Skip to content

Commit b68c550

Browse files
committed
fix(api): add missing 403 to GET /api/config and GET /api/config/service/{service}
Both handlers call requirePermission("view","config") but the spec only declared 403 on their PUT counterparts. The regression test added in this PR caught the gap. Add the missing 403 response to both GET operations.
1 parent c5c741c commit b68c550

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

‎internal/api/openapi.yaml‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -100,6 +100,8 @@ paths:
100100
$ref: '#/components/schemas/ConfigResponse'
101101
'401':
102102
$ref: '#/components/responses/Unauthorized'
103+
'403':
104+
$ref: '#/components/responses/Forbidden'
103105
put:
104106
operationId: updateConfig
105107
tags: [Configuration]
@@ -147,6 +149,8 @@ paths:
147149
$ref: '#/components/schemas/ServiceConfig'
148150
'401':
149151
$ref: '#/components/responses/Unauthorized'
152+
'403':
153+
$ref: '#/components/responses/Forbidden'
150154
'404':
151155
$ref: '#/components/responses/NotFound'
152156
put:

0 commit comments

Comments
 (0)