Release API Tools 0.2.0
Verify / verify (push) Canceled after 0s

This commit is contained in:
2026-09-02 10:18:45 +02:00
parent fbcd0e56d6
commit 98d1ff4afc
35 changed files with 2483 additions and 147 deletions
+21 -3
View File
@@ -2,11 +2,29 @@
The shell lazy-loads a React workbench. Pure core modules parse and validate
JSON-like values, hold a named in-memory document map, resolve only relative
local references, collect operations, derive bounded examples, compare
operation contracts and summarize saved exchanges. No module exposes a request
executor.
local references, collect OpenAPI HTTP operations or AsyncAPI channels,
send/receive operations and messages, derive bounded examples, compare
operation contracts and summarize saved exchanges. OpenAPI 3.2 fixed `query`
and bounded custom `additionalOperations` method tokens are retained. OpenAPI
3.1/3.2 webhook Path Items are inventoried and compared as receiver operations;
their names do not declare real delivery URLs, so examples use an explicit
placeholder and HAR matching excludes them. AsyncAPI 3.x root
operation/channel/message references and the older 2.x
publish/subscribe channel shape have separate, explicit adapters. HAR validation matches
captured URLs to the most specific path template, checks required parameters,
status and media declarations, and applies a bounded JSON Schema subset to
available JSON bodies. It emits only locations and messages: captured header
and body values never enter the report. No module exposes a request executor.
JSON uses hardened shared helpers. YAML is converted with bounded alias count
and then recursively checked for depth, node count, dangerous keys and plain
JSON values. Rendering uses React text nodes and read-only textareas. The
same-origin service worker caches only packaged application resources.
Contract checking is limited to 2,000 exchanges, 100,000 schema evaluation
steps, 5,000 diagnostics, 2 MiB per decoded JSON body, local references, and a
focused type/composition/object/array/scalar subset. It is evidence and coverage
analysis rather than a claim of complete OpenAPI conformance. AsyncAPI bindings,
traits, correlation expressions and multi-format schemas are inventoried as
inert data; only JSON-Schema-like payload/header objects receive heuristic
sample generation.
+12 -7
View File
@@ -1,12 +1,17 @@
# Privacy and security
Descriptions and exchanges remain in memory and are never transmitted or
persisted. All remote/absolute `$ref` forms fail closed. Displayed URLs are text,
not links. There is no Try It button, OAuth flow, DNS lookup, HTTP execution,
telemetry or external asset.
persisted. All remote/absolute `$ref` forms fail closed. Displayed URLs, broker
hosts, channel addresses, protocol bindings, and generated commands are text,
not live controls. There is no Try It button, broker connection, subscription,
publish action, OAuth flow, DNS lookup, HTTP execution, telemetry, or external
asset.
HAR and saved exchanges commonly contain tokens, cookies, personal data and
payloads. The summary does not render header values, yet the source editor still
contains them. Clear it before sharing. Generated examples are heuristic and
must not be treated as valid production data. Validation and compatibility
checks cover a useful subset, not every OpenAPI or JSON Schema rule.
payloads. Header and cookie values may be used transiently to check parameter
presence and shape, and JSON bodies may be parsed for local schema checks, but
the summary and contract report never retain or render those values. The source
editor still contains the original capture; clear it before sharing. Generated
examples are heuristic and must not be treated as valid production data.
Validation and compatibility checks cover a useful bounded subset, not every
OpenAPI or JSON Schema rule.