Skip to content

Commit 3825298

Browse files
AshGodfreyclaude
andauthored
revert: bump speakeasy-core/client-sdk-go (#2117) — restores registry auth (#2120)
## Why CLI **v1.795.2** breaks `speakeasy tag promote` for customers using registry tagging in CI (reported by Unkey): ``` Error: {"message":"err_unauthorized: unauthorized -- bearer token missing","status_code":403} Error: failed to tag registry images: error running speakeasy tag: ... speakeasy tag promote ``` **This is not a security exposure** — the server still enforces auth (`MustHaveConsistentWorkspaceIDClaimHTTP`). It's a spec/codegen defect: the client stopped *sending* credentials. `v1.795.1..v1.795.2` changes only `go.mod`/`go.sum`, and the operative line is `speakeasy-client-sdk-go/v3 v3.26.7 -> v3.27.0`. ## What broke v3.27.0 was the first regeneration of that SDK since 2025-05-06. It picked up a registry spec defect live since March: `openapi_artifacts.yaml` and `openapi_subscriptions.yaml` declare no top-level `security`, so once `speakeasy merge` began pushing global security down onto individual operations (#1952, registry#4559), their 13 operations composed as `security: []`. The generated SDK therefore dropped `utils.PopulateSecurity` from **all 11 Artifacts and both Subscriptions operations**. Verified against a local test server, identical calling code: | Operation | v3.26.7 | v3.27.0 | |---|---|---| | `Artifacts.PostTags` | `X-Api-Key` sent | **no auth header** | | `Artifacts.GetRevisions` | `X-Api-Key` sent | **no auth header** | | `Workspaces.Get` (control) | `X-Api-Key` sent | `X-Api-Key` sent | Affected CLI paths: `registry/tagging.go` -> `Artifacts.PostTags` (powers `tag promote`, `tag apply`, `ci tag`) and `internal/remote/sources.go:153` -> `Artifacts.GetRevisions`. This went unnoticed for five months because the other consumers (webapp, admin SDK) authenticate via `credentials: 'include'` cookies, so a missing security parameter is invisible to them. The header-authenticated public Go SDK was frozen by a broken regen since May 2025 — so it kept shipping correct pre-March code until now. ## Why revert rather than fix forward - Customers tracking `speakeasyVersion: latest` pick this up automatically; the breakage is spreading. - The real fix spans three repos (registry spec -> SDK regen -> CLI bump) and can't land quickly. - #2117 was explicit groundwork — "No behaviour change in this PR" — and what it enables (openapi-generation#55) is **still open**, so this gives up no live functionality. ## Verification - `go build ./...` — clean - `go test ./registry/... ./pkg/merge/...` — pass - Resolved deps back to `client-sdk-go v3.26.7` / `speakeasy-core v0.22.2`; all 11 `PopulateSecurity` calls restored ## Follow-up 1. Cut **v1.795.3** — the revert only helps once released. 2. Add top-level `security` to `openapi_artifacts.yaml` + `openapi_subscriptions.yaml` in speakeasy-registry. `openapi_admin.yaml` has the same defect (36 ops, no impact today). 3. Re-land #2117 on a fixed v3.27.1. 4. Consider a warning in `pkg/merge` when `setExplicitNoSecurity` marks operations unsecured — it silently performs a security-downgrading transform, which is what let this ship. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
1 parent 5c2f293 commit 3825298

2 files changed

Lines changed: 10 additions & 15 deletions

File tree

go.mod

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -50,14 +50,14 @@ require (
5050
github.com/speakeasy-api/openapi-generation/v2 v2.932.10
5151
github.com/speakeasy-api/sdk-gen-config v1.58.0
5252
github.com/speakeasy-api/speakeasy-agent-mode-content v0.2.12
53-
github.com/speakeasy-api/speakeasy-client-sdk-go/v3 v3.27.0
54-
github.com/speakeasy-api/speakeasy-core v0.23.0
53+
github.com/speakeasy-api/speakeasy-client-sdk-go/v3 v3.26.7
54+
github.com/speakeasy-api/speakeasy-core v0.22.2
5555
github.com/speakeasy-api/versioning-reports v0.7.0
5656
github.com/spf13/cobra v1.10.2
5757
github.com/spf13/pflag v1.0.9
5858
github.com/spf13/viper v1.19.0
5959
github.com/stoewer/go-strcase v1.3.1
60-
github.com/stretchr/testify v1.12.1
60+
github.com/stretchr/testify v1.12.0
6161
go.uber.org/zap v1.28.0
6262
goa.design/goa/v3 v3.24.1
6363
golang.org/x/oauth2 v0.36.0
@@ -233,7 +233,6 @@ require (
233233
github.com/spewerspew/spew v0.0.0-20230513223542-89b69fbbe2bd // indirect
234234
github.com/spf13/afero v1.11.0 // indirect
235235
github.com/spf13/cast v1.7.1 // indirect
236-
github.com/spyzhov/ajson v0.8.0 // indirect
237236
github.com/subosito/gotenv v1.6.0 // indirect
238237
github.com/swaggest/jsonschema-go v0.3.79 // indirect
239238
github.com/swaggest/refl v1.4.0 // indirect
@@ -263,7 +262,6 @@ require (
263262
go.opentelemetry.io/otel/trace v1.45.0 // indirect
264263
go.opentelemetry.io/proto/otlp v1.11.0 // indirect
265264
go.uber.org/multierr v1.11.0 // indirect
266-
go.yaml.in/yaml/v3 v3.0.5 // indirect
267265
go.yaml.in/yaml/v4 v4.0.0-rc.3 // indirect
268266
golang.org/x/crypto v0.54.0 // indirect
269267
golang.org/x/exp v0.0.0-20250620022241-b7579e27df2b // indirect

go.sum

Lines changed: 7 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -558,10 +558,10 @@ github.com/speakeasy-api/sdk-gen-config v1.58.0 h1:JrDgDU3XBIidv+TXFqYBvIomfeGEQ
558558
github.com/speakeasy-api/sdk-gen-config v1.58.0/go.mod h1:kD0NPNX5yaG4j+dcCpLL0hHKQbFk6X93obp+v1XlK5E=
559559
github.com/speakeasy-api/speakeasy-agent-mode-content v0.2.12 h1:dGONbW8WLNc4uSox1/k8O4JFggHoQy1v6R9cLqbTf5M=
560560
github.com/speakeasy-api/speakeasy-agent-mode-content v0.2.12/go.mod h1:AiZRZLL+sv9uwtTHIECc1dcTgfJrXrEB5QxcAGifMkI=
561-
github.com/speakeasy-api/speakeasy-client-sdk-go/v3 v3.27.0 h1:+nqvrNB9bpBN2UEC7lbEIJnpcNfg229mGH0sRK+Ebvc=
562-
github.com/speakeasy-api/speakeasy-client-sdk-go/v3 v3.27.0/go.mod h1:e1tYglmfstiLCAZaAbkVxkZ7NKM6ZTL2tlqTRaa6U+s=
563-
github.com/speakeasy-api/speakeasy-core v0.23.0 h1:QhyPovIUhLzl/97yJmLTqYEe3vVPVBU4XyRL9rlMC08=
564-
github.com/speakeasy-api/speakeasy-core v0.23.0/go.mod h1:2tl8YXzZCDlAxaPvF4ILBsWpzgGg+1ZA4XH7+Vwcnh0=
561+
github.com/speakeasy-api/speakeasy-client-sdk-go/v3 v3.26.7 h1:SoWZkRlpFlv8qibCfXWrBZay1JeLS9uqJ+1cu+DFgXo=
562+
github.com/speakeasy-api/speakeasy-client-sdk-go/v3 v3.26.7/go.mod h1:k9JD6Rj0+Iizc5COoLZHyRIOGGITpKZ2qBuFFO8SqNI=
563+
github.com/speakeasy-api/speakeasy-core v0.22.2 h1:hWJjOQVQ8GKIpqQLQYmQ54td5O5N25GD9KZ496L/Enk=
564+
github.com/speakeasy-api/speakeasy-core v0.22.2/go.mod h1:584TlOBtX4Bks5cwrbo1OPjzP3YMvzgH/NK1HKBqoo0=
565565
github.com/speakeasy-api/versioning-reports v0.7.0 h1:Q2uI1RrEiOkuudoILSu7Mtkg8+ObT/hZakAG9CD+8f0=
566566
github.com/speakeasy-api/versioning-reports v0.7.0/go.mod h1:LW5FABrvi5SBbeiD3HJYw0JZYe6Rw2Xna59pFJ2BmLI=
567567
github.com/spewerspew/spew v0.0.0-20230513223542-89b69fbbe2bd h1:csraKifkLpqDClUIbFTetjtraueL1KUhKBm6okL+ug4=
@@ -576,8 +576,6 @@ github.com/spf13/pflag v1.0.9 h1:9exaQaMOCwffKiiiYk6/BndUBv+iRViNW+4lEMi0PvY=
576576
github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
577577
github.com/spf13/viper v1.19.0 h1:RWq5SEjt8o25SROyN3z2OrDB9l7RPd3lwTWU8EcEdcI=
578578
github.com/spf13/viper v1.19.0/go.mod h1:GQUN9bilAbhU/jgc1bKs99f/suXKeUMct8Adx5+Ntkg=
579-
github.com/spyzhov/ajson v0.8.0 h1:sFXyMbi4Y/BKjrsfkUZHSjA2JM1184enheSjjoT/zCc=
580-
github.com/spyzhov/ajson v0.8.0/go.mod h1:63V+CGM6f1Bu/p4nLIN8885ojBdt88TbLoSFzyqMuVA=
581579
github.com/stoewer/go-strcase v1.3.1 h1:iS0MdW+kVTxgMoE1LAZyMiYJFKlOzLooE4MxjirtkAs=
582580
github.com/stoewer/go-strcase v1.3.1/go.mod h1:fAH5hQ5pehh+j3nZfvwdk2RgEgQjAoM8wodgtPmh1xo=
583581
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
@@ -594,8 +592,8 @@ github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/
594592
github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
595593
github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU=
596594
github.com/stretchr/testify v1.8.1/go.mod h1:w2LPCIKwWwSfY2zedu0+kehJoqGctiVI29o6fzry7u4=
597-
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
598-
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
595+
github.com/stretchr/testify v1.12.0 h1:K6Mr6jO9JICuend/5xzTM03ydSV3vdNRYAdPSukj8uI=
596+
github.com/stretchr/testify v1.12.0/go.mod h1:bOYBZb5qJ00vPzWfIqBUZPaxK8jWiXc6d3ErP4Ca9Gw=
599597
github.com/subosito/gotenv v1.6.0 h1:9NlTDc1FTs4qu0DDq7AEtTPNw6SVm7uBMsUCUjABIf8=
600598
github.com/subosito/gotenv v1.6.0/go.mod h1:Dk4QP5c2W3ibzajGcXpNraDfq2IrhjMIvMSWPKKo0FU=
601599
github.com/swaggest/assertjson v1.9.0 h1:dKu0BfJkIxv/xe//mkCrK5yZbs79jL7OVf9Ija7o2xQ=
@@ -682,9 +680,8 @@ go.uber.org/multierr v1.11.0 h1:blXXJkSxSSfBVBlC76pxqeO+LN3aDfLQo+309xJstO0=
682680
go.uber.org/multierr v1.11.0/go.mod h1:20+QtiLqy0Nd6FdQB9TLXag12DsQkrbs3htMFfDN80Y=
683681
go.uber.org/zap v1.28.0 h1:IZzaP1Fv73/T/pBMLk4VutPl36uNC+OSUh3JLG3FIjo=
684682
go.uber.org/zap v1.28.0/go.mod h1:rDLpOi171uODNm/mxFcuYWxDsqWSAVkFdX4XojSKg/Q=
683+
go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
685684
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
686-
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
687-
go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg=
688685
go.yaml.in/yaml/v4 v4.0.0-rc.3 h1:3h1fjsh1CTAPjW7q/EMe+C8shx5d8ctzZTrLcs/j8Go=
689686
go.yaml.in/yaml/v4 v4.0.0-rc.3/go.mod h1:aZqd9kCMsGL7AuUv/m/PvWLdg5sjJsZ4oHDEnfPPfY0=
690687
goa.design/goa/v3 v3.24.1 h1:BRCgMM+8bniJCHmsGxHSOwbz4KqnEVWyL2rb+Xo3rUo=

0 commit comments

Comments
 (0)