Skip to content

[P2] Implement or explicitly bound OpenAPI request validation #52

Description

@michielbdejong

Recorded during review of main at a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.

Finding

Catalog validation checks method and path only. Query parameters, bodies, and content types pass through without schema validation, falling short of the validating-proxy requirements in SECURITY.md. The provider metadata schema validation elsewhere in the code does not validate forwarded API requests.

Evidence

Desired outcome

Compile request validation rules from the catalog, or explicitly document the narrower supported boundary. Test rejection of invalid parameters, bodies, and content types before contacting an upstream.

Activity

  1. michielbdejong commented on Sep 16, 2026

    @michielbdejong
    ContributorAuthor

    Fixed in #73 — added Catalog::validate_request, a bounded, explicit check that a declared required query parameter is present, an enum-constrained parameter's value is one of the declared values, and a request body's presence/content-type match the operation's declared requestBody, wired into the proxy forwarding path. Documented as an explicit bounded subset (not full JSON Schema validation) in SECURITY.md.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions