed-origins.yml
  • Updated README.md generator (N/A)

Testing

  • Unit tests added/updated — configuration-loader/src/docs-yml/__test__/embeddingAllowedOrigins.test.ts (omitted → undefined, passthrough to allowedOrigins, missing allowed-origins rejected); 3/3 pass
  • pnpm turbo run compile for configuration-loader, docs-resolver, remote-workspace-runner, docs-validator passes
  • Manual testing completed

Link to Devin session: https://app.devin.ai/sessions/5852f54aac7e4702ba83e25ad2baec01
Open in Devin Desktop: https://app.devin.ai/desktop/session/5852f54aac7e4702ba83e25ad2baec01?variant=devin
Requested by: @willkendall01


Devin Review

devin-ai-integration Bot and others added 3 commits September 17, 2026 16:49
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

nitpickybot[bot]

This comment was marked as resolved.

…blank lines

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

2 flags not posted on this PR by your GitHub settings — view them in Devin Review. (Configure)

Devin Review

Comment thread packages/cli/configuration/src/docs-yml/DocsYmlSchemas.ts
willkendall01 and others added 3 commits September 17, 2026 16:58
…ed CSP sources

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Docs Generation Benchmark Results

Comparing PR branch against median of 5 nightly run(s) on main (latest: 2026-09-17T04:06:38Z).

Fixture main PR Delta
docs 268.5s (n=5) 244.0s (35 versions) -24.5s (-9.1%)

Docs generation runs fern generate --docs --preview end-to-end against the benchmark fixture with 35 API versions (each version: markdown processing + OpenAPI-to-IR + FDR upload).
Delta is computed against the nightly baseline on main.
Baseline from nightly run(s) on main (latest: 2026-09-17T04:06:38Z). Trigger benchmark-baseline to refresh.
Last updated: 2026-09-18 00:00 UTC

@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

SDK Generation Benchmark Results

Comparing PR branch against median of 5 nightly run(s) on main (latest: 2026-09-17T04:06:38Z).

Full benchmark table (click to expand)
Generator Spec main (generator) main (E2E) PR (generator) Delta
csharp-sdk square 95s (n=5) 113s (n=5) 85s -10s (-10.5%)
go-sdk square 134s (n=5) 295s (n=5) 118s -16s (-11.9%)
java-sdk square 221s (n=5) 272s (n=5) 191s -30s (-13.6%)
php-sdk square 78s (n=5) N/A 77s -1s (-1.3%)
python-sdk square 153s (n=5) 252s (n=5) 117s -36s (-23.5%)
ruby-sdk-v2 square 102s (n=5) 148s (n=5) 88s -14s (-13.7%)
rust-sdk square 181s (n=5) 204s (n=5) 150s -31s (-17.1%)
swift-sdk square 58s (n=5) 435s (n=5) 63s +5s (+8.6%)
ts-sdk square 170s (n=5) 167s (n=5) 148s -22s (-12.9%)

main (generator): generator-only time via --skip-scripts (includes Docker image build, container startup, IR parsing, and code generation — this is the same Docker-based flow customers use via fern generate). main (E2E): full customer-observable time including build/test scripts (nightly baseline, informational). Delta is computed against generator-only baseline.
⚠️ = generation exited with a non-zero exit code (timing may not reflect a successful run).
Baseline from nightly runs on main (latest: 2026-09-17T04:06:38Z). Trigger benchmark-baseline to refresh.
Last updated: 2026-09-18 00:00 UTC

@devin-ai-integration

Copy link
Copy Markdown
Contributor

Review

Overview. Additive plumbing of settings.embedding.allowed-origins from docs.yml → zod/SDK schemas → ParsedDocsConfiguration → DocsDefinitionResolver (DocsConfig.embedding) → mapDocsConfigToLedgerConfig, plus a valid-embedding-origins docs-validator rule and a CLI changelog entry. The shape matches what fern-platform#14896 reads (embedding.allowedOrigins). Looks good to merge; nothing blocking.

Notes (non-blocking):

  1. valid-embedding-origins is the only place a bad origin gets rejected — FDR accepts any string (see comment on the platform PR). Worth keeping this rule fatal (as it is) rather than relaxing it later.
  2. The regex rejects IPv6 literals (https://[::1]:3000) and IDN hosts; fine for a first cut, just noting since http://localhost:3000 is explicitly accepted and someone may try the IPv6 loopback.
  3. Both DocsDefinitionResolver and mapDocsConfigToLedgerConfig now carry a hand-rolled { allowedOrigins: string[] } shim; once @fern-api/fdr-sdk publishes with chore(generator-cli): upgrade @fern-api/replay to 0.10.3 (pinned), bump python SDK to 5.3.10 #14896 both TODOs can be dropped in one bump — might be worth a tracking issue so they don't linger like the translations one.
  4. No user-facing docs change: the docs.yml reference in fern-api/docs should get a settings.embedding entry when this ships (the docs: strings here are good source material).

Merge order is CLI PR → CLI release → platform PR, as the platform PR notes.

willkendall01 and others added 2 commits September 17, 2026 23:33
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@willkendall01
willkendall01 merged commit ab03363 into main Sep 18, 2026
234 checks passed
@willkendall01
willkendall01 deleted the devin/1789663742-docs-embedding-allowed-origins branch September 18, 2026 22:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants