Recorded during review of main at a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.
Finding
Catalog validation checks method and path only. Query parameters, bodies, and content types pass through without schema validation, falling short of the validating-proxy requirements in SECURITY.md. The provider metadata schema validation elsewhere in the code does not validate forwarded API requests.
Evidence
Desired outcome
Compile request validation rules from the catalog, or explicitly document the narrower supported boundary. Test rejection of invalid parameters, bodies, and content types before contacting an upstream.
Recorded during review of main at
a1eb305ccfa2f3fc8ddede4875765cf1b099bd2b. This issue records a finding only; no implementation changes were made or requested.Finding
Catalog validation checks method and path only. Query parameters, bodies, and content types pass through without schema validation, falling short of the validating-proxy requirements in SECURITY.md. The provider metadata schema validation elsewhere in the code does not validate forwarded API requests.
Evidence
Desired outcome
Compile request validation rules from the catalog, or explicitly document the narrower supported boundary. Test rejection of invalid parameters, bodies, and content types before contacting an upstream.