You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix(api): approve/cancel/RI-approve openapi describes token-only and omits responses; test gaps from #507 #528
The OpenAPI spec still describes purchase approve, cancel and RI-exchange approve as token-only and omits responses. Several test and doc gaps came out of the #507 review.
internal/api/openapi.yaml:493-517approvePurchase and :519-545cancelPurchase: "Token-based ... does not require session auth or CSRF", security: [], token query parameter required: true, no session mode, no 401/403/409.
internal/api/openapi.yaml:1064-1080approveRIExchange: summary says "token-based, no session required", no 401/403/409.
The email revoke routes (internal/api/router.go:171-172, /api/purchases/revoke/{token}) are not in the spec.
No approve-path test for an out-of-scope session plus token reaching the contact-email gate; only cancel and revoke cover it.
Stale doc comment at internal/api/handler_purchases_test.go:3259-3264 on TestHandler_cancelPurchase_Session_RejectsEachNonCancelableStatus: it says "admin session" and "the guard fires before authorizeSessionCancel".
The spec documents session and token modes with 401/403/409 for these routes and the email revoke route, the missing test exists, the comment is corrected, and the dead helpers are removed or wired.
Summary
The OpenAPI spec still describes purchase approve, cancel and RI-exchange approve as token-only and omits responses. Several test and doc gaps came out of the #507 review.
Location (origin/main 496d9d7)
internal/api/openapi.yaml:493-517approvePurchaseand:519-545cancelPurchase: "Token-based ... does not require session auth or CSRF",security: [], token query parameterrequired: true, no session mode, no 401/403/409.internal/api/openapi.yaml:1064-1080approveRIExchange: summary says "token-based, no session required", no 401/403/409.internal/api/router.go:171-172,/api/purchases/revoke/{token}) are not in the spec.internal/api/handler_purchases_test.go:3259-3264onTestHandler_cancelPurchase_Session_RejectsEachNonCancelableStatus: it says "admin session" and "the guard fires before authorizeSessionCancel".Handler.authenticate(internal/api/middleware.go:100) andcheckUserAPIKey(:219) have no production callers (sec(api): /api/info is prefix-matched as public, so authentication is skipped for /api/info/deployment #192).Context
From the #507 review. Related: #262.
Acceptance
The spec documents session and token modes with 401/403/409 for these routes and the email revoke route, the missing test exists, the comment is corrected, and the dead helpers are removed or wired.