Nits from the review of #285 (#281, merged as 72cc29cf). Details are in the review comment on #285.
- F1 — the banner points to a page that may not load.
cmd/server/main.go (~662): the API-only banner now points to /api/docs. That page is a Swagger UI shell whose CSS and JS load only from an external CDN (openapi.go ~1039/1049). API-only deployments may have no outbound internet, so consider naming /api/spec (the raw OpenAPI document) as well, or instead.
- F2 — the banner test does not tie the URL to the banner.
TestAPIOnlyBannerPointsToExistingEndpoint checks that the body contains /api/docs and then fetches the literal /api/docs. Extract the URL from the banner and fetch that, so a banner that only mentions /api/docs in passing cannot pass.
- F3 — latent:
allowedMethodsForPath ignores bare /api. In cmd/server/api_fallback.go (~73), it filters on strings.HasPrefix(path, "/api/"), which excludes exactly /api. The shadow check now covers bare /api, but the 405/Allow computation does not. Add the case and a test.
Nits from the review of #285 (#281, merged as
72cc29cf). Details are in the review comment on #285.cmd/server/main.go(~662): the API-only banner now points to/api/docs. That page is a Swagger UI shell whose CSS and JS load only from an external CDN (openapi.go~1039/1049). API-only deployments may have no outbound internet, so consider naming/api/spec(the raw OpenAPI document) as well, or instead.TestAPIOnlyBannerPointsToExistingEndpointchecks that the body contains/api/docsand then fetches the literal/api/docs. Extract the URL from the banner and fetch that, so a banner that only mentions/api/docsin passing cannot pass.allowedMethodsForPathignores bare/api. Incmd/server/api_fallback.go(~73), it filters onstrings.HasPrefix(path, "/api/"), which excludes exactly/api. The shadow check now covers bare/api, but the 405/Allowcomputation does not. Add the case and a test.