Skip to content

test: crawl every documented OpenAPI path through createApp - #1409

Open
dev-Vortex51 wants to merge 1 commit into
CalloraOrg:mainfrom
dev-Vortex51:security/issue-1321-crawl-every-documented-openapi-path-through
Open

dev-Vortex51 wants to merge 1 commit into
CalloraOrg:mainfrom
dev-Vortex51:security/issue-1321-crawl-every-documented-openapi-path-through

Conversation

@dev-Vortex51

Copy link
Copy Markdown

Overview

This PR makes the OpenAPI runtime contract test exercise the assembled application rather than isolated routers. It builds createApp() and issues a request for every path documented in docs/openapi.json, failing when a documented path returns 404, and warning about mounted-but-undocumented paths.

Related Issue

Changes

🧪 Runtime contract coverage

  • [MODIFY] tests/contract/openapi-runtime.test.ts

    • Builds the app via createApp() and iterates over every documented path in docs/openapi.json.
    • Asserts each documented path returns a non-404 status, so routers that are documented but never mounted (e.g. forecast, tenants, feature flags, refunds counts) are caught.
    • Emits warnings for mounted paths that are not documented, without failing the suite.
    • Runs in the unit suite without requiring Postgres.
  • [MODIFY] scripts/validate-openapi-contract.mjs

    • Aligns the static contract validation with the runtime crawl so npm run validate:openapi stays green and reports the same documented-path set.

Verification Results

npm test -- tests/contract/openapi-runtime.test.ts
npm run validate:openapi
Acceptance Criteria Status
Every documented path returns a non-404 status from createApp ✅ Runtime test requests each documented path via createApp()
Undocumented but mounted paths are listed as warnings ✅ Warnings emitted without failing the suite
The test runs in the unit suite without Postgres ✅ No DB dependency in the runtime crawl
npm run validate:openapi remains green ✅ Script aligned with the runtime path set

Security and Failure Modes

  • No safeguards are weakened: the test only adds coverage and does not relax existing assertions.
  • 404s on documented paths fail loudly, surfacing unmounted routers instead of silently passing.
  • Undocumented mounted paths are reported as warnings to avoid blocking on non-contract routes.

Compatibility

  • Test-only and script changes; no runtime behavior, API surface, or dependency changes.

Closes #1321

@dev-Vortex51

Copy link
Copy Markdown
Author

@greatest0fallt1me Please review and merge

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Crawl every documented OpenAPI path through createApp

1 participant