You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Non-blocking findings from the review of #1766 (the Scheduling externalReferences and appointment listing work). Line numbers refer to 8ae9467.
SEC-08's primary negative test now runs only in the merge queue. It moved from a database-free test to a Postgres-only one (products/scheduling/contracts/security-invariant-matrix.yaml:151), and PR CI does not run that suite by default. Keep a database-free refusal test alongside it.
The OpenAPI schema doesn't publish the runtime's limits.ExternalReference in products/scheduling/generated/registry-scheduling.openapi.json:472 omits the identifier pattern the runtime enforces and the per-appointment item bound, so clients cannot validate either before sending.
Non-blocking findings from the review of #1766 (the Scheduling
externalReferencesand appointment listing work). Line numbers refer to 8ae9467.products/scheduling/contracts/security-invariant-matrix.yaml:151), and PR CI does not run that suite by default. Keep a database-free refusal test alongside it.ExternalReferenceinproducts/scheduling/generated/registry-scheduling.openapi.json:472omits the identifier pattern the runtime enforces and the per-appointment item bound, so clients cannot validate either before sending.GET /v1/appointmentslists only the caller's own bookings. That matches the README, but scheduling: link an appointment to a Casework case (externalReferences) #1764 frames it as "a case can find its appointments": another principal working the same case cannot find them. Decide whether that is the intended scope and document it.