Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,7 @@ class OasResourceRenderer constructor(val api: Api, val vrapTypeProvider: VrapTy
| parameters:
| <<${method.queryParameters.joinToString("\n") { renderQueryParameter(method,it) }}>>""" else ""}${if (method.bodies.any { it.type != null }) """
| requestBody:
| content:
| <<${bodies.joinToString("\n") { renderBody(it, method) } }>>""" else ""}${if (annotations.isNotEmpty()) """
| <<${annotations.joinToString("\n") { it.renderAnnotation() }} >>""" else ""}
| responses:
Expand Down Expand Up @@ -126,14 +127,12 @@ class OasResourceRenderer constructor(val api: Api, val vrapTypeProvider: VrapTy
// val bodyExamples = requestExamples(body, method)
if (body.type is FileType) {
return """
|content:
| "*/*":
| schema:
| type: string
""".trimMargin().keepAngleIndent()
}
return """
|content:
| ${body.contentType}:${if (body.type != null) """
| schema:
| <<${body.type.renderAnyType()}>>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -127,4 +127,30 @@ class TestCodeGenerator {
Assertions.assertThat(dataSink.files.get("openapi.yaml")?.trim())
.isEqualTo("src/test/resources/fixtures/array-response.yaml".readFile())
}

@Test
fun multipartBodyRender() {
val generatorConfig = CodeGeneratorConfig(
basePackageName = "com/commercetools/importer",
outputFolder = Paths.get("build/gensrc-multipart")
)

val apiProvider = RamlApiProvider(Paths.get("src/test/resources/multipart-body-test.raml"))

val dataSink = MemoryDataSink()
val generatorModule = RamlGeneratorModule(apiProvider, generatorConfig, OasBaseTypes, dataSink = dataSink)
val generatorComponent = RamlGeneratorComponent(generatorModule, OasModelModule)
generatorComponent.generateFiles()

Assertions.assertThat(dataSink.files).hasSize(1)

Assertions.assertThat(
DiffUtils.diff(
"src/test/resources/fixtures/multipart-body.yaml".readFileLines(),
dataSink.files.get("openapi.yaml")?.trim()?.lines(),
).deltas).`as`("openapi.yaml").isEmpty()

Assertions.assertThat(dataSink.files.get("openapi.yaml")?.trim())
.isEqualTo("src/test/resources/fixtures/multipart-body.yaml".readFile())
}
}
45 changes: 45 additions & 0 deletions languages/oas/src/test/resources/fixtures/multipart-body.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
openapi: "3.0.0"

Check failure on line 1 in languages/oas/src/test/resources/fixtures/multipart-body.yaml

View check run for this annotation

Orca Security (EU) / Orca Security - Infrastructure as Code

[HIGH] Global Security Field Is Undefined

Details: OpenAPI specifications without a global security field may expose API endpoints without authentication or authorization controls, allowing unrestricted access. Define a global security requirement referencing schemes from securitySchemes to ensure baseline protection across all paths. Recommendation: A default security property should be defined
info:
title: Multipart Body Test API
version: "v1"

servers:
- url: https://example.com/{version}

Check warning on line 7 in languages/oas/src/test/resources/fixtures/multipart-body.yaml

View check run for this annotation

Orca Security (EU) / Orca Security - Infrastructure as Code

[INFO] Server URL Uses Undefined Variables

Details: Server URLs containing variables must declare those variables in the Server Object's 'variables' field. Undefined variables break API specification compliance and prevent proper URL template substitution. Define all URL template variables within the corresponding Server Object. Recommendation: servers.{{0}}.url uses server object variables defined in the server object variables

paths:
/test:
post:

Check warning on line 11 in languages/oas/src/test/resources/fixtures/multipart-body.yaml

View check run for this annotation

Orca Security (EU) / Orca Security - Infrastructure as Code

[LOW] No Global And Operation Security Defined

Details: OpenAPI specifications without security requirements at either the global or operation level lack authentication and authorization controls, allowing unrestricted access to API endpoints. Define security schemes globally or per operation to protect resources from unauthorized use. Recommendation: A security schema should be used
operationId: TestPost
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/TestRequest'

multipart/form-data:
schema:
$ref: '#/components/schemas/TestMultipartRequest'

Comment thread
Copilot marked this conversation as resolved.
responses:

Check warning on line 23 in languages/oas/src/test/resources/fixtures/multipart-body.yaml

View check run for this annotation

Orca Security (EU) / Orca Security - Infrastructure as Code

[LOW] Response Code Missing (v3)

Details: OpenAPI operations lack standard HTTP response codes for error handling and security scenarios. Missing response definitions prevent proper API documentation, client error handling, and security response patterns. Define appropriate response codes for each operation type based on HTTP standards and security requirements. Recommendation: 429 response should be set
"200":
description: |-
200
content: {}

Check warning on line 27 in languages/oas/src/test/resources/fixtures/multipart-body.yaml

View check run for this annotation

Orca Security (EU) / Orca Security - Infrastructure as Code

[LOW] Response on operations that should have a body has undefined schema

Details: OpenAPI responses for operations that return data must define a schema or content type. Without response schemas, API consumers cannot parse responses correctly, leading to integration failures and potential security issues from mishandled data. Define response schemas for all non-empty responses. Recommendation: paths.{{/test}}.{{post}}.responses.{{200}}.content should have at least one content-type defined

components:

Check warning on line 29 in languages/oas/src/test/resources/fixtures/multipart-body.yaml

View check run for this annotation

Orca Security (EU) / Orca Security - Infrastructure as Code

[MEDIUM] Field 'securityScheme' On Components Is Undefined

Details: OpenAPI 3.0 specifications lack defined security schemes in the components section, preventing standardized authentication and authorization enforcement across API operations. Without security schemes, APIs cannot enforce consistent access controls. Define security schemes in the components section and apply them to operations. Recommendation: A security scheme on components should be defined

schemas:
TestRequest:

Check warning on line 32 in languages/oas/src/test/resources/fixtures/multipart-body.yaml

View check run for this annotation

Orca Security (EU) / Orca Security - Infrastructure as Code

[INFO] Schema Has A Required Property Undefined

Details: OpenAPI schema objects list required properties that are not defined in the properties section, causing validation failures and API contract inconsistencies. Define all required fields within the schema properties to ensure valid specifications. Recommendation: Schema should have all required properties defined
type: "object"
required:
- prompt
properties:
prompt:
type: "string"
TestMultipartRequest:

Check warning on line 39 in languages/oas/src/test/resources/fixtures/multipart-body.yaml

View check run for this annotation

Orca Security (EU) / Orca Security - Infrastructure as Code

[INFO] Schema Has A Required Property Undefined

Details: OpenAPI schema objects list required properties that are not defined in the properties section, causing validation failures and API contract inconsistencies. Define all required fields within the schema properties to ensure valid specifications. Recommendation: Schema should have all required properties defined
type: "object"
required:
- prompt
properties:
prompt:
type: "string"
25 changes: 25 additions & 0 deletions languages/oas/src/test/resources/multipart-body-test.raml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
#%RAML 1.0
title: Multipart Body Test API
baseUri: https://example.com/{version}
version: v1
mediaType: application/json

types:
TestRequest:
type: object
properties:
prompt: string
TestMultipartRequest:
type: object
properties:
prompt: string

/test:
post:
body:
application/json:
type: TestRequest
multipart/form-data:
type: TestMultipartRequest
responses:
200:
Loading