aboutcode-org / aboutcode-org/vulnerablecode

OpenAPI schema for POST /api/v3/packages does not reflect paginated and polymorphic response

未關閉
#2,331 2 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

The current OpenAPI schema incorrectly documents the response structure of the POST /api/v3/packages/ endpoint.

The schema currently lists a 201 response as a direct mapping to #/components/schemas/PackageV3:
```json
"/api/v3/packages/": {
"post": {
"operationId": "v3_packages_create",
"tags": [
"v3"
],
"requestBody": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/PackageQuery"
}
},
"application/x-www-form-urlencoded": {
"schema": {
"$ref": "#/components/schemas/PackageQuery"
}
},
"multipart/form-data": {
"schema": {
"$ref": "#/components/schemas/PackageQuery"
}
}
}
},
"security": [
{
"cookieAuth": []
},
{
"tokenAuth": []
},
{}
],
"responses": {
"201": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/PackageV3"
}
}
},
"description": ""
}
}
}
},
```

However, the actual API response is paginated, and the contents of the results array vary depending on request parameters (such as the details boolean option), so the response can also contain a list of PURL strings, instead of `PackageV3` objects.

The response also has an incorrect status code in the schema (actual status code is 200).

This causes automated client generators to fail to parse the actual API responses because they expect a `201` flat object instead of the `200` paginated response structure.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。