Skip to content

fix: mark embedded auth type parameters required in OpenRPC - #802

Open
wakqasahmed wants to merge 1 commit into
Universal-Commerce-Protocol:mainfrom
wakqasahmed:fix/issue-787-embedded-auth-type-required
Open

fix: mark embedded auth type parameters required in OpenRPC#802
wakqasahmed wants to merge 1 commit into
Universal-Commerce-Protocol:mainfrom
wakqasahmed:fix/issue-787-embedded-auth-type-required

Conversation

@wakqasahmed

Copy link
Copy Markdown

Fixes #787.

The Embedded Protocol prose defines the ec.auth/ep.cart.auth authorization request type as REQUIRED, but the OpenRPC content descriptors for both methods omitted "required": true. Under OpenRPC an omitted required defaults to false, so downstream generators produced an optional type param, contradicting the normative prose and permitting requests a conforming embedded context should never send.

Added scripts/test_embedded_auth_required.py, a small contract test asserting both descriptors stay required: true (verified it fails against the pre-fix schema and passes after).

I read AGENTS.md's note that core schema edits may need an Enhancement Proposal -- treating this as a straightforward correction to match already-published normative prose rather than a new/breaking change, per how the issue itself describes it, but happy to follow whatever process the maintainers prefer if they see it differently.

Fixes Universal-Commerce-Protocol#787.

The Embedded Protocol prose defines the ec.auth/ep.cart.auth
authorization request 'type' as REQUIRED, but the OpenRPC content
descriptors for both methods omitted "required": true. Under OpenRPC
an omitted required defaults to false, so downstream generators
produced an optional type param, contradicting the normative prose.

Added a small contract test that fails if either descriptor drifts
from required=true again.
@damaz91 damaz91 added the status:needs-triage Signal that the PR is ready for human triage label Sep 3, 2026
@carolinerg1 carolinerg1 added status:under-review and removed status:needs-triage Signal that the PR is ready for human triage labels Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: mark embedded auth type parameters required in OpenRPC

3 participants