Skip to content

feat(python-flask): add opt-in Connexion 3 support - #24181

Merged
wing328 merged 4 commits into
OpenAPITools:masterfrom
Shaun-3adesign:feature/python-flask-connexion3
Jul 2, 2026
Merged

wing328 merged 4 commits into
OpenAPITools:masterfrom
Shaun-3adesign:feature/python-flask-connexion3

Conversation

@Shaun-3adesign

@Shaun-3adesign Shaun-3adesign commented Jul 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds an opt-in useConnexion3 boolean option (default false) to the python-flask server generator, giving users a way to generate Connexion-3-based servers instead of the current Connexion 2 pin. Addresses #17303, which has been open since Dec 2023 with the maintainer repeatedly inviting a contribution and several community members posting partial working fixes in the thread.

Also fixes #15062 (docs never explained why this generator uses Connexion instead of vanilla Flask) — bundled in since it's a one-line addition to a PR already touching this generator's help text. #21294 (operationId double-underscore breaking Connexion's resolver) is a different root cause and is left for its own PR.

Kept as an opt-in flag rather than a default bump, matching this repo's existing convention for breaking generator-output changes (useJackson3, useSpringBoot3/4).

Security motivation (verified, not assumed)

One commenter on #17303 specifically asked for this because staying on Connexion 2 blocks upgrading past a vulnerable Werkzeug. I ran pip-audit against the actual resolved dependency tree for both paths to check this concretely:

Flask Werkzeug Vulnerabilities found
v2 (current default) 2.1.1 2.2.3 10 real CVEs, including the exact one raised in the thread (CVE-2024-34069), plus CVE-2024-49766, CVE-2024-49767, CVE-2025-66221, CVE-2026-21860, CVE-2026-27199, CVE-2026-27205, PYSEC-2023-62, PYSEC-2023-221 (×2)
v3 (useConnexion3) 3.1.3 3.1.8 Zero — the only pip-audit hits in either scan are in pip/wheel themselves (base image tooling, not app dependencies)

What changes under the flag

  • requirements.mustache / setup.mustache: connexion[flask,swagger-ui,uvicorn]>=3.3.0,<4.0.0 + Flask>=2.2.0,<4.0.0 (floor pinned to 3.3.0, not 3.0.0, since that's the only version actually run/verified here, and the first with official Python 3.13/3.14 support). swagger-ui-bundle bumped to >=1.1.0 to match the floor Connexion's own extra already silently requires. The default (v2) path also gets an upper bound added to setup.py's connexion pin (<=2.14.2, matching requirements.txt) so pip install . can't silently resolve Connexion 3 onto Connexion-2-only code.
  • main.mustache: connexion.App → connexion.FlaskApp; JSON encoding moves from a Flask.json_encoder attribute (removed in v3) to a Jsonifier(cls=...) passed into add_api().
  • encoder.mustache: JSONEncoder becomes a plain json.JSONEncoder subclass instead of extending Connexion 2's removed FlaskJSONEncoder. Restored Flask's own datetime/date/Decimal/UUID handling explicitly (werkzeug.http.http_date() + str(...)) so date-time-typed model fields still serialize instead of raising TypeError — plain json.JSONEncoder has no support for these types at all.
  • CORS (featureCORS): flask_cors.CORS(app.app) silently does nothing under Connexion 3 — Connexion 3 wraps Flask in its own ASGI middleware stack, so requests can be handled before ever reaching flask-cors. Replaced with Connexion 3's documented app.add_middleware(CORSMiddleware, ...) from starlette.middleware.cors (already a Connexion dependency, no new package needed). allow_credentials is left at its default (False) to match flask-cors's own default — combining it with a wildcard origin is a CORS anti-pattern.
  • __init__test.mustache: Connexion 3's app.test_client() returns an httpx/Starlette client, not Flask's WSGI one. Added a small adapter so the existing self.client.open(...)/self.assert200(...) calls in controller_test.mustache keep working unchanged. Also drops flask_testing.TestCase (unmaintained since 2020, not Flask-3-compatible).
  • PythonFlaskConnexionServerCodegen.java: skip-marks (via the same x-skip-test mechanism the parent class already uses for other Connexion limitations) the generated test for any operation with multiple response content types, since Connexion 3 requires the handler to specify which one to return and the auto-generated stub doesn't — see CI section below.
  • One unconditional fix (applies to both v2 and v3 output): controller.mustache swaps connexion.request.is_json/.get_json() for Flask's own import flask / flask.request.*, since Connexion 3's connexion.request is now a Starlette Request and no longer exposes those methods. Module-qualified access (rather than from flask import request) avoids a parameter named request shadowing the import.

CI coverage

Added .github/workflows/samples-python-flask-connexion3-server.yaml, mirroring the existing samples-python-fastapi-server.yaml pattern, to actually install and run the generated sample's own test suite on every change to that folder. Getting this genuinely green (rather than shipping a red CI job) surfaced two real, honestly-documented limitations, both skip-marked with clear reasons in the generated tests: operations with multiple response content types (inherent Connexion 3 behavior change for stub controllers, not fixable at the template level), and a pre-existing, version-agnostic bug where the auto-generated test example for an array-typed request body is a single item instead of an array.

Verification

  • mvn -pl modules/openapi-generator -am package — compiles clean.
  • Full repo CI "Unit tests" command run verbatim: 4493 tests, 0 failures, 0 errors, 7 skipped.
  • bin/generate-samples.sh (all ~766 generators, no args) run twice — zero diff outside files intentionally touched.
  • Built and ran the generated useConnexion3: true sample's own Dockerfile: server starts, serves /v2/openapi.json, returns correct 401 on an auth-protected route, and correctly serializes a real returned model instance (including a real datetime field) end-to-end via direct HTTP request.
  • Verified CORS works correctly (and safely) after the fix: Access-Control-Allow-Origin: * present on a real response, without Access-Control-Allow-Credentials.
  • Established a genuine Connexion-2 baseline (separate Python 3.11 container — the generated Dockerfile's python:3-alpine floats to Python 3.14, which breaks even the unmodified v2 sample for unrelated reasons) to fairly compare test results between v2 and v3.
  • Replicated the new CI workflow's exact steps locally: 8 passed, 13 skipped, 0 failed.

Known gaps (not fixed here, flagged for visibility)

  • Separately discovered, unrelated to Connexion version: generating python-flask through any config with an additionalProperties block changes some */*-consumes skip-marking behavior for a couple of operations (reproduces even with useConnexion3: false). Worth its own issue/investigation; out of scope here.

Fixes #15062

Test plan

  • CI "Samples up-to-date" passes
  • CI "Unit tests" passes
  • New "Python Flask (Connexion 3) Server" workflow passes
  • Maintainer confirms useConnexion3 opt-in approach is acceptable per the contributing guidelines note on avoiding excessive generator options

Adds a new `useConnexion3` boolean generator option (default: false) to
the python-flask server generator, addressing OpenAPITools#17303. Connexion 3 has
been out since 2023, but requirements.mustache explicitly pinned
`connexion<=2.14.2` and `Flask==2.1.1` to avoid it, blocking users from
picking up newer Flask/Werkzeug (one comment on the issue specifically
cited this as blocking a CVE fix in werkzeug). The maintainer has
repeatedly invited a contribution on the thread since Dec 2023, and
several community members had already prototyped working fixes in the
comments.

Kept as an opt-in flag rather than a default bump, following this
repo's existing convention for breaking generator-output changes
(useJackson3, useSpringBoot3/4).

What changes under the flag, and why:
- requirements.mustache / setup.mustache: swap the Connexion 2/Flask
  2.1.1 pins for `connexion[flask,swagger-ui,uvicorn]>=3.3.0,<4.0.0` +
  `Flask>=2.2.0,<4.0.0`. The uvicorn extra is required because
  Connexion 3's `FlaskApp.run()` launches via uvicorn even for Flask
  apps -- confirmed by actually running the generated server, which
  fails at startup without it. The connexion floor is 3.3.0 (not just
  the first 3.0.0 release) because that's the only version we've
  actually run and verified, and it's also the first release with
  official Python 3.13/3.14 support per Connexion's own release notes.
  swagger-ui-bundle is bumped to >=1.1.0 to match the floor Connexion's
  own swagger-ui extra already silently requires.
- __main__.mustache: `connexion.App` -> `connexion.FlaskApp`, and the
  JSON encoder moves from a `Flask.json_encoder` attribute assignment
  (removed in v3) to a `Jsonifier(cls=...)` passed into `add_api()`.
- encoder.mustache: the generated `JSONEncoder` becomes a plain
  `json.JSONEncoder` subclass instead of extending Connexion 2's
  `FlaskJSONEncoder` (removed in v3); the `default()` body handling
  `Model.to_dict()` conversion is unchanged. Verified end-to-end (not
  just unit-level): patched a controller to return a real nested
  Pet/Category model instance, ran the actual generated server
  (uvicorn + Flask + Connexion 3) in Docker, and curled it -- got back
  correctly serialized JSON with attribute_map key translation intact
  (photo_urls -> photoUrls).
- __init__test.mustache: Connexion 3's `app.test_client()` returns an
  httpx/Starlette-based client, not Flask's WSGI test client -- so a
  small `_FlaskStyleTestClient`/`_FlaskStyleResponse` adapter is added
  to keep the existing `self.client.open(...)`/`self.assert200(...)`
  calling convention in controller_test.mustache working unchanged.
  Also drops `flask_testing.TestCase`, which is unmaintained since 2020
  and not Flask-3-compatible.
- test-requirements.mustache: drops the `Flask-Testing` pin under the
  flag, since Flask's own test client no longer needs it.
- CORS support (featureCORS): `flask_cors.CORS(app.app)` does not work
  under Connexion 3, because Connexion 3 wraps the Flask app in its own
  ASGI middleware stack and can route/short-circuit requests before
  they ever reach the inner WSGI app flask-cors is watching. Confirmed
  this was actually broken (zero Access-Control-* headers on a real
  request with an Origin header) before fixing it. Replaced with
  Connexion 3's own documented pattern --
  `app.add_middleware(CORSMiddleware, ...)` from
  `starlette.middleware.cors`, which comes for free as a connexion
  dependency, no separate package needed. flask-cors itself is no
  longer installed at all under useConnexion3. Reverified afterwards:
  Access-Control-Allow-Origin and Access-Control-Allow-Credentials both
  present on the response.

One unconditional (non-flag-gated) fix: controller.mustache swaps
`connexion.request.is_json`/`.get_json()` for Flask's own
`from flask import request`. Connexion 3's `connexion.request` is now a
Starlette Request and no longer exposes those Flask-specific methods.
Flask's own `request` object behaves identically under Connexion 2 and
3, so this is applied to both, and is a dependency-reduction as a side
effect. This is the only part of the diff that touches the existing
default sample output.

Also fixes OpenAPITools#15062 (python-flask docs never explained *why* the
generator uses Connexion instead of vanilla Flask) via a `getHelp()`
override scoped to the Flask subclass, bundled in here since it's a
one-line addition to a PR already touching this generator's docs.
OpenAPITools#21294 (operationId double-underscore breaking Connexion's resolver)
is a different root cause and is intentionally left for its own PR.

Security motivation, checked concretely rather than assumed: ran
pip-audit against the full resolved dependency tree for both paths.
v2 (current default, Flask==2.1.1/Werkzeug==2.2.3 as resolved): 10 real
CVEs across Flask+Werkzeug, including the exact one raised in the issue
thread (CVE-2024-34069) plus several more recent ones. v3
(useConnexion3, Flask==3.1.3/Werkzeug==3.1.8 as resolved): zero
vulnerabilities in any actual application dependency (the only
pip-audit hits in either scan are in pip/wheel themselves -- base image
tooling, not part of the app's declared dependencies, identical in both
scans).

Also surfaced, but explicitly NOT fixed here (separate, pre-existing,
unrelated to Connexion version -- reproduces even with
`useConnexion3: false`): generating python-flask through a config file
that has any `additionalProperties` block changes
`postProcessOperationsWithModels`'s `*/*`-consumes skip-marking
behavior for a couple of operations. Worth its own issue/investigation,
out of scope for this PR.

CI coverage: added bin/configs/python-flask-connexion3.yaml alongside
the existing bin/configs/python-flask.yaml, following the same pattern
used for other flag-gated variants (e.g. the *-jackson3.yaml configs),
so the "Samples up-to-date" job continuously verifies the new flag's
generated output.

Verification performed locally (this environment has no JDK/toolchain
installed, so all of the below ran inside Docker containers rather
than bare-metal):
- `mvn -pl modules/openapi-generator -am package` -- compiles clean.
- The full repo's CI "Unit tests" job command, run verbatim
  (`mvn clean --no-snapshot-updates --batch-mode --quiet --fail-at-end
  test`) across the whole reactor: 4493 tests run, 0 failures, 0
  errors, 7 skipped (confirmed via real surefire report files, not just
  the process exit code).
- Full `bin/generate-samples.sh` (all ~766 generators, no args) run
  twice in a row, mirroring the "Samples up-to-date" CI job exactly:
  zero diff outside the files intentionally touched by this change.
- Docs regenerated via `bin/utils/export_generator.sh python-flask`
  (not the full "Docs up-to-date" job across every generator, since
  this change only touches python-flask's own CliOptions/getHelp()).
- Built and ran the generated `useConnexion3: true` sample's own
  Dockerfile; server starts, serves `/v2/openapi.json`, returns a
  correct 401 on an auth-protected route without credentials, and
  correctly serializes a real returned model object end-to-end.
- Established a genuine Connexion-2 baseline in a separate
  Python-3.11 container (the generated Dockerfile's `python:3-alpine`
  base floats to Python 3.14, which breaks even the *unmodified* v2
  sample for unrelated reasons -- old Werkzeug's routing code hits a
  removed `ast.Str` API) to get a fair v2-vs-v3 comparison of the
  generated test suite. Both pass the same 8 real operations; the v3
  run's extra failures are either pre-existing test-fixture/spec bugs
  unrelated to Connexion version (confirmed present on the v2 baseline
  too), or a documented Connexion 3 behavior change where operations
  with multiple response content types require the handler to specify
  which one to return -- inherent to Connexion 3's stricter response
  handling for auto-generated placeholder stubs, not something
  template-level codegen changes can paper over.

Known gap, not fixed here: no CI job actually installs/runs the
generated python-flask server (the existing samples-python-server.yaml
workflow only covers python-aiohttp-srclayout) or the full "Docs
up-to-date" job across every generator, so ongoing regression coverage
for this flag's *runtime* behavior relies on the manual verification
above, not on CI.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

12 issues found across 55 files

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="samples/server/petstore/python-flask-connexion3/openapi_server/models/base_model.py">

<violation number="1" location="samples/server/petstore/python-flask-connexion3/openapi_server/models/base_model.py:64">
P2: The `__eq__` method in `base_model.mustache` directly accesses `other.__dict__`, which will raise `AttributeError` when comparing a `Model` instance to primitives or any object that lacks `__dict__` (e.g., `myModel == 42`). It also treats objects of different classes with matching `__dict__` contents as equal. Adding an `isinstance` guard and returning `NotImplemented` for unsupported types matches Python equality semantics and prevents unexpected runtime crashes in generated server code.</violation>
</file>

<file name="samples/server/petstore/python-flask-connexion3/git_push.sh">

<violation number="1" location="samples/server/petstore/python-flask-connexion3/git_push.sh:57">
P2: Piping `git push` output into `grep -v` masks the actual push exit status because the pipeline's final exit code is determined by `grep`, not `git push`. This can hide push failures (if grep exits 0) or incorrectly report failure (if grep finds nothing to output). Consider capturing the push output first, filtering it, then preserving the original exit code with a small adapter pattern.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread modules/openapi-generator/src/main/resources/python-flask/controller.mustache Outdated
Comment thread samples/server/petstore/python-flask-connexion3/.travis.yml Outdated
Comment thread samples/server/petstore/python-flask-connexion3/git_push.sh
Comment thread docs/generators/python-flask.md Outdated
Comment thread modules/openapi-generator/src/main/resources/python-flask/setup.mustache Outdated
The automated cubic review on PR OpenAPITools#24181 found 12 issues. Checked each
individually against the actual code rather than accepting blindly.
9 were real and are fixed here; 3 are pre-existing bugs in files this
PR never touches, left out of scope (noted below).

Fixed:

- PythonFlaskConnexionServerCodegen.java: guard against a NullPointerException
  if `useConnexion3` is explicitly set to a null value in additionalProperties
  -- use String.valueOf(...) instead of calling .toString() directly on a
  possibly-null Object, matching how the parent class already handles its
  other boolean options (FEATURE_CORS, USE_NOSE).

- __main__.mustache: the Connexion 3 CORS middleware combined
  allow_origins=["*"] with allow_credentials=True. Per the CORS spec this is
  unsafe -- wildcard origin plus credentials lets any site make authenticated
  cross-origin requests on a user's behalf, and newer Starlette releases may
  reject the combination outright at startup. flask-cors's own default
  (supports_credentials=False) never allowed this. Dropped allow_credentials
  to restore parity with the old default. Reverified: CORS still works
  (Access-Control-Allow-Origin: * on a real request), now without the
  credentials risk.

- controller.mustache: `from flask import request` shadows Flask's request
  proxy if a spec has an operation parameter literally named `request` --
  the local parameter would hide the module-level import inside that
  function body. Switched to `import flask` + `flask.request.*`, matching
  the safety Connexion 2's `connexion.request` module-qualified access
  already had.

- encoder.mustache (the serious one): the Connexion 3 encoder's fallback to
  plain `json.JSONEncoder` lost Flask's built-in handling of datetime/date/
  Decimal/UUID values. Generated models routinely hold raw `datetime`
  objects for `date-time`-format fields (e.g. Order.ship_date in the
  Petstore spec itself), and stdlib json has zero support for them --
  `TypeError: Object of type datetime is not JSON serializable` on any
  response containing one. Restored the same handling Flask's own
  DefaultJSONProvider._default provides: `werkzeug.http.http_date()` for
  date/datetime (RFC 2822, matching Flask's actual format -- not ISO 8601,
  to keep serialization output identical between the v2 and v3 paths, not
  just non-crashing), and str() for Decimal/UUID. Verified directly: built
  an Order with a real datetime ship_date and confirmed it now serializes
  instead of raising.

- PythonFlaskConnexionServerCodegen.java / docs/generators/python-flask.md:
  the useConnexion3 option's own description said it changes "pinned
  connexion/Flask/Flask-Testing dependency versions" -- inaccurate,
  Flask-Testing is removed outright under the flag, not re-pinned to a new
  version. Reworded and regenerated the doc.

- travis.mustache: the generated .travis.yml listed Python 3.2-3.8, which
  predates Connexion 3's own minimum (Python >=3.9). `pip install -r
  requirements.txt` would fail on every listed interpreter under
  useConnexion3. Gated a 3.9-3.12 matrix behind the flag.

- setup.mustache (three related issues):
  1. The default (useConnexion3=false) REQUIRES list pinned
     "connexion>=2.0.2" with no upper bound, while requirements.mustache's
     equivalent line correctly caps at <=2.14.2. `pip install .` (as
     opposed to `pip install -r requirements.txt`) could silently resolve
     Connexion 3 even on the untouched v2 path, breaking code that uses
     Connexion-2-only APIs. This was a pre-existing gap (the line itself
     predates this PR), but since this PR is what's actively splitting this
     exact list into two branches, fixing the drive-by inconsistency here
     is in scope and low-risk. Added the same <=2.14.2 ceiling.
  2. The useConnexion3 branch's connexion extras were missing swagger-ui
     (present in requirements.mustache but not here), so `pip install .`
     and `pip install -r requirements.txt` could resolve different
     dependency sets. Added the extra for parity.
  3. The useConnexion3 branch had no explicit Flask constraint, unlike
     requirements.mustache's Flask>=2.2.0,<4.0.0. Added it for the same
     parity reason (even though Connexion's own flask extra already
     transitively requires Flask>=2.2, matching the earlier
     swagger-ui-bundle-floor reasoning: pip would already resolve
     correctly, but the explicit pin keeps setup.py self-documenting and
     consistent with requirements.txt).

Explicitly NOT fixed (pre-existing bugs unrelated to Connexion version, in
files this PR does not otherwise touch -- reviewer found these correctly,
but fixing them here would be unrelated scope creep):

- base_model.mustache's `__eq__` crashes comparing a Model instance to a
  non-Model value (accesses `other.__dict__` unconditionally). Present
  identically in the v2 default output too; this file has no useConnexion3
  branching and was never edited by this PR.
- git_push.sh.mustache pipes `git push` through `grep -v`, masking the
  actual push exit code. Shared boilerplate across many generators, not
  specific to python-flask or Connexion version.
- controller_test.mustache generates a single-object example body for
  array-typed request parameters (create_users_with_array_input /
  create_users_with_list_input), which fails validation. This is the exact
  same pre-existing test-fixture bug already called out in the original PR
  description under "known gaps" -- it's masked under the v2 default output
  because those specific tests are separately skipped for an unrelated
  reason (Connexion's `*/*` consumes limitation), not because the example
  generation is actually correct there.

Reverified after all fixes: existing PythonFlaskConnexionServerCodegenTest
passes, full `bin/generate-samples.sh` run twice produces the same diff
scope with no collateral changes elsewhere, and the generated v3 test suite
still shows the same 9 pre-existing failures / 4 skips as before (no new
regressions from these changes).
@Shaun-3adesign

Copy link
Copy Markdown
Contributor Author

Thanks @cubic-dev-ai — went through all 12 findings individually against the actual code rather than accepting blindly. 9 were real and are fixed in 7b0bbc0; 3 are pre-existing bugs in shared files this PR doesn't otherwise touch, left out of scope:

Fixed:

  • NPE risk in PythonFlaskConnexionServerCodegen.java if useConnexion3 is explicitly null
  • CORS allow_origins=["*"] + allow_credentials=True anti-pattern — dropped credentials to match flask-cors's own default, reverified CORS still works
  • request parameter name-shadowing risk in controller.mustache — switched to module-qualified flask.request
  • The datetime/Decimal/UUID serialization loss in encoder.mustache — this was the most serious one. Confirmed it would genuinely crash (TypeError) on any response containing a date-time-typed field (e.g. the Petstore spec's own Order.ship_date). Restored via werkzeug.http.http_date() + str(), matching Flask's actual DefaultJSONProvider behavior exactly (RFC 2822, not ISO 8601, to keep v2/v3 output identical). Verified directly with a real Order instance.
  • Inaccurate useConnexion3 option description re: Flask-Testing (it's removed, not re-pinned)
  • Stale Python 3.2-3.8 matrix in the generated .travis.yml under useConnexion3 (Connexion 3 needs >=3.9)
  • Three setup.mustache/requirements.mustache parity issues (missing upper bound on the v2 path, missing swagger-ui extra and explicit Flask constraint on the v3 path)

Not fixed (pre-existing, unrelated to Connexion version, out of scope for this PR):

  • base_model.mustache's __eq__ crashing on non-Model comparisons — present identically in the current v2 default output, this file has no useConnexion3 branching and isn't touched by this PR
  • git_push.sh.mustache masking git push's exit code via grep -v — shared boilerplate across many generators, unrelated to this generator or Connexion version
  • The array-vs-object test example bug in create_users_with_array_input/create_users_with_list_input — this is the same pre-existing test-fixture issue already called out in the PR description under "known gaps"; it's masked in the current v2 output only because those tests are separately skipped for an unrelated reason (Connexion's */* consumes limitation)

Reverified after all fixes: existing Java test passes, full bin/generate-samples.sh produces the same diff scope with no collateral changes, and the generated v3 test suite shows the same pre-existing 9 failures/4 skips as before (no new regressions).

@cubic-dev-ai

cubic-dev-ai Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Thanks @cubic-dev-ai — went through all 12 findings individually against the actual code rather than accepting blindly. 9 were real and are fixed in 7b0bbc0; 3 are pre-existing bugs in shared files this PR doesn't otherwise touch, left out of scope:

Fixed:

  • NPE risk in PythonFlaskConnexionServerCodegen.java if useConnexion3 is explicitly null
  • CORS allow_origins=["*"] + allow_credentials=True anti-pattern — dropped credentials to match flask-cors's own default, reverified CORS still works
    ...

@Shaun-3adesign Nice triage — 9 real fixes and 3 clean deferrals looks right to me. Couple of quick observations from reading the patches:

  • encoder.mustache datetime handling — you're right that emulating Flask's own http_date format (RFC 2822) rather than ISO 8601 keeps v2/v3 wire-format identical, which avoids a nasty subtle breakage for anyone relying on response content matching existing snapshots. The werkzeug.http.http_date import is already a transitive dep via Flask too, so no new dependency. Good call.

  • controller.mustache flask.request switch — the module-qualified import flask + flask.request.is_json etc. handles the shadowing issue cleanly. I'd originally suggested this change without that protection, so thanks for catching the name collision risk from my initial review comment.

  • The 3 out-of-scope items — base_model.__eq__ and git_push.sh exit code masking are real bugs but live in shared files with zero useConnexion3 branching, so keeping this PR focused on the flag makes sense. The array-vs-object test fixture bug is also genuinely pre-existing (and called out in your own PR description, so no surprise there).

Everything checks out. The NPE guard in processOpts(), CORS credentials drop, setup.mustache/requirements.mustache parity fixes — all look correct in the diff. And the "same pre-existing 9 failures / 4 skips" revalidation means no new regressions introduced.

If you end up opening a follow-up for any of the pre-existing bugs (the base_model.__eq__ one in particular is a landmine for anyone using model equality), I can take a closer look at those too.

Tip: get faster answers by chatting with cubic’s review copilot in the review UI

Comment thread bin/configs/python-flask-connexion3.yaml
Adds .github/workflows/samples-python-flask-connexion3-server.yaml,
mirroring the existing samples-python-fastapi-server.yaml pattern, to
install the generated useConnexion3 sample's own requirements and run its
generated pytest suite on every change to that folder. This closes the
"known gap" called out in the original PR description: no CI job actually
installs/runs the generated python-flask server (the pre-existing
samples-python-server.yaml only covers python-aiohttp-srclayout).

Getting the generated test suite to actually pass cleanly (rather than
shipping a new CI job that's red from day one) surfaced a real bug in the
skip-marking logic added here:

PythonFlaskConnexionServerCodegen now overrides
postProcessOperationsWithModels to skip-mark, under useConnexion3, the
generated test for any operation that declares multiple response content
types (e.g. both application/xml and application/json, the standard
Petstore convention). Connexion 3 requires the handler to explicitly say
which content type it's returning in that case; the auto-generated stub
controllers don't, so calling them raises a 500
(NonConformingResponseHeaders) until the operation is actually
implemented. This mirrors the exact mechanism the parent class already
uses for other known Connexion limitations (unsupported/multiple
consumes) -- same x-skip-test vendor extension, same
@unittest.skip(reason) rendering in controller_test.mustache. Also
skip-marks the two operations with array-typed request bodies
(createUsersWithArrayInput/ListInput) for a separate, pre-existing,
version-agnostic reason: the auto-generated test example for an
array-typed body is a single item, not an array, which fails request
validation regardless of Connexion version. Under Connexion 2 this
happens to be masked because those same two operations are already
skipped for an unrelated reason (a `*/*` consumes quirk that, for reasons
not fully understood, does not trigger the same way under useConnexion3's
config path); under Connexion 3 the pre-existing example bug surfaces on
its own. Skip-marked with an honest reason rather than left failing or
silently hidden.

Diagnosing why the skip markers weren't showing up in the generated
output at all (despite the Java code demonstrably running and mutating
the right objects, confirmed via temporary debug logging) took a while:
DefaultGenerator never overwrites an api-test-template file
(controller_test.mustache -> test_*_controller.py) that already exists on
disk, specifically so it doesn't clobber a user's own edits to their
generated tests. Since this sample's test files were first generated
many regenerations ago, every run since had been silently skipping them
regardless of any template or codegen changes -- this fix only actually
landed in the committed output after deleting the existing test/
directory once so the next regen would write it fresh. (Supporting files
like __init__test.mustache -> test/__init__.py aren't subject to this
rule, which is why earlier changes to that file always showed up
correctly and this one didn't.)

Also tried and reverted a spec-level fix: adding an explicit `example:`
to the UserArray requestBody in
modules/openapi-generator/src/test/resources/3_0/python-flask/petstore.yaml,
hoping it would override the codegen's auto-synthesized single-object
example for the array-typed body. Verified directly that it made no
difference to the generated test data, so reverted it rather than leave
a no-op change in the spec, and used the skip-marking approach above
instead.

Verified clean end-to-end, replicating the new workflow's exact steps
(Python 3.11, `pip install -r requirements.txt && pip install -r
test-requirements.txt`, `pytest`) in Docker against the final regenerated
sample: 8 passed, 13 skipped, 0 failed. Also reran the existing
PythonFlaskConnexionServerCodegenTest and a full `bin/generate-samples.sh`
double-regen across all 766 generators -- both clean, with the diff
scoped to exactly the files above (confirmed the v2 default sample and
.openapi-generator/FILES manifest are both unaffected, once compared
against the correct post-regeneration steady state rather than a
one-off fresh-generation artifact).

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 5 files (changes from recent commits).

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread .github/workflows/samples-python-flask-connexion3-server.yaml
Review feedback on d06115c: the workflow's paths filters only covered
the sample directory, so a broken edit to the workflow file itself
would never get exercised by CI before merging -- it'd only fail (or
silently no-op) on some future unrelated change to the sample.

Added the workflow's own path to both push and pull_request paths
lists. This isn't a new pattern here: samples-python-petstore.yaml and
a few other existing python sample workflows already self-reference
their own path for the same reason, even though the two workflows this
one was originally modeled on (samples-python-fastapi-server.yaml,
samples-python-server.yaml) don't.
@wing328 wing328 added this to the 7.24.0 milestone Jul 2, 2026
@wing328
wing328 merged commit c36eb37 into OpenAPITools:master Jul 2, 2026
17 checks passed
@wing328

wing328 commented Jul 2, 2026

Copy link
Copy Markdown
Member

thanks for the contribution, which has been merged into master.

@Shaun-3adesign
Shaun-3adesign deleted the feature/python-flask-connexion3 branch July 2, 2026 20:44
MDoevenspeck added a commit to smals-belgium/openapi-generator that referenced this pull request Aug 25, 2026
* Prepare 7.24.0 snapshot (#23972)

* Revert "v7.23.0 release (#23970)"

This reverts commit b9d967acc9a3850cefb961da323ca12ae8125121.

* add mill plugin to release script

* 7.24.0 snapshot

* update samples

* update doc

* fix(python): remove redundant debug setter call in __deepcopy__ (#23958)

The `__deepcopy__` method copies all `__dict__` items (including
`_Configuration__debug`) via the for-loop, then calls
`result.debug = self.debug` which fires the property setter with the
same value already present. On Python 3.12+, the setter's
`logger.setLevel()` call triggers `logging.Manager._clear_cache()`
which iterates every registered logger — O(n_loggers) per deepcopy.

In applications with many loggers (kubernetes, boto3, django, etc.),
this causes severe performance degradation when Configuration objects
are deepcopied frequently (e.g., per-request in API clients).

Benchmark with 2000 registered loggers, 1000 deepcopy calls:
  Before: 0.190s
  After:  0.004s (45x faster)

The logger_file setter is kept because `logger_file_handler` is
explicitly excluded from the __dict__ copy loop and needs to be
re-created via the setter.

* [Rust-Axum] Support Server-Sent Events (SSE) (#23977)

* [kotlin-server][Java][JAX-RS] Fix path shadowing (#23414) (#23871)

* Add tests to demonstrate the bug

* Fix cross-tag path shadowing in JAX-RS common path extraction

* Regenerate samples

* [haskell-http-client] update stack resolver to lts-24.42 (#23981)

* build(deps-dev): bump shell-quote (#23984)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.7.2 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.7.2...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump shell-quote from 1.8.0 to 1.8.4 in /website (#23983)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.0 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.0...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [php-nextgen] Code improvements (#23986)

* [php-nextgen] Remove whitespace

* [php-nextgen]: Fix content types type

* [Rust-Axum] Fix generating error upon special model name (#23994)

* [Rust-Axum] Fix generating error upon special model name

* Update

* build(deps): bump qs, body-parser and express (#23852)

Bumps [qs](https://github.com/ljharb/qs), [body-parser](https://github.com/expressjs/body-parser) and [express](https://github.com/expressjs/express). These dependencies needed to be updated together.

Updates `qs` from 6.14.1 to 6.15.2
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/qs/compare/v6.14.1...v6.15.2)

Updates `body-parser` from 1.20.3 to 1.20.5
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/1.20.5/HISTORY.md)
- [Commits](https://github.com/expressjs/body-parser/compare/1.20.3...1.20.5)

Updates `express` from 4.21.2 to 4.22.2
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/v4.22.2/History.md)
- [Commits](https://github.com/expressjs/express/compare/4.21.2...v4.22.2)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 1.20.5
  dependency-type: indirect
- dependency-name: express
  dependency-version: 4.22.2
  dependency-type: indirect
- dependency-name: qs
  dependency-version: 6.15.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump shell-quote (#23996)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.1 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.1...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* update parser to 2.1.43 (#23999)

* build(deps-dev): bump shell-quote (#23989)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.3 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump shell-quote (#24001)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.3 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [php-nextgen] Remove request body handling if no request body exists (#23995)

* [php-nextgen] Remove request body handling if there is none

* [php-nextgen]: Regenerate to remove request body handling

* [php-nextgen] Add test for request body handling

* [php-nextgen] Don't import formpreocessor

* [php-nextgen] Regenerate code

* [php-nextge]: Move MultipartStream to inline use

* [php-nextgen]: Regenerate for imports

* [php-nextgen]: Remove whitespace

* [php-nextgen] Regenerate code to remove whitespace

* [php-nextgen] Remove form params and query params if not used

* [php-nextgen] Regenerate code

* Add validate Mojo to Maven Plugin (#23911)

* Add ValidateMojo as a new target to enable OpenAPI definition validation with the Maven plugin
Add validation harness both unit and integration tests for the 'validate' goal

* Add missing 'validate' goal to lifecycle mapping and refine execution ordering in ValidateMojo to fix "Skip flags are checked too late; input validation should come after the skip check." issue

---------

Co-authored-by: istvan.verhas <istvan.verhas@meta-inf.hu>

* [BUG][TYPESCRIPT-FETCH] Fix #23998: Form data requests with mime type parameters use URLSearchParams instead of FormData (#24000)

* Replace equality check with startsWith call

* Update examples

* [php-nextgen] oneof polymorphism (#23985)

* [php-nextgen]: Add oneof polymorphism

* [php-nextgen]: Regenerate sample with new models

* [php-nextgen]: Update generated files file

* [php-nextgen]: add polymorphism to docs

* [php-nextgen]: Add oneOf properties (currently not working)

* [php-nextgen]: Unify doc and signature types for params, properties and returns

* [php-nextgen]: Make api responses nullable only on nullable SUCCESS responses

* [php-nextgen]: Try to use correct model for api documentation

* [php-nextgen] Regenerate docs

* [php-nextgen] Improve and link javadocs

* update PHP samples

* build(deps): bump joi from 17.7.0 to 17.13.4 in /website (#24016)

Bumps [joi](https://github.com/hapijs/joi) from 17.7.0 to 17.13.4.
- [Commits](https://github.com/hapijs/joi/compare/v17.7.0...v17.13.4)

---
updated-dependencies:
- dependency-name: joi
  dependency-version: 17.13.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump shell-quote (#24018)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.3 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump shell-quote (#24019)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.2 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.2...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(typescript-fetch): support non-default file names (#24006)

* use class file name instead of just class name

* use correct case of variable

* go back

* reset all

* add another test case

* add correct fileName property to generator

* generate new sample

* update typescript samples

* [Java][vertx] Apply Vert.x pool defaults in buildWebClient for useVertx5 (#24015) (#24017)

PoolOptions(JsonObject) does not initialize defaults first, unlike its
no-arg constructor and unlike WebClientOptions(JsonObject). The vertx
template's two-arg ApiClient constructor delegates with an empty pool
config, so buildWebClient built PoolOptions(new JsonObject()), leaving
maxLifetimeUnit null (and pool sizes 0). The first API call then threw
a NullPointerException from HttpClientImpl via WebClient.create.

Overlay poolConfig on the serialized no-arg defaults so absent keys keep
their documented values while explicit pool settings still apply.
Regenerated the vertx5 and vertx5-supportVertxFuture samples.

* build(deps-dev): bump shell-quote (#24020)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.1 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.1...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Fix Kotlin boolean const enum literals (#24022)

* [kotlin-spring, java-spring] -  gate @JsonSetter on openApiNullable for optional non-nullable fields (#23993)

* fix(kotlin-spring, java-spring): gate @JsonSetter on openApiNullable for optional non-nullable fields

   For optional + non-nullable properties (required: false, nullable: false):
   - openApiNullable=false → @JsonSetter(nulls = Nulls.SKIP): silently ignores
     explicit JSON null, protecting any defined default from being overridden
   - openApiNullable=true → @JsonSetter(nulls = Nulls.FAIL): rejects explicit
     JSON null, enforcing the non-nullable contract (useful for PATCH semantics)

   Previously, Nulls.FAIL was unconditionally generated for all optional
   non-nullable fields regardless of openApiNullable, causing a breaking change
   for users on openApiNullable=false.

   Java Spring now also emits @JsonSetter(nulls = Nulls.SKIP) for the same case
   (previously it emitted nothing).

   Fixes #23976

   Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix documentation

* fix(kotlin-spring, java-spring): add @JsonInclude(NON_NULL) for optional non-nullable fields to prevent serializing them as explicit null in JSON

* simplify implementation

* gate by jackson config

* update samples

* build(deps-dev): bump shell-quote (#23979)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.1 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.1...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump tmp in /samples/client/petstore/typescript-angular-v19 (#24031)

Bumps [tmp](https://github.com/raszi/node-tmp) from 0.2.6 to 0.2.7.
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md)
- [Commits](https://github.com/raszi/node-tmp/compare/v0.2.6...v0.2.7)

---
updated-dependencies:
- dependency-name: tmp
  dependency-version: 0.2.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump js-yaml from 4.1.1 to 4.2.0 in /website (#24035)

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.1.1 to 4.2.0.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/commits)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.2.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump ws (#24034)

Bumps [ws](https://github.com/websockets/ws) from 6.2.3 to 6.2.4.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](https://github.com/websockets/ws/compare/6.2.3...6.2.4)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 6.2.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump @angular/common, @angular/forms, @angular/platform-browser, @angular/platform-browser-dynamic and @angular/router (#24032)

Bumps [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common), [@angular/forms](https://github.com/angular/angular/tree/HEAD/packages/forms), [@angular/platform-browser](https://github.com/angular/angular/tree/HEAD/packages/platform-browser), [@angular/platform-browser-dynamic](https://github.com/angular/angular/tree/HEAD/packages/platform-browser-dynamic) and [@angular/router](https://github.com/angular/angular/tree/HEAD/packages/router). These dependencies needed to be updated together.

Updates `@angular/common` from 19.0.1 to 22.0.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v22.0.1/packages/common)

Updates `@angular/forms` from 19.0.1 to 22.0.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v22.0.1/packages/forms)

Updates `@angular/platform-browser` from 19.0.1 to 22.0.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v22.0.1/packages/platform-browser)

Updates `@angular/platform-browser-dynamic` from 19.0.1 to 22.0.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v22.0.1/packages/platform-browser-dynamic)

Updates `@angular/router` from 19.0.1 to 22.0.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v22.0.1/packages/router)

---
updated-dependencies:
- dependency-name: "@angular/common"
  dependency-version: 22.0.1
  dependency-type: direct:production
- dependency-name: "@angular/forms"
  dependency-version: 22.0.1
  dependency-type: direct:production
- dependency-name: "@angular/platform-browser"
  dependency-version: 22.0.1
  dependency-type: direct:production
- dependency-name: "@angular/platform-browser-dynamic"
  dependency-version: 22.0.1
  dependency-type: direct:production
- dependency-name: "@angular/router"
  dependency-version: 22.0.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [KOTLIN-SPRING/KOTLIN-CLIENT] BUG - fix json deserialization when kotlin attribute name differs from json attribute name (#24036)

* add @param:JsonProperty

* add fix also for kotlin-client and add unit tests

* add test open api spec

* fix failing test by extending the lookup window

* [JAVA] Add logic and test case to avoid stackOverflow exception for circular allOf (#23968)

* Add logic and test case to avoid stackOverflow exception for circular allOf

* Add new test and fixes for sibling cases

* update python-fastapi multipart dep to newer version (#24043)

* build(deps-dev): bump hono (#24044)

Bumps [hono](https://github.com/honojs/hono) from 4.12.18 to 4.12.25.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](https://github.com/honojs/hono/compare/v4.12.18...v4.12.25)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump hono (#24041)

Bumps [hono](https://github.com/honojs/hono) from 4.12.18 to 4.12.25.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](https://github.com/honojs/hono/compare/v4.12.18...v4.12.25)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump hono (#24046)

Bumps [hono](https://github.com/honojs/hono) from 4.12.18 to 4.12.25.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](https://github.com/honojs/hono/compare/v4.12.18...v4.12.25)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump hono in /samples/client/others/typescript-angular (#24049)

Bumps [hono](https://github.com/honojs/hono) from 4.12.18 to 4.12.25.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](https://github.com/honojs/hono/compare/v4.12.18...v4.12.25)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump webpack-dev-server and @angular-devkit/build-angular (#24056)

Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server) to 5.2.5 and updates ancestor dependency [@angular-devkit/build-angular](https://github.com/angular/angular-cli). These dependencies need to be updated together.


Updates `webpack-dev-server` from 5.1.0 to 5.2.5
- [Release notes](https://github.com/webpack/webpack-dev-server/releases)
- [Changelog](https://github.com/webpack/webpack-dev-server/blob/main/CHANGELOG.md)
- [Commits](https://github.com/webpack/webpack-dev-server/compare/v5.1.0...v5.2.5)

Updates `@angular-devkit/build-angular` from 19.0.2 to 21.2.16
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular-cli/compare/19.0.2...v21.2.16)

---
updated-dependencies:
- dependency-name: webpack-dev-server
  dependency-version: 5.2.5
  dependency-type: indirect
- dependency-name: "@angular-devkit/build-angular"
  dependency-version: 21.2.16
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Add files via upload (#24073)

* Add files via upload

Added Carmatec Logo

* Delete website/static/img/companies/carmatec logo.png

Deleted

* Added Logo

Added Logo

* Update users.yml

Please check

* fix link to carmatec.com

* feat: add quiet mode to suppress verbose generation output (#11211) (#23831)

Implement a `--quiet` / `-q` flag to suppress donation banners and contributor
messages during code generation. This addresses issue #11211 by providing users
a way to reduce noisy console output while maintaining full generation semantics.

Changes:
- Add quiet mode configuration to WorkflowSettings (core module)
- Wire quiet setting through CodegenConfigurator
- Implement CLI option: `-q`, `--quiet` in Generate command
- Add Maven plugin parameter: `<quiet>true</quiet>`
- Add Gradle extension property: `openApiGenerator.quiet = true`
- Refactor postProcess() in DefaultCodegen and 19 language generators to wrap
  println statements with `if (!isQuietMode())` guard, ensuring all other
  lifecycle activities execute normally regardless of quiet mode
- Add GlobalSettings lookup utility `isQuietMode()` to language-specific codegen
- Update documentation for usage.md, Maven plugin README, Gradle plugin README
- Add comprehensive test coverage across all modules:
  * WorkflowSettingsTest: quiet setting serialization
  * GenerateTest: CLI quiet flag parsing
  * DefaultGeneratorTest: postProcess execution verification
  * GenerateTaskDslTest: Gradle quiet output suppression
  * CodeGenMojoTest: Maven plugin quiet behavior

Verification:
- DefaultGeneratorTest: 24 tests, 0 failures
- GenerateTaskDslTest: all tests pass
- Build: EXIT 0

This implementation maintains backward compatibility (quiet defaults to false)
and ensures semantic correctness by always invoking postProcess(), affecting
only the console output suppression behavior.

Closes #11211

* add OnCreated to JsonConverter (#24079)

* revert to DropWrite (#24080)

* [core] Allow oneOf members that declare x-implements (#23577) (#24076)

OneOfImplementorAdditionalData.addToImplementor used putIfAbsent + List.add
on the model's x-implements vendor extension. When a oneOf member schema
already declares x-implements in the spec, the parsed value is a scalar
string or an immutable list, so appending the oneOf interface threw
java.lang.UnsupportedOperationException during model post-processing.

Normalize the existing value into a fresh mutable list (preserving any
user-supplied interfaces) before appending. No behavior change for models
without a pre-existing x-implements.

* update ujson to newer version (python-fastapi) (#24086)

* build(deps-dev): bump hono (#24051)

Bumps [hono](https://github.com/honojs/hono) from 4.12.18 to 4.12.25.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](https://github.com/honojs/hono/compare/v4.12.18...v4.12.25)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [openapi, openapi-yaml] feature - add sortOutput option to deterministically sort paths and schemas, http methods, etc... (#24037)

* feat(openapi, openapi-yaml): add sortOutput option

Add a new 'sortOutput' generator option to the 'openapi' (JSON) and
'openapi-yaml' (YAML) documentation generators that produces a
deterministically ordered spec:

- Paths are sorted alphabetically by URL
- Schemas, parameters, requestBodies, responses, headers, examples,
  links, callbacks and securitySchemes are sorted alphabetically by name
- HTTP methods within each path are ordered by the classical convention:
  GET, PUT, POST, DELETE, OPTIONS, HEAD, PATCH, TRACE

Implementation details:
- OpenAPISorter: replaces Paths and all Components maps with TreeMaps
- PathItemSerializer: custom Jackson serializer writing operations in
  classical HTTP method order (only registered when sortOutput=true)
- SerializerUtils: overloaded toJsonString/toYamlString with sortOutput
  flag; createModule(boolean) registers PathItemSerializer when true
- OpenAPIGenerator / OpenAPIYamlGenerator: wire the new option through
  to the serializer

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* test(openapi, openapi-yaml): enhance output ordering tests for paths, schemas, and HTTP methods

* remove forbidden method invocations

* feat(openapi, openapi-yaml): add documentation. Remove factually not-working features from documentation

* improve documentation

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* [Core] bug - fix OAS 3.1 nullable validation when using older "nullable: true" syntax instead of type: [null, ...] (#24026)

* add (for now failing) tests

* fix check nullable implementation to trigger the warning

* Revert "fix check nullable implementation to trigger the warning"

This reverts commit 5e8ab244dbe1be33c7ad6c251d963d1522b06d95.

* Reapply "fix check nullable implementation to trigger the warning"

This reverts commit 5507fecc70dc48a3f2dffc7b406fdd9b1055e5d5.

* remove one test

* trigger warning on any value of nullable: in open api 3.1.0 version

* [CORE] - Feature: `forcedGenerateSchemas` — Force generation of schema-mapped or import-mapped schemas (#24066)

* feat: add support for forced schema generation to override schemaMappings or importMappings

* feat: enhance forced schema generation with detailed configuration options and wildcard support

* feat: refactor forced schema generation logic to improve clarity and functionality

* feat: backwards-compatibility with configOptions

* Added Service Cost (#24089)

* Add files via upload

* Add Service Cost entry to users.yml

* minor fix to users.yml

* Update python pydantic v1 workflow to test with supported python versions (#24091)

* update python pydantic v1 workflow to test with supported python versions

* update python pydantic v1 workflow to test with supported python versions

* [java] honor useJspecify in restclient/webclient ApiClient support class (#24055)

The restclient and webclient ApiClient support classes hardcoded
'import {javaxPackage}.annotation.Nullable;' regardless of useJspecify, so
generated clients used org.jspecify everywhere except ApiClient, which kept
jakarta/javax. Guard the import on useJspecify; @Nullable is used as a simple
name so only the import changes. Regenerated the two affected jspecify samples.

* [python] fix uniqueItems validation tests (#24092)

Pydantic 2 removed conlist(unique_items=True). The migration in
04fa53b6 kept OpenAPI arrays as lists because sets would lose ordering
and complicate JSON serialization, but left the old validation tests in
the synchronous and lazy-import samples.

Those tests do not require an exception, so they normally pass after
making a Petstore request and fail only when that request produces an
unrelated response validation error. Remove them from the Pydantic 2
samples.

Pydantic 1 still enforces uniqueItems. Make its test require the expected
validation error so a regression cannot silently pass.

* [python] run Petstore CI for lazy imports (#24093)

The Python Petstore workflow tests python-lazyImports in its matrix, but
its pull-request path filter does not include that directory. A change
confined to the lazy-import sample therefore receives no Python
Petstore coverage.

Add the missing path so the workflow runs whenever that sample changes.

* Remove @multani from Python's technical committee (#24099)

I'm no longer reviewing changes for the Python client, removing myself from the list.

* build(deps): bump actions/checkout from 4 to 7 (#24061)

Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [python] serialize structured YAML bodies (#24084)

The urllib3 client only serializes structured bodies when Content-Type
contains json. Kubernetes server-side apply uses
application/apply-patch+yaml, so dict bodies instead reach the
unsupported-content fallback.

JSON is valid YAML 1.2. Use the existing JSON serializer for structured
YAML bodies while preserving the pass-through behavior for serialized
str and bytes values.

* [julia-server] Use req.headers for HTTP.jl 2.x compatibility (#24102)

HTTP.jl 2.x removed the single-arg HTTP.headers(req) accessor, so
generated server read-handlers with header params throw a MethodError
(500) under HTTP 2. Use req.headers instead, which works on both
HTTP.jl 1.x and 2.x.

Regenerated the julia-server petstore sample to match.

* [Crystal] idiomatic api redesign (#24070)

* [crystal] Idiomatic redesign: namespaced client, single request path, leaner models

Overhaul the beta `crystal` client generator to emit idiomatic, DRY, multi-instance Crystal.

API layer:
- Namespaced sub-clients: `client.dcim.cable_terminations.list` (path-based routing via a
  CrystalApiRouting helper + addOperationToGroup) instead of a flat `DcimApi` with prefixed methods.
- A single generic `Connection#request(T) forall T` choke point (crest transport); operations are
  short declarative calls returning a typed `Response(T)` (no `_with_http_info` twins).
- Native multi-instance via a `Client` facade owning a per-instance `Connection`/`Configuration`
  (no global singleton). Operation header params wired through; array query params encoded as
  `key=a&key=b` via a configurable Crest params encoder.

Models:
- Trim ignored `@[JSON::Field]` args; `valid?` delegates to `list_invalid_properties`.
- Shared `Serializable` mixin for `to_h`/`to_body`/`to_s`/`eql?`; `==`/`hash` via the stdlib
  `def_equals_and_hash` macro.
- One declarative `validates(name, type, nilable, **rules)` macro replaces the per-model
  EnumAttributeValidator hierarchy and the duplicated min/max/length/pattern/items + enum checks.
  ~-39% model LOC on a large real-world spec; eager (rescuable) validation now actually fires.

Generated specs are meaningful (JSON round-trip / required enforcement / facade reachability)
instead of empty `skip` stubs.

Also fixes latent bugs: numeric enums quoted as strings, validating setters shadowed by property
setters, BigDecimal JSON, ::File-in-model, unresolved Array(Array), stale RecursiveHash references,
blank shard.yml authors, and a maxItems/minItems paren typo.

petstore `crystal spec` and the codegen unit tests pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* [crystal] Add crystal-qdrant sample (real-world anyOf / named-enum coverage)

Generated from the Qdrant REST API 4.4.10 spec (~320 models incl. anyOf unions and named
enums) with moduleName=Qdrant::Api and apiNamespace="" (api classes nest directly under the
module). Serves as a real, large integration gate: compiles and `crystal spec` runs green.

- bin/configs/crystal-qdrant.yaml
- modules/openapi-generator/src/test/resources/3_0/crystal/qdrant.json (embedded spec)
- samples/client/others/crystal-qdrant (generated client)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* [core] Restore sibling example for allOf with a single $ref (#23335) (#24081)

When a property is declared as `allOf: [ $ref ]` with a sibling `example`,
fromProperty() reassigns the working schema to the inner $ref schema before
computing the example, so toExampleValue() runs against a schema that has no
example and returns the literal string "null". The subsequent
"restore original schema" block re-applies the outer schema's nullable,
description, min/max, title, etc. but not the example.

Restore the example from the original (outer) schema in that block, mirroring
the existing handling of the other sibling attributes. Regression from 6.x.

Fixes #23335

* build(deps): bump http-proxy-middleware from 2.0.7 to 2.0.10 in /website (#24103)

Bumps [http-proxy-middleware](https://github.com/chimurai/http-proxy-middleware) from 2.0.7 to 2.0.10.
- [Release notes](https://github.com/chimurai/http-proxy-middleware/releases)
- [Changelog](https://github.com/chimurai/http-proxy-middleware/blob/v2.0.10/CHANGELOG.md)
- [Commits](https://github.com/chimurai/http-proxy-middleware/compare/v2.0.7...v2.0.10)

---
updated-dependencies:
- dependency-name: http-proxy-middleware
  dependency-version: 2.0.10
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [Java] ensure JsonTypeName not generated for class implementing oneOf with discriminator (#24024)

* fix 23997: ensure that no JsonTypeName is created when the parent interface has a discriminator mapping

* add test for @JsonTypeInfo

* Fix Cubic findings

* [python] honor proxy environment settings (#24082)

urllib3 does not read proxy environment variables, so generated clients
require users to copy them into Configuration.proxy. 97e079fd added
no_proxy handling, but 01ed5975 replaced the Python templates without
carrying it forward.

Resolve scheme-specific proxy and no-proxy defaults through
urllib.request while preserving explicit empty values as opt-outs.
Match domain, port, IPv4 CIDR, and IPv6 CIDR bypass entries without
adding requests to generated clients.

* build(deps): bump actions/cache from 5 to 6 (#24111)

Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](https://github.com/actions/cache/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [Kotlin][Spring] fix option useSpringBuiltInValidation not implemented (#24115)

* fix(kotlin-spring): documented option `useSpringBuiltInValidation` has no effect (#23950)

* update doc, template

* fix

---------

Co-authored-by: Tomáš Pecsérke <tomas.pecserke@gmail.com>

* remove rust-server-deprecated samples, workflow tests (#24117)

* [python] separate property and parameter mappings (#24121)

Unmapped Python operation parameters currently fall back from
`toParamName()` to `toVarName()`, which also applies model property
`nameMappings`. A mapping intended for a model property can therefore
rename an unrelated operation parameter with the same source name.

Apply explicit mappings to operation parameters only through
`parameterNameMappings` in the `python` and `python-pydantic-v1`
generators. Continue to normalize unmapped parameter names as Python
identifiers. This gives `nameMappings` and `parameterNameMappings` their
documented property and parameter scopes.

Configurations that intentionally used `nameMappings` to rename
parameters must add the same entries to `parameterNameMappings`. Retain
the `nameMappings` entries when they are also needed for model
properties.

* [rust-server] Fix panic on binary request bodies coerced to UTF-8 (#24116)

Co-authored-by: William Cheng <wing328hk@gmail.com>

* [python] Run regex pattern validators in mode="before" (#24065) (#24072)

The Python (pydantic v2) generator emitted regex `@field_validator`s
without a mode, so they defaulted to `mode="after"` and ran *after*
pydantic had already coerced the wire value to its declared Python type.

Consequences:
- A `string` with `format: date-time` reached the validator as a
  `datetime`; the template stringified it (`str(value)`), producing a
  non-RFC-3339 form that could no longer match the declared `pattern`,
  so valid responses were rejected.
- A `string` with `format: uuid` was coerced to `UUID`, then the
  validator returned `str(value)`, leaving the field value a `str`
  despite the `UUID` annotation.

Run the pattern check in `mode="before"` against the raw wire value and
only when it is a `str`, then let pydantic perform the normal
conversion. Already-typed Python values are passed through untouched.

Regenerated affected python samples (python, python-aiohttp,
python-httpx, python-lazyImports).

* [Java] Render object default for composed ($ref + default) schemas (#23971)

A property declared as a $ref to an object schema with a sibling default
(or an explicit allOf) is parsed as a composed schema, so its properties
live in the allOf members rather than directly on the schema. The composed
branch of AbstractJavaCodegen.toDefaultValue fell through to
super.toDefaultValue, which emits the raw default (e.g. {"one":"one"})
as Java and does not compile.

Resolve the composed schema's effective properties from its allOf members
and render the default through the same fluent-builder logic used for plain
object schemas (extracted into toObjectDefaultValue). When no object
properties can be resolved, return null instead of emitting uncompilable
output.

Fixes #23795

* [python] add supportHttpxSync option for sync httpx methods (#24128)

* [python] add supportHttpxSync option for sync httpx methods (#23032)

Add a new `supportHttpxSync` option to the Python generator (httpx library only) that generates synchronous `_sync` variants of each API method inside the same API class, instead of a separate `httpx-sync` library.

Following the maintainer's review feedback on #23044, each generated `_sync` method simply calls its asynchronous counterpart and waits for completion, so both synchronous and asynchronous methods are available from the same SDK (matching the sync/async layout already used by other generators).

- PythonClientCodegen: new `supportHttpxSync` CLI option, wired for the httpx library only (ignored with a warning otherwise)
- httpx/sync_helper.mustache: `run_sync()` helper running coroutines to completion on a dedicated, reused background event loop so the httpx AsyncClient stays bound to a single loop across calls
- api.mustache: generate `_sync`, `_sync_with_http_info` and `_sync_without_preload_content` variants under `{{#supportHttpxSync}}`
- api_doc / api_test: document and stub the sync variants
- new sample petstore python-httpx-sync (bin/configs/python-httpx-sync.yaml)
- docs/generators/python.md regenerated

* #23032 :

Fix FILES

* test new samples in github workflow

* copy tests

* update samples

---------

Co-authored-by: Antoine <antoine@lecomptoirdespharmacies.fr>

* [python] escape model wire names (#24120)

* [python] escape model wire names

Python model templates in the modern and Pydantic v1 clients
interpolate OpenAPI property names and discriminator names and values
directly into string literals. Quotes, backslashes, and control
characters can therefore produce invalid generated modules.

Render field aliases, dictionary keys, discriminator lookups, and
discriminator mappings through Python string-literal escaping in both
generators. Stop generation if a value cannot be encoded rather than
emitting unsafe source.

* [python] regenerate client samples

Regenerate the checked-in modern and Pydantic v1 Python petstore
clients after escaping model wire names. Existing inherited, oneOf,
anyOf, and nested models exercise quotes, backslashes, and control
characters in wire keys and discriminator values.

* [Java] Skip wildcard media types when selecting request Content-Type (#24118) (#24127)

selectHeaderContentType() could return a wildcard media type (e.g.
"application/*" or "*/*"). isJsonMime() reports such wildcards as
JSON-compatible, so the JSON branch returned the wildcard unchanged, and
the no-JSON fallback returned contentTypes[0] verbatim. Spring's
MediaType then throws IllegalArgumentException("Content-Type cannot
contain wildcard type '*'") when the value is used as a request header.

Now JSON-compatible wildcards fall back to concrete application/json, and
the no-JSON path returns the first non-wildcard media type (or
application/json if every candidate is a wildcard). Fixes restclient,
resttemplate and webclient ApiClient templates plus regenerated samples;
adds ApiClientTest covering wildcard handling.

* update python samples

* fix(ruby): JSON-encode query params with content:application/json (#24126)

* fix(ruby): JSON-encode query params with content:application/json

Parameters declared with `content: { "application/json": ... }` must be
serialized as JSON strings per the OpenAPI 3 spec. The core model field
`queryIsJsonMimeType` was already set correctly by DefaultCodegen; the Ruby
template was simply not using it, causing raw Ruby object representations to
be sent instead of JSON.

Adds `{{#queryIsJsonMimeType}}...to_json{{/queryIsJsonMimeType}}` branches to
api.mustache for both required and optional query params, updates the three
ruby echo_api samples accordingly, and adds a RubyClientCodegenTest to assert
the flag is set on content:application/json parameters.

Fixes: #2519 (partially — same root cause, jaxrs-cxf generator)
Related: #6367, #21934 (same bug in TypeScript generators)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Update samples/client/echo_api/ruby-httpx/lib/openapi_client/api/query_api.rb

Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>

* Regenerate samples after Cubic's suggested change

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>

* [python] test HTTPX sync wire names (#24130)

Commit 2b6b544f brings the HTTPX sync generated models in line with
3a307ab7. The handwritten oneOf and anyOf tests still construct payloads
with sanitized Python names, so the sample jobs now fail while
deserializing BasquePig.

Update those tests to send and assert the exact wire names. This keeps
the regression coverage aligned with the generated fields and catches
future sample drift.

* [jaxrs-spec] Add @JsonIgnoreProperties on the discriminator to avoid duplicated keys during serialisation  (#24132)

* [jaxrs-spec] add @JsonIgnoreProperties on discriminator to avoid duplicate key

Models with a discriminator emitted @JsonTypeInfo(As.PROPERTY) but also
declared the discriminator property as a regular @JsonProperty field, so
Jackson serialized the discriminator twice, producing a duplicate key in
the response body.

Mirror the Spring generator by emitting
@JsonIgnoreProperties(value = "<prop>", allowSetters = true) on the
discriminator-carrying model. allowSetters = true preserves the field
during deserialization. The JsonIgnoreProperties import was already added
unconditionally by AbstractJavaCodegen, so no Java change is required.

Regenerated the affected jaxrs-spec samples.

* [jaxrs-spec] test @JsonIgnoreProperties on discriminator children with legacyDiscriminatorBehavior=false

Add a dedicated fixture (discriminator-mapping-children.yaml) and test
asserting that when legacyDiscriminatorBehavior=false the discriminator is
propagated onto the allOf children reachable via the discriminator mapping,
so @JsonIgnoreProperties is emitted on the parent and every child, ensuring
the discriminator property is not serialized twice in either case.

* build(deps): bump actions/setup-dotnet from 5.3.0 to 5.4.0 (#24142)

Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 5.3.0 to 5.4.0.
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](https://github.com/actions/setup-dotnet/compare/v5.3.0...v5.4.0)

---
updated-dependencies:
- dependency-name: actions/setup-dotnet
  dependency-version: 5.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [python] centralize the Python constraint rules (#24141)

* fix: normalize OAS 3.1 schemas with type:[object,"null"] to set nullable:true correctly (#24140)

* fix: normalize OAS 3.1 schemas with type:[object,"null"] to set nullable:true correctly

* fix: ensure OAS 3.1 schemas with type array including "null" set nullable:true correctly and preserve properties

* Revert "fix: ensure OAS 3.1 schemas with type array including "null" set nullable:true correctly and preserve properties"

This reverts commit cb5aa4917299ccce88cb1867e8e646f0bf2651ae.

* Reapply "fix: ensure OAS 3.1 schemas with type array including "null" set nullable:true correctly and preserve properties"

This reverts commit b0d188d9c44f8e653e15acf9b5bced72f0b7fa38.

* add whitespace to retrigger tests

* Revert "add whitespace to retrigger tests"

This reverts commit 6a4bd103ecd3b98834816e9e94ad0f07bcd62762.

* Revert "Reapply "fix: ensure OAS 3.1 schemas with type array including "null" set nullable:true correctly and preserve properties""

This reverts commit 74eb333a3a551aff06c9353c0492616941f0c90d.

* Reapply "fix: ensure OAS 3.1 schemas with type array including "null" set nullable:true correctly and preserve properties"

This reverts commit b0d188d9c44f8e653e15acf9b5bced72f0b7fa38.

* Revert "fix: ensure OAS 3.1 schemas with type array including "null" set nullable:true correctly and preserve properties"

This reverts commit cb5aa4917299ccce88cb1867e8e646f0bf2651ae.

* Revert "fix: normalize OAS 3.1 schemas with type:[object,"null"] to set nullable:true correctly"

This reverts commit 29c620709dc60c932b382d022f4506925e17a8c8.

* Reapply "fix: normalize OAS 3.1 schemas with type:[object,"null"] to set nullable:true correctly"

This reverts commit f741e48e29a2fc8634d038ebcb9e7760cf405d93.

* Reapply "fix: ensure OAS 3.1 schemas with type array including "null" set nullable:true correctly and preserve properties"

This reverts commit cf56cf5c3107cbaa969b535b49faa4e3d890b53d.

* Revert "Reapply "fix: ensure OAS 3.1 schemas with type array including "null" set nullable:true correctly and preserve properties""

This reverts commit 500d93a500f910679b227063aeaab133f3ed0598.

* Reapply "Reapply "fix: ensure OAS 3.1 schemas with type array including "null" set nullable:true correctly and preserve properties""

This reverts commit 7f0b9a6006ba58ba73b4e9aa33c6d0991ff8ea30.

* Reapply "add whitespace to retrigger tests"

This reverts commit 68e6dfffafcd0578de9cd370f00fd9a4dd2d222d.

* ci: replace setup-cpp with apt-get in node2 to fix transient GPG key failures

setup-cpp internally adds ppa:ubuntu-toolchain-r/test, which fetches an
external GPG key. This occasionally times out in CI, causing the node2 job
to fail with 'Failed to install the llvm' even though the code is fine.

Replace the wget/setup-cpp/source chain with a single apt-get install of
clang, cmake, and ninja-build from Ubuntu's own repositories.  No PPAs, no
external GPG key fetches, no transient network failures.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix: add explicit source directory '.' to cmake invocation in cpp-restsdk pom.xml

CMake warns 'No source or binary directory provided' when called without
a positional source-dir argument or -S/-B flags. The warning notes this
will become a fatal error in future CMake releases.

Add '.' as the first cmake argument to explicitly set the source directory
to the current directory, which matches the implicit behaviour and silences
the warning.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix: force clang compiler in cpp-restsdk cmake invocation

The CI node2 job installs clang via apt, but cmake was defaulting to GCC
because no compiler was explicitly specified. Add CMAKE_C_COMPILER=clang
and CMAKE_CXX_COMPILER=clang++ to match the original intent of the setup,
which previously used setup-cpp --compiler llvm.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* ci: remove unnecessary ninja-build from node2 apt install

The cpp-restsdk pom.xml uses cmake + make (Unix Makefiles generator).
Ninja is never invoked, so ninja-build serves no purpose here.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(avro): order "null" first in union when default is null (#24135)

The avro-schema generator emitted an invalid union when a property combined a non-null type with an explicit `default: null` (commonly produced by `nullable: true` + `allOf` composition), e.g. `["model.Foo", "null"]` with `"default": null`.
Per the Avro specification, a union's default value must match the FIRST branch of the union, so the default `null` is only valid when `"null"` is the first branch. The invalid ordering is accepted by most schema parsers but fails at read time when the default is applied during schema evolution, crashing consumers.

The Swagger Parser represents an explicit `default: null` as a Jackson `NullNode` (a non-null Java object) rather than a Java `null`, so `toDefaultValue` returned the string "null" and the field was rendered through the concrete-default branch (`[<type>, "null"]`). Treat an explicit null default as "no default" so the field falls through to the existing nullable-union form (`["null", <type>]` with `"default": null`), which is valid. Real (non-null) defaults are unaffected.

Extends the issue6268 test spec with a nullable scalar and an allOf-composed
model reference, both using `default: null`, and regenerates the sample.

* fix(online): thread-safe fileMap with TTL cleanup, SLF4J logging, and Content-Length header (#24011)

* fix : thread safety, logging, and Content-Length in openapi-generator-online

* fix : thread-safe fileMap with 24h TTL cleanup in openapi-generator-online

* fix(online): enforce TTL at download time and make createdAt immutable

* fix : updated the failing test cases for GenApiControllerTest

* fix: Add GenApiServiceTest with TTL cleanup and concurrent generation tests

* fix(online): retain fileMap entry when temp directory deletion fails

* test(online): make GenApiServiceTest hermetic and leak-free

* [php-nextgen] Fix undefined variable $queryParams (#24136)

* [python][client] Add Decimal support to mapNumberTo functionality (#23916)

* [php-nextgen] Test with phpstan (#24146)

* test with phpstan

* update

* build(deps-dev): bump @sigstore/core (#24144)

Bumps [@sigstore/core](https://github.com/sigstore/sigstore-js) from 3.1.0 to 3.2.1.
- [Release notes](https://github.com/sigstore/sigstore-js/releases)
- [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@3.1.0...@sigstore/core@3.2.1)

---
updated-dependencies:
- dependency-name: "@sigstore/core"
  dependency-version: 3.2.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump @sigstore/core (#24145)

Bumps [@sigstore/core](https://github.com/sigstore/sigstore-js) from 3.1.0 to 3.2.1.
- [Release notes](https://github.com/sigstore/sigstore-js/releases)
- [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@3.1.0...@sigstore/core@3.2.1)

---
updated-dependencies:
- dependency-name: "@sigstore/core"
  dependency-version: 3.2.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* refactor: introduce DiscriminatorUtils to separate handling of discriminator discoverability and construction (#24143)

* [php-nextgen] Fix for enum allowed values, fixes #23813 (#23814)

* Add test for issue #23813

* fix(php-nextgen): First iteration to fix enums

* fix(php-nextgen): Re-add discriminator static properties

* fix(test): Rename the test file

* [dart-dio][built_value] Honor optional non-nullable properties in deserialize_properties.mustache (#23661)

* honor optional non-nullable in deserialize_properties

`class_members.mustache` makes the Dart getter `String?` whenever
`isNullable || !required` (the only sane Dart mapping: an optional
field can always be observably `null`), but
`deserialize_properties.mustache` only honored `isNullable`. The two
templates therefore disagreed: getter was `String?` but the
deserializer cast the value as non-nullable `String`, throwing
`type 'Null' is not a subtype of type 'String'` the moment the API
returned the field as `null`. The throw bubbled up through any
enclosing container, so a single null leaf could tank the entire
parent payload -- and most call paths swallowed the error silently.

Fix: in `deserialize_properties.mustache` the cast and the FullType
now key on the same condition as the getter: nullable when
`isNullable || !required`. The null-skip guard
(`if (valueDes == null) continue;`) is also extended to optional
non-nullable properties so we never reach the builder assignment
with a null on the wire.

Required + non-nullable, required + explicitly nullable, and
optional + explicitly nullable all keep their existing behavior --
only the previously-broken optional non-nullable path changes.

A new fixture `built_value_optional_nullable.yaml` exercises every
shape, and a new test
`DartDioClientCodegenTest.testOptionalNonNullablePropertyDeserializesAsNullable`
asserts the generated `watch_provider_entry.dart` contains the
expected lines for each.

Full Dart suite: 115 tests, 0 failures, 0 regressions.

* regenerate petstore sample with optional non-nullable fix

* fix regenerated samples and remove template trailing newline

  - Remove trailing newline in deserialize_properties.mustache that caused
    double blank lines in generated output
  - Regenerate all dart-dio samples (oneof, oneof_polymorphism_and_inheritance,
    oneof_primitive, petstore-timemachine) with optional non-nullable fix
  - Fix corrupt serializers.dart that had empty addBuilderFactory() calls
    causing compilation errors

---------

Co-authored-by: Antoine Le Dû <antoine@skypher.co>

* fix(python-flask): validate byte length for format:byte fields (#23177)

When a string field has format:byte with minLength/maxLength constraints,
the generated validation code incorrectly checks string length instead
of base64-decoded byte length.

Added conditional logic using isByteArray flag to validate decoded
byte length for byte array fields. Maintains existing string length
validation for non-byte fields.

Fixes #450

* [dart-dio] Fix webhook imports generating Map-style strings (#22611)

* Fix dart-dio webhook imports generating Map-style strings (issue #22586)

Webhook operations were generating broken import statements with Map-style
representation and HTML entity encoding:
  import '{import&#x3D;model.Pet, classname&#x3D;Pet}';

Instead of proper Dart package imports:
  import 'package:my-package/src/model/pet.dart';

This occurred because DartDioClientCodegen.postProcessOperationsWithModels()
applied import processing to regular operations, but postProcessWebhooksWithModels()
was missing the same logic.

Fix:
- Extracted shared import processing logic into processImports() method
- Added postProcessWebhooksWithModels() override to apply same logic
- Both operations and webhooks now use consistent import generation

Test:
- Added verifyWebhookImports() test using existing webhooks.yaml resource
- Verifies generated code does not contain Map-style imports
- Verifies generated code does not contain HTML entity encoding

* Refactor DartDio imports processing

* Update DartDioClientCodegenTest.java for doc clarity

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Ignore php-nextgen (oneof discriminatoar enum test) (#24152)

* ignore php nextgen oneof discriminatoar enum test

* ignore php nextgen oneof discriminatoar enum test

* [dart-dio][built_value] Register BuilderFactory for nested additionalProperties shapes (#24154)

* register BuilderFactory for nested additionalProperties shapes

For a property like
`{ additionalProperties: { type: array, items: { $ref: ... } } }` the
generator emits `Map<String, BuiltList<X>>` in the Dart class but never
registers the `BuiltList<X>` BuilderFactory. The only
factory-registration path that ran for additionalProperties looked at
`items.getAdditionalProperties()`, which is null for this very common
shape (a region map of arrays of $ref). built_value then fails at
runtime with `Bad state: No builder factory for BuiltList<X>` on the
first deserialization that touches the property.

Fix:
- `postProcessModelProperty` now also calls `registerNestedBuilderFactories`,
  which walks the property's `items` tree top-down and registers a
  factory for every container layer. Three small helpers
  (`renderInnerFullType`, `renderDartType`, `renderBuilderFactory`)
  compute the corresponding `FullType(...)` argument list and the
  matching `XBuilder<...>` instantiation for arbitrary nesting:
  `Map<String, List<X>>`, `List<Map<String, X>>`,
  `Map<String, Map<String, X>>`, `List<List<X>>`, `Set<...>`, etc.
- `BuiltValueSerializer` gets a new `composite(fullTypeArgs,
  builderInstantiation)` constructor that carries the pre-rendered
  expressions. The existing `(isArray, uniqueItems, isMap,
  isNullable, dataType)` form is unchanged -- needed because the
  original model can't represent something like
  `BuiltMap<String, BuiltList<X>>` (the `FullType` argument is
  recursive and isn't expressible with a single `dataType` string).
  `equals`/`hashCode` are extended so composite serializers dedup on
  `(fullTypeArgs, builderInstantiation)` and never collide with simple
  ones.
- `serializers.mustache` gets a new branch that emits the composite
  fields verbatim when present; otherwise the existing
  `isArray`/`isMap` dispatch runs unchanged.

Existing simple cases (direct return / parameter container types,
single-level additionalProperties already handled by the prior
branch) keep producing byte-identical output.

A new fixture `built_value_additional_properties_factory.yaml`
exercises the canonical `Map<String, List<$ref>>` shape, and a new
test
`DartDioClientCodegenTest.testNestedAdditionalPropertiesGetBuilderFactories`
asserts both the inner `BuiltList<WatchProviderEntry>` and the outer
`BuiltMap<String, BuiltList<WatchProviderEntry>>` factories appear in
the generated `serializers.dart`.

Full Dart suite: 115 tests, 0 failures, 0 regressions.

* fix duplicate builder factories and regenerate petstore sample

* regenerate petstore-timemachine serializers after rebase on master

---------

Co-authored-by: Antoine Le Dû <antoine@skypher.co>

* [typescript-fetch] Fix TS2590 in instanceOf guards for wide sanitized-name models (#23980) (#23982)

* [typescript-fetch] Fix TS2590 in instanceOf guards for wide sanitized-name models

The dual name/baseName membership check added in #23497 narrows the
`object` parameter on every clause of the type-predicate function. For
models with many required properties whose sanitized TS name differs
from the JSON baseName (e.g. snake_case APIs), the accumulated candidate
union grows past the compiler limit and trips TS2590 ("union type too
complex"), introduced in 7.23.0.

Read the membership/index-access checks through `value as Record<string,
any>` so TypeScript no longer narrows the predicate on each clause,
keeping the dual-key behavior from #23497 while restoring compilable
guards. Regenerated affected typescript-fetch samples.

Fixes #23980

* [typescript-fetch] Update test expectations for Record<string, any> casts in instanceOf guards

* [typescript] Align multipart file array handling (#24133)

* Align TypeScript multipart file array handling

* Add TypeScript fetch multipart file array sample

* Document TypeScript binary form array helper

* Fix TypeScript fetch multipart docs example

* Limit TypeScript fetch multipart docs examples

* chore: update typescript samples (#24159)

* Add note to mapping options (#24162)

* add note to mapping options

* add note to mapping options

* fix(kotlin): emit @get:JsonValue on nested Jackson enums (#24047)

Nested (inline) enum classes generated into Kotlin data classes were
missing the @get:JsonValue annotation that top-level enum classes already
carry. Without it, Jackson serializes an Int-valued nested enum by its
constant name instead of its numeric value, producing wrong JSON output.

Add @get:JsonValue (and the JsonValue import, guarded by hasEnums) to the
nested enum declaration in the kotlin-client data_class template, mirroring
enum_class.mustache. Regenerate affected Kotlin Jackson client samples and
add a regression test.

Fixes #23886

* Update pom.xml (#24166)

Dependency update for CVE-2026-54512

https://github.com/OpenAPITools/openapi-generator/issues/24165

* build: migrate to OSS Community Develocity Instance (#24050)

- Point Develocity server to https://community.develocity.cloud with project ID OpenAPITools
- Upgrade develocity-maven-extension to 2.4.1 and common-custom-user-data-maven-extension to 2.2.0
- Trim develocity.xml to remove keys with default values
- Rename GRADLE_ENTERPRISE_ACCESS_KEY to DEVELOCITY_ACCESS_KEY across all CI workflow files
- Update Revved up by Develocity badge in README to link to the community instance

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>

* build(deps-dev): bump @sigstore/verify (#24182)

Bumps [@sigstore/verify](https://github.com/sigstore/sigstore-js) from 3.1.0 to 3.1.1.
- [Release notes](https://github.com/sigstore/sigstore-js/releases)
- [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@3.1.0...@sigstore/verify@3.1.1)

---
updated-dependencies:
- dependency-name: "@sigstore/verify"
  dependency-version: 3.1.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump sigstore (#24183)

Bumps [sigstore](https://github.com/sigstore/sigstore-js) from 4.1.0 to 4.1.1.
- [Release notes](https://github.com/sigstore/sigstore-js/releases)
- [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@4.1.0...sigstore@4.1.1)

---
updated-dependencies:
- dependency-name: sigstore
  dependency-version: 4.1.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(python-flask): add opt-in Connexion 3 support (#24181)

* feat(python-flask): add opt-in Connexion 3 support

Adds a new `useConnexion3` boolean generator option (default: false) to
the python-flask server generator, addressing #17303. Connexion 3 has
been out since 2023, but requirements.mustache explicitly pinned
`connexion<=2.14.2` and `Flask==2.1.1` to avoid it, blocking users from
picking up newer Flask/Werkzeug (one comment on the issue specifically
cited this as blocking a CVE fix in werkzeug). The maintainer has
repeatedly invited a contribution on the thread since Dec 2023, and
several community members had already prototyped working fixes in the
comments.

Kept as an opt-in flag rather than a default bump, following this
repo's existing convention for breaking generator-output changes
(useJackson3, useSpringBoot3/4).

What changes under the flag, and why:
- requirements.mustache / setup.mustache: swap the Connexion 2/Flask
  2.1.1 pins for `connexion[flask,swagger-ui,uvicorn]>=3.3.0,<4.0.0` +
  `Flask>=2.2.0,<4.0.0`. The uvicorn extra is required because
  Connexion 3's `FlaskApp.run()` launches via uvicorn even for Flask
  apps -- confirmed by actually running the generated server, which
  fails at startup without it. The connexion floor is 3.3.0 (not just
  the first 3.0.0 release) because that's the only version we've
  actually run and verified, and it's also the first release with
  official Python 3.13/3.14 support per Connexion's own release notes.
  swagger-ui-bundle is bumped to >=1.1.0 to match the floor Connexion's
  own swagger-ui extra already silently requires.
- __main__.mustache: `connexion.App` -> `connexion.FlaskApp`, and the
  JSON encoder moves from a `F…
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] [python-flask] missing explanation why it uses connexion and not flask

2 participants