aboutcode-org / aboutcode-org/vulnerablecode

OpenAPI schema for POST /api/v3/packages does not reflect paginated and polymorphic response

Aperta
#2,331 2 commenti 1 reazione 0 assegnatari Vedi su GitHub
Lingua principale
Python
Stelle
702
Fork
328
Merge medio
3g 8h
PR unite (30g)
3

Descrizione

The current OpenAPI schema incorrectly documents the response structure of the POST /api/v3/packages/ endpoint.

The schema currently lists a 201 response as a direct mapping to #/components/schemas/PackageV3:
```json
"/api/v3/packages/": {
"post": {
"operationId": "v3_packages_create",
"tags": [
"v3"
],
"requestBody": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/PackageQuery"
}
},
"application/x-www-form-urlencoded": {
"schema": {
"$ref": "#/components/schemas/PackageQuery"
}
},
"multipart/form-data": {
"schema": {
"$ref": "#/components/schemas/PackageQuery"
}
}
}
},
"security": [
{
"cookieAuth": []
},
{
"tokenAuth": []
},
{}
],
"responses": {
"201": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/PackageV3"
}
}
},
"description": ""
}
}
}
},
```

However, the actual API response is paginated, and the contents of the results array vary depending on request parameters (such as the details boolean option), so the response can also contain a list of PURL strings, instead of `PackageV3` objects.

The response also has an incorrect status code in the schema (actual status code is 200).

This causes automated client generators to fail to parse the actual API responses because they expect a `201` flat object instead of the `200` paginated response structure.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.