Skip to content

Feature/fix values2#23632

Closed
Picazsoo wants to merge 8 commits intoOpenAPITools:masterfrom
Picazsoo:feature/fix-values2
Closed

Feature/fix values2#23632
Picazsoo wants to merge 8 commits intoOpenAPITools:masterfrom
Picazsoo:feature/fix-values2

Conversation

@Picazsoo
Copy link
Copy Markdown
Contributor

@Picazsoo Picazsoo commented Apr 27, 2026

PR checklist

  • Read the contribution guidelines.
  • Pull Request title clearly describes the work in the pull request and Pull Request description provides details about how to validate the work. Missing information here may result in delayed response from the community.
  • Run the following to build the project and update samples:
    ./mvnw clean package || exit
    ./bin/generate-samples.sh ./bin/configs/*.yaml || exit
    ./bin/utils/export_docs_generators.sh || exit
    
    (For Windows users, please run the script in WSL)
    Commit all changed files.
    This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
    These must match the expectations made by your contribution.
    You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example ./bin/generate-samples.sh bin/configs/java*.
    IMPORTANT: Do NOT purge/delete any folders/files (e.g. tests) when regenerating the samples as manually written tests may be removed.
  • File the PR against the correct branch: master (upcoming 7.x.0 minor release - breaking changes with fallbacks), 8.0.x (breaking changes without fallbacks)
  • If your PR solves a reported issue, reference it using GitHub's linking syntax (e.g., having "fixes #123" present in the PR description)
  • If your PR is targeting a particular programming language, @mention the technical committee members, so they are more likely to review the pull request.

Summary by cubic

Fixes Kotlin string and Markdown escaping across generators and docs to prevent string interpolation, bad annotations, and broken Markdown/code blocks. Adds shared lambdas and unescaped fields, and updates Kotlin templates for correct defaults and clean docs.

  • Bug Fixes

    • Escape path/header/query/cookie names and paths in Kotlin strings (no accidental $ interpolation; quotes/backslashes handled) in annotations and stubs (@Path/@Query/@Header/@Field/@Part, Retrofit paths, WireMock urlPathTemplate, Jackson @JsonProperty, etc.).
    • Render string default values correctly using unescaped defaults with proper quoting in models and params (Retrofit2, Volley, Spring, Ktor, Vertx, JAX-RS, Javalin, Misk, WireMock).
    • Escape Markdown in generated docs (summaries, notes, property descriptions, return types) via escapeMarkdown to avoid broken tables and premature code block endings.
    • Spring annotations: @Operation.summary uses escaped normal strings; description uses triple-quoted strings with $ escaped; @ApiResponse.description uses unescaped message with proper escaping.
    • Tests cover worst‑case Kotlin string escaping and $ handling in path constants and @JsonProperty (new OpenAPI spec).
  • Refactors

    • Add unescaped fields: unescapedDefaultValue (property/param), unescapedSummary (operation), unescapedMessage (response).
    • Add shared Mustache lambdas: escapeInNormalString, escapeDollarInMultiline, escapeMarkdown, removeLineBreak; remove ad‑hoc lambdas in kotlin-spring.
    • Update Kotlin client/server templates across okhttp, retrofit2, ktor, spring, volley, vertx, misk, wiremock, jaxrs-spec, and javalin to use the new lambdas and fields.

Written for commit a40fa01. Summary will update on new commits. Review in cubic

@Picazsoo Picazsoo marked this pull request as ready for review April 27, 2026 13:34
Copy link
Copy Markdown
Contributor

@cubic-dev-ai cubic-dev-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

7 issues found across 146 files

Note: This PR contains a large number of files. cubic only reviews up to 75 files per PR, so some files may not have been reviewed. cubic prioritises the most important files to review.

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="samples/client/petstore/kotlin-jackson/docs/PetApi.md">

<violation number="1" location="samples/client/petstore/kotlin-jackson/docs/PetApi.md:111">
P2: Unescaped `<Pet>` in Markdown signatures is parsed as HTML and can render incorrectly; generic type brackets should be escaped.</violation>
</file>

<file name="samples/client/others/kotlin-jvm-okhttp-non-ascii-headers/docs/PetApi.md">

<violation number="1" location="samples/client/others/kotlin-jvm-okhttp-non-ascii-headers/docs/PetApi.md:116">
P3: Unescaped `<Pet>` in the Markdown signature can be parsed as HTML and hide the generic type in rendered docs.</violation>

<violation number="2" location="samples/client/others/kotlin-jvm-okhttp-non-ascii-headers/docs/PetApi.md:164">
P3: Unescaped `<Pet>` in the Markdown signature can be parsed as HTML and hide the generic type in rendered docs.</violation>
</file>

<file name="samples/client/petstore/kotlin-explicit/docs/PetApi.md">

<violation number="1" location="samples/client/petstore/kotlin-explicit/docs/PetApi.md:111">
P3: Raw `<Pet>` in the Markdown signature can be parsed as an HTML tag, which breaks rendering of the generic return type in the generated docs. Restore HTML escaping for the angle brackets.</violation>
</file>

<file name="modules/openapi-generator/src/main/resources/kotlin-server/libraries/javalin5/paramDefault.mustache">

<violation number="1" location="modules/openapi-generator/src/main/resources/kotlin-server/libraries/javalin5/paramDefault.mustache:1">
P2: Duplicate `isUuid` rendering block will emit the UUID default fragment twice, producing invalid Kotlin defaults for UUID parameters.</violation>
</file>

<file name="modules/openapi-generator/src/main/java/org/openapitools/codegen/CodegenParameter.java">

<violation number="1" location="modules/openapi-generator/src/main/java/org/openapitools/codegen/CodegenParameter.java:37">
P2: `copy()` omits the newly added `unescapedDefaultValue` field, so cloned `CodegenParameter` instances lose this state.</violation>
</file>

<file name="modules/openapi-generator/src/main/resources/kotlin-spring/interfaceOptVar.mustache">

<violation number="1" location="modules/openapi-generator/src/main/resources/kotlin-spring/interfaceOptVar.mustache:2">
P2: `example` values are still emitted unescaped into Kotlin string literals, so examples containing quotes, backslashes, `$`, or newlines can break generated code or cause unintended interpolation.</violation>
</file>

Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.

Comment thread samples/client/petstore/kotlin-jackson/docs/PetApi.md Outdated
Comment thread samples/client/others/kotlin-jvm-okhttp-non-ascii-headers/docs/PetApi.md Outdated
Comment thread samples/client/others/kotlin-jvm-okhttp-non-ascii-headers/docs/PetApi.md Outdated
Comment thread samples/client/petstore/kotlin-explicit/docs/PetApi.md Outdated
Copy link
Copy Markdown
Contributor

@cubic-dev-ai cubic-dev-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 77 files (changes from recent commits).

Note: This PR contains a large number of files. cubic only reviews up to 75 files per PR, so some files may not have been reviewed. cubic prioritises the most important files to review.

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="modules/openapi-generator/src/main/resources/kotlin-client/api_doc.mustache">

<violation number="1" location="modules/openapi-generator/src/main/resources/kotlin-client/api_doc.mustache:30">
P2: Unescaped parameter descriptions inside the fenced code block can break Markdown rendering (e.g., backticks closing the fence).</violation>
</file>

Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.

Comment thread modules/openapi-generator/src/main/resources/kotlin-client/api_doc.mustache Outdated
@Picazsoo Picazsoo closed this Apr 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant