Add configurable OpenAPI security schemes and API version documentation - #153
Merged
vrslev merged 10 commits intoOct 5, 2026
Merged
Conversation
added 6 commits
September 30, 2026 13:14
Mernus
marked this pull request as draft
October 1, 2026 09:11
vrslev
marked this pull request as ready for review
October 1, 2026 10:09
vrslev
marked this pull request as draft
October 1, 2026 10:09
vrslev
approved these changes
Oct 1, 2026
Mernus
marked this pull request as ready for review
October 1, 2026 10:42
Codecov Report✅ All modified and coverable lines are covered by tests.
Flags with carried forward coverage won't be shown. Click here to find out more.
🚀 New features to boost your workflow:
|
Mernus
force-pushed
the
feature/openapi-security-schemes-version-documentation
branch
from
October 5, 2026 08:51
6d956fa to
8d991d2
Compare
Contributor
Author
|
Simplified Litestar security-scheme conversion, inlined version-extension validation, and removed single-use test fixtures. Fixed FastAPI OpenAPI augmentation for schemas without paths and with Paths Object extensions, plus Litestar bootstrap with OpenAPI disabled. Added regression coverage for pathless schemas, unsupported security-scheme models, and disabled version documentation. |
vrslev
approved these changes
Oct 5, 2026
vrslev
deleted the
feature/openapi-security-schemes-version-documentation
branch
October 5, 2026 15:43
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add optional OpenAPI configuration for FastAPI and Litestar:
x-accept-versioningextension.microbootstrap's version-documentation additions.
Both features are disabled by default and configured through the existing
Swagger settings and instrument lifecycle.
Security schemes
Configured definitions are merged into
components.securitySchemeswithoutreplacing existing components or security requirements. Identical definitions
are accepted; conflicting definitions raise
ValueError.Consumers can annotate their settings with the concrete scheme classes they
use. Python field names and OpenAPI aliases are supported.
This does not add authentication enforcement or global/operation-level
security requirements.
API version documentation
When configured, the vendor media type and supported versions are documented
for each operation. Overrides select an exact path and HTTP method.
FastAPI delegates lazily to the application's original OpenAPI generator.
Litestar extends standard
Operationobjects and rejects unsupported customoperation subclasses rather than silently discarding their fields.
Repeated schema reads do not duplicate documentation. This does not implement
runtime version negotiation, add an
Acceptparameter, change response mediatypes or introduce a Swagger UI version selector.
Compatibility updates
>=0.100>=0.110.1>=6.1>=7.1>=2.9>=2.21.1~=0.6.2>=0.6.7,<0.8The updated bounds reflect tested compatibility:
custom_labelsAPI already used by theexisting integration.
ASGIMiddlewareAPI and selects a tested framework/telemetry combination.
The FastStream adapter also omits the positional broker argument when no broker
is supplied, while forwarding a configured broker normally.
Consumers pinned below these bounds must update their dependency graph.
These bounds do not imply exhaustive validation of every permitted combination.
Validation
Python 3.12.7 environment with Litestar 2.24.0 and 2.21.1.