Bogireddy Gnanendra Reddy
06/18/2024, 5:54 AMMatt (pactflow.io / pact-js / pact-go)
Bogireddy Gnanendra Reddy
06/18/2024, 6:56 AMHi @Matt (pactflow.io / pact-js / pact-go) Thanks for the response. openapi: 3.0.3
info:
title: Reqres - OpenAPI 3.0
version: 1.0.0
servers:
- url: '<https://reqres.in/api>'
paths:
/register:
post:
tags:
- register
operationId: register
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/Register'
responses:
'200':
description: Successful operation
content:
application/json:
schema:
$ref: '#/components/schemas/RegisterResponse'
components:
schemas:
Register:
type: object
properties:
username:
type: string
example: username
email:
type: string
example: john.doe@email.com
password:
type: string
example: password
object:
$ref: '#/components/schemas/InnerRequestObject'
additionalProperties: false
InnerRequestObject:
type: object
properties:
street:
type: string
example: 305 Joe st
Postcode:
type: number
example: 54679
additionalProperties: false
RegisterResponse:
type: object
properties:
error:
type: string
example: string
securitySchemes:
openId: # <--- Arbitrary name for the security scheme. Used to refer to it from elsewhere.
type: openIdConnect
openIdConnectUrl: <https://example.com/.well-known/openid-configuration>
security:
- openId: []Bogireddy Gnanendra Reddy
06/18/2024, 7:01 AMMatt (pactflow.io / pact-js / pact-go)
Bogireddy Gnanendra Reddy
06/18/2024, 7:14 AMTy
06/18/2024, 7:31 AMsecurity definition? Since it applies to all operations/requests by default. I think this would mean Authorization is expected, even if this header is not explicitly defined per operationBogireddy Gnanendra Reddy
06/18/2024, 7:45 AMMatt (pactflow.io / pact-js / pact-go)
Matt (pactflow.io / pact-js / pact-go)
But when we send Authentication headers in consumer contract validation succeeded. If we specify any other header in the consumer contract other than Authentication it is getting faileditās not ignoring the Auth header, itās checking that one exists, without checking the contents of it. Itās erroring on other headers (presumably) as they are not defined in the OAS. Iād need to see the errors though
Bogireddy Gnanendra Reddy
06/18/2024, 7:53 AMMatt (pactflow.io / pact-js / pact-go)
Ty
06/18/2024, 8:30 AMsecurity definition creates an expectation for an Authorization header but it is not being treated as a hard requirement, so contract comparison is passing regardless of whether the consumer's contract contains it or notBogireddy Gnanendra Reddy
06/18/2024, 8:31 AMTy
06/18/2024, 8:48 AMparameters:
- name: Authorization
in: header
required: true
schema:
type: string
While this would probably fix the contract test(s), I'm not 100% sure what else it will impact (e.g. testing through the Swagger Editor made awkward)
There may be a better way though, so hopefully someone more familiar than me can provide a more elegant solution šBogireddy Gnanendra Reddy
06/18/2024, 9:03 AMMatt (pactflow.io / pact-js / pact-go)
Matt (pactflow.io / pact-js / pact-go)
Bogireddy Gnanendra Reddy
06/18/2024, 11:09 AMBogireddy Gnanendra Reddy
06/18/2024, 11:13 AMI do have have one more issue while validating above openapi spec file with below consumer contract {
"provider": {
"name": "example-provider"
},
"consumer": {
"name": "example-consumer"
},
"interactions": [
{
"description": "description",
"providerState": "provider state",
"request": {
"method": "POST",
"path": "/register",
"headers": {
"Content-Type": "application/json; charset=utf-8"
},
"body": {
"username": "username",
"email": "<mailto:john.doe@email.com|john.doe@email.com>",
"password": "password",
"Key": "Value",
InnerRequestObject: {
"Street": "305 Joe st",
"Postcode": 54679
}
},
"matchingRules": {
"headers": {
"$.Content-Type": {
"match": "regex",
"regex": "/^application/json; charset=utf-8$/"
}
}
}
},
"response": {
"status": 200
}
}
],
"metadata": {
"pactSpecificationVersion": "2.0.0"
}
}Bogireddy Gnanendra Reddy
06/18/2024, 11:15 AMBogireddy Gnanendra Reddy
06/18/2024, 11:17 AMMatt (pactflow.io / pact-js / pact-go)
Matt (pactflow.io / pact-js / pact-go)
Bogireddy Gnanendra Reddy
06/18/2024, 1:40 PMBogireddy Gnanendra Reddy
06/20/2024, 9:10 AMMatt (pactflow.io / pact-js / pact-go)
additionalProperties: true is allowed on request bodies, as this supports Postelās law.
> it may lead to in comaptible issue in production
No, not necessarily. The real problem is that your OAS (in the example, at least) is not very well defined. As all the fields are optional, this indeed could cause problems in production because any properties will pass that test. What you should do, is define schemas with the minimal required fields - this would fail the comparison, but for the right reasons.
Additional properties in the request arenāt problematic (you can choose to disable this of course), but what is problematic is if the consumer doesnāt send the minimum right properties in the request. The real issue is that your Pact contract doesnāt match the schema, and that your OAS isnāt enforcing the schema itself (via required).
Hereās how to fix itā¦
The real issue is that your Pact contract doesnāt match the schema, and that your OAS isnāt enforcing the schema itself (via required).
Your example:
{
"username": "username",
"email": "john.doe@email.com",
"password": "password",
"Key": "Value",
"InnerRequestObject": {
"Street": "305 Joe st",
"Postcode": 54679
}
}
Correct example:
{
"username": "username",
"email": "john.doe@email.com",
"password": "password",
"object": {
"street": "305 Joe st",
"postcode": 54679
}
}
Setting required properties on the schemas:
components:
schemas:
Register:
type: object
required:
- username
- email
- password
- object
properties:
username:
type: string
example: username
email:
type: string
example: john.doe@email.com
password:
type: string
example: password
object:
$ref: '#/components/schemas/InnerRequestObject'
InnerRequestObject:
type: object
required:
- street
- postcode
properties:
street:
type: string
example: 305 Joe st
postcode:
type: number
example: 54679
Example error if object is not provided, even with additional properties being sent:
Request body is incompatible with the request body schema in the spec file: must have required property 'object'Bogireddy Gnanendra Reddy
06/20/2024, 12:00 PM