Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion bkg/v2/BKG_v2.0.0.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,8 @@ info:
name: Digital Container Shipping Association (DCSA)
url: 'https://dcsa.org'
email: info@dcsa.org
security: []
security:
- bearerAuth: []
Comment on lines +59 to +60

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

1. Clients receive conflicting authentication 🐞 Bug ≡ Correctness

security now makes bearer authentication mandatory for every 2.0.0 operation without changing the
published API version, while every subsequent 2.0.x contract still declares security: [].
Consumers regenerating against 2.0.0 or moving among patch releases therefore receive incompatible
authentication requirements and must alter integration behavior despite using the same API
generation.
Agent Prompt
## Issue description
Adding mandatory bearer authentication only to the published 2.0.0 specification creates an incompatible contract relative to versions 2.0.1 through 2.0.5, all of which explicitly disable security.

## Fix Focus Areas
- bkg/v2/BKG_v2.0.0.yaml[59-60]
- bkg/v2/BKG_v2.0.0.yaml[2249-2253]
- bkg/v2/README.md[56-86]

## Recommended Fix
Do not mutate the released 2.0.0 authentication contract in place. Restore its existing security declaration and introduce mandatory authentication through a properly versioned release, updating the currently supported specification and release documentation consistently.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

tags:
- name: Booking
description: Booking endPoints to be implemented by **providers** of the Booking API
Expand Down Expand Up @@ -2245,6 +2246,11 @@ paths:
errorCodeText: Max Notifications reached
errorCodeMessage: A maximum of 10 Notifications can be created per hour
components:
securitySchemes:
bearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
headers:
API-Version:
schema:
Expand Down