You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[Optional] Sponsorship to speed up the bug fix or feature request (example)
Description
The Go client generator does not enforce string property constraints declared with enum or not: { enum: [...] } when unmarshaling generated models. In particular, a model whose kind property excludes "known" accepts that value. This makes oneOf variants overlap even though the schemas are mutually exclusive.
openapi-generator version
Reproduced with a local 7.26.0-SNAPSHOT CLI before PR #25089. That PR was based on upstream commit 271e4dd6e6d. The current latest master has not been retested separately.
The spec passes openapi-generator-cli validate with no validation errors. The CLI reports only recommendations that the three models are unused because the spec has no paths.
Unmarshal {"kind":"known"} into the generated Other model. It is accepted (err == nil) even though Other.kind declares not: { enum: [known] }. Known also accepts {"kind":"other"} (err == nil) despite its allowed enum.
Unmarshal {"kind":"known"} into TaggedUnion. The generated oneOf handling returns data matches more than one schema in oneOf(TaggedUnion).
Expected behavior: Known accepts {"kind":"known"} and rejects another string value; Other rejects {"kind":"known"} and accepts {"kind":"other"}. The oneOf value should therefore match only one variant.
Validation should also preserve optional properties, nullable enum semantics, and untyped not: enum behavior. JSON property names should be matched case-insensitively, as Go encoding/json does when unmarshaling structs.
Related issues/PRs
Related Java report: #25065. Related Python report: #25069. Go fix: #25089.
Suggest a fix
Use the allowed enum and nested not enum values retained in Go codegen property metadata to generate validation before model unmarshaling. Reject excluded values while preserving the existing UnmarshalJSON paths for required and additionalProperties models.
The proposed PR includes focused generator coverage for allowed and excluded string values, nullable and optional properties, quoted values, typed and untyped not: enum, case-insensitive property names, and validating UnmarshalJSON generation. Generated Go code compiles and passes runtime checks with go test ./....
Bug Report Checklist
Description
The Go client generator does not enforce string property constraints declared with
enumornot: { enum: [...] }when unmarshaling generated models. In particular, a model whosekindproperty excludes"known"accepts that value. This makesoneOfvariants overlap even though the schemas are mutually exclusive.openapi-generator version
Reproduced with a local
7.26.0-SNAPSHOTCLI before PR #25089. That PR was based on upstream commit271e4dd6e6d. The current latestmasterhas not been retested separately.OpenAPI declaration file content or url
The spec passes
openapi-generator-cli validatewith no validation errors. The CLI reports only recommendations that the three models are unused because the spec has no paths.Generation Details
Generator:
go, with default options.Steps to reproduce
{"kind":"known"}into the generatedOthermodel. It is accepted (err == nil) even thoughOther.kinddeclaresnot: { enum: [known] }.Knownalso accepts{"kind":"other"}(err == nil) despite its allowed enum.{"kind":"known"}intoTaggedUnion. The generatedoneOfhandling returnsdata matches more than one schema in oneOf(TaggedUnion).Expected behavior:
Knownaccepts{"kind":"known"}and rejects another string value;Otherrejects{"kind":"known"}and accepts{"kind":"other"}. TheoneOfvalue should therefore match only one variant.Validation should also preserve optional properties, nullable enum semantics, and untyped
not: enumbehavior. JSON property names should be matched case-insensitively, as Goencoding/jsondoes when unmarshaling structs.Related issues/PRs
Related Java report: #25065. Related Python report: #25069. Go fix: #25089.
Suggest a fix
Use the allowed enum and nested
notenum values retained in Go codegen property metadata to generate validation before model unmarshaling. Reject excluded values while preserving the existingUnmarshalJSONpaths for required andadditionalPropertiesmodels.The proposed PR includes focused generator coverage for allowed and excluded string values, nullable and optional properties, quoted values, typed and untyped
not: enum, case-insensitive property names, and validatingUnmarshalJSONgeneration. Generated Go code compiles and passes runtime checks withgo test ./....