fix: resolve open validation issues (#313 #316 #319 #320 #321 #322 #323) - #326
Merged
Merged
Conversation
- router/paths: strip server base paths when the host has a variable, try every server whose base path prefixes the request, and read path parameters from the path the router matched (fixes a panic with strict server matching and a variable in the base path) (#313) - requests/responses: share one media-range matcher that prefers the most specific key and no longer panics on a Content-Type without a slash (#316) - responses: validate every response header that is present, by the readings its schema allows; match a default response without content; ignore Content-Type header declarations (#321) - parameters: accept whole numbers written as 1.0 or 1e3 for integers, compare integer enums numerically, schema-validate header and cookie numbers, reject NaN/Inf and empty matrix values (both panicked), and compile parameter schemas with their document's OpenAPI version (#319, #320) - parameters: ignore a path template's #fragment when the request has none, as the router does, instead of reporting the parameter missing - helpers: enforce OpenAPI int32/int64 formats with WithFormatAssertions (#320) - schema_validation: never marshal document-owned yaml nodes in place (#322) - tests: stop relying on json.Marshal rejecting map[interface{}]interface{}, which Go 1.27 accepts (#323) Fixes #313, fixes #316, fixes #319, fixes #320, fixes #321, fixes #322, fixes #323 Co-authored-by: adrienyhuel <14916484+adrienyhuel@users.noreply.github.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #326 +/- ##
==========================================
+ Coverage 98.28% 98.36% +0.08%
==========================================
Files 75 79 +4
Lines 9266 9433 +167
==========================================
+ Hits 9107 9279 +172
+ Misses 132 129 -3
+ Partials 27 25 -2
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the open, non-feature issues from the issue triage, plus several crashes found along the way.
Changes
https://{host}/api/v1), restoring the Added secondary parsing if the initial base path parsing fails; the s… #68 fallback. When several servers prefix the request, each is tried in document order. Path parameters are read from the path the router matched, which fixes a panic with strict server matching and a variable in the base path.type/*+suffix,type/*,*/subtype, then*/*. It no longer panics on aContent-Typewithout a slash.requiredonly controls presence. Values are read the way the schema allows (each declared type, then JSON, then the raw string). Adefaultresponse withoutcontentnow matches, and a declaredContent-Typeheader is ignored, as OpenAPI requires.1.0or1e3are accepted as integers, and integer enums compare numerically. Header and cookie numbers are schema-validated, sominimum,maximumandformatapply.WithFormatAssertions()enforces the OpenAPIint32andint64formats; aWithCustomFormatof the same name still wins. Parameter schemas compile with their document's OpenAPI version./pages/{id}#sectionignores its fragment when the request has none, as the router does. Before this,/pages/5was reported as missingid.json.Marshalrejectingmap[interface{}]interface{}, which Go 1.27 accepts.Crashes fixed
ValidateHttpRequestruns validators in goroutines, so each of these took down the whole process:Content-Typeofapplication(no slash) in request body validationNaNorInfin a number query or path parameter/things/;matrix=)Behaviour changes
ExampleNewValidator_responseHeaderNotRequiredis updated.a+bstaysa+b.1.0is accepted as an integer.router.Routegains a publicRequestPathfield.Verification
TestNormalizeJSON_ReturnsMarshalErroron 1.27), and with-race.The media-range matcher builds on #318 by @adrienyhuel, who is credited as co-author.
Fixes #313, fixes #316, fixes #319, fixes #320, fixes #321, fixes #322, fixes #323
🤖 Generated with Claude Code