Skip to content

AD-10125 Update Swagger 2.2 - #18

Merged
OBPeteS merged 3 commits into
mainfrom
MLA-v2.2
Oct 1, 2026
Merged

OBPeteS merged 3 commits into
mainfrom
MLA-v2.2

Conversation

@MichalZawilski

Copy link
Copy Markdown

No description provided.

@MichalZawilski
MichalZawilski marked this pull request as draft September 24, 2026 11:15
@OBPeteS
OBPeteS requested a lite review from Copilot September 28, 2026 14:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Resolve the documented security discovery, error schema, ETag, and UUID validation issues.

Review effort: Lite
Findings: 3 Medium severity

Open (3)
What changed in this PR

Updates the MLA Participant API specification from v2.1 to v2.2 for Raidiam Connect.

Changes:

  • Updates servers, endpoint path, authentication, and scopes.
  • Adds conditional polling, ETags, 304 Not Modified, and interaction IDs.
  • Refines response schemas, examples, and validation.
File Summary
MLAPartcipantAPI/​mla-participant.yaml Defines the v2.2 MLA Participant API contract.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread MLAPartcipantAPI/mla-participant.yaml
Comment thread MLAPartcipantAPI/mla-participant.yaml
Comment thread MLAPartcipantAPI/mla-participant.yaml Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Environment-specific authentication and required response-header semantics are not represented correctly in the machine-readable contract.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
Resolved since last review (3)
Previously missed (1)

In code that hasn't changed since last review

Low severity Mark guaranteed 304 interaction ID header as required

MLAPartcipantAPI/​mla-participant.yaml:134

This 304 contract says the interaction ID is always echoed or generated, but the header remains optional by default in OpenAPI. Add required: true to match that guarantee.

This issue also appears in the following locations of the same file:

  • line 142
  • line 152
  • line 168

Comment on lines +147 to +148
WWW-Authenticate:
$ref: '#/components/headers/WWWAuthenticate'

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed that this would be left as optional

Comment on lines +9 to +12
This is the participant-facing extract of the MLA Status operation as served by Raidiam
Connect. It is the same operation, request shape, response structure and error responses
as the legacy `/v2.1/organisation/mlastatus` endpoint; what moves is the hostname, the
token issuer and the version prefix.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed to preserve as-is

@OBPeteS
OBPeteS marked this pull request as ready for review October 1, 2026 13:46
@OBPeteS
OBPeteS merged commit b654a34 into main Oct 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants