Skip to content

add openapi spec to manifests and link from element to manifest - #314

Merged
slashburygin merged 1 commit into
masterfrom
openapi_spec
May 6, 2026
Merged

add openapi spec to manifests and link from element to manifest#314
slashburygin merged 1 commit into
masterfrom
openapi_spec

Conversation

@slashburygin

Copy link
Copy Markdown
Contributor

No description provided.

@slashburygin
slashburygin force-pushed the openapi_spec branch 2 times, most recently from 8963b29 to 31f3997 Compare May 1, 2026 04:23

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the OpenAPI specifications by adding openapi_spec and manifest fields, introducing new resource schemas, and removing several required fields across various models. It also upgrades the restalchemy dependency and includes a database migration. The core logic is modified to support dynamic schema construction from external URLs. A critical security vulnerability was identified in the build_full_schema function, which is susceptible to Server-Side Request Forgery (SSRF) due to insufficient validation of fetched specifications.

Comment thread exordos_core/elements/dm/utils.py
@slashburygin
slashburygin force-pushed the openapi_spec branch 11 times, most recently from 0a6be19 to c670a7e Compare May 5, 2026 13:16
@slashburygin
slashburygin merged commit d61fd14 into master May 6, 2026
16 checks passed
@slashburygin
slashburygin deleted the openapi_spec branch May 6, 2026 05:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants