Repository navigation
feat: Require the API key on every /api/v1/ endpoint - #8
Merged
Merged
Conversation
The hosted instance served coverage, drift, impact, and the task queue to anyone, and the api_v1 writes (claim, complete, conflict actions) never checked a key at all. require_api_key now guards all of them; /api/docs/, /api/openapi.json, and the landing page stay open. The six api.py reads declare requires_auth so the spec shows the lock.
Code Impact AnalysisComparing: Changed Files (5)
Affected Requirements (18)
Affected Modules (17)
Affected Projects (1)
EvidenceEdges carrying this change — annotated: 47 | contract: 0 | inferred: 4 | dependency: 0 Affected Tests (77)pytest spectrace/requirements/tests/test_api_v1_results.py::test_detect_conflicts__excludes_structured_when_false
pytest spectrace/requirements/tests/test_api_v1_results.py::test_detect_conflicts__handles_empty_body
pytest spectrace/requirements/tests/test_api_v1_results.py::test_detect_conflicts__passes_custom_params
pytest spectrace/requirements/tests/test_api_v1_results.py::test_detect_conflicts__rejects_invalid_json
pytest spectrace/requirements/tests/test_api_v1_results.py::test_detect_conflicts__returns_results
pytest spectrace/requirements/tests/test_api_v1_results.py::test_get_conflict__returns_404_for_unknown
pytest spectrace/requirements/tests/test_api_v1_results.py::test_get_conflict__returns_detail
pytest spectrace/requirements/tests/test_api_v1_results.py::test_latest_run__filters_by_source
pytest spectrace/requirements/tests/test_api_v1_results.py::test_latest_run__returns_404_when_empty
pytest spectrace/requirements/tests/test_api_v1_results.py::test_latest_run__returns_latest
pytest spectrace/requirements/tests/test_api_v1_results.py::test_list_conflicts__filters_by_confidence
pytest spectrace/requirements/tests/test_api_v1_results.py::test_list_conflicts__filters_by_pattern
pytest spectrace/requirements/tests/test_api_v1_results.py::test_list_conflicts__filters_by_requirement_id
pytest spectrace/requirements/tests/test_api_v1_results.py::test_list_conflicts__filters_by_resolved
pytest spectrace/requirements/tests/test_api_v1_results.py::test_list_conflicts__rejects_invalid_limit…and 62 more. Informed-consent gate: this comment warns, it does not block the merge. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The hosted instance served coverage, drift, impact, and the task queue to anyone, and the api_v1 writes (claim, complete, conflict detect/resolve) never checked a key at all.
require_api_keynow guards all 20/api/v1/views;/api/docs/,/api/openapi.json, and the landing page stay open. WithSPECTRACE_API_KEYunset, dev mode still bypasses with a warning, so local workflows and the test suite run unchanged.requires_auth=True, so the OpenAPI spec now shows the lock on 9 operations.docs/integration.mdstates the new rule.X-API-KeyandBearer, dev-mode bypass, and the public surface staying open.Verified
pytest: 1287 passed.After merge
Fly already holds
SPECTRACE_API_KEY, so afly deployputs the gate live; agents and CI holding the key are unaffected.🤖 Generated with Claude Code
https://claude.ai/code/session_01S5JK8c9t5YJWcgD7Jsoo6t