fix(spec): add app condition to AuthenticatorEnrollmentPolicyRuleCond…#1682
Merged
prachi-okta merged 1 commit intomasterfrom Mar 6, 2026
Merged
Conversation
…itions, fix NetworkZoneLocationArray indentation, restructure OAuth2ClientJsonWebKey discriminator with allOf/oneOf
543de9e to
5c077cc
Compare
aniket-okta
approved these changes
Mar 4, 2026
|
@prachi-okta Please raise an issue on OAS3 and mention the link here as well. Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix(spec): correct OpenAPI spec issues in api.yaml
Summary
Four spec fixes across
AuthenticatorEnrollmentPolicyRuleConditions,NetworkZoneLocationArray,OAuth2ClientJsonEncryptionKeyRequest, andOAuth2ClientJsonSigningKeyRequest.Changes
1.
AuthenticatorEnrollmentPolicyRuleConditions— add missingappfieldThe
appcondition was present in other policy rule condition schemas (e.g.OktaSignOnPolicyRuleConditions) but was missing fromAuthenticatorEnrollmentPolicyRuleConditions, making it impossible to set app-scoped conditions on authenticator enrollment policy rules.2.
NetworkZoneLocationArray— fixinclude/excludeproperty descriptionsincludeandexcludehad their$refanddescriptionas sibling keys, which is invalid OpenAPI (a$refignores all siblings). Wrapped inallOfso the description is properly applied alongside the referenced schema.3.
OAuth2ClientJsonEncryptionKeyRequest— add missingalgfieldThe
addJwkendpoint uses aoneOfofOAuth2ClientJsonSigningKeyRequestandOAuth2ClientJsonEncryptionKeyRequest. The code generator merges properties from both into theAddJwkRequestwrapper class. Becausealgwas absent from the encryption key schema, it was dropped from the merged class — causingMissingMethodExceptionfailures inApplicationSSOPublicKeysITwhen calling.alg("RSA-OAEP").4.
OAuth2ClientJsonSigningKeyRequest— fixdiscriminatorandrequiredindentationdiscriminatorandrequiredwere incorrectly nested inside theproperties:block (treated as property names by the parser). Moved both to schema level so the OpenAPI code generator correctly generates Java inheritance forOAuth2ClientJsonWebKeyRsaRequestandOAuth2ClientJsonWebKeyECRequest. The now-redundantktyoverrides in the sub-schemas were removed to avoid incompatible return type errors in the generated Java.