fix: allow user-token deletion of encoded item keys - #39
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
All reviewed changes are covered by passing contract validation and regression tests.
Review effort: Lite
Findings: None
What changed in this PR
Updates the OpenAPI contract to support user-token deletion of encoded keys while preserving consumer-token validation.
Changes:
- Makes
operatoroptional for applicable deletion routes. - Adds regression coverage and documentation.
- Bumps the contract version to
0.3.12and updates the changelog.
| File | Description |
|---|---|
tests/test_user_token_contract.py |
Verifies optional operator handling for both deletion routes. |
CHANGELOG.md |
Records the fix in version 0.3.12. |
apollo-openapi.yaml |
Updates the contract version and encoded deletion parameter documentation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
User-token requests to delete keys containing
/or\fail during Spring parameter binding because the encoded-items DELETE contract requiresoperator. Ordinary-key deletion already allows the server to resolve the operator from the token owner.Make the encoded DELETE query parameter optional, document the user-token and consumer-token behavior, and add a contract regression test for both deletion routes. Bump the document version to
0.3.12and record the fix in the changelog. Consumer tokens still require an explicit operator in Apollo's existing validation logic.Validation:
./generate.sh --verifypassed.