Skip to content

Follow-ups to #285: API-only banner points to a CDN-backed /api/docs, banner test not strict, 405 Allow ignores bare /api #300

Description

@dborup

Nits from the review of #285 (#281, merged as 72cc29cf). Details are in the review comment on #285.

  1. F1 — the banner points to a page that may not load. cmd/server/main.go (~662): the API-only banner now points to /api/docs. That page is a Swagger UI shell whose CSS and JS load only from an external CDN (openapi.go ~1039/1049). API-only deployments may have no outbound internet, so consider naming /api/spec (the raw OpenAPI document) as well, or instead.
  2. F2 — the banner test does not tie the URL to the banner. TestAPIOnlyBannerPointsToExistingEndpoint checks that the body contains /api/docs and then fetches the literal /api/docs. Extract the URL from the banner and fetch that, so a banner that only mentions /api/docs in passing cannot pass.
  3. F3 — latent: allowedMethodsForPath ignores bare /api. In cmd/server/api_fallback.go (~73), it filters on strings.HasPrefix(path, "/api/"), which excludes exactly /api. The shadow check now covers bare /api, but the 405/Allow computation does not. Add the case and a test.

Activity

  1. added 2 commits that reference this issue on Oct 7, 2026
  2. dborup commented on Oct 7, 2026

    @dborup
    OwnerAuthor

    Fixed by #320 (merged as 6444294d938083f6d935d0445c27bc6a7bbf360e).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesttype:choreMaintenance, refactoring, cleanup

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions