Skip to content

fix(openapi): bind wildcard path parameters safely - #2197

Closed
gkze wants to merge 1 commit into
UsefulSoftwareCo:mainfrom
gkze:codex/openapi-wildcard-path
Closed

gkze wants to merge 1 commit into
UsefulSoftwareCo:mainfrom
gkze:codex/openapi-wildcard-path

Conversation

@gkze

@gkze gkze commented Oct 7, 2026

Copy link
Copy Markdown

Summary

OpenAPI operations with router-style {*identifier} templates expose identifier as an input, but invocation leaves the wildcard unresolved. Bind the declared name, preserve slash separators, and encode each segment. Reject literal . and .. segments before URL normalization can escape the operation prefix; ordinary and reserved-expansion parameters keep their existing behavior.

Verification

  • OpenAPI package: 353 tests passed across 53 files, including 16 wildcard regression cases. Before the fix, wildcard invocation reproduced Unresolved path parameters: *identifier.
  • OpenAPI package and e2e typechecks passed; repository lint and format checks passed.
  • Selfhost e2e OpenAPI · wildcard paths execute with the declared parameter passed against an isolated published service emulator: imported schema, sandbox execution returning HTTP 200, missing input rejection, and traversal rejection. Browser recording and Playwright trace captured locally. They are not uploaded because the trace contains the emulator instance capability URL.
  • Added a patch changeset. Full monorepo tests/typecheck and hosted deployment verification have not been run.

Scope

Only wildcard request construction changes. No spec importer/reference-resolution changes, source overrides, connection configuration, routing, or credentials are modified.

@RhysSullivan

Copy link
Copy Markdown
Collaborator

We're clearing the backlog ahead of the v2 launch, so we're closing this. If it still applies to v2, please open a new issue or PR against v2.

Sent from my Claude

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants