Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion bkg/v2/BKG_v2.0.0.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,8 @@ info:
name: Digital Container Shipping Association (DCSA)
url: 'https://dcsa.org'
email: info@dcsa.org
security: []
security:
- BearerAuth: []
Comment on lines +59 to +60

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

1. Valid integrations lose authentication choice 🐞 Bug ≡ Correctness

The root security requirement makes JWT bearer authentication mandatory for every operation,
including the consumer-hosted /v2/booking-notifications callback whose subscription setup is
explicitly outside this specification. Integrations using another bilateral authentication mechanism
therefore conflict with this isolated 2.0.0 contract, while every subsequent Booking 2.0.x
specification continues to declare no standardized security mechanism.
Agent Prompt
## Issue description
The root security declaration incorrectly mandates JWT bearer authentication across all Booking operations and consumer-hosted notification callbacks, although authentication arrangements are outside this technology-agnostic specification.

## Fix Focus Areas
- bkg/v2/BKG_v2.0.0.yaml[59-60]
- bkg/v2/BKG_v2.0.0.yaml[2249-2253]

## Recommended Fix
Restore the root `security: []` declaration and remove the `BearerAuth` security scheme. Authentication must be enforced by each implementation or standardized separately with all supported mechanisms and endpoint roles defined.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

tags:
- name: Booking
description: Booking endPoints to be implemented by **providers** of the Booking API
Expand Down Expand Up @@ -2245,6 +2246,11 @@ paths:
errorCodeText: Max Notifications reached
errorCodeMessage: A maximum of 10 Notifications can be created per hour
components:
securitySchemes:
BearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
headers:
API-Version:
schema:
Expand Down