Skip to content

fix(api): approve/cancel/RI-approve openapi describes token-only and omits responses; test gaps from #507 #528

Description

@cristim

Summary

The OpenAPI spec still describes purchase approve, cancel and RI-exchange approve as token-only and omits responses. Several test and doc gaps came out of the #507 review.

Location (origin/main 496d9d7)

  • internal/api/openapi.yaml:493-517 approvePurchase and :519-545 cancelPurchase: "Token-based ... does not require session auth or CSRF", security: [], token query parameter required: true, no session mode, no 401/403/409.
  • internal/api/openapi.yaml:1064-1080 approveRIExchange: summary says "token-based, no session required", no 401/403/409.
  • The email revoke routes (internal/api/router.go:171-172, /api/purchases/revoke/{token}) are not in the spec.
  • No approve-path test for an out-of-scope session plus token reaching the contact-email gate; only cancel and revoke cover it.
  • Stale doc comment at internal/api/handler_purchases_test.go:3259-3264 on TestHandler_cancelPurchase_Session_RejectsEachNonCancelableStatus: it says "admin session" and "the guard fires before authorizeSessionCancel".
  • Handler.authenticate (internal/api/middleware.go:100) and checkUserAPIKey (:219) have no production callers (sec(api): /api/info is prefix-matched as public, so authentication is skipped for /api/info/deployment #192).

Context

From the #507 review. Related: #262.

Acceptance

The spec documents session and token modes with 401/403/409 for these routes and the email revoke route, the missing test exists, the comment is corrected, and the dead helpers are removed or wired.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions