Schemathesis v4.30.1 ━━━━━━━━━━━━━━━━━━━━ ✅ Loaded specification from http://0.0.0.0:43007/swagger.v1.json (in 0.20s) Base URL: http://0.0.0.0:43007/api/v1 Specification: Open API 2.0 Operations: 537 selected / 537 total Configuration: /home/stranger6667/data/programming/workbench/target s/gitea/schemathesis.toml Dictionaries: 4 dictionaries / 4 entries ✅ API capabilities: Supports NULL byte in headers: ✘ Accepts backslash and control characters in URL paths: ✓ ❌ Examples (in 0.57s) ✅ 3 passed ❌ 7 failed ⏭ 527 skipped ❌ Coverage (in 241.62s) ✅ 322 passed ❌ 215 failed ❌ Fuzzing (in 2433.57s) ✅ 143 passed ❌ 394 failed ❌ Stateful (in 923.95s) Scenarios: 4688 API Links: 243 covered / 8754 selected / 8754 total ✅ 4350 passed ❌ 338 failed =================================== FAILURES =================================== __________________ DELETE /admin/actions/runners/{runner_id} ___________________ 1. Test Case ID: znv1fQ - Undocumented HTTP status code Received: 401 Documented: 204, 400, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'X-GITEA-OTP;' -H 'Authorization: [Filtered]' -H 'Sudo: (t=x' 'http://0.0.0.0:43007/api/v1/admin/actions/runners/%C2%B3%F0%BE%8E%85%F3%8D%B8%AD%C2%9F%7C-%23%C2%93%C2%A8%C3%88f?access_token=%5BFiltered%5D&sudo=9k%0A%28%F0%A4%90%B7%C3%98%C3%BA%C3%9D%C3%BD%C3%97%F3%85%AB%89pm5%F0%B0%89%98%7B%F1%82%BA%97v%C3%A4' 2. Test Case ID: fBXJEy - Undocumented HTTP status code Received: 403 Documented: 204, 400, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP;' -H 'Sudo: (t=x' 'http://0.0.0.0:43007/api/v1/admin/actions/runners/%C2%B3%F0%BE%8E%85%F3%8D%B8%AD%C2%9F%7C-%23%C2%93%C2%A8%C3%88f?access_token=%5BFiltered%5D&sudo=' ___________________________ DELETE /admin/hooks/{id} ___________________________ 1. Test Case ID: Kw1nWG - Undocumented HTTP status code Received: 404 Documented: 204 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/admin/hooks/-9223372036854775808 ____________________ DELETE /admin/unadopted/{owner}/{repo} ____________________ 1. Test Case ID: v3SxKB - Undocumented HTTP status code Received: 404 Documented: 204, 403 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/admin/unadopted/0/0 2. Test Case ID: zs1b4C - Undocumented HTTP status code Received: 401 Documented: 204, 403 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Sudo;' -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/admin/unadopted/admin/Qk%27%3FAD ________________________ DELETE /admin/users/{username} ________________________ 1. Test Case ID: pEmwei - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/users/workbench-user?purge=true' 2. Test Case ID: SjOVQJ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"target is an organization but not user","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/admin/users/workbench-user 3. Test Case ID: b1mVaV - Undocumented HTTP status code Received: 401 Documented: 204, 403, 404, 422 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/admin/users/workbench-user ____________________ DELETE /admin/users/{username}/badges _____________________ 1. Test Case ID: odS6xd - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"badge_slugs": ["badge1", "badge2"]}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/badges 2. Test Case ID: RHxC7a - Undocumented HTTP status code Received: 404 Documented: 204, 403, 422 [404] Not Found: `{"message":"user redirect does not exist [name: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"badge_slugs": ["badge1", "badge2"]}' http://0.0.0.0:43007/api/v1/admin/users/0/badges 3. Test Case ID: 5KLsPa - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (`-û"ß\Ÿe `, `¸Ï™»`, `Þüqí𶂏Žl ` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [422] Unprocessable Content: `{"message":"[BadgeSlugs]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"-\u00fb\"\u00df\\\u009fe\u001e\u0017": [], "\u00f7": [null, [], {"\ud83e\udf54Q0\udb33\ude30\u00a8\n": null}], "\ud9f0\udc0f\u00df\u00dc[\u00c3\ud9f0\udf07": [], "\u00b8\u00cf\u0099\u00bb": [], "\u00de\u00fcq\u00ed\ud898\udc8f\u008el\u000b": {"0\u00ce\u00be": null, "\u00c2\u00fc": -777, "\ud8d8\uddec": true}}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/badges ______________________________ DELETE /orgs/{org} ______________________________ 1. Test Case ID: 4rYxSq - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench 2. Test Case ID: GZw4ns - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench ________________ DELETE /orgs/{org}/actions/runners/{runner_id} ________________ 1. Test Case ID: 4nmUF6 - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/runners/0 _______________ DELETE /orgs/{org}/actions/secrets/{secretname} ________________ 1. Test Case ID: 1plqZ3 - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/secrets/affected 2. Test Case ID: 1G2gNg - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/secrets/Error _____________ DELETE /orgs/{org}/actions/variables/{variablename} ______________ 1. Test Case ID: EDzaCA - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/u 2. Test Case ID: YPNNIz - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/false __________________________ DELETE /orgs/{org}/avatar ___________________________ 1. Test Case ID: Bt4shP - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/avatar _____________________ DELETE /orgs/{org}/blocks/{username} _____________________ 1. Test Case ID: 6b6ktJ - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/blocks/admin 2. Test Case ID: a1Zd6z - Undocumented HTTP status code Received: 401 Documented: 204, 404, 422 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: L@:=m' 'http://0.0.0.0:43007/api/v1/orgs/workbench/blocks/admin?sudo=s%C2%BE%C2%90%12L%EC%A5%AA%F1%86%AA%9Am&access_token=%5BFiltered%5D&token=%5BFiltered%5D' 3. Test Case ID: HzkXhl - Undocumented HTTP status code Received: 403 Documented: 204, 404, 422 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Sudo: L@:=m' 'http://0.0.0.0:43007/api/v1/orgs/workbench/blocks/admin?access_token=%5BFiltered%5D&sudo=' 4. Test Case ID: qUpoy1 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204, 404, 422 [400] Bad Request: `{"message":"cannot unblock the user","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/blocks/admin ________________________ DELETE /orgs/{org}/hooks/{id} _________________________ 1. Test Case ID: 60gkI3 - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/hooks/1 2. Test Case ID: kz4e0C - Undocumented HTTP status code Received: 403 Documented: 204, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP;' -H 'Sudo: $Z|6' http://0.0.0.0:43007/api/v1/orgs/workbench/hooks/1 ________________________ DELETE /orgs/{org}/labels/{id} ________________________ 1. Test Case ID: c8oEPy - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/labels/1 2. Test Case ID: JjaFE1 - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/labels/1 ____________________ DELETE /orgs/{org}/members/{username} _____________________ 1. Test Case ID: oZk8OP - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/members/admin 2. Test Case ID: VI516y - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/members/admin _______________________ DELETE /orgs/{org}/projects/{id} _______________________ 1. Test Case ID: L9fLq2 - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1 _____________ DELETE /orgs/{org}/projects/{id}/columns/{column_id} _____________ 1. Test Case ID: BARi7k - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns/1 ____ DELETE /orgs/{org}/projects/{id}/columns/{column_id}/issues/{issue_id} ____ 1. Test Case ID: HODM5z - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns/9999/issues/15 _________________ DELETE /orgs/{org}/public_members/{username} _________________ 1. Test Case ID: Jtb9gD - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/public_members/admin ___________________________ DELETE /orgs/{org}/repos ___________________________ 1. Test Case ID: uaGZ3G - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/repos _________________________ DELETE /repos/{owner}/{repo} _________________________ 1. Test Case ID: LpBRJR - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo _________ DELETE /repos/{owner}/{repo}/actions/artifacts/{artifact_id} _________ 1. Test Case ID: 2j9MJb - Undocumented HTTP status code Received: 403 Documented: 204, 400, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X DELETE -H 'Sudo: ,' -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: G' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/artifacts/0 2. Test Case ID: IkFDFD - Undocumented HTTP status code Received: 401 Documented: 204, 400, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/artifacts/0?token=%5BFiltered%5D&access_token=%5BFiltered%5D' _____________________ DELETE /repos/{owner}/{repo}/avatar ______________________ 1. Test Case ID: ZO7Zt7 - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/avatar ________________ DELETE /repos/{owner}/{repo}/branches/{branch} ________________ 1. Test Case ID: 5tAzM2 - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/branches/0 __________ DELETE /repos/{owner}/{repo}/collaborators/{collaborator} ___________ 1. Test Case ID: nwsyXQ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"user does not exist [uid: 0, name: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/collaborators/0 _______________ DELETE /repos/{owner}/{repo}/contents/{filepath} _______________ 1. Test Case ID: ldkLek - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"sha does not match [given: 83e0599c2e9d180479e163ad6e7fb7eb32b851a2, expected: e69de29bb2d1d6434b8b29ae775ad8c2e48c5391]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"sha": "83e0599c2e9d180479e163ad6e7fb7eb32b851a2"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/contents/0 _________________ DELETE /repos/{owner}/{repo}/hooks/git/{id} __________________ 1. Test Case ID: xf8Dre - Undocumented HTTP status code Received: 403 Documented: 204, 404 [403] Forbidden: `{"message":"must be allowed to edit Git hooks","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/hooks/git/83e0599c2e9d180479e163ad6e7fb7eb32b851a2 _________________ DELETE /repos/{owner}/{repo}/issues/{index} __________________ 1. Test Case ID: IbOH3m - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1 ______________ DELETE /repos/{owner}/{repo}/issues/{index}/blocks ______________ 1. Test Case ID: dc9lWr - Undocumented HTTP status code Received: 422 Documented: 200, 404 [422] Unprocessable Content: `{"message":"[]: json: cannot unmarshal JSON array into Go structs.IssueMeta","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"W\u00013`\uda3f\ude89\u0099\u00c4": ["\\0\udbe1\uddd2", false]}, "\u0083\u00a4", {"\t\u00df\u0092\u0003\ud9fe\udf55": "\u00ec@\u0010\ud952\udee4\u00dc", "\u0094": {}}, ["\u0011\u00ae\udbc2\uddfb\u00de$\ud84c\udf31\udb14\udcda\ud9ce\udf33\ud98d\udd7dF\u00efF2\u00ad3\"\u00b0", {"^MD": 85187, "EP\u00ac": false, "": true}], []]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/%0D%F1%AE%8C%AB%C2%BA%F1%96%9D%90%13%40%C2%8C%C2%86/blocks ___________ DELETE /repos/{owner}/{repo}/issues/{index}/dependencies ___________ 1. Test Case ID: zRgzzI - Undocumented HTTP status code Received: 422 Documented: 200, 404, 423 [422] Unprocessable Content: `{"message":"[]: jsontext: invalid character '\\x00' at start of value","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/0/dependencies ____________ DELETE /repos/{owner}/{repo}/issues/{index}/reactions _____________ 1. Test Case ID: cljd5g - Undocumented HTTP status code Received: 422 Documented: 204, 403, 404 [422] Unprocessable Content: `{"message":"[]: jsontext: invalid character '\\x00' at start of value","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/reactions ______________ DELETE /repos/{owner}/{repo}/issues/{index}/times _______________ 1. Test Case ID: ZWg8eD - Undocumented HTTP status code Received: 401 Documented: 204, 400, 403, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H $'Sudo: Ltq7|rz@Xg,.IK\t=' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/times?token=%5BFiltered%5D&sudo=&access_token=%5BFiltered%5D' ______ DELETE /repos/{owner}/{repo}/releases/{id}/assets/{attachment_id} _______ 1. Test Case ID: 1Rmeqm - Undocumented HTTP status code Received: 401 Documented: 204, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/1/assets/18716060?sudo=%F0%B9%81%B5%C2%8D%F3%BA%93%BD%0D&token=%5BFiltered%5D&access_token=%5BFiltered%5D' __________________ DELETE /repos/{owner}/{repo}/subscription ___________________ 1. Test Case ID: 0aKKGZ - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/subscription 2. Test Case ID: W5NeyP - Undocumented HTTP status code Received: 401 Documented: 204, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/subscription?token=%5BFiltered%5D&sudo=&access_token=%5BFiltered%5D' ___________________ DELETE /repos/{owner}/{repo}/tags/{tag} ____________________ 1. Test Case ID: N21Xk7 - Undocumented HTTP status code Received: 401 Documented: 204, 404, 405, 409, 422, 423 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Sudo: RejectedPositiveData' -H 'X-GITEA-OTP: Q' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/tags/0?token=%5BFiltered%5D' 2. Test Case ID: dYFIY9 - Undocumented HTTP status code Received: 403 Documented: 204, 404, 405, 409, 422, 423 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: Q' -H 'Sudo: RejectedPositiveData' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/tags/0?access_token=%5BFiltered%5D' _________________ DELETE /repos/{owner}/{repo}/topics/{topic} __________________ 1. Test Case ID: aJdI9G - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/topics/0 2. Test Case ID: VR4nZh - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"invalidTopics":"ºñ","message":"Topic name is invalid"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/topics/%C2%BA%C3%B1 ______________________________ DELETE /teams/{id} ______________________________ 1. Test Case ID: SMAkXR - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/teams/1 2. Test Case ID: g2xZDd - Unexpected response to a request without authentication Expected 401 or 403, got `404 Not Found` for `DELETE /teams/{id}` [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE http://0.0.0.0:43007/api/v1/teams/1 ____________________ DELETE /teams/{id}/members/{username} _____________________ 1. Test Case ID: DmGFiY - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 404 [500] Internal Server Error: `{"message":"user is the last member of owner team [uid: 1]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/teams/2/members/admin 2. Test Case ID: p6BXIV - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/teams/21/members/affected ____________________ DELETE /teams/{id}/repos/{org}/{repo} _____________________ 1. Test Case ID: eBVO8K - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/teams/2/repos/%F0%9E%9A%AF/demo ________________________________ DELETE /token _________________________________ 1. Test Case ID: d8SZ2n - Undocumented HTTP status code Received: 404 Documented: 204 [404] Not Found: `{"message":"invalid access token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/token ____________________ DELETE /user/applications/oauth2/{id} _____________________ 1. Test Case ID: OKh8hS - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 404 [500] Internal Server Error: `{"message":"failed to delete OAuth2 application: application is locked: e90ee53c-94e2-48ac-9358-a874fb9e0662","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/applications/oauth2/1 2. Test Case ID: A0fJ5v - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/applications/oauth2/24 _____________________________ DELETE /user/avatar ______________________________ 1. Test Case ID: n3ASZY - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/avatar 2. Test Case ID: EJUSYK - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: Pbi?X]' -H 'Sudo: _mrYR:' 'http://0.0.0.0:43007/api/v1/user/avatar?access_token=%5BFiltered%5D&sudo=%F2%92%98%B9' ________________________ DELETE /user/blocks/{username} ________________________ 1. Test Case ID: afRXU2 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204, 404, 422 [400] Bad Request: `{"message":"cannot unblock the user","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/blocks/admin _____________________________ DELETE /user/emails ______________________________ 1. Test Case ID: a7bdaD - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"emails": []}' http://0.0.0.0:43007/api/v1/user/emails 2. Test Case ID: HHz0aM - Undocumented HTTP status code Received: 422 Documented: 204, 404 [422] Unprocessable Content: `{"message":"[]: json: cannot unmarshal JSON object into Go string within \"/emails/0\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"emails": [{}]}' http://0.0.0.0:43007/api/v1/user/emails 3. Test Case ID: Qc2slA - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - emails: Incorrect type [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"emails": null}' http://0.0.0.0:43007/api/v1/user/emails ______________________ DELETE /user/following/{username} _______________________ 1. Test Case ID: VEqKVZ - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/following/admin 2. Test Case ID: u1lcIC - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/following/workbench __________________________ DELETE /user/gpg_keys/{id} __________________________ 1. Test Case ID: 0NLz3G - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/gpg_keys/-9223372036854775808 2. Test Case ID: IcQVu0 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `id` in path - violates `format`, `minimum`, `maximum` at /properties/id [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/gpg_keys/-41019207480008335360 ___________________________ DELETE /user/hooks/{id} ____________________________ 1. Test Case ID: 8tvsHG - Undocumented HTTP status code Received: 404 Documented: 204 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/hooks/-9223372036854775808 _____________________ DELETE /user/starred/{owner}/{repo} ______________________ 1. Test Case ID: nVxhor - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/starred/admin/demo 2. Test Case ID: B5ExqN - Undocumented HTTP status code Received: 401 Documented: 204, 403, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X DELETE -H 'X-GITEA-OTP;' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/starred/admin/demo?sudo=%C3%96%C2%A1%23%7B-%17%C2%8E%C3%9A%F3%99%BB%B8%07%C2%B0%F1%91%B5%BC%F0%B1%9E%84%C3%944%C3%8A%C3%BC%10%29%C3%97%C2%88%1B%28D%C3%A6%C3%9B%C2%B0%1F%F0%9E%97%8B%C2%B3%F2%92%8E%86%7F%C3%A7%C2%A7%F2%8A%8A%B9%C3%93%C2%B2%F1%8F%89%9C%23_%C2%A7%C3%9F%15%C2%B6&access_token=%5BFiltered%5D&token=%5BFiltered%5D' ___________________________ GET /admin/actions/jobs ____________________________ 1. Test Case ID: Q21vPG - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"invalid status ","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/actions/jobs?status=&page=0&limit=0&sort=&order=' 2. Test Case ID: ETHK4Q - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `{"jobs":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/actions/jobs?page=null&page=null' 3. Test Case ID: 1KgsVF - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"Invalid sort order: \"\\U000658fa\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/actions/jobs?status=%F1%90%8B%8D%F4%87%A3%86%C3%A1%F4%83%A7%89%F3%AF%8F%A8%C3%B9%C3%97&limit=418580264059225&order=%F1%A5%A3%BA&page=24347&sort=%C2%B3%F0%9A%BE%88%C3%AF%F4%84%B7%B4%C3%BD%F1%B5%9F%A9%C3%A1%C3%A7O%F1%BE%AE%AC~%00' __________________________ GET /admin/actions/runners __________________________ 1. Test Case ID: Txgu8P - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `disabled` in query - disabled: Incorrect type [200] OK: `{"runners":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/actions/runners?disabled=null&disabled=null' ___________________________ GET /admin/actions/runs ____________________________ 1. Test Case ID: 0O47nM - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"invalid status ","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/actions/runs?event=&branch=&status=&actor=&head_sha=&page=0&limit=0' 2. Test Case ID: dozUUX - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `{"workflow_runs":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/actions/runs?page=null&page=null' 3. Test Case ID: hxjj4A - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 404 [500] Internal Server Error: `{"message":"user does not exist [uid: 0, name: &\b񏋀\u0017]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/actions/runs?branch=%F3%82%84%BA%C3%85%18%3A%07v&head_sha=%03%C2%8D%1C%13h&actor=%26%08%F1%8F%8B%80%17%C2%81' _______________________________ GET /admin/cron ________________________________ 1. Test Case ID: R79ytk - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[{"name":"update_mirrors","schedule":"@every 10m","next":"2026-10-10T10:04:25Z","prev":"0001-01-01T00:00:00Z","exec_times":0},{"name":"repo_health_check","schedule":"@midnight","next":"2026-10-11T00:00:00Z","prev":"0001-01-01T00:00:00Z","exec_times":0},{"name":"check_repo_stats","schedule":"@midnight","next":"2026-10-11T00:00:00Z","prev":"2026-10-10T09:54:25.199487391Z","exec_times":1},{"name":"archive_cleanup","schedule":"@midnight","next":"2026-10-11T00:00:00Z","prev":"2026-10-10T09:54:25.199477753Z","exe // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/cron?page=null&page=null' 2. Test Case ID: XFX13p - Undocumented HTTP status code Received: 401 Documented: 200, 403 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/cron?page=-412791537' ______________________________ GET /admin/emails _______________________________ 1. Test Case ID: 8OiqQO - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[{"email":"admin@example.com","verified":true,"primary":true,"user_id":1,"username":"admin"},{"email":"workbench@example.com","verified":true,"primary":true,"user_id":2,"username":"workbench-user"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/emails?page=null&page=null' ___________________________ GET /admin/emails/search ___________________________ 1. Test Case ID: Jgo6XK - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[{"email":"admin@example.com","verified":true,"primary":true,"user_id":1,"username":"admin"},{"email":"workbench@example.com","verified":true,"primary":true,"user_id":2,"username":"workbench-user"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/emails/search?page=null&page=null' _______________________________ GET /admin/hooks _______________________________ 1. Test Case ID: UWe9v1 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `type` in query - type: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/hooks?type=null&type=null' ____________________________ GET /admin/hooks/{id} _____________________________ 1. Test Case ID: fM3lfY - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/admin/hooks/-9223372036854775808 _______________________________ GET /admin/orgs ________________________________ 1. Test Case ID: G6S5f9 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[{"id":3,"name":"workbench","full_name":"","email":"","avatar_url":"http://0.0.0.0:43007/avatars/1f303fd10424e23d36ee4dbd6af13c4d735f75bfe318b1259474fa53863403ba","description":"","website":"","location":"","visibility":"public","repo_admin_change_team_access":false,"username":"workbench"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/orgs?page=null&page=null' 2. Test Case ID: zyJZdJ - Undocumented HTTP status code Received: 401 Documented: 200, 403 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Sudo: c>_;$5' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/orgs?token=%5BFiltered%5D&limit=908721&page=1879946323' _____________________________ GET /admin/packages ______________________________ 1. Test Case ID: yOqx9T - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `type` in query - type: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/packages?type=null&type=null' _____________________________ GET /admin/unadopted _____________________________ 1. Test Case ID: tlAftj - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/unadopted?page=null&page=null' 2. Test Case ID: LGbcXS - Server error - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json - Undocumented HTTP status code Received: 500 Documented: 200, 403 [500] Internal Server Error: `PANIC: runtime error: invalid memory address or nil pointer dereference /usr/local/go/src/runtime/panic.go:859 (0x492004) /go/src/gitea.dev/modules/web/routing/logger_manager.go:87 (0x157033b) /usr/local/go/src/runtime/panic.go:859 (0x492004) /usr/local/go/src/runtime/panic.go:336 (0x494eb4) /usr/local/go/src/runtime/signal_unix.go:931 (0x494e85) /go/src/gitea.dev/services/repository/adopt.go:344 (0x22464d0) /usr/local/go/src/path/filepath/path.go:311 (0x63e12f) /usr/local/go/src/path/filepath/path.go:333 ( // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/unadopted?query=%C3%AE%F3%AF%8E%BB%F1%BC%A5%AD%C3%82%19%F3%83%81%90M%2AG%5B&page=-10952179&limit=3337' 3. Test Case ID: qsnhXy - Undocumented HTTP status code Received: 401 Documented: 200, 403 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: d~bxM{Pd' -H 'Sudo: 56@,Ejo' 'http://0.0.0.0:43007/api/v1/admin/unadopted?access_token=%5BFiltered%5D' _______________________________ GET /admin/users _______________________________ 1. Test Case ID: gnt4Gf - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `source_id` in query - source_id: Value greater than maximum [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/users?source_id=9223372036854775808' 2. Test Case ID: 9HhkRA - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"Invalid sort mode: \"ä³\\U000e0c4a \\U0003cdedäHA\\U000c2de0\\U0007d3c1\\U00103d4e\\U000386ad\\U000e494dÉ\\x1cß|\\U000678e2å\\u0097\\u0080è¨\\U0005a396e\\x05\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/users?visibility=%F1%A6%84%9A%0D%7BZ%C2%B0%5E%C2%AD%03%C3%B5%C2%B7&sort=%C3%A4%C2%B3%F3%A0%B1%8A+%F0%BC%B7%AD%C3%A4HA%F3%82%B7%A0%F1%BD%8F%81%F4%83%B5%8E%F0%B8%9A%AD%F3%A4%A5%8D%C3%89%1C%C3%9F%7C%F1%A7%A3%A2%C3%A5%C2%97%C2%80%C3%A8%C2%A8%F1%9A%8E%96e%05&is_prohibit_login=false&source_id=0&login_name=' ______________________ GET /admin/users/{username}/badges ______________________ 1. Test Case ID: RQKfEo - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: 6>EKE2&!' 'http://0.0.0.0:43007/api/v1/admin/users/admin/badges?access_token=%5BFiltered%5D&token=%5BFiltered%5D' ___________________________ GET /gitignore/templates ___________________________ 1. Test Case ID: i8w6ER - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /gitignore/templates` [200] OK: `["AL","Actionscript","Ada","Agda","Alteryx","AltiumDesigner","Android","Anjuta","Ansible","AppEngine","AppceleratorTitanium","ArchLinuxPackages","Archives","AtmelStudio","AutoIt","AutomationStudio","Autotools","B4X","Backup","Ballerina","Bazaar","Bazel","Beef","Bitrix","BricxCC","C","C++","CDK","CFWheels","CMake","CUDA","CVS","CakePHP","Calabash","ChefCookbook","Clojure","Cloud9","CodeIgniter","CodeKit","CodeSniffer","CommonLisp","Composer","Concrete5","Coq","Cordova","CraftCMS","D","DM","Dart","DartEditor" // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/gitignore/templates _______________________ GET /gitignore/templates/{name} ________________________ 1. Test Case ID: vYqUut - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /gitignore/templates/{name}` [200] OK: `{"name":"Flutter","source":"# Miscellaneous\n*.class\n*.lock\n*.log\n*.pyc\n*.swp\n.buildlog/\n.history\n\n\n\n# Flutter repo-specific\n/bin/cache/\n/bin/internal/bootstrap.bat\n/bin/internal/bootstrap.sh\n/bin/mingit/\n/dev/benchmarks/mega_gallery/\n/dev/bots/.recipe_deps\n/dev/bots/android_tools/\n/dev/devicelab/ABresults*.json\n/dev/docs/doc/\n/dev/docs/flutter.docs.zip\n/dev/docs/lib/\n/dev/docs/pubspec.yaml\n/dev/integration_tests/**/xcuserdata\n/dev/integration_tests/**/Pods\n/packages/flutter/coverag // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/gitignore/templates/Flutter _____________________________ GET /label/templates _____________________________ 1. Test Case ID: XVJKGE - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /label/templates` [200] OK: `["Advanced","Default"]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/label/templates 2. Test Case ID: qqImtl - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'X-GITEA-OTP: Uq{fHrCgq' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/label/templates?sudo=4%C2%AE%C3%9B%C3%96z%F0%BD%9D%92&access_token=%5BFiltered%5D&token=%5BFiltered%5D' 3. Test Case ID: 7G0P2p - Undocumented HTTP status code Received: 403 Documented: 200 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: Uq{fHrCgq' 'http://0.0.0.0:43007/api/v1/label/templates?access_token=%5BFiltered%5D&sudo=&token=%5BFiltered%5D' _________________________ GET /label/templates/{name} __________________________ 1. Test Case ID: 09FcCm - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Sudo: OI@' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/label/templates/Advanced?sudo=%C2%8C%C3%AC&access_token=%5BFiltered%5D' ________________________________ GET /licenses _________________________________ 1. Test Case ID: XipBwQ - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /licenses` [200] OK: `[{"key":"0BSD","name":"0BSD","url":"http://localhost:3000/api/v1/licenses/0BSD"},{"key":"AGPL-3.0","name":"AGPL-3.0","url":"http://localhost:3000/api/v1/licenses/AGPL-3.0"},{"key":"Apache-2.0","name":"Apache-2.0","url":"http://localhost:3000/api/v1/licenses/Apache-2.0"},{"key":"BSD-2-Clause","name":"BSD-2-Clause","url":"http://localhost:3000/api/v1/licenses/BSD-2-Clause"},{"key":"BSD-3-Clause","name":"BSD-3-Clause","url":"http://localhost:3000/api/v1/licenses/BSD-3-Clause"},{"key":"BSD-3-Clause-Clear","name // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/licenses 2. Test Case ID: TI0ksi - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/licenses?access_token=%5BFiltered%5D&token=%5BFiltered%5D&sudo=%C2%80' _____________________________ GET /licenses/{name} _____________________________ 1. Test Case ID: 3cVfkb - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /licenses/{name}` [200] OK: `{"key":"BSD-3-Clause","name":"BSD-3-Clause","url":"http://localhost:3000/api/v1/licenses/BSD-3-Clause","implementation":"Create a text file (typically named LICENSE or LICENSE.txt) in the root of your source code and copy the text of the license into the file","body":"Copyright (c) . \n\nRedistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:\n\n1. Redistributions of source code must retain the above copyrig // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/licenses/BSD-3-Clause ______________________________ GET /notifications ______________________________ 1. Test Case ID: ZRy4UD - Undocumented HTTP status code Received: 422 Documented: 200 [422] Unprocessable Content: `{"message":"parsing time \"null\" as \"2006-01-02T15:04:05Z07:00\": cannot parse \"null\" as \"2006\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/notifications?since=null&since=null' 2. Test Case ID: TlAJuI - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `since` in query - violates `format` at /properties/since [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/notifications?since=' __________________________________ GET /orgs ___________________________________ 1. Test Case ID: gAJssN - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /orgs` [200] OK: `[{"id":3,"name":"workbench","full_name":"","email":"","avatar_url":"http://0.0.0.0:43007/avatars/1f303fd10424e23d36ee4dbd6af13c4d735f75bfe318b1259474fa53863403ba","description":"","website":"","location":"","visibility":"public","repo_admin_change_team_access":false,"username":"workbench"}]` Reproduce with: curl -X GET 'http://0.0.0.0:43007/api/v1/orgs?page=0&limit=0' 2. Test Case ID: iipd7T - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[{"id":3,"name":"workbench","full_name":"","email":"","avatar_url":"http://0.0.0.0:43007/avatars/1f303fd10424e23d36ee4dbd6af13c4d735f75bfe318b1259474fa53863403ba","description":"","website":"","location":"","visibility":"public","repo_admin_change_team_access":false,"username":"workbench"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs?page=null&page=null' _______________________________ GET /orgs/{org} ________________________________ 1. Test Case ID: LmImij - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /orgs/{org}` [200] OK: `{"id":3,"name":"S","full_name":"","email":"","avatar_url":"http://0.0.0.0:43007/avatars/1f303fd10424e23d36ee4dbd6af13c4d735f75bfe318b1259474fa53863403ba","description":"","website":"","location":"","visibility":"public","repo_admin_change_team_access":false,"username":"S"}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/orgs/workbench 2. Test Case ID: FXTbKQ - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'X-GITEA-OTP: X _' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench?sudo=%F3%BD%B3%A96%F1%A2%A9%B7%C3%95&token=%5BFiltered%5D&access_token=%5BFiltered%5D' _________________________ GET /orgs/{org}/actions/jobs _________________________ 1. Test Case ID: AT3ddd - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"invalid status ¸µ\u001d","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/actions/jobs?status=%C2%B8%C2%B5%1D&limit=60077836122948064&page=-2641' 2. Test Case ID: Zui4id - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became array) [200] OK: `{"jobs":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/actions/jobs?page=3904593710&limit=%5B2.4033522706268905e-25%5D&limit=%5B%27null%27%2C+%27null%27%2C+%27null%27%5D&limit=%5B%7B%27%3D%5CU000d4d47%27%3A+%27null%27%2C+%27%F0%A3%BA%9Al%27%3A+%27null%27%2C+%27%27%3A+-1.631157595044347e-253%7D%2C+%7B%7D%2C+%27false%27%5D&limit=%5B-96681958%2C+%27false%27%2C+3347%5D&limit=%7B%27%5CU0007663b%C3%9B%27%3A+%27%5Cx95%5Cx0f%C2%B3%2B%C3%BE%5CU0009b46e%40%2C%7D%C3%8BZ%5Cx9d%5CU000a2a83%5Cx9f%5Cx1a%27%2C+%27%5Cx88%C3%B3%27%3A+%27true%27%2C+%27k%C3%B8%27%3A+56%7D&limit=%5B%5D&limit=%7B%27%C3%9E%5Cx91%5CU000a8356%23g%27%3A+%7B%27None%27%3A+-1.3041972019553555e%2B93%7D%2C+%27c%27%3A+%5B%5D%2C+%27%C3%96%27%3A+%5B%5B%27true%27%5D%2C+2.8530193055024972e%2B16%2C+%5B-2118%5D%5D%7D&limit=%5B%7B%27c%5Cx97%5Cx08%27%3A+7296329%2C+%27%5Cx82%5Cx06y%27%3A+16062641999854.0%2C+%27%C3%A2%27%3A+%27true%27%7D%5D&limit=%5B%5D&limit=%7B%27%5Cxad%5CU0003f8b6%3E%C3%BBK%C3%9F%5Cx83%5CU000bc8a3i%24r%5Cx1bL%C3%B7%5Cx9b%5CU00072413k8%5CU000d5642-%60%C2%BF%5CU000d47a2%5CU000a84efm%2A%5Cx9e%5Cx8en%27%3A+%27%C3%BC%C3%91%C2%BA%C3%8C%27%2C+%27%C3%8D%27%3A+%5B%27true%27%2C+%27%C3%9F%27%2C+%27G%2CW%5CU0008a9b1%5Cx94%C3%B9%C3%8A%2A%27%5D%7D&limit=%5B%5D&limit=%C2%BE%C3%B3%03Q&limit=true&limit=false&limit=false&limit=-1.1125369292536007e-308&limit=-1.823450099999731e%2B16&limit=%7B%27S%27%3A+%27null%27%2C+%27JsonSchemaError%27%3A+%7B%27%5CU000ad7bc%C3%B1%27%3A+%27false%27%7D%7D&limit=9%7D&limit=58728362491325.0&limit=%C3%85%C2%AB%C2%B3%C2%AE%F3%88%B8%A2%C2%AE%2A%C2%A0%5B%3B%F1%BF%AB%80&limit=s%F4%8D%B6%99&limit=%C3%90&limit=%C3%96%C2%BE%F3%94%BC%88%07&limit=%1C%C2%9E%C2%B6X%F1%95%8F%B7%5C&limit=false&limit=%5B%5D&limit=%5B%27true%27%2C+%7B%7D%2C+%27null%27%5D&limit=%5B%5B%27null%27%5D%5D&limit=%5B-1274117.8621164644%5D&limit=%7B%27G%C3%8A%5CU000ae380%C3%B7%27%3A+%7B%27%27%3A+%27false%27%2C+%27%5CU0003ad7f%5Cx0e%5CU000af351%5Cx0b%C2%B3%C2%A3%C3%9E%5Cxa0i%27%3A+-2717500219%2C+%27n%C3%98%5CrK%C3%B1%5Cx0b%5Cx11%C3%B3%5Cx1a%5Cx9f%5Cx06%C3%BF%5Cx80%27%3A+%27true%27%7D%2C+%27f%5CU000dedc1k%5Cx1c%27%3A+-3.353312906314767e%2B68%2C+%27Ku%C3%AA%C3%BB%F0%AC%8C%BE%C3%A5%C2%B9%27%3A+%5B%27va%5Cxa0%5Cx11%5Cx91%7B%5Cx89L%C3%98%5Cx9a%C2%AB%C2%B0%C2%A6z%27%5D%7D&limit=%C2%8Ak&limit=W%2A%C3%A6%C2%90%F1%A6%BF%94%C2%8E%F2%99%9E%8E4%C3%B7%F1%B7%AE%82%C2%A5%2F%C2%A6%C2%AC8&limit=false' _______________________ GET /orgs/{org}/actions/runners ________________________ 1. Test Case ID: kYxNzm - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `disabled` in query - violates `type` at /properties/disabled (was boolean, became null) [200] OK: `{"runners":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/actions/runners?disabled=null' _________________ GET /orgs/{org}/actions/runners/{runner_id} __________________ 1. Test Case ID: bfVmST - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/runners/0 _________________________ GET /orgs/{org}/actions/runs _________________________ 1. Test Case ID: EnavO2 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"invalid status ¥_Ëå¦\u001e˜稐\të","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/actions/runs?head_sha=%C2%B2%0A%25&branch=0d%1E&page=-14080&status=%C2%A5_%C3%8B%C3%A5%C2%A6%1E%C2%98%E7%A8%90%09%C3%AB' 2. Test Case ID: gELAWI - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 404 [500] Internal Server Error: `{"message":"user does not exist [uid: 0, name: ŠÈ]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/actions/runs?actor=%C2%8A%C3%88&event=%7C%F1%B6%9A%B7%15%C2%BD%1E%C3%80%2B%F3%A3%8C%AB%F1%8A%B4%B8Z%C3%96%C3%AD%2BT%C3%AB%1F%F1%9E%98%BA%C3%A5%11%C2%B9%15%C3%81%C2%A0%17%F2%80%AB%B9%01%F0%92%B4%B5%F4%8C%90%A1%F4%81%B3%B5&head_sha=%0F%05%C3%97&branch=%C3%8C%C3%B6%F0%AE%96%9D&page=-213' 3. Test Case ID: AyjTkv - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became string) [200] OK: `{"workflow_runs":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/actions/runs?page=%C2%AC%C3%97D%C2%86%C3%81%C3%B3%F3%83%93%8B%C3%A3%C2%A0&branch=%C3%A4' _______________________ GET /orgs/{org}/actions/secrets ________________________ 1. Test Case ID: 6GC9TT - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `limit`, `page` in query - violates `type` at /properties/limit (was integer, became object) - violates `type` at /properties/page (was integer, became boolean) [200] OK: `[{"name":"O","description":"","created_at":"2026-10-10T10:34:06Z"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/actions/secrets?limit=%F3%89%85%AD%F3%BD%87%96%C3%9B%7D%F0%BE%8E%83%F4%83%8E%88%7F&limit=i_%F1%AC%BD%8C&limit=%11n%C3%8C%13%22%C3%A4T%C2%AF%F2%89%A0%A5&limit=%C2%AD&limit=&limit=%F2%B9%93%A5%F2%8C%9F%A7%C3%99%08%F2%B9%96%87I%E3%AD%9E%F2%91%95%8F%7DE%7B%C3%92&page=false' _______________ GET /orgs/{org}/actions/variables/{variablename} _______________ 1. Test Case ID: Wqhg0j - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/u 2. Test Case ID: kTL6kK - Undocumented HTTP status code Received: 401 Documented: 200, 400, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: _CJ+-Yhysxu$D#' 'http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/u?access_token=%5BFiltered%5D&sudo=%C2%92&token=%5BFiltered%5D' _______________________ GET /orgs/{org}/activities/feeds _______________________ 1. Test Case ID: MDqtRW - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /orgs/{org}/activities/feeds` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/orgs/workbench/activities/feeds 2. Test Case ID: j3NgwA - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became array) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/activities/feeds?limit=1.2549880401898368e-20&limit=false&limit=%C3%BAZ%17%C3%8C%C3%925%F2%9F%A5%A2%C2%A1%C3%AD%1A&limit=&limit=%03&limit=categories&limit=%C3%99-%07%0C%F3%B8%AC%BC%F2%90%92%94%C2%B6_%C3%93c&limit=%F3%A8%AE%90%3C&limit=null&limit=%5B%5D&limit=%7B%27%C2%B1X%C2%B5%27%3A+%5B%5D%2C+%27%5CU000c1742Q%C3%A2%5CU000b58fd%5CU0005fc6c%3D_%25%5C%5C%27%3A+%7B%27S%5Cx92%5Cx1dM%5Cx91%5Cx15Q%27%3A+-318%7D%2C+%27%23%5Cx81%5CU00066537%5Cx8c%5D%5Cn9%5CU0010880b%C3%88%5CU0008d0d7%5Cx91%C3%B4%27%3A+%7B%7D%7D&limit=1.2574911199542354e-269&limit=&limit=J%C3%BA%C3%A8%02.%03%C3%83%3Df%C3%A5%C3%9B%F2%9B%8C%B3' ____________________________ GET /orgs/{org}/blocks ____________________________ 1. Test Case ID: 5DFyzA - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/0/blocks?page=0&limit=0' 2. Test Case ID: vrODto - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `page`, `limit` in query - violates `type` at /properties/page (was integer, became array) - violates `type` at /properties/limit (was integer, became boolean) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/blocks?page=-1.86390655305782e%2B16&page=%C3%A3&page=%C2%AB%C3%8C%C2%B1&page=%F1%AB%A7%AE%F2%87%98%80&page=%C3%80%F2%BD%82%8F0%23%3E%F1%BE%BB%BC%C3%8A%F3%AF%86%AF&page=%F0%BD%90%89%F0%9D%BA%98%0A%1CL%C3%9A&page=%C3%A0t~%C3%81l%C2%A3%C2%B9&page=%7B%27categories%27%3A+%27true%27%7D&page=%7B%7D&page=Performance&page=%11%F4%84%AC%82%F2%A9%AE%A1%C3%B6%F2%9A%80%A8%C2%BA&page=%C3%B4%C2%BC%C3%9D&page=%C3%9C%3B%C3%92%C2%A1%C3%99&page=true&page=false&page=%7B%7D&page=8584&page=%5B%5D&page=%5B%5B-691%2C+%27%C3%98%5CU000eeafa%27%2C+%5B%27false%27%5D%5D%2C+%5B%5D%2C+%5B%5D%5D&page=%7B%27%5Cx16%5Cx13%27%3A+1973%2C+%27%27%3A+%27%5CU00019278%C3%829%5Cx8a%5CU000de338N6%C3%84w%C3%B5%5CU00062be0%C3%AF%5Cx16%C3%84%C3%BD%5Cx9aH%C3%88%2F%27%7D&page=z%F0%9E%83%AF%C2%95%F1%B9%93%88%05%C2%B2%12r%2An%03%F2%A6%BF%B6&page=2.9739211322055012e%2B16&page=true&page=&page=5.718912927643821e%2B16&page=__proto__&page=%C3%9E%C3%A0%F3%A8%82%AA&page=%C2%94%C2%9B&page=%C2%9F%3B&page=%C3%8A%F3%81%81%9E&page=AllowHeaderMismatch&page=true&limit=false' ______________________ GET /orgs/{org}/blocks/{username} _______________________ 1. Test Case ID: kGybEb - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/blocks/admin 2. Test Case ID: 6aVrqn - Missing Content-Type header The following media types are documented in the schema: - `application/json` [404] Not Found: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/blocks/admin ____________________________ GET /orgs/{org}/hooks _____________________________ 1. Test Case ID: H357zh - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `limit`, `page` in query - violates `type` at /properties/limit (was integer, became object) - violates `type` at /properties/page (was integer, became object) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/hooks?page=pK%5B%C2%BAG%C2%B6%5C%C3%8D%E1%84%A6&page=%C2%8F%F3%9C%A8%95S&limit=%C3%B1E%C2%89%C3%B2%C2%A7%C3%92%F1%AD%B8%BBS%0E%F2%B8%87%BF%C2%83%F1%AF%84%97&limit=%EA%9B%A93F&limit=&limit=%C3%80%C2%9E' __________________________ GET /orgs/{org}/hooks/{id} __________________________ 1. Test Case ID: zva0kC - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/hooks/1 ____________________________ GET /orgs/{org}/labels ____________________________ 1. Test Case ID: FLWsxv - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /orgs/{org}/labels` [200] OK: `[{"id":13,"name":"0BSD","exclusive":true,"is_archived":false,"color":"00aabb","description":"Ì𝯴“񨘢","url":"http://localhost:3000/api/v1/orgs/S/labels/13"},{"id":12,"name":"Apache-2.0","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/orgs/S/labels/12"},{"id":49,"name":"Apache-2.0","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/orgs/S/labels/49"},{"id":45,"name":"BSD-2-Clause","exclusive":fal // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/orgs/workbench/labels 2. Test Case ID: n9xIrB - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became array) [200] OK: `[{"id":13,"name":"0BSD","exclusive":true,"is_archived":false,"color":"00aabb","description":"Ì𝯴“񨘢","url":"http://localhost:3000/api/v1/orgs/S/labels/13"},{"id":12,"name":"Apache-2.0","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/orgs/S/labels/12"},{"id":49,"name":"Apache-2.0","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/orgs/S/labels/49"},{"id":45,"name":"BSD-2-Clause","exclusive":fal // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/labels?limit=145084736&page=5.56570168887081e%2B16' _________________________ GET /orgs/{org}/labels/{id} __________________________ 1. Test Case ID: qTEK0D - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/labels/1 ___________________________ GET /orgs/{org}/members ____________________________ 1. Test Case ID: wket4S - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became string) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/members?limit=O%C2%98%C3%8C%10%C3%8D%C3%97%F2%A4%B3%B5%C2%822%F2%95%AF%B4&page=266' 2. Test Case ID: t3DcPQ - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `[{"id":4,"login":"workbench-user","type":"Organization","login_name":"","source_id":0,"full_name":"admin/cleanup_packages","email":"","avatar_url":"http://0.0.0.0:43007/avatars/fa25ceee0d7be94b95c0208f7456232d4e85b901ba9bb49d8219ba29e2313dc7","html_url":"http://0.0.0.0:43007/workbench-user","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:58:40Z","restricted":false,"active":true,"prohibit_login":true,"location":"","website":"","description":"\r{¹4òÙ´wS𘖩cãwà","visibi // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/members ______________________ GET /orgs/{org}/members/{username} ______________________ 1. Test Case ID: FUuFMl - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/members/admin 2. Test Case ID: 9jPlFm - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/members/workbench-user ___________________________ GET /orgs/{org}/projects ___________________________ 1. Test Case ID: hrXPlj - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /orgs/{org}/projects` [200] OK: `[{"id":72,"title":"First issue","description":"","owner_id":3,"repo_id":0,"creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"lo // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/orgs/workbench/projects 2. Test Case ID: afRpC3 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became boolean) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/projects?limit=false&page=69654847395995' ________________________ GET /orgs/{org}/projects/{id} _________________________ 1. Test Case ID: 6UBx6k - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1 ____________________ GET /orgs/{org}/projects/{id}/columns _____________________ 1. Test Case ID: lYNWUN - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns ______________ GET /orgs/{org}/projects/{id}/columns/{column_id} _______________ 1. Test Case ID: mkfCm4 - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns/1 ___________ GET /orgs/{org}/projects/{id}/columns/{column_id}/issues ___________ 1. Test Case ID: 9WNpya - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns/1/issues ________________________ GET /orgs/{org}/public_members ________________________ 1. Test Case ID: tPHVUc - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /orgs/{org}/public_members` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/orgs/workbench/public_members 2. Test Case ID: kK5feB - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became boolean) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/public_members?limit=false&page=1867' 3. Test Case ID: THMcSv - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'X-GITEA-OTP: }ZJ' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/public_members?access_token=%5BFiltered%5D&token=%5BFiltered%5D' 4. Test Case ID: tmNS0o - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `[{"id":4,"login":"workbench-user","type":"Organization","login_name":"","source_id":0,"full_name":"admin/cleanup_packages","email":"","avatar_url":"http://0.0.0.0:43007/avatars/fa25ceee0d7be94b95c0208f7456232d4e85b901ba9bb49d8219ba29e2313dc7","html_url":"http://0.0.0.0:43007/workbench-user","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:58:40Z","restricted":false,"active":true,"prohibit_login":true,"location":"","website":"","description":"\r{¹4òÙ´wS𘖩cãwà","visibi // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/public_members __________________ GET /orgs/{org}/public_members/{username} ___________________ 1. Test Case ID: Dxmm6a - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/public_members/admin ____________________________ GET /orgs/{org}/repos _____________________________ 1. Test Case ID: trza8Q - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /orgs/{org}/repos` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/orgs/workbench/repos 2. Test Case ID: miYQ9E - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became object) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/repos?page=%27%F0%A4%B5%AB%C3%96&page=%1C&page=%F1%86%A1%8F&page=%F3%BB%87%82%C3%96%2F%01%F0%BF%A0%8C%C2%8C%0E%F2%95%B3%90%C3%92%F0%A2%BE%94P%16M%F1%AD%BA%92%F1%A0%98%9A1%3A%F3%9E%BA%A6%14V&page=%C3%BE&page=&page=%5E%3B%C2%84%F0%99%90%B1%C3%B7%3A%5E%F2%8F%92%A6%C2%AA&page=total&page=%C2%BEL%F0%A5%B4%89%C2%9F&page=%C3%A75%C3%84%C3%9B&page=%C2%AB%F4%86%B0%8B%F2%92%B3%BD%C2%9129&limit=1153419868905' ____________________________ GET /orgs/{org}/teams _____________________________ 1. Test Case ID: Q3JX18 - Response violates schema (3 violations) null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Team/properties/units: { "type": "array", "description": "Deprecated: This variable should be replaced by UnitsMap ... "items": { "type": "string" }, "x-deprecated": true, "x-go-name": "Units", "example": [ "repo.code", "repo.issues", "repo.ext_issues", "repo.wiki", "repo.pulls", "repo.releases", "repo.projects", "repo.ext_wiki" ] } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Organization: { "type": "object", "description": "Organization represents an organization", "properties": { "avatar_url": { "description": "The URL of the organization's avatar", "type": "string", "x-go-name": "AvatarURL" }, "description": { "description": "The description of the organization", "type": "string", "x-go-name": "Description" }, "email": { "description": "The email address of the organization", "type": "string", "x-go-name": "Email" }, // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Team/properties/units_map: { "type": "object", "additionalProperties": { "type": "string" }, "x-go-name": "UnitsMap", "example": { "repo.code": "read", "repo.ext_issues": "none", "repo.ext_wiki": "none", "repo.issues": "write", "repo.projects": "none", "repo.pulls": "owner", "repo.releases": "none", "repo.wiki": "admin" } } Value: null [200] OK: `[{"id":4,"name":"Owners","description":"","organization":null,"includes_all_repositories":false,"permission":"none","units":[""],"units_map":{"":"admin"},"can_create_org_repo":true,"visibility":"private"},{"id":13,"name":"AGPL-3.0","description":"","organization":null,"includes_all_repositories":true,"permission":"read","units":null,"units_map":null,"can_create_org_repo":false,"visibility":"private"},{"id":9,"name":"Apache-2.0","description":"","organization":null,"includes_all_repositories":true,"permissio // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/teams 2. Test Case ID: MyYknt - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became object) [200] OK: `[{"id":4,"name":"Owners","description":"","organization":null,"includes_all_repositories":false,"permission":"none","units":[""],"units_map":{"":"admin"},"can_create_org_repo":true,"visibility":"private"},{"id":13,"name":"AGPL-3.0","description":"","organization":null,"includes_all_repositories":true,"permission":"read","units":null,"units_map":null,"can_create_org_repo":false,"visibility":"private"},{"id":9,"name":"Apache-2.0","description":"","organization":null,"includes_all_repositories":true,"permissio // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/teams?page=&page=%F2%9A%91%BA%C2%AB%F3%96%86%B4%7Bl%10%C2%B6%F0%A7%A1%8C%C3%AC%06%C2%A4wD%C2%82%F2%BD%98%9C%C2%93%C3%9A%C3%B6&page=Workbench&page=%17%7D%F2%A7%AF%85H&limit=419' _________________________ GET /orgs/{org}/teams/search _________________________ 1. Test Case ID: RpiZSL - Response violates schema (3 violations) null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Team/properties/units: { "type": "array", "description": "Deprecated: This variable should be replaced by UnitsMap ... "items": { "type": "string" }, "x-deprecated": true, "x-go-name": "Units", "example": [ "repo.code", "repo.issues", "repo.ext_issues", "repo.wiki", "repo.pulls", "repo.releases", "repo.projects", "repo.ext_wiki" ] } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Organization: { "type": "object", "description": "Organization represents an organization", "properties": { "avatar_url": { "description": "The URL of the organization's avatar", "type": "string", "x-go-name": "AvatarURL" }, "description": { "description": "The description of the organization", "type": "string", "x-go-name": "Description" }, "email": { "description": "The email address of the organization", "type": "string", "x-go-name": "Email" }, // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Team/properties/units_map: { "type": "object", "additionalProperties": { "type": "string" }, "x-go-name": "UnitsMap", "example": { "repo.code": "read", "repo.ext_issues": "none", "repo.ext_wiki": "none", "repo.issues": "write", "repo.projects": "none", "repo.pulls": "owner", "repo.releases": "none", "repo.wiki": "admin" } } Value: null [200] OK: `{"ok":true,"data":[{"id":4,"name":"Owners","description":"","organization":null,"includes_all_repositories":false,"permission":"none","units":[""],"units_map":{"":"admin"},"can_create_org_repo":true,"visibility":"private"},{"id":13,"name":"AGPL-3.0","description":"","organization":null,"includes_all_repositories":true,"permission":"read","units":null,"units_map":null,"can_create_org_repo":false,"visibility":"private"},{"id":9,"name":"Apache-2.0","description":"","organization":null,"includes_all_repositorie // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/teams/search 2. Test Case ID: HG5zke - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `page`, `include_desc` in query - violates `type` at /properties/page (was integer, became object) - violates `type` at /properties/include_desc (was boolean, became number) [200] OK: `{"ok":true,"data":[{"id":4,"name":"Owners","description":"","organization":null,"includes_all_repositories":false,"permission":"none","units":[""],"units_map":{"":"admin"},"can_create_org_repo":true,"visibility":"private"},{"id":13,"name":"AGPL-3.0","description":"","organization":null,"includes_all_repositories":true,"permission":"read","units":null,"units_map":null,"can_create_org_repo":false,"visibility":"private"},{"id":9,"name":"Apache-2.0","description":"","organization":null,"includes_all_repositorie // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/orgs/workbench/teams/search?page=&include_desc=-7.070559818937115e-149' ____________________________ GET /packages/{owner} _____________________________ 1. Test Case ID: tFJUJ5 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became array) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/packages/admin?limit=-201707976&type=pypi&page=%F3%BE%92%BD%3C&page=false&page=%C2%86%C2%9F%C3%8F%21%26&page=r.&q=%C3%96%06' ___________________________ GET /repos/issues/search ___________________________ 1. Test Case ID: uoG4RK - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/issues/search` [200] OK: `[]` Reproduce with: curl -X GET 'http://0.0.0.0:43007/api/v1/repos/issues/search?state=open&labels=&milestones=&q=&type=issues&since=2000-01-01T00%3A00%3A00Z&before=2000-01-01T00%3A00%3A00Z&assigned=true&created=true&mentioned=true&review_requested=true&reviewed=true&owner=&created_by=&team=&page=1&limit=0' 2. Test Case ID: NF7yBX - Response violates schema (7 violations) null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/assignees: { "type": "array", "items": { "$ref": "#/components/schemas/User" }, "x-go-name": "Assignees" } Value: null null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/projects: { "type": "array", "items": { "$ref": "#/components/schemas/Project" }, "x-go-name": "Projects" } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Milestone: { "type": "object", "description": "Milestone milestone is a collection of issues on one repo... "properties": { "closed_at": { "type": "string", "format": "date-time", "x-go-name": "Closed" }, "closed_issues": { "description": "ClosedIssues is the number of closed issues in th... "type": "integer", "format": "int64", "x-go-name": "ClosedIssues" }, "created_at": { "type": "string", "format": "date-time", "x-go-name": "Created" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PullRequestMeta: { "type": "object", "description": "PullRequestMeta PR info if an issue is a PR", "properties": { "draft": { "type": "boolean", "x-go-name": "IsWorkInProgress" }, "html_url": { "type": "string", "x-go-name": "HTMLURL" }, "merged": { "type": "boolean", "x-go-name": "HasMerged" }, "merged_at": { "type": "string", "format": "date-time", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/due_date: { "type": "string", "format": "date-time", "x-go-name": "Deadline" } Value: null - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `type` in query - type: Incorrect type [200] OK: `[{"id":1,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/1","html_url":"http://0.0.0.0:43007/admin/demo/issues/1","number":1,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restrict // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/issues/search?type=null&type=null' 3. Test Case ID: gxjsoK - Undocumented HTTP status code Received: 404 Documented: 200, 400, 422 [404] Not Found: `{"message":"user does not exist [uid: 0, name: †4#9^ñ\u00177\u0014]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/issues/search?limit=117&assigned=false&state=all&created_by=%C2%864%239%5E%C3%B1%177%14&review_requested=true&milestones=%02' 4. Test Case ID: QAtii8 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"owner organisation is required for filtering on team","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/issues/search?state=closed&type=issues&team=False&since=2026-10-10T09%3A59%3A34Z&reviewed=false&milestones=%F3%91%90%9A%F1%8E%B5%9B%C2%BDZ%C2%BC&before=6255-09-09T18%3A51%3A29Z&created=false&page=539113&labels=%C2%9F%F2%B2%A1%B9%C3%82&created_by=%C2%B7%C3%96&review_requested=false&mentioned=true' ______________________________ GET /repos/search _______________________________ 1. Test Case ID: jhkRsI - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/search` [200] OK: `{"ok":true,"data":[]}` Reproduce with: curl -X GET 'http://0.0.0.0:43007/api/v1/repos/search?q=&topic=true&includeDesc=true&uid=-9223372036854775808&priority_owner_id=-9223372036854775808&team_id=1&starredBy=-9223372036854775808&private=true&is_private=true&template=true&archived=true&mode=&exclusive=true&sort=&order=&page=0&limit=0' 2. Test Case ID: V3ggvP - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `uid` in query - uid: Value greater than maximum [200] OK: `{"ok":true,"data":[]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/search?uid=9223372036854775808' 3. Test Case ID: qOsP3b - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `{"ok":true,"data":[{"id":5,"owner":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"\rÝ𑀮°𓚒­뜸#œÔ򛝠Í𴳓ÑێB","website":"","desc // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/search?priority_owner_id=33873' 4. Test Case ID: oFV4Zg - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"invalid search mode","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/search?exclusive=true&limit=18639430&mode=%C2%B5%7C&team_id=1' 5. Test Case ID: MUkBM2 - Undocumented HTTP status code Received: 403 Documented: 200, 422 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'X-GITEA-OTP: 0' -H 'Sudo: _%c9' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/search?template=false&mode=-%C2%B5' __________________________ GET /repos/{owner}/{repo} ___________________________ 1. Test Case ID: zUc1Vt - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}` [200] OK: `{"id":1,"owner":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"\rÝ𑀮°𓚒­뜸#œÔ򛝠Í𴳓ÑێB","website":"","description":"˜\u0012 Ï // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo 2. Test Case ID: 1ZQFxX - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: None' 'http://0.0.0.0:43007/api/v1/repos/admin/demo?token=%5BFiltered%5D&access_token=%5BFiltered%5D&sudo=Ucym%C2%82%C2%89w%C2%BC%7F%0A%F3%B4%91%93%F1%9D%A9%83x%C3%BD%C2%9CfV%F1%AA%B9%BF%0C%C2%ADl' _________________ GET /repos/{owner}/{repo}/actions/artifacts __________________ 1. Test Case ID: uWRFz9 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/actions/artifacts` [200] OK: `{"artifacts":[],"total_count":0}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/artifacts ____________________ GET /repos/{owner}/{repo}/actions/jobs ____________________ 1. Test Case ID: 2dpOpZ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"Invalid sort order: \"\\U00036cbcÌ\\x1ad\\U000efeef#\\a\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/jobs?page=-68874601&status=zX&limit=-439720166597273714688&order=%F0%B6%B2%BC%C3%8C%1Ad%F3%AF%BB%AF%23%07&sort=%F0%B6%90%92%F1%8A%BD%95%C2%A5%C2%AC%0F%C3%B9%F2%8A%AB%BD%C2%8A%C2%B3F%5B%F0%BB%A5%8DW%C2%ADp%3B%C3%AA7%F1%AE%B7%BE%2B%C2%9B%2C%07%C3%AF%F2%84%B5%97%00%7C%F1%A7%B4%B4%F1%B5%BA%81%C2%96%F1%90%8A%93%C2%9D' _______________ GET /repos/{owner}/{repo}/actions/jobs/{job_id} ________________ 1. Test Case ID: NR1B7A - Undocumented HTTP status code Received: 401 Documented: 200, 400, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/jobs/0?token=%5BFiltered%5D&access_token=%5BFiltered%5D&sudo=%C3%B2' 2. Test Case ID: FR0b4o - Undocumented HTTP status code Received: 403 Documented: 200, 400, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/jobs/0?access_token=%5BFiltered%5D&token=%5BFiltered%5D&sudo=%C3%B2' __________________ GET /repos/{owner}/{repo}/actions/runners ___________________ 1. Test Case ID: 0wS3m7 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `disabled` in query - violates `type` at /properties/disabled (was boolean, became integer) [200] OK: `{"runners":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/runners?disabled=-716' ____________________ GET /repos/{owner}/{repo}/actions/runs ____________________ 1. Test Case ID: lwj3xI - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 404 [500] Internal Server Error: `{"message":"user does not exist [uid: 0, name: 񖶂å]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/runs?branch=%C2%AD%0Am&page=11929&actor=%F1%96%B6%82%C3%A5' 2. Test Case ID: spmFIe - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"invalid status 񐼍}ª²N","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/runs?status=%F1%90%BC%8D%7D%C2%AA%C2%B2N' 3. Test Case ID: QhoaY1 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `exclude_pull_requests` in query - violates `type` at /properties/exclude_pull_requests (was boolean, became integer) [200] OK: `{"workflow_runs":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/runs?exclude_pull_requests=-169' ____________ GET /repos/{owner}/{repo}/actions/runs/{run}/artifacts ____________ 1. Test Case ID: kkibNF - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/actions/runs/{run}/artifacts` [200] OK: `{"artifacts":[],"total_count":0}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/runs/1/artifacts ______________ GET /repos/{owner}/{repo}/actions/runs/{run}/logs _______________ 1. Test Case ID: XknOhY - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: application/zip [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/actions/runs/0/logs ___________________ GET /repos/{owner}/{repo}/actions/tasks ____________________ 1. Test Case ID: ZRKewa - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/actions/tasks` [200] OK: `{"workflow_runs":[],"total_count":0}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/tasks 2. Test Case ID: 6lRVvK - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became null) [200] OK: `{"workflow_runs":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/tasks?limit=null&page=16777216' 3. Test Case ID: 1hpQzv - Undocumented HTTP status code Received: 401 Documented: 200, 400, 403, 404, 409, 422 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Sudo: b- ' -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: sI!)' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/tasks?limit=-933&access_token=%5BFiltered%5D' _________________ GET /repos/{owner}/{repo}/actions/variables __________________ 1. Test Case ID: m6Bq0a - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became null) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables?page=null&limit=4613' __________ GET /repos/{owner}/{repo}/actions/variables/{variablename} __________ 1. Test Case ID: jMHLHd - Undocumented HTTP status code Received: 401 Documented: 200, 400, 404 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables/false 2. Test Case ID: kmCPoz - Undocumented HTTP status code Received: 403 Documented: 200, 400, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables/false?token=%5BFiltered%5D&sudo=%C2%B3qp%0AN' _________________ GET /repos/{owner}/{repo}/actions/workflows __________________ 1. Test Case ID: 139YYs - Server error - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [500] Internal Server Error: `PANIC: runtime error: invalid memory address or nil pointer dereference /usr/local/go/src/runtime/panic.go:859 (0x492004) /go/src/gitea.dev/modules/web/routing/logger_manager.go:87 (0x157033b) /usr/local/go/src/runtime/panic.go:859 (0x492004) /usr/local/go/src/runtime/panic.go:336 (0x494eb4) /usr/local/go/src/runtime/signal_unix.go:931 (0x494e85) /go/src/gitea.dev/modules/git/repo_object.go:40 (0xfcfafc) /go/src/gitea.dev/modules/git/repo_commit_nogogit.go:110 (0xfcb964) /go/src/gitea.dev/modules/git/repo_c // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/0/actions/workflows ________ GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs ________ 1. Test Case ID: Kg6oh4 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 403, 404 [500] Internal Server Error: `{"message":"user does not exist [uid: 0, name: \b󘌯񦿚𧺥\u0000]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/workflows/%C2%B6%0DU%C3%81%F1%92%A5%B4/runs?scoped_workflow_source_repo_id=-29939&head_sha=%C3%85%F1%82%BE%97%C2%B7%F0%B7%9B%8D&branch=t&limit=-27466&actor=%08%F3%98%8C%AF%F1%A6%BF%9A%F0%A7%BA%A5%00' 2. Test Case ID: C2lI0G - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"invalid status ","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/workflows/%F2%9B%A6%87%C3%85%C3%89%C2%81%C2%A4%C3%94%01/runs?page=-28556&event=%C2%81%C2%B5%F0%B9%89%B32O%C2%82%5B%C2%BCT&branch=%F3%8D%86%93%25%C3%84&exclude_pull_requests=true&head_sha=%EA%8D%AF%C2%B9%C3%94%C3%99%01%F2%A3%8D%BB%F1%B5%AC%8CXA&actor=%0D%C3%97%C2%A9%F1%AC%81%98%C2%87&limit=524384&scoped_workflow_source_repo_id=5355352&status=' __________________ GET /repos/{owner}/{repo}/activities/feeds __________________ 1. Test Case ID: 4nOi3X - Response violates schema null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null [200] OK: `[{"id":119,"user_id":1,"op_type":"comment_issue","act_user_id":1,"act_user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":true,"prohibit_login":false,"location":"","websit // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/activities/feeds 2. Test Case ID: Tsn0Qv - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/activities/feeds` [200] OK: `[{"id":119,"user_id":1,"op_type":"comment_issue","act_user_id":1,"act_user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location": // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/activities/feeds 3. Test Case ID: sUKK3i - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `date`, `page` in query - violates `format` at /properties/date - violates `type` at /properties/page (was integer, became string) [200] OK: `[{"id":119,"user_id":1,"op_type":"comment_issue","act_user_id":1,"act_user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":true,"prohibit_login":false,"location":"","websit // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/activities/feeds?date=&page=%F3%96%A9%A6%C2%B6%F1%87%83%A4%C2%90l%C3%BC%C3%B3%F2%AB%A5%9F%C3%94%C3%99%F0%B6%96%AE%C3%BA%C3%9E%C2%9DV%C2%99o7%0Fm%C2%9E%23%C3%B9P%C3%9E%C2%99%C2%8C%C2%A1' 4. Test Case ID: MXAcsd - Response violates schema null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Comment: { "type": "object", "description": "Comment represents a comment on a commit or issue", "properties": { "assets": { "description": "Attachments contains files attached to the comment", "type": "array", "items": { "$ref": "#/components/schemas/Attachment" }, "x-go-name": "Attachments" }, "body": { "description": "Body contains the comment text content", "type": "string", "x-go-name": "Body" }, "created_at": { "type": "string", // Output truncated... } Value: null [200] OK: `[{"id":119,"user_id":1,"op_type":"comment_issue","act_user_id":1,"act_user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":true,"prohibit_login":false,"location":"","websit // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/activities/feeds?date=%C2%B9%F1%B1%A3%87%F0%BB%A5%9A%C2%8D%F1%86%A3%9D&limit=206114904&page=-4557254362649' _________________ GET /repos/{owner}/{repo}/archive/{archive} __________________ 1. Test Case ID: lckQiK - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 404 [400] Bad Request: `{"message":"unknown format: 0","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/archive/0 _____________________ GET /repos/{owner}/{repo}/assignees ______________________ 1. Test Case ID: aFU0s0 - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/assignees?sudo=&access_token=%5BFiltered%5D&token=%5BFiltered%5D' _________________ GET /repos/{owner}/{repo}/branch_protections _________________ 1. Test Case ID: ySI7mD - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/branch_protections _____________ GET /repos/{owner}/{repo}/branch_protections/{name} ______________ 1. Test Case ID: DOGCJB - Response violates schema null is not of type "array" Validated against the response schema for status code 200. Schema at /properties/status_check_contexts: { "type": "array", "items": { "type": "string" }, "x-go-name": "StatusCheckContexts" } Value: null [200] OK: `{"branch_name":"‹Go³󀨻󫵛B","rule_name":"‹Go³󀨻󫵛B","priority":6,"enable_push":false,"enable_push_whitelist":false,"push_whitelist_usernames":[],"push_whitelist_teams":[],"push_whitelist_deploy_keys":false,"enable_force_push":false,"enable_force_push_allowlist":false,"force_push_allowlist_usernames":[],"force_push_allowlist_teams":[],"force_push_allowlist_deploy_keys":false,"enable_merge_whitelist":false,"merge_whitelist_usernames":[],"merge_whitelist_teams":[],"enable_bypass_allowlist":false,"bypass_allowlist_u // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/branch_protections/%C2%8BGo%C2%B3%F3%80%A8%BB%F3%AB%B5%9BB 2. Test Case ID: pEKSkd - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/branch_protections/repo_health_check?sudo=&token=%5BFiltered%5D&access_token=%5BFiltered%5D' ______________________ GET /repos/{owner}/{repo}/branches ______________________ 1. Test Case ID: PdAntF - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/0/0/branches?page=0&limit=0&q=' 2. Test Case ID: CRLmPe - Response violates schema (4 violations) null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/PayloadCommit/properties/added: { "type": "array", "description": "List of files added in this commit", "items": { "type": "string" }, "x-go-name": "Added" } Value: null null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/PayloadCommit/properties/modified: { "type": "array", "description": "List of files modified in this commit", "items": { "type": "string" }, "x-go-name": "Modified" } Value: null null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/PayloadCommit/properties/removed: { "type": "array", "description": "List of files removed in this commit", "items": { "type": "string" }, "x-go-name": "Removed" } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PayloadUser: { "type": "object", "description": "PayloadUser represents the author or committer of a commit", "properties": { "email": { "type": "string", "format": "email", "x-go-name": "Email" }, "name": { "description": "Full name of the commit author", "type": "string", "x-go-name": "Name" }, "username": { "description": "username of the user", "type": "string", "x-go-name": "UserName" } // Output truncated... } Value: null [200] OK: `[{"name":"main","commit":{"id":"81fd78e7708f93ca17ba2ebde334ba4566b26bca","message":"Add Ö\n","url":"http://localhost:3000/admin/demo/commit/81fd78e7708f93ca17ba2ebde334ba4566b26bca","author":{"name":"admin","email":"admin@example.com","username":"admin"},"committer":{"name":"admin","email":"admin@example.com","username":"admin"},"verification":{"verified":false,"reason":"gpg.error.not_signed_commit","signature":"","signer":null,"payload":""},"timestamp":"2026-10-10T09:59:25Z","added":null,"removed":null,"m // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/branches 3. Test Case ID: Yc9DlL - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/branches` [200] OK: `[{"name":"main","commit":{"id":"81fd78e7708f93ca17ba2ebde334ba4566b26bca","message":"Add Ö\n","url":"http://localhost:3000/admin/demo/commit/81fd78e7708f93ca17ba2ebde334ba4566b26bca","author":{"name":"admin","email":"admin@example.com","username":"admin"},"committer":{"name":"admin","email":"admin@example.com","username":"admin"},"verification":{"verified":false,"reason":"gpg.error.not_signed_commit","signature":"","signer":null,"payload":""},"timestamp":"2026-10-10T09:59:25Z","added":null,"removed":null,"m // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/branches _________________ GET /repos/{owner}/{repo}/branches/{branch} __________________ 1. Test Case ID: 5U0xoa - Response violates schema (4 violations) null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/PayloadCommit/properties/added: { "type": "array", "description": "List of files added in this commit", "items": { "type": "string" }, "x-go-name": "Added" } Value: null null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/PayloadCommit/properties/modified: { "type": "array", "description": "List of files modified in this commit", "items": { "type": "string" }, "x-go-name": "Modified" } Value: null null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/PayloadCommit/properties/removed: { "type": "array", "description": "List of files removed in this commit", "items": { "type": "string" }, "x-go-name": "Removed" } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PayloadUser: { "type": "object", "description": "PayloadUser represents the author or committer of a commit", "properties": { "email": { "type": "string", "format": "email", "x-go-name": "Email" }, "name": { "description": "Full name of the commit author", "type": "string", "x-go-name": "Name" }, "username": { "description": "username of the user", "type": "string", "x-go-name": "UserName" } // Output truncated... } Value: null [200] OK: `{"name":"0","commit":{"id":"83e0599c2e9d180479e163ad6e7fb7eb32b851a2","message":"Initial commit\n","url":"http://localhost:3000/admin/demo/commit/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","author":{"name":"admin","email":"admin@example.com","username":"admin"},"committer":{"name":"admin","email":"admin@example.com","username":"admin"},"verification":{"verified":false,"reason":"gpg.error.not_signed_commit","signature":"","signer":null,"payload":""},"timestamp":"2026-10-10T09:54:25Z","added":null,"removed":nu // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/branches/0 2. Test Case ID: q3cGwq - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/branches/{branch}` [200] OK: `{"name":"0","commit":{"id":"83e0599c2e9d180479e163ad6e7fb7eb32b851a2","message":"Initial commit\n","url":"http://localhost:3000/admin/demo/commit/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","author":{"name":"admin","email":"admin@example.com","username":"admin"},"committer":{"name":"admin","email":"admin@example.com","username":"admin"},"verification":{"verified":false,"reason":"gpg.error.not_signed_commit","signature":"","signer":null,"payload":""},"timestamp":"2026-10-10T09:54:25Z","added":null,"removed":nu // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/branches/0 ____________ GET /repos/{owner}/{repo}/collaborators/{collaborator} ____________ 1. Test Case ID: syymm6 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"user does not exist [uid: 0, name: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/collaborators/0 2. Test Case ID: uOpu3D - Undocumented HTTP status code Received: 401 Documented: 204, 404, 422 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/collaborators/0 ______________________ GET /repos/{owner}/{repo}/commits _______________________ 1. Test Case ID: vCDYMj - Response violates schema null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PayloadUser: { "type": "object", "description": "PayloadUser represents the author or committer of a commit", "properties": { "email": { "type": "string", "format": "email", "x-go-name": "Email" }, "name": { "description": "Full name of the commit author", "type": "string", "x-go-name": "Name" }, "username": { "description": "username of the user", "type": "string", "x-go-name": "UserName" } // Output truncated... } Value: null [200] OK: `[{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/81fd78e7708f93ca17ba2ebde334ba4566b26bca","sha":"81fd78e7708f93ca17ba2ebde334ba4566b26bca","created":"2026-10-10T09:59:25Z","html_url":"http://localhost:3000/admin/demo/commit/81fd78e7708f93ca17ba2ebde334ba4566b26bca","commit":{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/81fd78e7708f93ca17ba2ebde334ba4566b26bca","author":{"name":"admin","email":"admin@example.com","date":"2026-10-10T09:59:25Z"},"committer":{"name":"admin // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/commits 2. Test Case ID: gzeZMS - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/commits` [200] OK: `[{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/81fd78e7708f93ca17ba2ebde334ba4566b26bca","sha":"81fd78e7708f93ca17ba2ebde334ba4566b26bca","created":"2026-10-10T09:59:25Z","html_url":"http://localhost:3000/admin/demo/commit/81fd78e7708f93ca17ba2ebde334ba4566b26bca","commit":{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/81fd78e7708f93ca17ba2ebde334ba4566b26bca","author":{"name":"admin","email":"admin@example.com","date":"2026-10-10T09:59:25Z"},"committer":{"name":"admin // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/commits 3. Test Case ID: blavWR - Response violates schema null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PayloadCommitVerification: { "type": "object", "description": "PayloadCommitVerification represents the GPG verification... "properties": { "payload": { "description": "The signed payload content", "type": "string", "x-go-name": "Payload" }, "reason": { "description": "The reason for the verification status", "type": "string", "x-go-name": "Reason" }, "signature": { "description": "The GPG signature of the commit", "type": "string", "x-go-name": "Signature" }, // Output truncated... } Value: null [200] OK: `[{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/81fd78e7708f93ca17ba2ebde334ba4566b26bca","sha":"81fd78e7708f93ca17ba2ebde334ba4566b26bca","created":"2026-10-10T09:59:25Z","html_url":"http://localhost:3000/admin/demo/commit/81fd78e7708f93ca17ba2ebde334ba4566b26bca","commit":{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/81fd78e7708f93ca17ba2ebde334ba4566b26bca","author":{"name":"admin","email":"admin@example.com","date":"2026-10-10T09:59:25Z"},"committer":{"name":"admin // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/commits?verification=false' 4. Test Case ID: 9vm1uX - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 404, 409 [500] Internal Server Error: `{"message":"exit status 128 - fatal: bad revision 'à?'","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/commits?since=2026-10-10T09%3A58%3A54Z&verification=false&limit=-3698140&stat=true&page=304250263527209&sha=93597659152b3882f4a31a4289c9fbc1197a2738&until=0472-06-16T12%3A58%3A32Z&path=R%C3%A0%3F6%C3%8D%C2%84%F0%BA%92%8C%F2%84%A5%B5%60&files=true¬=%C3%A0%13' 5. Test Case ID: nFiJGh - Response violates schema null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Commit/properties/files: { "type": "array", "description": "Files contains information about files affected by the co... "items": { "$ref": "#/components/schemas/CommitAffectedFiles" }, "x-go-name": "Files" } Value: null [200] OK: `[{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/81fd78e7708f93ca17ba2ebde334ba4566b26bca","sha":"81fd78e7708f93ca17ba2ebde334ba4566b26bca","created":"2026-10-10T09:59:25Z","html_url":"http://localhost:3000/admin/demo/commit/81fd78e7708f93ca17ba2ebde334ba4566b26bca","commit":{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/81fd78e7708f93ca17ba2ebde334ba4566b26bca","author":{"name":"admin","email":"admin@example.com","date":"2026-10-10T09:59:25Z"},"committer":{"name":"admin // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/commits?files=false' 6. Test Case ID: pQgI1e - Undocumented HTTP status code Received: 403 Documented: 200, 404, 409 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/commits?page=1462989676243&limit=-347&sudo=%08%C2%B6%C2%9A%16%F2%A3%A9%B6%C2%A6p%06%11%C3%BF%F2%AE%AC%B4%C3%83%F2%AA%8E%9B%C2%8E%C2%9E%F2%98%97%8C%2ACGw%C2%B6%F0%BF%A5%A2%0FN%C3%ABMOZ' ________________ GET /repos/{owner}/{repo}/commits/{ref}/status ________________ 1. Test Case ID: GpOdnn - Response violates schema "" is not one of "pending", "success" or 4 other candidates Validated against the response schema for status code 200. Schema at /definitions/CommitStatus/properties/status: { "enum": [ "pending", "success", "error", "failure", "warning", "skipped" ], "description": "State represents the status state (pending, success, erro... "type": "string", "x-go-enum-desc": "pending CommitStatusPending is for when the CommitStat... "x-go-name": "State" } Value: "" [200] OK: `{"state":"pending","sha":"83e0599c2e9d180479e163ad6e7fb7eb32b851a2","total_count":1,"statuses":[{"id":33,"status":"","target_url":"","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","context":"","creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_u // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/commits/0/status 2. Test Case ID: EFW11r - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/commits/{ref}/status` [200] OK: `{"state":"pending","sha":"83e0599c2e9d180479e163ad6e7fb7eb32b851a2","total_count":1,"statuses":[{"id":33,"status":"","target_url":"","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","context":"","creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_u // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/commits/0/status _______________ GET /repos/{owner}/{repo}/commits/{ref}/statuses _______________ 1. Test Case ID: 8KGOMO - Response violates schema "" is not one of "pending", "success" or 4 other candidates Validated against the response schema for status code 200. Schema at /definitions/CommitStatus/properties/status: { "enum": [ "pending", "success", "error", "failure", "warning", "skipped" ], "description": "State represents the status state (pending, success, erro... "type": "string", "x-go-enum-desc": "pending CommitStatusPending is for when the CommitStat... "x-go-name": "State" } Value: "" [200] OK: `[{"id":33,"status":"","target_url":"","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","context":"","creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00: // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/commits/0/statuses 2. Test Case ID: M0qUH3 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/commits/{ref}/statuses` [200] OK: `[{"id":33,"status":"","target_url":"","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","context":"","creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00: // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/commits/0/statuses 3. Test Case ID: BZViFD - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `sort`, `state`, `page` in query - violates `enum` at /properties/sort - violates `enum` at /properties/state - violates `type` at /properties/page (was integer, became array) [200] OK: `[{"id":33,"status":"","target_url":"","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","context":"","creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00: // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/commits/0/statuses?page=false&sort=&state=' 4. Test Case ID: wEOHjM - Undocumented HTTP status code Received: 403 Documented: 200, 400, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: U =' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/commits/%F3%AF%8C%BC%C3%A7v%C2%87/statuses?state=warning' 5. Test Case ID: OMm3AM - Undocumented HTTP status code Received: 401 Documented: 200, 400, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: U =' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/commits/%F3%AF%8C%BC%C3%A7v%C2%87/statuses?access_token=%5BFiltered%5D' _________________ GET /repos/{owner}/{repo}/compare/{basehead} _________________ 1. Test Case ID: WO77Dt - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/compare/{basehead}` [200] OK: `{"total_commits":0,"commits":[]}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/compare/0 2. Test Case ID: Frgq9c - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"unsupported ref suffix \"~ó[\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/compare/~%C3%B3%5B' ______________________ GET /repos/{owner}/{repo}/contents ______________________ 1. Test Case ID: X5dqbc - Response violates schema (4 violations) null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/content: { "type": "string", "description": "`content` is populated when `type` is `file`, otherwise n... "x-go-name": "Content" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/encoding: { "type": "string", "description": "`encoding` is populated when `type` is `file`, otherwise ... "x-go-name": "Encoding" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/submodule_git_url: { "type": "string", "description": "`submodule_git_url` is populated when `type` is `submodul... "x-go-name": "SubmoduleGitURL" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/target: { "type": "string", "description": "`target` is populated when `type` is `symlink`, otherwise... "x-go-name": "Target" } Value: null [200] OK: `[{"name":"\u0011†","path":"\u0011†","sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","last_commit_sha":"fa3dc8f9c4ab67028decf3dcd42e044247311257","last_committer_date":"2026-10-10T09:59:23Z","last_author_date":"2026-10-10T09:59:23Z","type":"file","mode":"100644","size":0,"encoding":null,"content":null,"target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/%11%C2%86?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/%11%C2%86","git_url":"http://0.0.0.0:43007/api/v1/rep // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/contents 2. Test Case ID: OlC4C2 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/contents` [200] OK: `[{"name":"\u0011†","path":"\u0011†","sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","last_commit_sha":"fa3dc8f9c4ab67028decf3dcd42e044247311257","last_committer_date":"2026-10-10T09:59:23Z","last_author_date":"2026-10-10T09:59:23Z","type":"file","mode":"100644","size":0,"encoding":null,"content":null,"target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/%11%C2%86?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/%11%C2%86","git_url":"http://0.0.0.0:43007/api/v1/rep // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/contents ______________ GET /repos/{owner}/{repo}/contents-ext/{filepath} _______________ 1. Test Case ID: a2VbHX - Response violates schema (4 violations) null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/content: { "type": "string", "description": "`content` is populated when `type` is `file`, otherwise n... "x-go-name": "Content" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/encoding: { "type": "string", "description": "`encoding` is populated when `type` is `file`, otherwise ... "x-go-name": "Encoding" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/submodule_git_url: { "type": "string", "description": "`submodule_git_url` is populated when `type` is `submodul... "x-go-name": "SubmoduleGitURL" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/target: { "type": "string", "description": "`target` is populated when `type` is `symlink`, otherwise... "x-go-name": "Target" } Value: null [200] OK: `{"file_contents":{"name":"0","path":"0","sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","type":"file","mode":"100644","size":0,"encoding":null,"content":null,"target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/0?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/0","git_url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/git/blobs/e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","download_url":"http://0.0.0.0:43007/admin/demo/raw/branch/main/0","submodule_git_url":null,"_ // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/contents-ext/0 2. Test Case ID: o1CuMg - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/contents-ext/{filepath}` [200] OK: `{"file_contents":{"name":"0","path":"0","sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","type":"file","mode":"100644","size":0,"encoding":null,"content":null,"target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/0?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/0","git_url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/git/blobs/e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","download_url":"http://0.0.0.0:43007/admin/demo/raw/branch/main/0","submodule_git_url":null,"_ // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/contents-ext/0 3. Test Case ID: bGsRia - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 404 [400] Bad Request: `{"message":"unknown include option \"~.Ob\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/contents-ext/%F0%96%A5%B0%09%C2%8C%C2%AD%C3%97%C3%81%C3%87%0CZ%C2%8F%C2%9A%C2%AB%23G%F1%B8%AB%B5Ow%28%C2%9F%C2%88%2C?ref=&includes=~.Ob' 4. Test Case ID: OAQbkb - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'X-GITEA-OTP: Z~O}' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/contents-ext/%0A%C2%92%C2%A2%F2%A7%9B%86S%F2%95%BB%BD%F3%A0%89%83?access_token=%5BFiltered%5D' 5. Test Case ID: PPNDVi - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: Z~O}' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/contents-ext/%0A%C2%92%C2%A2%F2%A7%9B%86S%F2%95%BB%BD%F3%A0%89%83?access_token=%5BFiltered%5D' ________________ GET /repos/{owner}/{repo}/contents/{filepath} _________________ 1. Test Case ID: 2maf69 - Response violates schema (2 violations) null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/submodule_git_url: { "type": "string", "description": "`submodule_git_url` is populated when `type` is `submodul... "x-go-name": "SubmoduleGitURL" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/target: { "type": "string", "description": "`target` is populated when `type` is `symlink`, otherwise... "x-go-name": "Target" } Value: null [200] OK: `{"name":"0","path":"0","sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","last_commit_sha":"aa7cbf35920bb549090447015c53b2426900df88","last_committer_date":"2026-10-10T09:59:22Z","last_author_date":"2026-10-10T09:59:22Z","type":"file","mode":"100644","size":0,"encoding":"base64","content":"","target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/0?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/0","git_url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/git/blobs/e69 // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/contents/0 2. Test Case ID: dMm3WO - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/contents/{filepath}` [200] OK: `{"name":"0","path":"0","sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","last_commit_sha":"aa7cbf35920bb549090447015c53b2426900df88","last_committer_date":"2026-10-10T09:59:22Z","last_author_date":"2026-10-10T09:59:22Z","type":"file","mode":"100644","size":0,"encoding":"base64","content":"","target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/0?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/0","git_url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/git/blobs/e69 // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/contents/0 ______________ GET /repos/{owner}/{repo}/editorconfig/{filepath} _______________ 1. Test Case ID: gBOq4y - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H $'Sudo: OZ\t' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/%C3%91/editorconfig/5V%F2%B9%AD%B9?sudo=%0B%C2%B3%C3%AC%C3%B0%C2%A5%F1%96%A5%B0J&ref=refs%2Fheads%2Fa%C2%A7%F0%95%95%AE%F1%8D%80%A6&token=%5BFiltered%5D&access_token=%5BFiltered%5D' ___________________ GET /repos/{owner}/{repo}/file-contents ____________________ 1. Test Case ID: WDzC8Y - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 404 [400] Bad Request: `{"message":"invalid body parameter","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/file-contents?body=Workbench' _______________________ GET /repos/{owner}/{repo}/forks ________________________ 1. Test Case ID: 7pozp7 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/forks` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/forks __________________ GET /repos/{owner}/{repo}/git/blobs/{sha} ___________________ 1. Test Case ID: mzinpB - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/git/blobs/{sha}` [200] OK: `{"content":"dHJlZSAyNzYyMzlhZjliZjJkYmU2ODg3ZDRkNjIwYWZjMmIwZTFkOTNhYjhjCmF1dGhvciBhZG1pbiA8YWRtaW5AZXhhbXBsZS5jb20+IDE3OTE2MjYwNjUgKzAwMDAKY29tbWl0dGVyIGFkbWluIDxhZG1pbkBleGFtcGxlLmNvbT4gMTc5MTYyNjA2NSArMDAwMAoKSW5pdGlhbCBjb21taXQK","encoding":"base64","url":"http://localhost:3000/api/v1/repos/admin/demo/git/blobs/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","sha":"83e0599c2e9d180479e163ad6e7fb7eb32b851a2","size":165}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/git/blobs/83e0599c2e9d180479e163ad6e7fb7eb32b851a2 2. Test Case ID: yEgdds - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"length 14 has no matched object format: \u000f󖸌󌆸񞰧\b","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/git/blobs/%0F%F3%96%B8%8C%F3%8C%86%B8%F1%9E%B0%A7%08 _________________ GET /repos/{owner}/{repo}/git/commits/{sha} __________________ 1. Test Case ID: S3qLnH - Response violates schema (2 violations) null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/CommitStats: { "type": "object", "description": "CommitStats is statistics for a RepoCommit", "properties": { "additions": { "description": "Additions is the number of lines added", "type": "integer", "format": "int64", "x-go-name": "Additions" }, "deletions": { "description": "Deletions is the number of lines deleted", "type": "integer", "format": "int64", "x-go-name": "Deletions" }, "total": { "description": "Total is the total number of lines changed", "type": "integer", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PayloadUser: { "type": "object", "description": "PayloadUser represents the author or committer of a commit", "properties": { "email": { "type": "string", "format": "email", "x-go-name": "Email" }, "name": { "description": "Full name of the commit author", "type": "string", "x-go-name": "Name" }, "username": { "description": "username of the user", "type": "string", "x-go-name": "UserName" } // Output truncated... } Value: null [200] OK: `{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/78e499c3107f08afc3a96578ccb82320e3cf67d3","sha":"78e499c3107f08afc3a96578ccb82320e3cf67d3","created":"2026-10-10T09:59:23Z","html_url":"http://localhost:3000/admin/demo/commit/78e499c3107f08afc3a96578ccb82320e3cf67d3","commit":{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/78e499c3107f08afc3a96578ccb82320e3cf67d3","author":{"name":"admin","email":"admin@example.com","date":"2026-10-10T09:59:23Z"},"committer":{"name":"admin" // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/git/commits/78e499c3107f08afc3a96578ccb82320e3cf67d3?stat=false&files=true&verification=true' 2. Test Case ID: lNuXNr - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/git/commits/{sha}` [200] OK: `{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/78e499c3107f08afc3a96578ccb82320e3cf67d3","sha":"78e499c3107f08afc3a96578ccb82320e3cf67d3","created":"2026-10-10T09:59:23Z","html_url":"http://localhost:3000/admin/demo/commit/78e499c3107f08afc3a96578ccb82320e3cf67d3","commit":{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/78e499c3107f08afc3a96578ccb82320e3cf67d3","author":{"name":"admin","email":"admin@example.com","date":"2026-10-10T09:59:23Z"},"committer":{"name":"admin" // Output truncated...` Reproduce with: curl -X GET 'http://0.0.0.0:43007/api/v1/repos/admin/demo/git/commits/78e499c3107f08afc3a96578ccb82320e3cf67d3?stat=false&files=true&verification=true' 3. Test Case ID: FvcJHA - Response violates schema null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PayloadCommitVerification: { "type": "object", "description": "PayloadCommitVerification represents the GPG verification... "properties": { "payload": { "description": "The signed payload content", "type": "string", "x-go-name": "Payload" }, "reason": { "description": "The reason for the verification status", "type": "string", "x-go-name": "Reason" }, "signature": { "description": "The GPG signature of the commit", "type": "string", "x-go-name": "Signature" }, // Output truncated... } Value: null [200] OK: `{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/aa7cbf35920bb549090447015c53b2426900df88","sha":"aa7cbf35920bb549090447015c53b2426900df88","created":"2026-10-10T09:59:22Z","html_url":"http://localhost:3000/admin/demo/commit/aa7cbf35920bb549090447015c53b2426900df88","commit":{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/aa7cbf35920bb549090447015c53b2426900df88","author":{"name":"admin","email":"admin@example.com","date":"2026-10-10T09:59:22Z"},"committer":{"name":"admin" // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/git/commits/aa7cbf35920bb549090447015c53b2426900df88?verification=false' 4. Test Case ID: Cdnczq - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `stat`, `verification` in query - violates `type` at /properties/stat (was boolean, became integer) - violates `type` at /properties/verification (was boolean, became integer) [200] OK: `{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/3a845a5d717ef6bc0cafd41d55759365aa42391a","sha":"3a845a5d717ef6bc0cafd41d55759365aa42391a","created":"2026-10-10T09:59:24Z","html_url":"http://localhost:3000/admin/demo/commit/3a845a5d717ef6bc0cafd41d55759365aa42391a","commit":{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/3a845a5d717ef6bc0cafd41d55759365aa42391a","author":{"name":"admin","email":"admin@example.com","date":"2026-10-10T09:59:24Z"},"committer":{"name":"admin" // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/git/commits/3a845a5d717ef6bc0cafd41d55759365aa42391a?stat=-1&verification=-1' 5. Test Case ID: qhZWyv - Response violates schema null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Commit/properties/files: { "type": "array", "description": "Files contains information about files affected by the co... "items": { "$ref": "#/components/schemas/CommitAffectedFiles" }, "x-go-name": "Files" } Value: null [200] OK: `{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","sha":"83e0599c2e9d180479e163ad6e7fb7eb32b851a2","created":"2026-10-10T09:54:25Z","html_url":"http://localhost:3000/admin/demo/commit/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","commit":{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","author":{"name":"admin","email":"admin@example.com","date":"2026-10-10T09:54:25Z"},"committer":{"name":"admin" // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/git/commits/0?files=false' 6. Test Case ID: DCUhha - Response violates schema null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null [200] OK: `{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/9739d8558d623cf6bd4e9bc9c28688b8bd081b8c","sha":"9739d8558d623cf6bd4e9bc9c28688b8bd081b8c","created":"2026-10-10T09:58:54Z","html_url":"http://localhost:3000/admin/demo/commit/9739d8558d623cf6bd4e9bc9c28688b8bd081b8c","commit":{"url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/9739d8558d623cf6bd4e9bc9c28688b8bd081b8c","author":{"name":"cleanup_hook_task_table","email":"workbench@example.com","date":"2026-10-10T09:58:54Z"},"comm // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/git/commits/9739d8558d623cf6bd4e9bc9c28688b8bd081b8c 7. Test Case ID: rMDqi1 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"no valid ref or sha:  ™L\u000bÀÖTe¬\u001f","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/git/commits/%C2%A0%C2%99L%0B%C3%80%C3%96Te%C2%AC%1F?verification=true' ____________ GET /repos/{owner}/{repo}/git/commits/{sha}.{diffType} ____________ 1. Test Case ID: eKZvDk - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: text/plain [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/git/commits/0.diff 2. Test Case ID: 6zW4i0 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/git/commits/{sha}.{diffType}` [200] OK: `commit 83e0599c2e9d180479e163ad6e7fb7eb32b851a2 Author: admin Date: Sat Oct 10 09:54:25 2026 +0000 Initial commit diff --git a/README.md b/README.md new file mode 100644 index 0000000..45d053e --- /dev/null +++ b/README.md @@ -0,0 +1,2 @@ +# demo +` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/git/commits/83e0599c2e9d180479e163ad6e7fb7eb32b851a2.diff 3. Test Case ID: LgxzO6 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 404 [500] Internal Server Error: `{"message":"getRepoRawDiffForFileCmd: object does not exist [id: yk󨾥¶6Aè, rel_path: ]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/git/commits/yk%F3%A8%BE%A5%C2%B66A%C3%A8.patch 4. Test Case ID: RR6fUL - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `text/plain` [200] OK: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/git/commits/9ec587167381a457c043966bc660ea737115e531.diff __________________ GET /repos/{owner}/{repo}/git/notes/{sha} ___________________ 1. Test Case ID: FBSVa5 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"no valid ref or sha: 񐩿½Yš‡þCž˜\u0017","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/git/notes/%F1%90%A9%BF%C2%BDY%C2%9A%C2%87%C3%BEC%C2%9E%C2%98%17?files=false&verification=true' ______________________ GET /repos/{owner}/{repo}/git/refs ______________________ 1. Test Case ID: gk8RwS - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/git/refs` [200] OK: `[{"ref":"refs/heads/0","url":"http://localhost:3000/api/v1/repos/admin/demo/git/refs/heads/0","object":{"type":"commit","sha":"83e0599c2e9d180479e163ad6e7fb7eb32b851a2","url":"http://localhost:3000/api/v1/repos/admin/demo/git/commits/83e0599c2e9d180479e163ad6e7fb7eb32b851a2"}},{"ref":"refs/heads/a§𕕮񍀦","url":"http://localhost:3000/api/v1/repos/admin/demo/git/refs/heads/a%C2%A7%F0%95%95%AE%F1%8D%80%A6","object":{"type":"commit","sha":"83e0599c2e9d180479e163ad6e7fb7eb32b851a2","url":"http://localhost:3000/api/ // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/git/refs ___________________ GET /repos/{owner}/{repo}/git/refs/{ref} ___________________ 1. Test Case ID: FrqZuT - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: cjR^m' -H 'Sudo: N*#=[<:' http://0.0.0.0:43007/api/v1/repos/admin/demo/git/refs/%F1%9B%90%A10CP%F0%AF%AB%B9 ___________________ GET /repos/{owner}/{repo}/git/tags/{sha} ___________________ 1. Test Case ID: qUAmxN - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"object does not exist [id: 83e0599c2e9d180479e163ad6e7fb7eb32b851a2, rel_path: ]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/git/tags/83e0599c2e9d180479e163ad6e7fb7eb32b851a2 __________________ GET /repos/{owner}/{repo}/git/trees/{sha} ___________________ 1. Test Case ID: Rq6Mj8 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/git/trees/{sha}` [200] OK: `{"sha":"276239af9bf2dbe6887d4d620afc2b0e1d93ab8c","url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/git/trees/276239af9bf2dbe6887d4d620afc2b0e1d93ab8c","tree":[{"path":"README.md","mode":"100644","type":"blob","size":8,"sha":"45d053e6af47b13ff2f184275f260c8abfc963bf","url":"http://localhost:3000/api/v1/repos/admin/demo/git/blobs/45d053e6af47b13ff2f184275f260c8abfc963bf"}],"truncated":false,"page":1,"total_count":1}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/git/trees/83e0599c2e9d180479e163ad6e7fb7eb32b851a2 2. Test Case ID: WLx8Yx - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"sha not found [\u0010bUº񘂎󅼰Ž¢󳧫€𜣸ß°6S]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/git/trees/%10bU%C2%BA%F1%98%82%8E%F3%85%BC%B0%C2%8E%C2%A2%F3%B3%A7%AB%C2%80%F0%9C%A3%B8%C3%9F%C2%B06S?page=12728870888' 3. Test Case ID: 6oMsWw - Response violates schema null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/GitTreeResponse/properties/tree: { "type": "array", "description": "Entries contains the tree entries (files and directories)", "items": { "$ref": "#/components/schemas/GitEntry" }, "x-go-name": "Entries" } Value: null [200] OK: `{"sha":"6d1f438bcfd6249129c371d21fa1b3f5bdaa4aff","url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/git/trees/6d1f438bcfd6249129c371d21fa1b3f5bdaa4aff","tree":null,"truncated":false,"page":1824884,"total_count":2}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/git/trees/f56bf4bc0ce9e7b1cefc6c13dfa9812d4c9ffbc5?page=1824884&per_page=201&recursive=true' 4. Test Case ID: TPmNF0 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `per_page` in query - violates `type` at /properties/per_page (was integer, became string) [200] OK: `{"sha":"a129b1479c8a60937cb586d39ce71d3c7341b35b","url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/git/trees/a129b1479c8a60937cb586d39ce71d3c7341b35b","tree":[{"path":"\u0011†","mode":"100644","type":"blob","size":0,"sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","url":"http://localhost:3000/api/v1/repos/admin/demo/git/blobs/e69de29bb2d1d6434b8b29ae775ad8c2e48c5391"},{"path":"%˜<񰩛","mode":"100644","type":"blob","size":0,"sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","url":"http://localhost:3000/api/v1 // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/git/trees/a129b1479c8a60937cb586d39ce71d3c7341b35b?per_page=%C2%B1%F3%A9%83%9D%12' _____________________ GET /repos/{owner}/{repo}/hooks/git ______________________ 1. Test Case ID: rIh0LD - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"must be allowed to edit Git hooks","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/hooks/git ___________________ GET /repos/{owner}/{repo}/hooks/git/{id} ___________________ 1. Test Case ID: PH5Dg7 - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"must be allowed to edit Git hooks","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/hooks/git/83e0599c2e9d180479e163ad6e7fb7eb32b851a2 _____________________ GET /repos/{owner}/{repo}/hooks/{id} _____________________ 1. Test Case ID: cdCEHZ - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/%C3%B8%0B/demo/hooks/1?sudo=%F0%AE%BA%8A%F4%89%97%88%0F%08%C3%87%5D%C3%80' ____________________ GET /repos/{owner}/{repo}/issue_config ____________________ 1. Test Case ID: hIVGw5 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issue_config` [200] OK: `{"blank_issues_enabled":true,"contact_links":[]}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issue_config _______________ GET /repos/{owner}/{repo}/issue_config/validate ________________ 1. Test Case ID: 5B2RG6 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issue_config/validate` [200] OK: `{"valid":true,"message":""}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issue_config/validate __________________ GET /repos/{owner}/{repo}/issue_templates ___________________ 1. Test Case ID: PxRdYL - Response violates schema null is not of type "array" Validated against the response schema for status code 200. Schema: { "type": "array", "items": { "$ref": "#/components/schemas/IssueTemplate" }, "components": { "schemas": { "IssueTemplateStringSlice": { "type": "array", "items": { "type": "string" }, "x-go-package": "gitea.dev/modules/structs" }, "IssueFormField": { "description": "IssueFormField represents a form field", "type": "object", "properties": { "attributes": { // Output truncated... } Value: null [200] OK: `null` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issue_templates 2. Test Case ID: hU839p - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issue_templates` [200] OK: `null` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issue_templates _______________________ GET /repos/{owner}/{repo}/issues _______________________ 1. Test Case ID: OTFCeT - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues __________________ GET /repos/{owner}/{repo}/issues/comments ___________________ 1. Test Case ID: 0tNXzt - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues/comments` [200] OK: `[{"id":1,"html_url":"http://0.0.0.0:43007/admin/demo/issues/1#issuecomment-1","pull_request_url":"","issue_url":"http://0.0.0.0:43007/admin/demo/issues/1","user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026 // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/comments 2. Test Case ID: VQ3XyY - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `before`, `since` in query - violates `format` at /properties/before - violates `format` at /properties/since [200] OK: `[{"id":1,"html_url":"http://0.0.0.0:43007/admin/demo/issues/1#issuecomment-1","pull_request_url":"","issue_url":"http://0.0.0.0:43007/admin/demo/issues/1","user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026 // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/comments?before=&since=' ___________________ GET /repos/{owner}/{repo}/issues/pinned ____________________ 1. Test Case ID: qlstZq - Response violates schema (6 violations) null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/assignees: { "type": "array", "items": { "$ref": "#/components/schemas/User" }, "x-go-name": "Assignees" } Value: null null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/projects: { "type": "array", "items": { "$ref": "#/components/schemas/Project" }, "x-go-name": "Projects" } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Milestone: { "type": "object", "description": "Milestone milestone is a collection of issues on one repo... "properties": { "closed_at": { "type": "string", "format": "date-time", "x-go-name": "Closed" }, "closed_issues": { "description": "ClosedIssues is the number of closed issues in th... "type": "integer", "format": "int64", "x-go-name": "ClosedIssues" }, "created_at": { "type": "string", "format": "date-time", "x-go-name": "Created" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PullRequestMeta: { "type": "object", "description": "PullRequestMeta PR info if an issue is a PR", "properties": { "draft": { "type": "boolean", "x-go-name": "IsWorkInProgress" }, "html_url": { "type": "string", "x-go-name": "HTMLURL" }, "merged": { "type": "boolean", "x-go-name": "HasMerged" }, "merged_at": { "type": "string", "format": "date-time", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null [200] OK: `[{"id":1,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/1","html_url":"http://0.0.0.0:43007/admin/demo/issues/1","number":1,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restrict // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/pinned 2. Test Case ID: 3jteBJ - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues/pinned` [200] OK: `[{"id":1,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/1","html_url":"http://0.0.0.0:43007/admin/demo/issues/1","number":1,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z", // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/pinned ___________________ GET /repos/{owner}/{repo}/issues/{index} ___________________ 1. Test Case ID: otGht2 - Response violates schema (6 violations) null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/assignees: { "type": "array", "items": { "$ref": "#/components/schemas/User" }, "x-go-name": "Assignees" } Value: null null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/projects: { "type": "array", "items": { "$ref": "#/components/schemas/Project" }, "x-go-name": "Projects" } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Milestone: { "type": "object", "description": "Milestone milestone is a collection of issues on one repo... "properties": { "closed_at": { "type": "string", "format": "date-time", "x-go-name": "Closed" }, "closed_issues": { "description": "ClosedIssues is the number of closed issues in th... "type": "integer", "format": "int64", "x-go-name": "ClosedIssues" }, "created_at": { "type": "string", "format": "date-time", "x-go-name": "Created" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PullRequestMeta: { "type": "object", "description": "PullRequestMeta PR info if an issue is a PR", "properties": { "draft": { "type": "boolean", "x-go-name": "IsWorkInProgress" }, "html_url": { "type": "string", "x-go-name": "HTMLURL" }, "merged": { "type": "boolean", "x-go-name": "HasMerged" }, "merged_at": { "type": "string", "format": "date-time", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null [200] OK: `{"id":1,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/1","html_url":"http://0.0.0.0:43007/admin/demo/issues/1","number":1,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricte // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1 2. Test Case ID: 6DZSAT - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues/{index}` [200] OK: `{"id":1,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/1","html_url":"http://0.0.0.0:43007/admin/demo/issues/1","number":1,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z"," // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1 _______________ GET /repos/{owner}/{repo}/issues/{index}/assets ________________ 1. Test Case ID: raGa7A - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues/{index}/assets` [200] OK: `[{"id":1,"name":"attachment.png","size":67,"download_count":0,"created_at":"2026-10-10T09:59:37Z","uuid":"5e16a7fd-85ec-4fbb-b1a4-a35211fd3b95","browser_download_url":"http://0.0.0.0:43007/attachments/5e16a7fd-85ec-4fbb-b1a4-a35211fd3b95"},{"id":2,"name":"attachment.png","size":67,"download_count":0,"created_at":"2026-10-10T09:59:37Z","uuid":"0208ab4d-757f-4f57-bf97-e94dc2ddc270","browser_download_url":"http://0.0.0.0:43007/attachments/0208ab4d-757f-4f57-bf97-e94dc2ddc270"},{"id":3,"name":"attachment.png"," // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/assets ________ GET /repos/{owner}/{repo}/issues/{index}/assignees/{assignee} _________ 1. Test Case ID: 46t8BW - Undocumented HTTP status code Received: 403 Documented: 204, 400, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: m0' http://0.0.0.0:43007/api/v1/repos/%F3%BF%A5%B6%C2%87/demo/issues/1/assignees/c%3B%F1%8B%8B%A4 _______________ GET /repos/{owner}/{repo}/issues/{index}/blocks ________________ 1. Test Case ID: KCbf1K - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues/{index}/blocks` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/4/blocks 2. Test Case ID: dKQV7g - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/%11%18%C3%BFQD%1A-%C3%98%7F%F3%AC%84%B86/blocks?access_token=%5BFiltered%5D&limit=220&sudo=%19%F2%8F%8A%89&page=65987' ______________ GET /repos/{owner}/{repo}/issues/{index}/comments _______________ 1. Test Case ID: qFNWRH - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues/{index}/comments` [200] OK: `[{"id":1,"html_url":"http://0.0.0.0:43007/admin/demo/issues/1#issuecomment-1","pull_request_url":"","issue_url":"http://0.0.0.0:43007/admin/demo/issues/1","user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026 // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/comments _______________ GET /repos/{owner}/{repo}/issues/{index}/labels ________________ 1. Test Case ID: D1IRhN - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues/{index}/labels` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/labels ______________ GET /repos/{owner}/{repo}/issues/{index}/reactions ______________ 1. Test Case ID: PuUXgz - Response violates schema null is not of type "array" Validated against the response schema for status code 200. Schema: { "type": "array", "items": { "$ref": "#/components/schemas/Reaction" }, "components": { "schemas": { "User": { "description": "User represents a user", "type": "object", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", // Output truncated... } Value: null [200] OK: `null` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/reactions 2. Test Case ID: mLLjK0 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues/{index}/reactions` [200] OK: `null` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/reactions ____________ GET /repos/{owner}/{repo}/issues/{index}/subscriptions ____________ 1. Test Case ID: uwhzZy - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues/{index}/subscriptions` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/subscriptions 2. Test Case ID: DlBpog - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became null) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/subscriptions?limit=-2700394302487132635136&page=null' ______________ GET /repos/{owner}/{repo}/issues/{index}/timeline _______________ 1. Test Case ID: fMBoZ4 - Response violates schema (7 violations) null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Comment: { "type": "object", "description": "Comment represents a comment on a commit or issue", "properties": { "assets": { "description": "Attachments contains files attached to the comment", "type": "array", "items": { "$ref": "#/components/schemas/Attachment" }, "x-go-name": "Attachments" }, "body": { "description": "Body contains the comment text content", "type": "string", "x-go-name": "Body" }, "created_at": { "type": "string", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Issue: { "type": "object", "description": "Issue represents an issue in a repository", "properties": { "assets": { "type": "array", "items": { "$ref": "#/components/schemas/Attachment" }, "x-go-name": "Attachments" }, "assignee": { "$ref": "#/components/schemas/User" }, "assignees": { "type": "array", "items": { "$ref": "#/components/schemas/User" }, // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Label: { "type": "object", "description": "Label a label to an issue or a pr", "properties": { "color": { "type": "string", "x-go-name": "Color", "example": "00aabb" }, "description": { "description": "Description provides additional context about the... "type": "string", "x-go-name": "Description" }, "exclusive": { "type": "boolean", "x-go-name": "Exclusive", "example": false }, // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Milestone: { "type": "object", "description": "Milestone milestone is a collection of issues on one repo... "properties": { "closed_at": { "type": "string", "format": "date-time", "x-go-name": "Closed" }, "closed_issues": { "description": "ClosedIssues is the number of closed issues in th... "type": "integer", "format": "int64", "x-go-name": "ClosedIssues" }, "created_at": { "type": "string", "format": "date-time", "x-go-name": "Created" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Team: { "type": "object", "description": "Team represents a team in an organization", "properties": { "can_create_org_repo": { "description": "Whether the team can create repositories in the o... "type": "boolean", "x-go-name": "CanCreateOrgRepo" }, "description": { "description": "The description of the team", "type": "string", "x-go-name": "Description" }, "id": { "description": "The unique identifier of the team", "type": "integer", "format": "int64", "x-go-name": "ID" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/TrackedTime: { "type": "object", "description": "TrackedTime worked time for an issue / pr", "properties": { "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, "id": { "description": "ID is the unique identifier for the tracked time ... "type": "integer", "format": "int64", "x-go-name": "ID" }, "issue": { "$ref": "#/components/schemas/Issue" }, "issue_id": { // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null [200] OK: `[{"id":1,"type":"comment","html_url":"http://0.0.0.0:43007/admin/demo/issues/1#issuecomment-1","pull_request_url":"","issue_url":"http://0.0.0.0:43007/admin/demo/issues/1","user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/timeline 2. Test Case ID: QoANeT - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/issues/{index}/timeline` [200] OK: `[{"id":1,"type":"comment","html_url":"http://0.0.0.0:43007/admin/demo/issues/1#issuecomment-1","pull_request_url":"","issue_url":"http://0.0.0.0:43007/admin/demo/issues/1","user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/timeline 3. Test Case ID: 48owMA - Response violates schema null is not of type "array" Validated against the response schema for status code 200. Schema: { "type": "array", "items": { "$ref": "#/components/schemas/TimelineComment" }, "components": { "schemas": { "User": { "description": "User represents a user", "type": "object", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", // Output truncated... } Value: null [200] OK: `null` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/timeline?since=2026-10-11T00%3A00%3A00Z' 4. Test Case ID: bUtQQ4 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 404 [500] Internal Server Error: `{"message":"issue does not exist [id: 0, repo_id: 1, index: 20608180]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/20608180/timeline?limit=-2780&before=0027-10-16T21%3A49%3A31.05868-11%3A56&page=-5112369&since=2026-10-10T10%3A00%3A44Z' ________________ GET /repos/{owner}/{repo}/issues/{index}/times ________________ 1. Test Case ID: IGz43s - Response violates schema (6 violations) null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/assignees: { "type": "array", "items": { "$ref": "#/components/schemas/User" }, "x-go-name": "Assignees" } Value: null null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/projects: { "type": "array", "items": { "$ref": "#/components/schemas/Project" }, "x-go-name": "Projects" } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Milestone: { "type": "object", "description": "Milestone milestone is a collection of issues on one repo... "properties": { "closed_at": { "type": "string", "format": "date-time", "x-go-name": "Closed" }, "closed_issues": { "description": "ClosedIssues is the number of closed issues in th... "type": "integer", "format": "int64", "x-go-name": "ClosedIssues" }, "created_at": { "type": "string", "format": "date-time", "x-go-name": "Created" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PullRequestMeta: { "type": "object", "description": "PullRequestMeta PR info if an issue is a PR", "properties": { "draft": { "type": "boolean", "x-go-name": "IsWorkInProgress" }, "html_url": { "type": "string", "x-go-name": "HTMLURL" }, "merged": { "type": "boolean", "x-go-name": "HasMerged" }, "merged_at": { "type": "string", "format": "date-time", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null [200] OK: `[{"id":1,"created":"2026-10-10T09:59:59Z","time":1,"user_id":1,"user_name":"admin","issue_id":1,"issue":{"id":1,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/1","html_url":"http://0.0.0.0:43007/admin/demo/issues/1","number":1,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","lang // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/times ________________________ GET /repos/{owner}/{repo}/keys ________________________ 1. Test Case ID: 55Up2l - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became null) [200] OK: `[{"id":5,"key_type":"token","key_id":0,"key":"","url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/keys/5","title":"\u0007Ýr񸵅󌩬󎯖E;","fingerprint":"gdt_KB********H0","created_at":"2026-10-10T10:00:03Z","read_only":false,"repository":{"id":1,"owner":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/a // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/keys?limit=null' 2. Test Case ID: 8rniD8 - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP;' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/keys?fingerprint=%C3%A8&limit=-23113261&key_id=%5BFiltered%5D&token=%5BFiltered%5D&sudo=I_&page=1193155626125&access_token=%5BFiltered%5D' _______________________ GET /repos/{owner}/{repo}/labels _______________________ 1. Test Case ID: G8578h - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/labels` [200] OK: `[{"id":1,"name":"","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/labels/1"},{"id":54,"name":"\u00129´\n","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/labels/54"},{"id":52,"name":"Apache-2.0","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/labels/52"},{"id":78,"name":"BSD-2-Cl // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/labels 2. Test Case ID: KKjDrz - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: )1' -H 'X-GITEA-OTP: }ddX' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/labels?access_token=%5BFiltered%5D&limit=8343407&page=-2312&token=%5BFiltered%5D&sudo=%C2%A3%C2%B4%C2%98%F1%B1%AF%97y3' 3. Test Case ID: g9au5W - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became boolean) [200] OK: `[{"id":1,"name":"","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/labels/1"},{"id":54,"name":"\u00129´\n","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/labels/54"},{"id":52,"name":"Apache-2.0","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/labels/52"},{"id":78,"name":"BSD-2-Cl // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/labels?limit=false' 4. Test Case ID: YqY1Yu - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/labels?sudo=%C2%A4' ____________________ GET /repos/{owner}/{repo}/labels/{id} _____________________ 1. Test Case ID: TYBQsW - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/labels/{id}` [200] OK: `{"id":1,"name":"","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/labels/1"}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/labels/1 _____________________ GET /repos/{owner}/{repo}/languages ______________________ 1. Test Case ID: DmX8rq - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/languages` [200] OK: `{}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/languages 2. Test Case ID: b9Rm9s - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'X-GITEA-OTP: _@>u^+' -H 'Authorization: [Filtered]' -H 'Sudo: 999999999999999999999999999999' 'http://0.0.0.0:43007/api/v1/repos/admin/%C2%94%C2%BD%C2%87/languages?access_token=%5BFiltered%5D&sudo=' 3. Test Case ID: yk2wIn - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: _@>u^+' -H 'Sudo: 999999999999999999999999999999' 'http://0.0.0.0:43007/api/v1/repos/admin/%C2%94%C2%BD%C2%87/languages?access_token=%5BFiltered%5D&sudo=' ______________________ GET /repos/{owner}/{repo}/licenses ______________________ 1. Test Case ID: ObZMMj - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/licenses` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/licenses __________________ GET /repos/{owner}/{repo}/media/{filepath} __________________ 1. Test Case ID: Kz431o - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: application/octet-stream [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/0/0/media/0?ref=' _____________________ GET /repos/{owner}/{repo}/milestones _____________________ 1. Test Case ID: PyW6Y7 - Response violates schema (2 violations) null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Milestone/properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Milestone/properties/due_on: { "type": "string", "format": "date-time", "x-go-name": "Deadline" } Value: null [200] OK: `[{"id":29,"title":"","description":"","state":"open","open_issues":0,"closed_issues":0,"created_at":"2026-10-10T10:00:11Z","updated_at":"2026-10-10T10:00:11Z","closed_at":null,"due_on":null},{"id":28,"title":"‹ò?¯𱩺½ç\u000b×Ü𣩪m𑄌򢀣>ÔÁÆ","description":"PœçÐ\nÓ\\","state":"open","open_issues":0,"closed_issues":0,"created_at":"2026-10-10T10:00:11Z","updated_at":"2026-10-10T10:00:11Z","closed_at":null,"due_on":null},{"id":2,"title":"","description":"","state":"open","open_issues":0,"closed_issues":0,"created_at":" // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/milestones 2. Test Case ID: z42VHM - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/milestones` [200] OK: `[{"id":29,"title":"","description":"","state":"open","open_issues":0,"closed_issues":0,"created_at":"2026-10-10T10:00:11Z","updated_at":"2026-10-10T10:00:11Z","closed_at":null,"due_on":null},{"id":28,"title":"‹ò?¯𱩺½ç\u000b×Ü𣩪m𑄌򢀣>ÔÁÆ","description":"PœçÐ\nÓ\\","state":"open","open_issues":0,"closed_issues":0,"created_at":"2026-10-10T10:00:11Z","updated_at":"2026-10-10T10:00:11Z","closed_at":null,"due_on":null},{"id":2,"title":"","description":"","state":"open","open_issues":0,"closed_issues":0,"created_at":" // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/milestones __________________ GET /repos/{owner}/{repo}/new_pin_allowed ___________________ 1. Test Case ID: gIfOcZ - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/new_pin_allowed` [200] OK: `{"issues":true,"pull_requests":true}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/new_pin_allowed ___________________ GET /repos/{owner}/{repo}/notifications ____________________ 1. Test Case ID: f2DiQr - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/0/0/notifications?all=true&status-types=&subject-type=issue&since=2000-01-01T00%3A00%3A00Z&before=2000-01-01T00%3A00%3A00Z&page=0&limit=0' 2. Test Case ID: LS1qZu - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `subject-type` in query - violates `enum` at /properties/subject-type/items [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/notifications?subject-type=6' ______________________ GET /repos/{owner}/{repo}/projects ______________________ 1. Test Case ID: NF8mqS - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/projects` [200] OK: `[{"id":128,"title":"󫪁","description":"","owner_id":0,"repo_id":1,"creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":" // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/projects 2. Test Case ID: MSH2h8 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became null) [200] OK: `[{"id":128,"title":"󫪁","description":"","owner_id":0,"repo_id":1,"creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":true,"prohibit_login":false,"location":"","website // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/projects?state=open&page=null&limit=-667175654722540288' ___________________ GET /repos/{owner}/{repo}/projects/{id} ____________________ 1. Test Case ID: F9s7JS - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/projects/{id}` [200] OK: `{"id":100,"title":"h¢T󈺍񴤪¯%Wڃ𠱦¯Å","description":"","owner_id":0,"repo_id":1,"creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_logi // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/projects/100 ______ GET /repos/{owner}/{repo}/projects/{id}/columns/{column_id}/issues ______ 1. Test Case ID: Qlhntk - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'X-GITEA-OTP: started_at' -H 'Sudo: K&' -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/%C2%97%F4%89%98%BE/projects/1/columns/11/issues _______________________ GET /repos/{owner}/{repo}/pulls ________________________ 1. Test Case ID: KA4gn3 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/pulls` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/pulls 2. Test Case ID: Tmua68 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 404, 500 [400] Bad Request: `{"message":"user does not exist [uid: 0, name: 񢐭]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/pulls?base_branch=%F1%B7%BC%BC%F3%AC%83%BD%09%C2%BA%26%C3%AE%F3%B2%84%AD&poster=%F1%A2%90%AD' 3. Test Case ID: j4Oz1q - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `milestone`, `state`, `limit` in query - violates `type` at /properties/milestone (was integer, became null) - violates `enum` at /properties/state - violates `type` at /properties/limit (was integer, became string) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/pulls?state=&limit=&milestone=null' ____________________ GET /repos/{owner}/{repo}/pulls/pinned ____________________ 1. Test Case ID: 12G1rX - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/pulls/pinned` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/pulls/pinned 2. Test Case ID: nELfDT - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Sudo: kJl' -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/pulls/pinned 3. Test Case ID: 7vrGGI - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/pulls/pinned?access_token=%5BFiltered%5D&token=%5BFiltered%5D&sudo=%F3%A9%AB%92%C3%98%C3%B5' ______________ GET /repos/{owner}/{repo}/pulls/{index}.{diffType} ______________ 1. Test Case ID: Gp7PyB - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: text/plain [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/0/0/pulls/-9223372036854775808.diff?binary=true' ____________________ GET /repos/{owner}/{repo}/push_mirrors ____________________ 1. Test Case ID: wuRbJi - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became string) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/push_mirrors?limit=%F1%AE%8B%B8%C3%BES%F0%B2%8E%92' ___________________ GET /repos/{owner}/{repo}/raw/{filepath} ___________________ 1. Test Case ID: ks9z3Y - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: application/octet-stream [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/0/0/raw/0?ref=' 2. Test Case ID: DfmDs0 - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/octet-stream [200] OK: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/raw/0?ref=%1F%C2%A1%C3%80%C2%94%F2%AE%A6%A8' 3. Test Case ID: adtb5k - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/raw/{filepath}` [200] OK: Reproduce with: curl -X GET 'http://0.0.0.0:43007/api/v1/repos/admin/demo/raw/0?ref=%1F%C2%A1%C3%80%C2%94%F2%AE%A6%A8' ______________________ GET /repos/{owner}/{repo}/releases ______________________ 1. Test Case ID: fJpfWw - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/releases` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/releases 2. Test Case ID: F8CdZC - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `draft`, `pre-release` in query - violates `type` at /properties/draft (was boolean, became null) - violates `type` at /properties/pre-release (was boolean, became null) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/releases?draft=null&pre-release=null' ________________ GET /repos/{owner}/{repo}/releases/tags/{tag} _________________ 1. Test Case ID: N77Cw1 - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Sudo: ]AO=pa^z' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/tags/0?token=%5BFiltered%5D&access_token=%5BFiltered%5D' 2. Test Case ID: t2wX6D - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: ]AO=pa^z' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/tags/0?sudo=&access_token=%5BFiltered%5D' ___________________ GET /repos/{owner}/{repo}/releases/{id} ____________________ 1. Test Case ID: UTerK8 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/releases/{id}` [200] OK: `{"id":1,"tag_name":"򄻃›","target_commitish":"main","name":"󑴱","body":"Workbench","url":"http://localhost:3000/api/v1/repos/admin/demo/releases/1","html_url":"http://localhost:3000/admin/demo/releases/tag/%F2%84%BB%83%C2%9B","tarball_url":"http://localhost:3000/admin/demo/archive/%F2%84%BB%83%C2%9B.tar.gz","zipball_url":"http://localhost:3000/admin/demo/archive/%F2%84%BB%83%C2%9B.zip","upload_url":"http://localhost:3000/api/v1/repos/admin/demo/releases/1/assets","draft":false,"prerelease":false,"created_at":" // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/1 2. Test Case ID: NQrflr - Response violates schema null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Release/properties/published_at: { "type": "string", "format": "date-time", "x-go-name": "PublishedAt" } Value: null [200] OK: `{"id":5,"tag_name":"|󑉇­P􏰧Aôãé¦C\u0005𜡪񓒽","target_commitish":"ï","name":"👍🏻","body":"GNU LESSER GENERAL PUBLIC LICENSE\n\nVersion 2.1, February 1999\n\nCopyright (C) 1991, 1999 Free Software Foundation, Inc.\n51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA\n\nEveryone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed.\n\n[This is the first released version of the Lesser GPL. It also counts as the successor of the GNU Library Public Lic // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/5 ________________ GET /repos/{owner}/{repo}/releases/{id}/assets ________________ 1. Test Case ID: 00iPSZ - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/releases/{id}/assets` [200] OK: `[{"id":46,"name":"attachment","size":3,"download_count":0,"created_at":"2026-10-10T10:10:16Z","uuid":"ee539d03-4164-448e-a8bc-02fe499e2104","browser_download_url":"http://0.0.0.0:43007/attachments/ee539d03-4164-448e-a8bc-02fe499e2104"},{"id":47,"name":"attachment","size":19,"download_count":0,"created_at":"2026-10-10T10:10:16Z","uuid":"23a1915a-7459-4e90-96ba-ab1763b7b424","browser_download_url":"http://0.0.0.0:43007/attachments/23a1915a-7459-4e90-96ba-ab1763b7b424"},{"id":48,"name":"attachment","size":2,"d // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/1/assets ________ GET /repos/{owner}/{repo}/releases/{id}/assets/{attachment_id} ________ 1. Test Case ID: KLDRcg - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/releases/{id}/assets/{attachment_id}` [200] OK: `{"id":47,"name":"attachment","size":19,"download_count":0,"created_at":"2026-10-10T10:10:16Z","uuid":"23a1915a-7459-4e90-96ba-ab1763b7b424","browser_download_url":"http://0.0.0.0:43007/attachments/23a1915a-7459-4e90-96ba-ab1763b7b424"}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/1/assets/47 __________________ GET /repos/{owner}/{repo}/signing-key.gpg ___________________ 1. Test Case ID: SRU1jb - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: text/plain - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/signing-key.gpg __________________ GET /repos/{owner}/{repo}/signing-key.pub ___________________ 1. Test Case ID: MdaymH - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: text/plain - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/signing-key.pub 2. Test Case ID: DdHEek - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/signing-key.pub?sudo=%C2%BDX%F2%8B%A1%B8%F3%A6%AC%BE&access_token=%5BFiltered%5D&token=%5BFiltered%5D' _____________________ GET /repos/{owner}/{repo}/stargazers _____________________ 1. Test Case ID: 9miqCI - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/stargazers` [200] OK: `[{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"","website":"","description":"","visibility":"public","followers_count":0, // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/stargazers 2. Test Case ID: hZEJT9 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became array) [200] OK: `[{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":true,"prohibit_login":false,"location":"","website":"","description":"","visibility":"public","followers_count":0,"following // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/stargazers?page=false&page=%C2%89&page=false&page=-5.4043705342027566e%2B224' ___________________ GET /repos/{owner}/{repo}/statuses/{sha} ___________________ 1. Test Case ID: BGCyvr - Response violates schema "" is not one of "pending", "success" or 4 other candidates Validated against the response schema for status code 200. Schema at /definitions/CommitStatus/properties/status: { "enum": [ "pending", "success", "error", "failure", "warning", "skipped" ], "description": "State represents the status state (pending, success, erro... "type": "string", "x-go-enum-desc": "pending CommitStatusPending is for when the CommitStat... "x-go-name": "State" } Value: "" [200] OK: `[{"id":33,"status":"","target_url":"","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","context":"","creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00: // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2 2. Test Case ID: LZQZL1 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/statuses/{sha}` [200] OK: `[{"id":33,"status":"","target_url":"","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","context":"","creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00: // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2 3. Test Case ID: ZjPQ42 - Undocumented HTTP status code Received: 401 Documented: 200, 400, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Sudo: QmR7RV' -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: NZ6npd3BP' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/statuses/e69de29bb2d1d6434b8b29ae775ad8c2e48c5391?access_token=%5BFiltered%5D&token=%5BFiltered%5D&sort=highestindex&sudo=&state=pending&page=12678380743251&limit=-17356' 4. Test Case ID: Zx0GXe - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became array) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/statuses/3bbebab7873a45a97f500f7ccfae28f36cd9670d?state=pending&sort=leastindex&limit=501958&page=-4.625613578638728e-275&page=true&page=%10%F3%8A%96%B1%22%C2%82&page=&page=total_cases&page=%C3%89&page=%C3%80%F0%9D%83%A4%C2%91%60&page=%C2%BB%C2%A0%F1%AF%9D%8E%C3%B9&page=%F2%AE%BD%8E%03%11%60%C2%87&page=%F2%AA%8E%9DsF%05%F0%92%B6%BE%C3%A0%F0%9B%88%80&page=%C3%A2%F2%86%B5%9C%E0%A2%A0%C2%B1%C3%88&page=%F1%88%BA%AF%F1%B5%AB%98%C2%9A%EC%9B%80%2C%11%C2%92%C3%87%C2%B5&page=%C3%B6%C3%A08&page=S%C3%96&page=%C3%B2%C2%AA%29n&page=%C2%97%C3%A6w%C3%B4%C2%883%C2%A2%00%F2%AD%85%AE%C2%8E%C2%A0db%C2%ADH%C2%8EX%3E%C2%8C%26%C3%89&page=3.0315695344258984e%2B16&page=0%2F0&page=%C2%83%C2%BF%17%C2%BC%C3%BFkQ%0Af%C2%AF%7B%C3%91&page=&page=&page=6.276475987695384e%2B16&page=false' ____________________ GET /repos/{owner}/{repo}/subscribers _____________________ 1. Test Case ID: wMqUe0 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/subscribers` [200] OK: `[{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"","website":"","description":"","visibility":"public","followers_count":0, // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/subscribers __________________ GET /repos/{owner}/{repo}/tag_protections ___________________ 1. Test Case ID: xns2gc - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/tag_protections ________________________ GET /repos/{owner}/{repo}/tags ________________________ 1. Test Case ID: oESuAD - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/tags` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/tags 2. Test Case ID: JSOWqr - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became string) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/tags?limit=%C2%91&page=3179055' 3. Test Case ID: 2qCkHw - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Sudo: 8{H' -H 'X-GITEA-OTP;' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/tags?page=64449184213053&access_token=%5BFiltered%5D' _____________________ GET /repos/{owner}/{repo}/tags/{tag} _____________________ 1. Test Case ID: BOvnDP - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Sudo: iNu/' -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/tags/%C3%8A%F0%BF%94%87 2. Test Case ID: s3zTyf - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/tags/0?access_token=%5BFiltered%5D&token=%5BFiltered%5D&sudo=%C2%A9' _______________________ GET /repos/{owner}/{repo}/teams ________________________ 1. Test Case ID: GgaJQN - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 405 Documented: 200, 404 [405] Method Not Allowed: `{"message":"repo is not owned by an organization","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/teams ____________________ GET /repos/{owner}/{repo}/teams/{team} ____________________ 1. Test Case ID: RL1uVG - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [405] Method Not Allowed: `{"message":"repo is not owned by an organization","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/teams/0 _______________________ GET /repos/{owner}/{repo}/times ________________________ 1. Test Case ID: 0ZOrUp - Response violates schema (6 violations) null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/assignees: { "type": "array", "items": { "$ref": "#/components/schemas/User" }, "x-go-name": "Assignees" } Value: null null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/projects: { "type": "array", "items": { "$ref": "#/components/schemas/Project" }, "x-go-name": "Projects" } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Milestone: { "type": "object", "description": "Milestone milestone is a collection of issues on one repo... "properties": { "closed_at": { "type": "string", "format": "date-time", "x-go-name": "Closed" }, "closed_issues": { "description": "ClosedIssues is the number of closed issues in th... "type": "integer", "format": "int64", "x-go-name": "ClosedIssues" }, "created_at": { "type": "string", "format": "date-time", "x-go-name": "Created" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PullRequestMeta: { "type": "object", "description": "PullRequestMeta PR info if an issue is a PR", "properties": { "draft": { "type": "boolean", "x-go-name": "IsWorkInProgress" }, "html_url": { "type": "string", "x-go-name": "HTMLURL" }, "merged": { "type": "boolean", "x-go-name": "HasMerged" }, "merged_at": { "type": "string", "format": "date-time", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null [200] OK: `[{"id":1,"created":"2026-10-10T09:59:59Z","time":1,"user_id":1,"user_name":"admin","issue_id":1,"issue":{"id":1,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/1","html_url":"http://0.0.0.0:43007/admin/demo/issues/1","number":1,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","lang // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/times 2. Test Case ID: 3Y0lNv - Undocumented HTTP status code Received: 422 Documented: 200, 400, 403, 404 [422] Unprocessable Content: `{"message":"parsing time \"2\\xc3\\xbf\\xf1\\xa2\\x86\\xac\\xc2\\xb5\\xc3\\x90\\xf2\\xbb\\xb0\\xbb\" as \"2006-01-02T15:04:05Z07:00\": cannot parse \"2\\xc3\\xbf\\xf1\\xa2\\x86\\xac\\xc2\\xb5\\xc3\\x90\\xf2\\xbb\\xb0\\xbb\" as \"2006\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/times?before=8160-01-07T13%3A25%3A11Z&since=2%C3%BF%F1%A2%86%AC%C2%B5%C3%90%F2%BB%B0%BB&page=87080847' 3. Test Case ID: wQWoIq - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became object) [200] OK: `[{"id":1,"created":"2026-10-10T09:59:59Z","time":1,"user_id":1,"user_name":"admin","issue_id":1,"issue":{"id":1,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/1","html_url":"http://0.0.0.0:43007/admin/demo/issues/1","number":1,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","lang // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/times?limit=%C2%B5%C2%BF&limit=%F2%B0%AC%B3&limit=%C3%9B%F0%91%82%86sz%F1%97%90%8A%C2%B8n%C2%A1%F0%AD%A5%86%C3%8E%C3%A7%C2%BB%C3%94%7F%F1%BF%BC%AF' _______________________ GET /repos/{owner}/{repo}/topics _______________________ 1. Test Case ID: l1cCzG - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/topics` [200] OK: `{"topics":["0"]}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/topics ________________ GET /repos/{owner}/{repo}/wiki/page/{pageName} ________________ 1. Test Case ID: jasQts - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Sudo;' -H 'X-GITEA-OTP: 75A-0G0h'"'"'+\>Ie-o' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/wiki/page/%2B0.0?sudo=ContractViolations' 2. Test Case ID: leSoqu - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/wiki/page/0?token=%5BFiltered%5D&sudo=%7F%C2%9C%C2%96%C2%B8%06%C3%B2%F3%88%A2%82%C3%80%C3%81%F1%A4%8C%85%07m%C2%A6%F0%A8%81%89%F1%BA%BC%AD%C3%93%F2%A8%94%A4%C3%A1%C2%9E%C2%93%C3%A3%F2%92%97%9A%C2%8D%F3%84%A3%96%C2%BD' _____________________ GET /repos/{owner}/{repo}/wiki/pages _____________________ 1. Test Case ID: rDkhWo - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /repos/{owner}/{repo}/wiki/pages` [200] OK: `[{"title":"\u0007Ýr񸵅󌩬󎯖E;","html_url":"http://localhost:3000/admin/demo/wiki/%07%C3%9Dr%F1%B8%B5%85%F3%8C%A9%AC%F3%8E%AF%96E%3B","sub_url":"%07%C3%9Dr%F1%B8%B5%85%F3%8C%A9%AC%F3%8E%AF%96E%3B","last_commit":{"sha":"93350908d7ec6ce2b9eb59bce45c2a68149c8b83","author":{"name":"admin","email":"admin@example.com","date":"2026-10-10T10:00:37Z"},"commiter":{"name":"admin","email":"admin@example.com","date":"2026-10-10T10:00:37Z"},"message":"Add Ö\n\n"}},{"title":"\"³","html_url":"http://localhost:3000/admin/demo/wik // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/repos/admin/demo/wiki/pages ____________________________ GET /repositories/{id} ____________________________ 1. Test Case ID: QiCAkh - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `{"id":27,"owner":{"id":4,"login":"workbench-user","type":"Organization","login_name":"","source_id":0,"full_name":"admin/demo","email":"","avatar_url":"http://0.0.0.0:43007/avatars/fa25ceee0d7be94b95c0208f7456232d4e85b901ba9bb49d8219ba29e2313dc7","html_url":"http://0.0.0.0:43007/workbench-user","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:58:40Z","restricted":false,"active":false,"prohibit_login":false,"location":"","website":"","description":"","visibility":"p // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repositories/27 ______________________________ GET /settings/api _______________________________ 1. Test Case ID: 5rRCCv - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /settings/api` [200] OK: `{"max_response_items":50,"default_paging_num":30,"default_git_trees_per_page":1000,"default_max_blob_size":10485760,"default_max_response_size":104857600}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/settings/api ___________________________ GET /settings/attachment ___________________________ 1. Test Case ID: ZRsuuc - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /settings/attachment` [200] OK: `{"enabled":true,"allowed_types":".avif,.cpuprofile,.csv,.dmp,.docx,.fodg,.fodp,.fods,.fodt,.gif,.gz,.jpeg,.jpg,.json,.jsonc,.log,.md,.mov,.mp4,.odf,.odg,.odp,.ods,.odt,.patch,.pdf,.png,.pptx,.svg,.tgz,.txt,.webm,.webp,.xls,.xlsx,.zip","max_size":100,"max_files":5}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/settings/attachment ___________________________ GET /settings/repository ___________________________ 1. Test Case ID: cOobpQ - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /settings/repository` [200] OK: `{"mirrors_disabled":false,"http_git_disabled":false,"migrations_disabled":false,"stars_disabled":false,"time_tracking_disabled":false,"lfs_disabled":true}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/settings/repository 2. Test Case ID: Udna9q - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'X-GITEA-OTP: DXeP' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/settings/repository?access_token=%5BFiltered%5D&token=%5BFiltered%5D&sudo=%C2%86' 3. Test Case ID: kNLBit - Undocumented HTTP status code Received: 403 Documented: 200 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/settings/repository?sudo=%F2%99%8E%8D%C3%AD%60%C2%86%C2%A9%C3%8B%13%C2%B4' _______________________________ GET /settings/ui _______________________________ 1. Test Case ID: TTvccl - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /settings/ui` [200] OK: `{"default_theme":"gitea-auto","allowed_reactions":["+1","-1","laugh","hooray","confused","heart","rocket","eyes"],"custom_emojis":["git","gitea","codeberg","gitlab","github","gogs"]}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/settings/ui _____________________________ GET /signing-key.gpg _____________________________ 1. Test Case ID: X9jw0H - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: text/plain - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"no signing key","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/signing-key.gpg 2. Test Case ID: Y9IVET - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/signing-key.gpg?access_token=%5BFiltered%5D&sudo=%1F%F3%8D%BE%87' 3. Test Case ID: Fks3Ya - Undocumented HTTP status code Received: 403 Documented: 200 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: Security' -H 'X-GITEA-OTP;' http://0.0.0.0:43007/api/v1/signing-key.gpg _____________________________ GET /signing-key.pub _____________________________ 1. Test Case ID: dnm3TR - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: text/plain - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"no signing key","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/signing-key.pub _______________________ GET /teams/{id}/activities/feeds _______________________ 1. Test Case ID: zPSG1j - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/teams/1/activities/feeds?page=null&page=null' 2. Test Case ID: zExF7F - Response violates schema (2 violations) "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Comment: { "type": "object", "description": "Comment represents a comment on a commit or issue", "properties": { "assets": { "description": "Attachments contains files attached to the comment", "type": "array", "items": { "$ref": "#/components/schemas/Attachment" }, "x-go-name": "Attachments" }, "body": { "description": "Body contains the comment text content", "type": "string", "x-go-name": "Body" }, "created_at": { "type": "string", // Output truncated... } Value: null [200] OK: `[{"id":176,"user_id":4,"op_type":"create_repo","act_user_id":1,"act_user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":true,"prohibit_login":false,"location":"\ // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/teams/2/activities/feeds ___________________________ GET /teams/{id}/members ____________________________ 1. Test Case ID: qsTSJC - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":true,"prohibit_login":false,"location":"","website":"","description":"","visibility":"public","followers_count":0,"following // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/teams/1/members?page=null&page=null' 2. Test Case ID: J0XWXd - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `[{"id":7,"login":"S","type":"Organization","login_name":"","source_id":0,"full_name":"","email":"","avatar_url":"http://0.0.0.0:43007/avatars/0f23d86c4ef637c2c2f809328c0166af50b5f3280697f9f56de9d22f2bc16c92","html_url":"http://0.0.0.0:43007/S","language":"","is_admin":false,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T10:24:29Z","restricted":false,"active":false,"prohibit_login":false,"location":"","website":"","description":"","visibility":"public","followers_count":0,"following_count":0,"star // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/teams/21/members ____________________________ GET /teams/{id}/repos _____________________________ 1. Test Case ID: LwMtPk - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/teams/1/repos?page=null&page=null' 2. Test Case ID: l3prUX - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `[{"id":22,"owner":{"id":4,"login":"workbench-user","type":"Organization","login_name":"","source_id":0,"full_name":"admin/demo","email":"","avatar_url":"http://0.0.0.0:43007/avatars/fa25ceee0d7be94b95c0208f7456232d4e85b901ba9bb49d8219ba29e2313dc7","html_url":"http://0.0.0.0:43007/workbench-user","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:58:40Z","restricted":false,"active":false,"prohibit_login":false,"location":"","website":"","description":"","visibility":" // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/teams/2/repos __________________________________ GET /token __________________________________ 1. Test Case ID: 9dlVJc - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"invalid access token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/token 2. Test Case ID: u3FEMM - Undocumented HTTP status code Received: 403 Documented: 200 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: COM1' -H 'Sudo: dF' http://0.0.0.0:43007/api/v1/token 3. Test Case ID: kkRXkv - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP;' -H 'Sudo;' http://0.0.0.0:43007/api/v1/token ______________________________ GET /topics/search ______________________________ 1. Test Case ID: TfwoEQ - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /topics/search` [200] OK: `{"topics":[]}` Reproduce with: curl -X GET 'http://0.0.0.0:43007/api/v1/topics/search?q=&page=0&limit=0' 2. Test Case ID: EQhzTV - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: Missing `q` at query [200] OK: `{"topics":[]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/topics/search?page=0&limit=0' 3. Test Case ID: ceJfvN - Undocumented HTTP status code Received: 401 Documented: 200, 403, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/topics/search?limit=-14652279&sudo=7%F3%BC%AC%BB%3C%7D%C2%98sF%F2%AA%A4%A3f%2A&q=%F1%A9%9A%9D%C2%88L%F3%82%8E%AB%22&token=%5BFiltered%5D&page=2280125508&access_token=%5BFiltered%5D' ____________________________ GET /user/actions/jobs ____________________________ 1. Test Case ID: 6GNUJt - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"invalid status ","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/actions/jobs?status=&page=0&limit=0&sort=&order=' 2. Test Case ID: xtH2gn - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `{"jobs":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/actions/jobs?page=null&page=null' 3. Test Case ID: 3zclQP - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"Invalid sort mode: \"ÿ\\U000cbefd\\U0008c4c6.\\u008d¿\\u0080¢÷\\u008aX\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/actions/jobs?limit=-2305843009213693953&page=-512&status=added&sort=%C3%BF%F3%8B%BB%BD%F2%8C%93%86.%C2%8D%C2%BF%C2%80%C2%A2%C3%B7%C2%8AX' __________________________ GET /user/actions/runners ___________________________ 1. Test Case ID: pOCLBA - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `disabled` in query - disabled: Incorrect type [200] OK: `{"runners":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/actions/runners?disabled=null&disabled=null' 2. Test Case ID: 0XARPE - Undocumented HTTP status code Received: 401 Documented: 200, 400, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: bc6e' 'http://0.0.0.0:43007/api/v1/user/actions/runners?sudo=LPT1&token=%5BFiltered%5D' 3. Test Case ID: A4QQZq - Undocumented HTTP status code Received: 403 Documented: 200, 400, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: bc6e' 'http://0.0.0.0:43007/api/v1/user/actions/runners?access_token=%5BFiltered%5D&disabled=false' ____________________________ GET /user/actions/runs ____________________________ 1. Test Case ID: yVSO0j - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"invalid status ","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/actions/runs?event=&branch=&status=&actor=&head_sha=&page=0&limit=0' 2. Test Case ID: rAsV4F - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `{"workflow_runs":[],"total_count":0}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/actions/runs?page=null&page=null' 3. Test Case ID: vN1s7P - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 404 [500] Internal Server Error: `{"message":"user does not exist [uid: 0, name: cHs‹񉪑Ë×񙑺]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/actions/runs?actor=cHs%C2%8B%F1%89%AA%91%C3%8B%C3%97%F1%99%91%BA%7F' _________________________ GET /user/actions/variables __________________________ 1. Test Case ID: 4JxOu1 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/actions/variables?page=null&page=null' ________________________ GET /user/applications/oauth2 _________________________ 1. Test Case ID: VYxLi8 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/applications/oauth2?page=null&page=null' _______________________________ GET /user/blocks _______________________________ 1. Test Case ID: tY7202 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/blocks?page=null&page=null' _________________________ GET /user/blocks/{username} __________________________ 1. Test Case ID: pqt1rC - Missing Content-Type header The following media types are documented in the schema: - `application/json` [404] Not Found: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/blocks/admin _____________________________ GET /user/followers ______________________________ 1. Test Case ID: YhARpN - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/followers?page=null&page=null' _____________________________ GET /user/following ______________________________ 1. Test Case ID: WKCLCL - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/following?page=null&page=null' 2. Test Case ID: 2anAQ6 - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `[{"id":5,"login":"A","type":"Organization","login_name":"","source_id":0,"full_name":"","email":"","avatar_url":"http://0.0.0.0:43007/avatars/375a42122bfbf4668c8bcd857c01a98fb0d525b738694b58ca97b14291fb04d5","html_url":"http://0.0.0.0:43007/A","language":"","is_admin":false,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:58:41Z","restricted":false,"active":true,"prohibit_login":false,"location":"","website":"","description":"","visibility":"public","followers_count":1,"following_count":0,"starr // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/following ______________________________ GET /user/gpg_keys ______________________________ 1. Test Case ID: hlzycA - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/gpg_keys?page=null&page=null' _______________________________ GET /user/hooks ________________________________ 1. Test Case ID: 1Q4wZV - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/hooks?page=null&page=null' 2. Test Case ID: 0U1r19 - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Sudo;' -H 'X-GITEA-OTP;' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/hooks?page=-65537&limit=9127989240&sudo=%C3%B2%5BW%EC%A2%BDz&access_token=%5BFiltered%5D&token=%5BFiltered%5D' 3. Test Case ID: I2msPB - Undocumented HTTP status code Received: 403 Documented: 200 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Sudo: %(s U4eAig`;_=8b|U_>6O4' -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: s2' 'http://0.0.0.0:43007/api/v1/user/hooks?sudo=&limit=37699043&page=12418&access_token=%5BFiltered%5D' _____________________________ GET /user/hooks/{id} _____________________________ 1. Test Case ID: UtxgMJ - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/hooks/-9223372036854775808 ________________________________ GET /user/keys ________________________________ 1. Test Case ID: CeOHcN - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/keys?page=null&page=null' ________________________________ GET /user/orgs ________________________________ 1. Test Case ID: UYbIiR - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[{"id":3,"name":"workbench","full_name":"","email":"","avatar_url":"http://0.0.0.0:43007/avatars/1f303fd10424e23d36ee4dbd6af13c4d735f75bfe318b1259474fa53863403ba","description":"","website":"","location":"","visibility":"public","repo_admin_change_team_access":false,"username":"workbench"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/orgs?page=null&page=null' ______________________________ GET /user/projects ______________________________ 1. Test Case ID: nj0mjh - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `state` in query - state: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/projects?state=null&state=null' 2. Test Case ID: TOhJKf - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: }' -H 'X-GITEA-OTP;' 'http://0.0.0.0:43007/api/v1/user/projects?access_token=%5BFiltered%5D&token=%5BFiltered%5D&limit=-382&state=closed&page=43334060&sudo=l%F2%8E%85%AF%C2%A33%C2%BA%23N%06G%F0%B7%82%913%C3%849B%C2%A8%C3%BB%C2%84a_%0B%C3%9D6%F2%8D%A7%B3%1B%C3%86%7Db%03_m%C2%98%C3%8B' 3. Test Case ID: XMAJnn - Undocumented HTTP status code Received: 403 Documented: 200 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: }' -H 'X-GITEA-OTP;' 'http://0.0.0.0:43007/api/v1/user/projects?access_token=%5BFiltered%5D&limit=0&page=0&state=all&sudo=' _______________________ GET /user/projects/{id}/columns ________________________ 1. Test Case ID: V7fy8p - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/projects/1/columns?sudo=Yn%C3%AEw%F0%9C%A3%B7%C3%94%C2%93R%F3%B7%AC%BD%C3%A28%C2%8F%F0%90%A3%8F%C2%96&limit=161974211&page=20936225&token=%5BFiltered%5D&access_token=%5BFiltered%5D' _______________________________ GET /user/repos ________________________________ 1. Test Case ID: Up2TyR - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[{"id":1,"owner":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"","website":"","description":"","visibility":"public","followers_c // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/repos?page=null&page=null' 2. Test Case ID: 8ZemCn - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/repos ______________________________ GET /user/starred _______________________________ 1. Test Case ID: cfOyaN - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/starred?page=null&page=null' 2. Test Case ID: W72XQl - Undocumented HTTP status code Received: 401 Documented: 200, 403 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/starred?limit=20514465006191836' _______________________ GET /user/starred/{owner}/{repo} _______________________ 1. Test Case ID: sFbGt4 - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/starred/admin/demo 2. Test Case ID: huNSXg - Undocumented HTTP status code Received: 401 Documented: 204, 403, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/starred/admin/demo?sudo=%C2%A4&token=%5BFiltered%5D&access_token=%5BFiltered%5D' ____________________________ GET /user/stopwatches _____________________________ 1. Test Case ID: wW4aHF - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/stopwatches?page=null&page=null' ___________________________ GET /user/subscriptions ____________________________ 1. Test Case ID: euXoar - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[{"id":1,"owner":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"","website":"","description":"","visibility":"public","followers_c // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/subscriptions?page=null&page=null' 2. Test Case ID: 9rJd44 - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/subscriptions?access_token=%5BFiltered%5D&sudo=%C3%82%F1%9B%82%94%1F%C2%8A%C2%B8%F3%80%BD%B5%F2%99%AF%90&token=%5BFiltered%5D' _______________________________ GET /user/teams ________________________________ 1. Test Case ID: O30ajb - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[{"id":1,"name":"Owners","description":"","organization":{"id":3,"name":"workbench","full_name":"","email":"","avatar_url":"http://0.0.0.0:43007/avatars/1f303fd10424e23d36ee4dbd6af13c4d735f75bfe318b1259474fa53863403ba","description":"","website":"","location":"","visibility":"public","repo_admin_change_team_access":false,"username":"workbench"},"includes_all_repositories":true,"permission":"owner","units":["repo.code","repo.issues","repo.releases","repo.ext_wiki","repo.ext_issues","repo.projects","repo.pack // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/teams?page=null&page=null' 2. Test Case ID: llVnDz - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Sudo: a*' 'http://0.0.0.0:43007/api/v1/user/teams?token=%5BFiltered%5D' _______________________________ GET /user/times ________________________________ 1. Test Case ID: CBDt22 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `since` in query - since: Value not matching the 'date-time' format [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/times?since=' 2. Test Case ID: 9DW44J - Undocumented HTTP status code Received: 422 Documented: 200 [422] Unprocessable Content: `{"message":"parsing time \"null\" as \"2006-01-02T15:04:05Z07:00\": cannot parse \"null\" as \"2006\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/times?since=null&since=null' 3. Test Case ID: 6Wev17 - Response violates schema (6 violations) null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/assignees: { "type": "array", "items": { "$ref": "#/components/schemas/User" }, "x-go-name": "Assignees" } Value: null null is not of type "array" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/projects: { "type": "array", "items": { "$ref": "#/components/schemas/Project" }, "x-go-name": "Projects" } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Milestone: { "type": "object", "description": "Milestone milestone is a collection of issues on one repo... "properties": { "closed_at": { "type": "string", "format": "date-time", "x-go-name": "Closed" }, "closed_issues": { "description": "ClosedIssues is the number of closed issues in th... "type": "integer", "format": "int64", "x-go-name": "ClosedIssues" }, "created_at": { "type": "string", "format": "date-time", "x-go-name": "Created" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/PullRequestMeta: { "type": "object", "description": "PullRequestMeta PR info if an issue is a PR", "properties": { "draft": { "type": "boolean", "x-go-name": "IsWorkInProgress" }, "html_url": { "type": "string", "x-go-name": "HTMLURL" }, "merged": { "type": "boolean", "x-go-name": "HasMerged" }, "merged_at": { "type": "string", "format": "date-time", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Issue/properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null [200] OK: `[{"id":1,"created":"2026-10-10T09:59:59Z","time":1,"user_id":1,"user_name":"admin","issue_id":1,"issue":{"id":1,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/1","html_url":"http://0.0.0.0:43007/admin/demo/issues/1","number":1,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","lang // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/times ______________________________ GET /users/search _______________________________ 1. Test Case ID: 9OIdEC - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /users/search` [200] OK: `{"ok":true,"data":[]}` Reproduce with: curl -X GET 'http://0.0.0.0:43007/api/v1/users/search?q=&uid=-9223372036854775808&page=0&limit=0' 2. Test Case ID: v2uDro - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `uid` in query - uid: Value greater than maximum [200] OK: `{"ok":true,"data":[]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/search?uid=9223372036854775808' ____________________________ GET /users/{username} _____________________________ 1. Test Case ID: yOAka1 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /users/{username}` [200] OK: `{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"\rÝ𑀮°𓚒­뜸#œÔ򛝠Í𴳓ÑێB","website":"","description":"˜\u0012 Ïé","visi // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/users/admin 2. Test Case ID: oWA0WP - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `{"id":5,"login":"A","type":"Organization","login_name":"","source_id":0,"full_name":"","email":"","avatar_url":"http://0.0.0.0:43007/avatars/375a42122bfbf4668c8bcd857c01a98fb0d525b738694b58ca97b14291fb04d5","html_url":"http://0.0.0.0:43007/A","language":"","is_admin":false,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:58:41Z","restricted":false,"active":true,"prohibit_login":false,"location":"","website":"","description":"","visibility":"public","followers_count":0,"following_count":0,"starre // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/users/A 3. Test Case ID: KwgtQb - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H $'X-GITEA-OTP: >qln;OgF}#2\t}raQ(N5YWrWg%YLR>5.\t1Fln' -H 'Authorization: [Filtered]' -H 'Sudo: Y|$=`+*>X H' 'http://0.0.0.0:43007/api/v1/users/admin?token=%5BFiltered%5D&access_token=%5BFiltered%5D' 4. Test Case ID: iRHNIU - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H $'X-GITEA-OTP: >qln;OgF}#2\t}raQ(N5YWrWg%YLR>5.\t1Fln' -H 'Sudo: Y|$=`+*>X H' 'http://0.0.0.0:43007/api/v1/users/admin?access_token=%5BFiltered%5D&sudo=' ____________________ GET /users/{username}/activities/feeds ____________________ 1. Test Case ID: j4mVxi - Response violates schema (2 violations) "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Comment: { "type": "object", "description": "Comment represents a comment on a commit or issue", "properties": { "assets": { "description": "Attachments contains files attached to the comment", "type": "array", "items": { "$ref": "#/components/schemas/Attachment" }, "x-go-name": "Attachments" }, "body": { "description": "Body contains the comment text content", "type": "string", "x-go-name": "Body" }, "created_at": { "type": "string", // Output truncated... } Value: null [200] OK: `[{"id":184,"user_id":1,"op_type":"publish_release","act_user_id":1,"act_user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":true,"prohibit_login":false,"location // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/users/admin/activities/feeds 2. Test Case ID: LbZj51 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /users/{username}/activities/feeds` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/users/admin/activities/feeds 3. Test Case ID: YYTaaj - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `only-performed-by` in query - violates `type` at /properties/only-performed-by (was boolean, became number) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/admin/activities/feeds?limit=217699246&page=23265809311&only-performed-by=-1.7686110351494702e-87&date=0772-12-10' _______________________ GET /users/{username}/followers ________________________ 1. Test Case ID: oQZzBp - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became string) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/admin/followers?page=g%C3%B1%C2%B1&limit=350' 2. Test Case ID: gMa7vp - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/admin/followers?limit=-33637&sudo=%C3%B7%C3%BA%C2%BA%F2%BD%96%B4&page=-55629&token=%5BFiltered%5D&access_token=%5BFiltered%5D' _______________________ GET /users/{username}/following ________________________ 1. Test Case ID: XYXg8x - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - page: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/workbench-user/following?page=null&page=null' 2. Test Case ID: g0ZEwA - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/users/admin/following ________________________ GET /users/{username}/gpg_keys ________________________ 1. Test Case ID: 3AXoDA - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/users/workbench/gpg_keys 2. Test Case ID: K8OVS0 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became string) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/admin/gpg_keys?page=%F0%9D%95%BF%F0%9D%96%8D%F0%9D%96%8A+%F0%9D%96%96%F0%9D%96%9A%F0%9D%96%8E%F0%9D%96%88%F0%9D%96%90+%F0%9D%96%87%F0%9D%96%97%F0%9D%96%94%F0%9D%96%9C%F0%9D%96%93+%F0%9D%96%8B%F0%9D%96%94%F0%9D%96%9D+%F0%9D%96%8F%F0%9D%96%9A%F0%9D%96%92%F0%9D%96%95%F0%9D%96%98+%F0%9D%96%94%F0%9D%96%9B%F0%9D%96%8A%F0%9D%96%97+%F0%9D%96%99%F0%9D%96%8D%F0%9D%96%8A+%F0%9D%96%91%F0%9D%96%86%F0%9D%96%9F%F0%9D%96%9E+%F0%9D%96%89%F0%9D%96%94%F0%9D%96%8C&limit=440' 3. Test Case ID: 2wMokq - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: \n;bFgo[YA=dbtve)*e)oBMM' -H 'Sudo: _!K.r@y)$]0rkfUnl' 'http://0.0.0.0:43007/api/v1/users/admin/gpg_keys?sudo=%C2%81%F3%93%B4%B7&limit=-97&token=%5BFiltered%5D&page=-16386' 4. Test Case ID: CUgzCg - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: \n;bFgo[YA=dbtve)*e)oBMM' -H 'Sudo: _!K.r@y)$]0rkfUnl' 'http://0.0.0.0:43007/api/v1/users/admin/gpg_keys?page=0&access_token=%5BFiltered%5D&sudo=%13%05%C2%AB&limit=-16386' ________________________ GET /users/{username}/heatmap _________________________ 1. Test Case ID: hUPxjc - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /users/{username}/heatmap` [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/users/admin/heatmap __________________________ GET /users/{username}/keys __________________________ 1. Test Case ID: l4FzcE - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became string) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/admin/keys?limit=%04%C3%A9' __________________________ GET /users/{username}/orgs __________________________ 1. Test Case ID: 9VfaRY - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `page` in query - violates `type` at /properties/page (was integer, became array) [200] OK: `[{"id":8,"name":"4","full_name":"workbench-user/BSD-3-Clause-Clear","email":"","avatar_url":"http://0.0.0.0:43007/avatars/a375eb49b5a81c304a1b09bfb6581746ff1d2aa1adb07ec0b4450329e3192b06","description":"#F3","website":"","location":"\u000e… ÿ","visibility":"limited","repo_admin_change_team_access":true,"username":"4"},{"id":5,"name":"A","full_name":",󚒿!hF½‰ë򧱒Ín§𣍔š􃨑¨􎃿­K󷁌曟w÷\u0000򽈩0","email":"","avatar_url":"http://0.0.0.0:43007/avatars/375a42122bfbf4668c8bcd857c01a98fb0d525b738694b58ca97b14291fb04d5","descrip // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/admin/orgs?page=true&page=%1D&page=-1.6873181774857518e%2B158&page=false&page=true&page=%7B%27%C3%9F%F0%93%AA%84G%27%3A+%5B-63429444336513%2C+%27true%27%2C+%27%5Cx9b%27%5D%2C+%27%27%3A+-2.2243133463817124e%2B16%7D&page=%7B%7D&page=%5B%27null%27%2C+%27false%27%5D&page=%7B%27%27%3A+%7B%27%C3%A3%5CU000bdfd3%C3%8B%5Cx16%5Cx05%5Cx8e%27%3A+%27false%27%7D%7D&page=r%F1%96%8F%A7%F0%AA%B3%9B%C2%92%C3%90%C3%BF%40%F2%82%B3%96%3AHIc&page=%7B%27%5CU0008d56br%5CU000d931a%5CU0006766di%3A%C3%AD%27%3A+%27if%27%2C+%27+%3D%5Cx0e%5Cx92%27%3A+%27false%27%2C+%27%5Cx91%27%3A+%27null%27%7D&page=%7B%27%C3%BEf%C2%B3%27%3A+%27null%27%2C+%27%5Cx8dc%5Cx9eRt%27%3A+-1.192092896e-07%2C+%27%27%3A+4.514711554388697e-206%7D&page=%5B%27%27%2C+-1.9%5D&page=true' _________________ GET /users/{username}/orgs/{org}/permissions _________________ 1. Test Case ID: 2XCHZL - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/users/admin/orgs/workbench/permissions ________________________ GET /users/{username}/projects ________________________ 1. Test Case ID: fciyDW - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /users/{username}/projects` [200] OK: `[]` Reproduce with: curl -X GET 'http://0.0.0.0:43007/api/v1/users/workbench-user/projects?state=open&page=0&limit=0' 2. Test Case ID: QjcImQ - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `state` in query - state: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/workbench-user/projects?state=null&state=null' 3. Test Case ID: pBzkwI - Undocumented HTTP status code Received: 403 Documented: 200, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X GET -H 'Sudo: _nPr9?4y' -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: T\xk' http://0.0.0.0:43007/api/v1/users/admin/projects _________________________ GET /users/{username}/repos __________________________ 1. Test Case ID: XmBvng - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /users/{username}/repos` [200] OK: `[{"id":1,"owner":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"\rÝ𑀮°𓚒­뜸#œÔ򛝠Í𴳓ÑێB","website":"","description":"˜\u0012  // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/users/admin/repos 2. Test Case ID: jI5RPQ - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became null) [200] OK: `[{"id":1,"owner":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"\rÝ𑀮°𓚒­뜸#œÔ򛝠Í𴳓ÑێB","website":"","description":"˜\u0012  // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/admin/repos?limit=null' 3. Test Case ID: P5Zuqf - Undocumented HTTP status code Received: 401 Documented: 200, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H $'X-GITEA-OTP: jY(z>KO\t' -H 'Sudo: f,972O' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/admin/repos?page=6619&token=%5BFiltered%5D&sudo=&limit=-5122959&access_token=%5BFiltered%5D' ________________________ GET /users/{username}/starred _________________________ 1. Test Case ID: GN7BSg - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became array) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/A/starred?limit=&limit=5.763193003944241e%2B16&limit=false&limit=-1.1816886388060529e%2B288&limit=-6.4703506026650744e%2B16&limit=true&limit=%5B%5B7911%5D%2C+%27b%C2%B7%C2%AB%5Cx9f%C3%9F%C2%A4%5Cx9c%5Cx15%C2%B2%5Cuf58f~~q%5Cx83%5Cr%5CU000a7561%27%2C+%5B%27null%27%2C+%27true%27%5D%5D&limit=%7B%278%5Cx1f%C2%BA%27%3A+%27null%27%2C+%27%E0%A4%AE%E0%A4%A8%E0%A5%80%E0%A4%B7+%D9%85%D9%86%D8%B4%27%3A+%5B%5D%2C+%27E%5Cx81%5CU000e06b9%C3%92%C3%84zd%5Cx80%C3%A1%27%3A+-3.7176728875008315e-22%7D&limit=%5B%5D&limit=%7B%27%5CU000f1e30q%5CU000f5410%27%3A+%27null%27%2C+%27D%5Cx9es%27%3A+185607%2C+%27%27%3A+-3.321743606388193e%2B122%7D&limit=%5B%27true%27%5D&limit=%5B%5D&limit=%7B%7D&limit=%13&limit=%5B%27null%27%5D&limit=%7B%7D&limit=%5B%7B%7D%2C+%7B%27A%27%3A+-2.2883455366924016e%2B16%2C+%27E%5CU000f0eea%5Cx98%5Cx80%5Cx83%C2%B9%27%3A+%27false%27%2C+%27%C3%9B%C3%B4%5CU000612448%5Cx99T%C3%8Am%27%3A+%7B%7D%7D%2C+%27null%27%5D&limit=null&limit=%5B%27null%27%2C+%27false%27%2C+-2.2882369467680796e%2B16%5D&limit=%7B%27phases%27%3A+%27%27%2C+%27%3F%27%3A+%27false%27%2C+%27%5CU0008e216~fG2%F0%A7%B1%BF%5Cx8f%C3%B54%5Cx1d%26StC%27%3A+%27false%27%7D&limit=%7B%27%27%3A+%5B%27%5CU000463d8%27%5D%2C+%27%C3%BFfE%5Cx89%27%3A+%7B%27%C3%AD%5Cx90%27%3A+%7B%27%5CU0006023aKd%C3%9C%C3%83%E5%B9%ADh%27%3A+%27null%27%2C+%27h%26%C3%98%5CU0009ec9bxiF%40%5Cx85%27%3A+%27false%27%2C+%27K%C3%9C%27%3A+-6.735984531777515e%2B16%7D%7D%7D&limit=%7B%27%C3%83%40%27%3A+%27false%27%2C+%27%E0%A4%AA%E0%A4%A8%E0%A5%8D%E0%A4%B9+%E0%A4%AA%E0%A4%A8%E0%A5%8D%E0%A4%B9+%E0%A4%A4%E0%A5%8D%E0%A4%B0+%E0%A4%B0%E0%A5%8D%E0%A4%9A+%E0%A4%95%E0%A5%83%E0%A4%95%E0%A5%83+%E0%A4%A1%E0%A5%8D%E0%A4%A1+%E0%A4%A8%E0%A5%8D%E0%A4%B9%E0%A5%83%E0%A5%87+%D8%A5%D9%84%D8%A7+%D8%A8%D8%B3%D9%85+%D8%A7%D9%84%D9%84%D9%87%27%3A+%7B%27U1A%C3%AF%5Cx85a%5CU000c4734%C3%A5%C3%BC%5Cx94%C3%9A2%27%3A+1.2291416589149707e-298%2C+%27%EB%B9%A44%3A%C2%B9%27%3A+%27TRUE%27%7D%2C+%27Y%5Cx98%27%3A+%27%C2%B9%27%7D&limit=%7B%7D&limit=%5B%5B37475953977120342016%5D%2C+%5B%5D%2C+%7B%27%C3%A2%C3%94%C3%84%7D%27%3A+%5B%5D%7D%5D&limit=%7B%7D&limit=1.0210935150071676e%2B16' _____________________ GET /users/{username}/subscriptions ______________________ 1. Test Case ID: ANbmeF - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `[{"id":2,"owner":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"\rÝ𑀮°𓚒­뜸#œÔ򛝠Í𴳓ÑێB","website":"","description":"˜\u0012  // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/users/admin/subscriptions 2. Test Case ID: xHncvQ - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `page`, `limit` in query - violates `type` at /properties/page (was integer, became object) - violates `type` at /properties/limit (was integer, became null) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/A/subscriptions?limit=null&page=%C3%AF%C3%91D&page=%F2%A8%A8%B4%C3%B7%2C%C3%91%2B%7D%F1%92%9C%BEV&page=K%C3%A7%C3%B8%C2%89&page=%C2%86F&page=%02%C3%A4&page=%EB%B9%97f%C3%9B%F2%B4%98%B9%22fk%F3%B0%AA%86%F1%95%BD%85&page=%C2%B8a%C2%B2%F1%82%88%A6%F0%B3%BF%9Aw%19%C3%88&page=%C3%81%C3%88%F2%8F%A1%80%7B&page=%F0%BD%B7%B2&page=%C3%BF%C2%95%2A%C2%9B%C2%BC%12.%F1%86%84%A1G%C3%9D%23%07m7P%F1%88%89%97%C2%9CE%C2%95%C2%9D%C2%9F%3El&page=%F1%AD%97%8A&page=%7B' _________________________ GET /users/{username}/tokens _________________________ 1. Test Case ID: dxsPv5 - Undocumented HTTP status code Received: 404 Documented: 200, 403 [404] Not Found: `{"message":"user redirect does not exist [name: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/0/tokens?page=0&limit=0' 2. Test Case ID: CcGlQE - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `limit` in query - violates `type` at /properties/limit (was integer, became boolean) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/admin/tokens?page=-12756624&limit=true' 3. Test Case ID: nZmeIQ - Undocumented HTTP status code Received: 401 Documented: 200, 403 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: r:8=ra?@3=' -H 'Sudo: bK3Pz^oW@S' 'http://0.0.0.0:43007/api/v1/users/admin/tokens?sudo=%F3%80%88%B8o%F2%B5%9A%88&access_token=%5BFiltered%5D' _________________________________ GET /version _________________________________ 1. Test Case ID: 3nLoyx - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /version` [200] OK: `{"version":"28.1.0"}` Reproduce with: curl -X GET http://0.0.0.0:43007/api/v1/version ______________ OPTIONS /admin/actions/runners/registration-token _______________ 1. Test Case ID: Ei7NuX - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/admin/actions/runners/registration-token _____________________ OPTIONS /admin/users/{username}/orgs _____________________ 1. Test Case ID: 6XFiSt - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "email": "", "full_name": "", "location": "", "repo_admin_change_team_access": false, "username": "", "visibility": "public", "website": ""}' http://0.0.0.0:43007/api/v1/admin/users/0/orgs ____________ OPTIONS /orgs/{org}/actions/runners/registration-token ____________ 1. Test Case ID: 9u1VBj - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/0/actions/runners/registration-token ________________ OPTIONS /orgs/{org}/projects/{id}/columns/move ________________ 1. Test Case ID: ywaZLh - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"column_ids": []}' http://0.0.0.0:43007/api/v1/orgs/0/projects/-9223372036854775808/columns/move _________________________ OPTIONS /repos/issues/search _________________________ 1. Test Case ID: IsLHlq - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/issues/search?state=open&labels=&milestones=&q=&type=issues&since=2000-01-01T00%3A00%3A00Z&before=2000-01-01T00%3A00%3A00Z&assigned=true&created=true&mentioned=true&review_requested=true&reviewed=true&owner=&created_by=&team=&page=1&limit=0' _______ OPTIONS /repos/{owner}/{repo}/actions/runners/registration-token _______ 1. Test Case ID: QFETBP - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/actions/runners/registration-token __________ OPTIONS /repos/{owner}/{repo}/branch_protections/priority ___________ 1. Test Case ID: kNyjLz - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"ids": []}' http://0.0.0.0:43007/api/v1/repos/0/0/branch_protections/priority ___________________ OPTIONS /repos/{owner}/{repo}/hooks/git ____________________ 1. Test Case ID: 4u6OmH - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/hooks/git ________________ OPTIONS /repos/{owner}/{repo}/issues/comments _________________ 1. Test Case ID: zkYdgu - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/0/0/issues/comments?since=2000-01-01T00%3A00%3A00Z&before=2000-01-01T00%3A00%3A00Z&page=0&limit=0' _________________ OPTIONS /repos/{owner}/{repo}/issues/pinned __________________ 1. Test Case ID: cnBwDE - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/issues/pinned _______ OPTIONS /repos/{owner}/{repo}/issues/{index}/subscriptions/check _______ 1. Test Case ID: qCHMyg - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, PUT List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/subscriptions/check __________________ OPTIONS /repos/{owner}/{repo}/keys/tokens ___________________ 1. Test Case ID: wtrZmZ - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"read_only": false, "title": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/keys/tokens ___________ OPTIONS /repos/{owner}/{repo}/projects/{id}/columns/move ___________ 1. Test Case ID: Uqvr9K - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"column_ids": []}' http://0.0.0.0:43007/api/v1/repos/0/0/projects/-9223372036854775808/columns/move __________ OPTIONS /repos/{owner}/{repo}/pulls/comments/{id}/resolve ___________ 1. Test Case ID: sIGV3L - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/pulls/comments/-9223372036854775808/resolve _________ OPTIONS /repos/{owner}/{repo}/pulls/comments/{id}/unresolve __________ 1. Test Case ID: Mjn9po - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/pulls/comments/-9223372036854775808/unresolve __________________ OPTIONS /repos/{owner}/{repo}/pulls/pinned __________________ 1. Test Case ID: TDpcN7 - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/pulls/pinned ____________ OPTIONS /repos/{owner}/{repo}/pulls/{index}.{diffType} ____________ 1. Test Case ID: Fy3MRo - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/0/0/pulls/-9223372036854775808.diff?binary=true' ______ OPTIONS /repos/{owner}/{repo}/pulls/{index}/comments/{id}/replies _______ 1. Test Case ID: 9q6Hjf - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"body": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/pulls/-9223372036854775808/comments/-9223372036854775808/replies _______ OPTIONS /repos/{owner}/{repo}/pulls/{index}/requested_reviewers ________ 1. Test Case ID: jw2P91 - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"reviewers": [], "team_reviewers": []}' http://0.0.0.0:43007/api/v1/repos/0/0/pulls/-9223372036854775808/requested_reviewers _____ OPTIONS /repos/{owner}/{repo}/pulls/{index}/reviews/{id}/dismissals ______ 1. Test Case ID: xaWpqt - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"message": "", "priors": false}' http://0.0.0.0:43007/api/v1/repos/0/0/pulls/-9223372036854775808/reviews/-9223372036854775808/dismissals ____ OPTIONS /repos/{owner}/{repo}/pulls/{index}/reviews/{id}/undismissals _____ 1. Test Case ID: t8UJ8t - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/pulls/-9223372036854775808/reviews/-9223372036854775808/undismissals ______________ OPTIONS /repos/{owner}/{repo}/pulls/{index}/update ______________ 1. Test Case ID: Tro35i - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/0/0/pulls/-9223372036854775808/update?style=merge' ________________ OPTIONS /repos/{owner}/{repo}/releases/latest _________________ 1. Test Case ID: LYqopz - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/releases/latest _______________ OPTIONS /user/actions/runners/registration-token _______________ 1. Test Case ID: wrIihh - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/actions/runners/registration-token ___________________ OPTIONS /user/projects/{id}/columns/move ___________________ 1. Test Case ID: E8oDYP - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PATCH List exactly the methods this resource supports in `Allow` [405] Method Not Allowed: Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"column_ids": []}' http://0.0.0.0:43007/api/v1/user/projects/-9223372036854775808/columns/move ___________________ PATCH /admin/actions/runners/{runner_id} ___________________ 1. Test Case ID: tFNKb2 - Undocumented HTTP status code Received: 401 Documented: 200, 400, 404, 422 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H $'X-GITEA-OTP: :Vi]27I-8$#G\tO-!)\ud901\uded4": "\u0006\ud9eb\udf26\u00dc\u00bfr"}}' http://0.0.0.0:43007/api/v1/repos/admin/demo/hooks/1 _______________ PATCH /repos/{owner}/{repo}/issues/comments/{id} _______________ 1. Test Case ID: 01bhvn - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 3 additional properties not defined in the schema (`-`, `ƒ‘žè`, ``). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. - Undocumented HTTP status code Received: 422 Documented: 200, 204, 403, 404, 423 [422] Unprocessable Content: `{"message":"[Body]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u009d": [true, 39265914228, -6.063105731577269e+16], "\u0083\u0091\u009e\u00e8": [{"\u00e7": [], "=\uda51\udf60\u00f3L\b\u00be": -3991304727, "\uda3c\udeab\u0003": {"\u008f\u00acx\uda71\udf83\u00a1\u0007\ud91f\udcd3(0": 440}}, [-16908529740146213388288, 6.871059699206486e-54, 0.0]], "-": null, "body": "The Clear BSD License\n\nCopyright (c) [xxxx]-[xxxx] [Owner Organization]\nAll rights reserved.\n\nRedistribution and use in source and binary forms, with or without modification, are permitted (subject to the limitations in the disclaimer below) provided that the following conditions are met:\n\n * Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.\n\n * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.\n\n * Neither the name of [Owner Organization] nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission.\n\nNO EXPRESS OR IMPLIED LICENSES TO ANY PARTY'"'"'S PATENT RIGHTS ARE GRANTED BY THIS LICENSE. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS \"AS IS\" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.\n"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/comments/1 __________________ PATCH /repos/{owner}/{repo}/issues/{index} __________________ 1. Test Case ID: eOc9v3 - Response violates schema (7 violations) null is not of type "array" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/assignees: { "type": "array", "items": { "$ref": "#/components/schemas/User" }, "x-go-name": "Assignees" } Value: null null is not of type "array" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/projects: { "type": "array", "items": { "$ref": "#/components/schemas/Project" }, "x-go-name": "Projects" } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/Milestone: { "type": "object", "description": "Milestone milestone is a collection of issues on one repo... "properties": { "closed_at": { "type": "string", "format": "date-time", "x-go-name": "Closed" }, "closed_issues": { "description": "ClosedIssues is the number of closed issues in th... "type": "integer", "format": "int64", "x-go-name": "ClosedIssues" }, "created_at": { "type": "string", "format": "date-time", "x-go-name": "Created" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/PullRequestMeta: { "type": "object", "description": "PullRequestMeta PR info if an issue is a PR", "properties": { "draft": { "type": "boolean", "x-go-name": "IsWorkInProgress" }, "html_url": { "type": "string", "x-go-name": "HTMLURL" }, "merged": { "type": "boolean", "x-go-name": "HasMerged" }, "merged_at": { "type": "string", "format": "date-time", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/due_date: { "type": "string", "format": "date-time", "x-go-name": "Deadline" } Value: null [201] Created: `{"id":31,"url":"http://localhost:3000/api/v1/repos/admin/Apache-2.0/issues/31","html_url":"http://0.0.0.0:43007/admin/Apache-2.0/issues/31","number":31,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-1 // Output truncated...` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": [[]], "content_version": 45, "state": "open"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/31 ______ PATCH /repos/{owner}/{repo}/issues/{index}/assets/{attachment_id} _______ 1. Test Case ID: WYnOxg - Undocumented HTTP status code Received: 403 Documented: 201, 404, 422, 423 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Sudo: z' -H 'Content-Type: application/json' -d '{"em": [[-141, 9007199254740992]], "name": "attachment.png"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/assets/73 ___________ PATCH /repos/{owner}/{repo}/issues/{index}/comments/{id} ___________ 1. Test Case ID: QmUbxW - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 200, 204, 403, 404 [422] Unprocessable Content: `{"message":"[Body]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u000b": {"Y": 4.119309024409073e+16, "\u000f(1\u00d9\u0014\udba8\udcb5\uda87\udcd6\u00e9\"": -5.6207863482295135e+110, "u\u008a\uda80\ude9b\ud9a9\udfe1\u00f4": null}, "": false, "\uda2d\udf41\u000b\u00ef": ["\u001ch\u00a7}q"], "\ud95a\ude56\u00b0\n": [], "\u008e\u00d6\u0098h\uda3c\udd75\u00ef\u00976\ud86a\udd92\ud822\udd8f_\u0011\u0000 \u00f31t\u00cdy\u00a7_": {"\u00f6\u0083\u00fc\u00ac\u6e0c8": 2862994227886331.0}, "body": "Q"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/comments/4 __________ PATCH /repos/{owner}/{repo}/issues/{index}/pin/{position} ___________ 1. Test Case ID: kN79BO - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/pin/1 2. Test Case ID: fbs5g1 - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 403, 404 [500] Internal Server Error: `{"message":"The Position can't be lower than 1","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/pin/-9223372036854775808 ___________________ PATCH /repos/{owner}/{repo}/labels/{id} ____________________ 1. Test Case ID: EJyUv0 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - invalid syntax: random bytes [200] OK: `{"id":1,"name":"","exclusive":false,"is_archived":false,"color":"00aabb","description":"","url":"http://localhost:3000/api/v1/repos/admin/Apache-2.0/labels/1"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:43007/api/v1/repos/admin/demo/labels/1 _________________ PATCH /repos/{owner}/{repo}/milestones/{id} __________________ 1. Test Case ID: jDNAvX - Undocumented HTTP status code Received: 422 Documented: 200, 404 [422] Unprocessable Content: `{"message":"[]: json: cannot unmarshal JSON string into Go time.Time within \"/due_on\": parsing time \"2024-01-01T12:99:00Z\": minute out of range","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\r\u000eg": [], "": false, "due_on": "2024-01-01T12:99:00Z", "title": "\u3b89", "state": "closed", "description": "\u00a3\udbe8\udc1aY\u000e\u008f\ud845\uddb7\u00ef\u00d1`\u00c2\u00df\u0084\u00d3+"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/milestones/80d813304cce7ce1e538097133572f371a018407 __________________ PATCH /repos/{owner}/{repo}/projects/{id} ___________________ 1. Test Case ID: NJWsho - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [423] Locked: `{"message":"repo is archived","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"state": "open"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/projects/1 2. Test Case ID: 35DEdp - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - invalid syntax: random bytes [423] Locked: `{"message":"repo is archived","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:43007/api/v1/repos/admin/demo/projects/1 ________ PATCH /repos/{owner}/{repo}/projects/{id}/columns/{column_id} _________ 1. Test Case ID: 0QMSQB - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [423] Locked: `{"message":"repo is archived","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/projects/1/columns/25987514168042 2. Test Case ID: 7IIC6t - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - invalid syntax: random bytes [423] Locked: `{"message":"repo is archived","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:43007/api/v1/repos/admin/demo/projects/1/columns/3 __________________ PATCH /repos/{owner}/{repo}/releases/{id} ___________________ 1. Test Case ID: xvr2bG - Response violates schema null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/Release/properties/published_at: { "type": "string", "format": "date-time", "x-go-name": "PublishedAt" } Value: null [200] OK: `{"id":5,"tag_name":"|󑉇­P􏰧Aôãé¦C\u0005𜡪񓒽","target_commitish":"ï","name":"👍🏻","body":"GNU LESSER GENERAL PUBLIC LICENSE\n\nVersion 2.1, February 1999\n\nCopyright (C) 1991, 1999 Free Software Foundation, Inc.\n51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA\n\nEveryone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed.\n\n[This is the first released version of the Lesser GPL. It also counts as the successor of the GNU Library Public Lic // Output truncated...` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00a8\u00f9r\u0086\u00b70\ud8c4\ude05": {}, "name": "p\u00cc\u00f0\u5c1e", "prerelease": true, "tag_name": "\u00f6\uda3a\udf78\ud987\udc71\u00b6\ud897\udc00\u00f8a\ud8e4\udfbd:", "body": "Copyright (c) \n\nRedistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:\n\n1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.\n\n2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.\n\nTHIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS \"AS IS\" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.\n", "draft": false}' http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/5 2. Test Case ID: bNaLWa - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 404 [500] Internal Server Error: `{"message":" is archived","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/11 _______ PATCH /repos/{owner}/{repo}/releases/{id}/assets/{attachment_id} _______ 1. Test Case ID: du10wO - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - invalid syntax: random bytes [201] Created: `{"id":83,"name":"attachment.png","size":67,"download_count":0,"created_at":"2026-10-10T10:10:18Z","uuid":"d051bbdf-1445-4cca-ac95-1d69b25bac4f","browser_download_url":"http://0.0.0.0:43007/attachments/d051bbdf-1445-4cca-ac95-1d69b25bac4f"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'N,r��?\x1bl\x1b\x06\x16:�j�' http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/1/assets/83 _______________ PATCH /repos/{owner}/{repo}/tag_protections/{id} _______________ 1. Test Case ID: ZON0Sq - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [423] Locked: `{"message":"repo is archived","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/tag_protections/1 _______________ PATCH /repos/{owner}/{repo}/wiki/page/{pageName} _______________ 1. Test Case ID: 1i4m6r - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 200, 400, 403, 404, 423 [422] Unprocessable Content: `{"message":"[Title]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/wiki/page/0 2. Test Case ID: kVY0v1 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (``, `": ”t`, `ÉP9󉠋‘􋤊:򷍙g𥁁Å󴈓=¹©󎻪򋩹񇹹À~񥈬·ÔÆ` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"message":"illegal base64 data at input byte 0","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud952\udfcd\u00cf\ud901\ude38 \u00b5\udab3\udd00": [], "": ["\u00a4e\u0089\ud963\udeed", null, 935692895902], "\u00cf\udb91\udcda\u001c": {"": {"Y\u00b3W": 424719, "\udaf4\udf3ap\u00f7\uda50\udf94\u008aV!>\u0018": null}}, "\":\t\u0094\u0011\u0005t": -1.9187212447944453e-108, "\u00c9P9\udae6\udc0b\u0091\udbee\udd0a:\uda9c\udf59g\ud854\udc41\u00c5\udb90\ude13=\u00b9\u00a9\udafb\udeea\ud9ee\ude79\ud8df\ude79\u00c0~\ud954\ude2c\u00b7\u00d4\u00c6": {"\u00a6\u0083J\ud9d6\udfb5\u00d4\u00de": [2.225073858507203e-309], "\u008b\ud99a\udc8a\u0089{\ud8e2\ude56\u0086\u00d3\u0088\u00fd\u00f9": 1372, "q\u00ce": {}}, "message": "W", "title": "\udb6e\ude81", "content_base64": "\u0016\ud83e\udce3\u00f9\u0016\u00fd\u00f2]\u00ea\u00f6\u008e\u00fei"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/wiki/page/f%0A%F2%B2%B0%A6 ______________________________ PATCH /teams/{id} _______________________________ 1. Test Case ID: 3cj9W3 - Response violates schema null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/Organization: { "type": "object", "description": "Organization represents an organization", "properties": { "avatar_url": { "description": "The URL of the organization's avatar", "type": "string", "x-go-name": "AvatarURL" }, "description": { "description": "The description of the organization", "type": "string", "x-go-name": "Description" }, "email": { "description": "The email address of the organization", "type": "string", "x-go-name": "Email" }, // Output truncated... } Value: null [200] OK: `{"id":1,"name":"Owners","description":"","organization":null,"includes_all_repositories":true,"permission":"owner","units":["repo.code","repo.releases","repo.packages","repo.actions","repo.issues","repo.pulls","repo.wiki","repo.ext_wiki","repo.ext_issues","repo.projects"],"units_map":{"repo.code":"owner","repo.issues":"owner","repo.releases":"owner","repo.packages":"owner","repo.pulls":"owner","repo.wiki":"owner","repo.ext_wiki":"read","repo.ext_issues":"read","repo.projects":"owner","repo.actions":"owner"} // Output truncated...` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"units": ["repo.code", "repo.issues", "repo.ext_issues", "repo.wiki", "repo.pulls", "repo.releases", "repo.projects", "repo.ext_wiki"], "units_map": {"repo.code": "read", "repo.ext_issues": "none", "repo.ext_wiki": "none", "repo.issues": "write", "repo.projects": "none", "repo.pulls": "owner", "repo.releases": "none", "repo.wiki": "admin"}, "can_create_org_repo": false, "description": "", "includes_all_repositories": false, "name": "", "permission": "read", "visibility": "public"}' http://0.0.0.0:43007/api/v1/teams/1 2. Test Case ID: KM6mcB - Undocumented HTTP status code Received: 422 Documented: 200, 404 [422] Unprocessable Content: `{"message":"[Visibility]: In","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"can_create_org_repo": false, "description": "", "includes_all_repositories": false, "name": "Owners", "permission": "read", "units": ["repo.code", "repo.issues", "repo.ext_issues", "repo.wiki", "repo.pulls", "repo.releases", "repo.projects", "repo.ext_wiki"], "units_map": {"repo.code": "read", "repo.ext_issues": "none", "repo.ext_wiki": "none", "repo.issues": "write", "repo.projects": "none", "repo.pulls": "owner", "repo.releases": "none", "repo.wiki": "admin"}, "visibility": "AAA"}' http://0.0.0.0:43007/api/v1/teams/1 3. Test Case ID: M0Sy3O - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - visibility: Incorrect type [200] OK: `{"id":1,"name":"Owners","description":"","organization":null,"includes_all_repositories":true,"permission":"owner","units":["repo.projects","repo.actions","repo.code","repo.releases","repo.wiki","repo.ext_wiki","repo.packages","repo.issues","repo.pulls","repo.ext_issues"],"units_map":{"repo.pulls":"owner","repo.ext_issues":"read","repo.packages":"owner","repo.issues":"owner","repo.releases":"owner","repo.wiki":"owner","repo.ext_wiki":"read","repo.projects":"owner","repo.actions":"owner","repo.code":"owner"} // Output truncated...` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"can_create_org_repo": false, "description": "", "includes_all_repositories": false, "name": "Owners", "permission": "read", "units": ["repo.code", "repo.issues", "repo.ext_issues", "repo.wiki", "repo.pulls", "repo.releases", "repo.projects", "repo.ext_wiki"], "units_map": {"repo.code": "read", "repo.ext_issues": "none", "repo.ext_wiki": "none", "repo.issues": "write", "repo.projects": "none", "repo.pulls": "owner", "repo.releases": "none", "repo.wiki": "admin"}, "visibility": null}' http://0.0.0.0:43007/api/v1/teams/1 ___________________ PATCH /user/actions/runners/{runner_id} ____________________ 1. Test Case ID: 9EacX0 - Undocumented HTTP status code Received: 401 Documented: 200, 400, 404, 422 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: $' 'http://0.0.0.0:43007/api/v1/user/actions/runners/%C2%95g%C3%B6?sudo=1%C2%91%C2%AC%C2%9BP%C2%91%C3%B6A%C3%87q%C2%8AT%C3%98%1C&access_token=%5BFiltered%5D&token=%5BFiltered%5D' _____________________ PATCH /user/applications/oauth2/{id} _____________________ 1. Test Case ID: nl3lrz - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 200, 400, 404 [422] Unprocessable Content: `{"message":"[Name]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"confidential_client": false, "name": "", "redirect_uris": [], "skip_secondary_authorization": "[Filtered]"}' http://0.0.0.0:43007/api/v1/user/applications/oauth2/-9223372036854775808 2. Test Case ID: tJVTlw - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (``, ``, `mC` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"message":"invalid redirect URI: Çà󼯺u𒬱{\u001bÓ򇾧a6򍳳ýÅ𒌯ME","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": [-119738, 1.8509308349110066e+182, true], "\u001b": {"Sy\u00fd\uda10\udd53": "", "": null}, "\u00b9": false, "\ud8a6\udd49": {"\u00c5p": "Y%\u00f3(\u0099\uda7b\udc65O\u00f8b\ud9aa\udc22\u0002\ud9d1\ude62\ud950\udd52\u0098\u00b1d,\u001c?\u009d", "": true}, "mC": [], "skip_secondary_authorization": "[Filtered]", "redirect_uris": ["\u00c7\u00e0\udbb2\udffau\ud80a\udf31{\u001b\u00d3\ud9df\udfa7a6\ud9f7\udcf3\u00fd\u00c5\ud808\udf2fME", "", "\u023a", "\u00c2m"], "confidential_client": false, "name": "BSD-3-Clause"}' http://0.0.0.0:43007/api/v1/user/applications/oauth2/1 3. Test Case ID: 1lE3Xr - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 404 [500] Internal Server Error: `{"message":"UID mismatch","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"redirect_uris": [""], "skip_secondary_authorization": "[Filtered]", "confidential_client": true, "name": "\u00c5\u00e8\ud844\ude94O\u00e0]*\ud977\udf01"}' http://0.0.0.0:43007/api/v1/user/applications/oauth2/1 ____________________________ PATCH /user/hooks/{id} ____________________________ 1. Test Case ID: iru6U7 - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"active": false, "authorization_header": "[Filtered]", "branch_filter": "", "config": {}, "events": [], "name": ""}' http://0.0.0.0:43007/api/v1/user/hooks/-9223372036854775808 2. Test Case ID: 3OtZdW - Undocumented HTTP status code Received: 422 Documented: 200 [422] Unprocessable Content: `{"message":"[]: json: cannot unmarshal JSON object into Go string within \"/name\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"active": false, "authorization_header": "[Filtered]", "branch_filter": "", "config": {}, "events": [], "name": {}}' http://0.0.0.0:43007/api/v1/user/hooks/-9223372036854775808 3. Test Case ID: rKuhrD - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 3 additional properties not defined in the schema (`•񻞒`, `¯{ðJ`, `򧩨nío| ÀrL񠕓²񒍕ÍóË=®`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [422] Unprocessable Content: `{"message":"[BranchFilter]: unterminated character class","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u0095\ud9ad\udf92": {"": {}, "r\u00a6\u00f0q": {}, "\u00f1\ud8d0\udf5cy\u00fa\ud80e\udd5c\u000e\u00fd": true}, "\uda5e\ude68n\u00edo\u008d| \u00c0rL\u0007\ud941\udd53\u00b2\u0013\ud908\udf55\u0090\u00cd\u00f3\u00cb=\u00ae": "", "\u00af{\u00f0J": [[null, true]], "branch_filter": "\u00b9\u0004\ud856\ude18\u00cf\u00ea[ZD\u00f2\u0081\u00ed\u0094", "config": {"\u00ac:": "\u0012\ud9b2\ude3d\u0007(\u009c\"\u00dc\ud882\udeb2\u00e3\uda13\ude18\u00af\uda77\ude2b", "": "\u009f\uec60\u00b21", "\udb1c\udc05w\u00ce\u00e1\u00f2\u0004]": "", "F\uda73\ude0dh]\u001d\udbdd\udee4#\u00d4\u00c1D8\uda85\ude62": "\u0086\udb91\udc72\u00cc\u00d2\udbe1\udf7b", "z\udb23\udfb1[0\u00ed\u00de": "\uda5d\udfee"}, "authorization_header": "[Filtered]"}' http://0.0.0.0:43007/api/v1/user/hooks/1 __________________________ PATCH /user/projects/{id} ___________________________ 1. Test Case ID: TVfFcT - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Title]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"card_type": "", "description": "", "state": "open", "title": ""}' http://0.0.0.0:43007/api/v1/user/projects/-9223372036854775808 ________________ PATCH /user/projects/{id}/columns/{column_id} _________________ 1. Test Case ID: A17gDe - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Title]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "", "sorting": 0, "title": ""}' http://0.0.0.0:43007/api/v1/user/projects/-9223372036854775808/columns/-9223372036854775808 _____________________________ PATCH /user/settings _____________________________ 1. Test Case ID: DS8gjA - Undocumented HTTP status code Received: 422 Documented: 200 [422] Unprocessable Content: `{"message":"[]: json: cannot unmarshal JSON object into Go string within \"/website\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "diff_view_style": "", "full_name": "", "hide_activity": false, "hide_email": false, "language": "", "location": "", "theme": "", "website": {}}' http://0.0.0.0:43007/api/v1/user/settings 2. Test Case ID: QTOsbF - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - website: Incorrect type [200] OK: `{"full_name":"","website":"","description":"","location":"","language":"","theme":"","diff_view_style":"","hide_email":false,"hide_activity":false}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "diff_view_style": "", "full_name": "", "hide_activity": false, "hide_email": false, "language": "", "location": "", "theme": "", "website": null}' http://0.0.0.0:43007/api/v1/user/settings 3. Test Case ID: eA66yE - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (``, `ÊÛ򧵎¬Õ0KxXœQ›­%`¾,Ÿ€󐅨Nr`, `5󍶐µ¼󿻤  𝎽󖏵€ÓsRdc{` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [422] Unprocessable Content: `{"message":"[Website]: Url","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": [[null, null, "\u00ee\ud91b\uded0\ud9cb\udda6\ud9f0\udd65l\u00e6\ue57d\u0095\u0086\ud8da\udc2f\u00b6\u00f5"], null, false], "5\udaf7\udd90\u00b5\u00bc\udbbf\udee4\t\u001e\ud834\udfbd\udb18\udff5\u0080\u00d3sRdc{": {}, "\uda09\ude43": {}, "\u001f\u00ca\u00db\uda5f\udd4e\u00ac\u0010\u00d50KxX\u009cQ\u009b\u00ad%`\u00be,\u009f\u0080\u0012\udb00\udd68N\u0006r": [{"\u00e8": -14136985982610689753088, "\u00ea=": "\u00990\uda03\udd19\u0081\u0094P", "total": -8611331816091}, [127025603], [-225382264468]], "\udbfb\udc90\udb83\udf5aU": [-4.94032263927985e+16, []], "full_name": "`\u0016\uda75\udc12\u00cf\u00ba", "diff_view_style": "", "website": "\udb09\udf02\u00ad`\u0018\u0004\u00d8\udae4\udc7e", "theme": "", "location": "\udae4\udf62\u00c1\u00820\u00e7\u0095\u008cRG\u00a4\u00f2\u00f5\u0097\u0001\u0010p\udb54\udea8", "hide_email": false}' http://0.0.0.0:43007/api/v1/user/settings 4. Test Case ID: P486Tj - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": "\u00ff", "8\u00c8": {"\n\u00e2\ud998\udee5\ud918\udd69": {}, "U\u00b5aa\uda18\udf8a\ud991\ude3d\u00a3": 4.19495163794202e+21, "\u00b1\u00de\u0088\ud8ee\ude72R\u00a4d\udbad\udc04\u009a\ud870\uddde\u00f3\ud945\udd32\udb08\uddc4\u000e": []}, "$": [false, false, false], "\t": [{}], "\uda12\udf7e\u00ca?\u0090\u1ca7\ud961\udfcd\u0081\udac4\udd3e\u00f9\\": [], "hide_email": false, "diff_view_style": "\u0087", "theme": "\r\u00e0u\u008c\u0012\u008f\u009b", "website": "e"}' 'http://0.0.0.0:43007/api/v1/user/settings?sudo=&token=%5BFiltered%5D' ________________ POST /admin/actions/runners/registration-token ________________ 1. Test Case ID: M1ejop - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/admin/actions/runners/registration-token ___________________________ POST /admin/cron/{task} ____________________________ 1. Test Case ID: QxOnM9 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/admin/cron/0 2. Test Case ID: DuZa5z - Undocumented HTTP status code Received: 401 Documented: 204, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/cron/responses?access_token=%5BFiltered%5D' ______________________________ POST /admin/hooks _______________________________ 1. Test Case ID: JwLsAG - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201 [422] Unprocessable Content: `{"message":"Missing config option: url","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"active": false, "authorization_header": "[Filtered]", "branch_filter": "", "config": {}, "events": [], "name": "", "type": "dingtalk"}' http://0.0.0.0:43007/api/v1/admin/hooks 2. Test Case ID: 96xeo3 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"active": false, "authorization_header": "[Filtered]", "branch_filter": "", "config": {}, "events": [], "name": "", "type": "dingtalk"}' http://0.0.0.0:43007/api/v1/admin/hooks _____________________ POST /admin/unadopted/{owner}/{repo} _____________________ 1. Test Case ID: FZ6ubp - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/admin/unadopted/0/0 ______________________________ POST /admin/users _______________________________ 1. Test Case ID: bANX8X - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Username]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"created_at": "2000-01-01T00:00:00Z", "email": "", "full_name": "", "login_name": "", "must_change_password": "[Filtered]", "password": "[Filtered]", "restricted": false, "send_notify": false, "source_id": 0, "username": "", "visibility": "public"}' http://0.0.0.0:43007/api/v1/admin/users 2. Test Case ID: i8Ew4A - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"created_at": "2000-01-01T00:00:00Z", "email": "", "full_name": "", "login_name": "", "must_change_password": "[Filtered]", "password": "[Filtered]", "restricted": false, "send_notify": false, "source_id": 0, "username": "", "visibility": "public"}' http://0.0.0.0:43007/api/v1/admin/users 3. Test Case ID: u07ePo - Undocumented HTTP status code Received: 401 Documented: 201, 400, 403, 409, 422 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Sudo;' -H 'Content-Type: application/json' -d '{"": [], "username": "\u00f2", "email": "\u009f$\u00e8\u000b\ud9a2\udea4\u001b\ud891\udff3\u0005\ud847\uddf4\udbe3\udf0d\uda9d\udf6b\u00eb\ud884\udf25"}' 'http://0.0.0.0:43007/api/v1/admin/users?access_token=%5BFiltered%5D&sudo=E%C2%AE' _____________________ POST /admin/users/{username}/badges ______________________ 1. Test Case ID: AF6sG5 - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 403 [500] Internal Server Error: `{"message":"badge does not exist [slug: badge1]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"badge_slugs": ["badge1", "badge2"]}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/badges 2. Test Case ID: CJR6x9 - Undocumented HTTP status code Received: 422 Documented: 204, 403 [422] Unprocessable Content: `{"message":"[]: json: cannot unmarshal JSON object into Go string within \"/badge_slugs/0\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"badge_slugs": [{}]}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/badges 3. Test Case ID: McUFRD - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[BadgeSlugs]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/badges 4. Test Case ID: VttB2i - Undocumented HTTP status code Received: 404 Documented: 204, 403 [404] Not Found: `{"message":"user redirect does not exist [name: s]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00ad": {}, "\u00a0\u00bf": {}, "\ud810\udc06\u00d6=\u00e6\udae4\udffc\u00df\ud966\ude65\u001a\uda0d\udf30": [], "\u00ec\u00e1\u0006\u00ce\u00c4\u00e9~": [{}, {}, {}], "\ud86f\udf88\udb09\udd59": {"Li\u0083\u00d7": "\udb4d\udf76\u00a3\u00c5\ud868\udeab@\u009a\u00e3\u00e2\u00b0"}}' http://0.0.0.0:43007/api/v1/admin/users/S/badges 5. Test Case ID: xwmHqR - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"badge_slugs": []}' http://0.0.0.0:43007/api/v1/admin/users/A/badges ______________________ POST /admin/users/{username}/keys _______________________ 1. Test Case ID: CDFK2d - Undocumented HTTP status code Received: 404 Documented: 201, 403, 422 [404] Not Found: `{"message":"user redirect does not exist [name: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"key": "[Filtered]", "read_only": false, "title": ""}' http://0.0.0.0:43007/api/v1/admin/users/0/keys 2. Test Case ID: SwRvmn - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"key": "[Filtered]", "read_only": false, "title": ""}' http://0.0.0.0:43007/api/v1/admin/users/0/keys 3. Test Case ID: i1r9rt - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Title]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"key": "[Filtered]", "title": ""}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/keys ______________________ POST /admin/users/{username}/orgs _______________________ 1. Test Case ID: QCJwYY - Undocumented HTTP status code Received: 404 Documented: 201, 403, 422 [404] Not Found: `{"message":"user redirect does not exist [name: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "email": "", "full_name": "", "location": "", "repo_admin_change_team_access": false, "username": "", "visibility": "public", "website": ""}' http://0.0.0.0:43007/api/v1/admin/users/0/orgs 2. Test Case ID: bMOakD - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"description": "", "email": "", "full_name": "", "location": "", "repo_admin_change_team_access": false, "username": "", "visibility": "public", "website": ""}' http://0.0.0.0:43007/api/v1/admin/users/0/orgs 3. Test Case ID: kgBXTV - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 403, 422 [500] Internal Server Error: `{"message":"user is not allowed to create organizations","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"username": "A"}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/orgs 4. Test Case ID: mATS4B - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (`𹬳`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [422] Unprocessable Content: `{"message":"[Website]: Url","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u009d\ud8a6\udf33": {"": {}, "L\u00f0": "\ud8ae\udd7a\u009d\u0010\u00b4D\u00c0`oU\u0090f\u008a5'"'"'\u00e2\udbeb\udc1aP\u00e7J\u000b0", "\u00cc\u00ff\u0081": {"'"'"'t\u0095B\u00a9sh{\ud9eb\udc0b\u0012\udaad\udea3\udac1\uded1\u0099\u00ff\ud8cc\udcfe\uda12\ude29\udaf4\udfc2|\u00b6t": null}}, "description": "4b\u0097", "full_name": "QG8", "visibility": "limited", "website": "\u00cf\u00d0J\u00c9\uda12\udd45KK", "username": "A"}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/orgs 5. Test Case ID: hcdi4x - Undocumented HTTP status code Received: 401 Documented: 201, 403, 422 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Sudo: 3'"'"'5' -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: 5tW$Bc)' -H 'Content-Type: application/json' -d '{"S\u009c": [], "T:\ud97d\udc97\u0007\u0006\udbd2\ude7eJ\u00f6\u008f\u00e4>\"\u00cc\u0005G\u0017ve\\\u0015\u00d4G\uda16\udc2eB\\\u00fd\ud919\udc7b\u00cdd\udbc3\udd1f\ud99b\uddafu\u0012\u001f": {}, "location": "p\u00ee\udb04\ude492[d", "description": "\u00de\u00e2\u00bf\u0012", "visibility": "limited", "repo_admin_change_team_access": false, "full_name": "\u00d9\u00d6\u00b2\u00f4g", "email": "", "username": "A"}' 'http://0.0.0.0:43007/api/v1/admin/users/workbench-user/orgs?access_token=%5BFiltered%5D&token=%5BFiltered%5D' _____________________ POST /admin/users/{username}/rename ______________________ 1. Test Case ID: DCWONG - Undocumented HTTP status code Received: 404 Documented: 204, 403, 422 [404] Not Found: `{"message":"user redirect does not exist [name: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"new_username": ""}' http://0.0.0.0:43007/api/v1/admin/users/0/rename 2. Test Case ID: MtF3wV - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"new_username": ""}' http://0.0.0.0:43007/api/v1/admin/users/0/rename 3. Test Case ID: BdHaOT - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[NewName]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"new_username": ""}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/rename 4. Test Case ID: Q7UeV8 - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00db\u00c0\uda56\udd7f\ud828\udddbQ\n*l\u00acT\u0090\udb66\udccc\ud8b9\udd04": [[]], "\u00b2\ud95f\ude3dnm|d\u000b\u001a": {"U": 938244, "\u00d7\udb35\udf1f\udb9c\ude64m\u00d8\u00ec\ud99a\ude1d\u00f5\u001e'"'"'\u0094\u00f0~n": null, "\u00d1n\ud85d\udcc3\u00df\u0011d": {"\u000f\ud976\ude29\u0018\u0017": "U\u00c1\u0089\u00df", "\tL": 219}}, "r": {}, "new_username": "Z"}' http://0.0.0.0:43007/api/v1/admin/users/workbench/rename ______________________ POST /admin/users/{username}/repos ______________________ 1. Test Case ID: x8MRKE - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"auto_init": false, "default_branch": "", "description": "", "gitignores": "", "issue_labels": "", "license": "", "name": "", "object_format_name": "sha1", "private": false, "readme": "", "template": false, "trust_model": "default"}' http://0.0.0.0:43007/api/v1/admin/users/0/repos 2. Test Case ID: QbYWtn - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Name]: AlphaDashDot","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "\u00bf"}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/repos 3. Test Case ID: wMKYw1 - Response violates schema "" is not a "email" Validated against the response schema for status code 201. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [201] Created: `{"id":15,"owner":{"id":4,"login":"workbench-user","type":"Organization","login_name":"","source_id":0,"full_name":"admin/demo","email":"","avatar_url":"http://0.0.0.0:43007/avatars/fa25ceee0d7be94b95c0208f7456232d4e85b901ba9bb49d8219ba29e2313dc7","html_url":"http://0.0.0.0:43007/workbench-user","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:58:40Z","restricted":false,"active":false,"prohibit_login":false,"location":"","website":"","description":"","visibility":"p // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "repo_health_check"}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/repos 4. Test Case ID: D0V8c1 - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 403, 404, 409, 422 [500] Internal Server Error: `{"message":"initRepository: prepareRepoCommit: GetRepoInitFile[È]: file does not exist","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": [{}], "\udb40\udcb2\u0010\ud8cf\ude7c\ud911\udd0fMC>\u0013\u00a7J\ud897\udd43": [false, "\b\u00db", 15348], "\u00d5\uda36\udde1uz\udac5\uddfd": 1500703091022370.0, "O\u0010f9E\u00b8": {}, "\u001d\u0002": [], "auto_init": true, "description": "O\udb9b\udf3b\ud9bd\udf62", "name": "AGPL-3.0", "gitignores": "\u00c8", "license": "\ud81e\udede\u00b4\ud8cc\udcd9?\u00e5u6\u00f0f\u00d2\u0097\u00c5\f\u00f1P\u001c\ud812\udc9d\ud93e\ude0c7", "issue_labels": ""}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/repos 5. Test Case ID: Jbnizy - Undocumented HTTP status code Received: 401 Documented: 201, 400, 403, 404, 409, 422 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'X-GITEA-OTP;' -H 'Sudo: 6ZVoyz-\!]' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "", "license": "q"}' 'http://0.0.0.0:43007/api/v1/admin/users/workbench-user/repos?token=%5BFiltered%5D&access_token=%5BFiltered%5D&sudo=' ________________________________ POST /markdown ________________________________ 1. Test Case ID: Jccbjl - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `text/html` [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"Context": "", "Mode": "", "Text": "", "Wiki": false}' http://0.0.0.0:43007/api/v1/markdown 2. Test Case ID: uJ6vVZ - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: text/html [422] Unprocessable Content: `{"message":"[]: json: cannot unmarshal JSON object into Go bool within \"/Wiki\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"Context": "", "Mode": "", "Text": "", "Wiki": {}}' http://0.0.0.0:43007/api/v1/markdown 3. Test Case ID: RwRBTr - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - wiki: Incorrect type [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"Context": "", "Mode": "", "Text": "", "Wiki": null}' http://0.0.0.0:43007/api/v1/markdown 4. Test Case ID: Wltm7X - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"Context": "", "Mode": "", "Text": "", "Wiki": false}' http://0.0.0.0:43007/api/v1/markdown 5. Test Case ID: rxZkjt - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: text/html [422] Unprocessable Content: `unsupported render mode: O` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"Text": "\u001d\u0084\uda72\udd07k\ud926\udf2dO\u009f\u0004", "Mode": "O"}' http://0.0.0.0:43007/api/v1/markdown ______________________________ POST /markdown/raw ______________________________ 1. Test Case ID: jP0AiS - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `text/html` [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: text/plain' http://0.0.0.0:43007/api/v1/markdown/raw 2. Test Case ID: 8nFRIZ - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: Missing request body [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/markdown/raw 3. Test Case ID: g2zvK0 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/markdown/raw _________________________________ POST /markup _________________________________ 1. Test Case ID: GTOL3g - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `text/html` [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"Context": "", "FilePath": "", "Mode": "", "Text": "", "Wiki": false}' http://0.0.0.0:43007/api/v1/markup 2. Test Case ID: uf2N0u - Undocumented Content-Type Received: application/json;charset=utf-8 Documented: text/html [422] Unprocessable Content: `{"message":"[]: json: cannot unmarshal JSON object into Go bool within \"/Wiki\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"Context": "", "FilePath": "", "Mode": "", "Text": "", "Wiki": {}}' http://0.0.0.0:43007/api/v1/markup 3. Test Case ID: RgPCQw - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - wiki: Incorrect type [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"Context": "", "FilePath": "", "Mode": "", "Text": "", "Wiki": null}' http://0.0.0.0:43007/api/v1/markup 4. Test Case ID: rIfegu - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"Context": "", "FilePath": "", "Mode": "", "Text": "", "Wiki": false}' http://0.0.0.0:43007/api/v1/markup 5. Test Case ID: 2UTKeo - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/markup 6. Test Case ID: uwtbBy - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: text/html [422] Unprocessable Content: `unsupported render mode: ®` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"Mode": "\u00ae", "FilePath": "\u0006\ud8b7\udc39\udae6\udf6c\u00ff\ud83a\udee6>\udb4a\udfc6", "Context": "", "Wiki": false, "Text": "\u00c2"}' http://0.0.0.0:43007/api/v1/markup ____________________________ POST /org/{org}/repos _____________________________ 1. Test Case ID: wy5z59 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Name]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"auto_init": false, "default_branch": "", "description": "", "gitignores": "", "issue_labels": "", "license": "", "name": "", "object_format_name": "sha1", "private": false, "readme": "", "template": false, "trust_model": "default"}' http://0.0.0.0:43007/api/v1/org/0/repos 2. Test Case ID: xVakrI - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"auto_init": false, "default_branch": "", "description": "", "gitignores": "", "issue_labels": "", "license": "", "name": "", "object_format_name": "sha1", "private": false, "readme": "", "template": false, "trust_model": "default"}' http://0.0.0.0:43007/api/v1/org/0/repos __________________________________ POST /orgs __________________________________ 1. Test Case ID: aXcY79 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[UserName]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "email": "", "full_name": "", "location": "", "repo_admin_change_team_access": false, "username": "", "visibility": "public", "website": ""}' http://0.0.0.0:43007/api/v1/orgs 2. Test Case ID: twqU7u - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"description": "", "email": "", "full_name": "", "location": "", "repo_admin_change_team_access": false, "username": "", "visibility": "public", "website": ""}' http://0.0.0.0:43007/api/v1/orgs _____________ POST /orgs/{org}/actions/runners/registration-token ______________ 1. Test Case ID: cQB22U - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/0/actions/runners/registration-token 2. Test Case ID: Hbl9ND - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/orgs/0/actions/runners/registration-token 3. Test Case ID: vNQl2t - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/runners/registration-token ______________ POST /orgs/{org}/actions/variables/{variablename} _______________ 1. Test Case ID: 44liHB - Undocumented HTTP status code Received: 404 Documented: 201, 400, 409, 500 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "value": ""}' http://0.0.0.0:43007/api/v1/orgs/0/actions/variables/0 2. Test Case ID: YMwwUe - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"description": "", "value": ""}' http://0.0.0.0:43007/api/v1/orgs/0/actions/variables/0 3. Test Case ID: 8CiuOj - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/0 4. Test Case ID: 9LMOyj - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 400, 409, 500 [422] Unprocessable Content: `{"message":"[Value]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": ""}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/false 5. Test Case ID: VhCvkb - Missing Content-Type header The following media types are documented in the schema: - `application/json` [201] Created: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u009e8\u00cb\uda76\udec7\ud83b\udfa7\u00c0V\uda60\udd4a\u00c4": {"\u00ab\u0082hD7": []}, "3\u0004": ["^K\u008a\u008e\ud878\udc7c6\u00f3", -1.0525138248442676e-45, "False"], "\u00beFU\u0083u\u00ee2": {}, "\u00b8\u00e0\u00df\u00e3": [], "\u00bf": {}, "description": "\u0087\u0098c\u00a7\u0003", "value": "\bD"}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/affected 6. Test Case ID: SVkWiZ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (`QÄÙÐ8򰧙ù´Ð`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"message":"name must start with a letter or underscore and contain only letters, numbers, and underscores","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"Q\u00c4\u00d9\u00d08\u0001\uda82\uddd9\u00f9\u00b4\u00d0": {}, "description": "K", "value": "\uda27\udc18Q \u00fb"}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/%C2%B4 ___________________________ POST /orgs/{org}/avatar ____________________________ 1. Test Case ID: GXTMDo - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"image": ""}' http://0.0.0.0:43007/api/v1/orgs/0/avatar 2. Test Case ID: Y26ZwZ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 204, 404 [422] Unprocessable Content: `{"message":"[Image]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/orgs/workbench/avatar 3. Test Case ID: jkYtiH - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 2 additional properties not defined in the schema (``, `&񣈖.󪷱§Èó`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. - Undocumented HTTP status code Received: 400 Documented: 204, 404 [400] Bad Request: `{"message":"illegal base64 data at input byte 2","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"&\ud94c\ude16.\udb6b\uddf1\u00a7\u00c8\u00f3\u0019": [], "": {"": null, "\ud8b3\udca0": "\u00a3\u00e1(", "\u00cd\u00e4$\udbe5\uddaa": -4.935587799213213e-190}, "image": "41\u00f8"}' http://0.0.0.0:43007/api/v1/orgs/workbench/avatar ____________________________ POST /orgs/{org}/hooks ____________________________ 1. Test Case ID: iYlL4q - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"active": false, "authorization_header": "[Filtered]", "branch_filter": "", "config": {}, "events": [], "name": "", "type": "dingtalk"}' http://0.0.0.0:43007/api/v1/orgs/0/hooks 2. Test Case ID: PqoE9R - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 404 [422] Unprocessable Content: `{"message":"Missing config option: url","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"config": {}, "type": "gogs"}' http://0.0.0.0:43007/api/v1/orgs/workbench/hooks ___________________________ POST /orgs/{org}/labels ____________________________ 1. Test Case ID: JgO1QZ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Name]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#00aabb", "exclusive": false, "is_archived": false, "description": "", "name": ""}' http://0.0.0.0:43007/api/v1/orgs/workbench/labels 2. Test Case ID: zu9g5Q - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"color": "#00aabb", "description": "", "exclusive": false, "is_archived": false, "name": ""}' http://0.0.0.0:43007/api/v1/orgs/0/labels __________________________ POST /orgs/{org}/projects ___________________________ 1. Test Case ID: NKnwqb - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"card_type": "", "description": "", "template_type": "", "title": ""}' http://0.0.0.0:43007/api/v1/orgs/0/projects 2. Test Case ID: JoiZ17 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 3 additional properties not defined in the schema (``, `ƒ=G„ËS(`, `ÊË2`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [422] Unprocessable Content: `{"message":"invalid template_type \"\\U000afd99\\\"𬇤¼\\u0080AÞ#\\u008a$/\\U0004a720?\\x02u㙶\\u0089ª&å\\x05\\U0005dec1ø\\x17\" (expected none, basic_kanban, bug_triage)","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00ca\u00cb2": [true], "": [], "\u0083=G\u0084\u00cbS(": {"\u00aa\n\uda29\udc23\u00c4\u00b7X": null, "\u00b5\u00f9\u00a6f(\u00fd\ud99b\udf2f\u00f3\\": null, "\ud948\udc896W": null}, "template_type": "\uda7f\udd99\"\ud870\udde4\u00bc\u0080A\u00de#\u008a$/\ud8e9\udf20?\u0002u\u3676\u0089\u00aa&\u00e5\u0005\ud937\udec1\u00f8\u0017", "description": "O\udb9b\udf3b\ud9bd\udf62", "card_type": "\t\u0082\u41ce", "title": "First issue"}' http://0.0.0.0:43007/api/v1/orgs/workbench/projects ____________________ POST /orgs/{org}/projects/{id}/columns ____________________ 1. Test Case ID: JX0bq6 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"color": "", "title": ""}' http://0.0.0.0:43007/api/v1/orgs/0/projects/-9223372036854775808/columns 2. Test Case ID: egGd1L - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"title": "First issue"}' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns 3. Test Case ID: oapJPI - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns 4. Test Case ID: qmavGG - Undocumented HTTP status code Received: 401 Documented: 201, 403, 404, 422 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP;' 'http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns?token=%5BFiltered%5D&sudo=L' _________________ POST /orgs/{org}/projects/{id}/columns/move __________________ 1. Test Case ID: di8jnR - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"column_ids": []}' http://0.0.0.0:43007/api/v1/orgs/0/projects/-9223372036854775808/columns/move 2. Test Case ID: AeZGtz - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"column_ids": []}' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns/move 3. Test Case ID: mI3bCZ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns/move __________ POST /orgs/{org}/projects/{id}/columns/{column_id}/default __________ 1. Test Case ID: HMF4tj - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/orgs/0/projects/-9223372036854775808/columns/-9223372036854775808/default 2. Test Case ID: V8uEnc - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns/1/default _____ POST /orgs/{org}/projects/{id}/columns/{column_id}/issues/{issue_id} _____ 1. Test Case ID: CzrKnx - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/orgs/0/projects/-9223372036854775808/columns/-9223372036854775808/issues/1 2. Test Case ID: mooznd - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/columns/1/issues/15 ____________ POST /orgs/{org}/projects/{id}/issues/{issue_id}/move _____________ 1. Test Case ID: gKyAR2 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"column_id": 0, "sorting": 0}' http://0.0.0.0:43007/api/v1/orgs/0/projects/-9223372036854775808/issues/1/move 2. Test Case ID: AYPNQE - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"column_id": 0}' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/issues/15/move 3. Test Case ID: 87ras2 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/projects/1/issues/4783/move ___________________________ POST /orgs/{org}/rename ____________________________ 1. Test Case ID: 8S7O80 - Undocumented HTTP status code Received: 404 Documented: 204, 403, 422 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"new_name": ""}' http://0.0.0.0:43007/api/v1/orgs/0/rename 2. Test Case ID: nnJ6YM - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"new_name": ""}' http://0.0.0.0:43007/api/v1/orgs/0/rename 3. Test Case ID: fXrMQI - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[NewName]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"new_name": ""}' http://0.0.0.0:43007/api/v1/orgs/workbench/rename 4. Test Case ID: eWBjbq - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"*Ct\ud904\udc29\u00f2\u00fa\u00e6\u00c6#\u0090v": ["v\u00a5\u71682\u00ba\ud8cc\udf68\udb2a\ude5cS\u00b1\u0099", null, [null, -2550885, -6.924862739300686e-108]], "\u000f": [null, "\u00f4u\ud90f\udd7b\u0017\u00a5\ud830\udc67\u0000", -6.3014309879643576e+16], "\u0080\ud867\udc88\u0094\ud9c7\udd8d^}\u00e0\ud88e\udf83": [[-1543], [{"\u00d4r\u00da": true}]], "": [{}], "/\u0086": [[-3.1565718662657007e+268, false]], "new_name": "S"}' http://0.0.0.0:43007/api/v1/orgs/workbench/rename ____________________________ POST /orgs/{org}/repos ____________________________ 1. Test Case ID: AQS8w6 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"auto_init": false, "default_branch": "", "description": "", "gitignores": "", "issue_labels": "", "license": "", "name": "", "object_format_name": "sha1", "private": false, "readme": "", "template": false, "trust_model": "default"}' http://0.0.0.0:43007/api/v1/orgs/0/repos 2. Test Case ID: bUFjB2 - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": ""}' http://0.0.0.0:43007/api/v1/orgs/workbench/repos ____________________________ POST /orgs/{org}/teams ____________________________ 1. Test Case ID: 9xYK9N - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Name]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"units": ["repo.actions", "repo.packages", "repo.code", "repo.issues", "repo.ext_issues", "repo.wiki", "repo.pulls", "repo.releases", "repo.projects", "repo.ext_wiki"], "units_map": {"repo.actions": "read", "repo.code": "read", "repo.ext_issues": "none", "repo.ext_wiki": "none", "repo.issues": "write", "repo.packages": "read", "repo.projects": "none", "repo.pulls": "owner", "repo.releases": "none", "repo.wiki": "admin"}, "can_create_org_repo": false, "description": "", "includes_all_repositories": false, "name": "", "permission": "read", "visibility": "public"}' http://0.0.0.0:43007/api/v1/orgs/workbench/teams 2. Test Case ID: X5rli1 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"can_create_org_repo": false, "description": "", "includes_all_repositories": false, "name": "", "permission": "read", "units": ["repo.actions", "repo.packages", "repo.code", "repo.issues", "repo.ext_issues", "repo.wiki", "repo.pulls", "repo.releases", "repo.projects", "repo.ext_wiki"], "units_map": {"repo.actions": "read", "repo.code": "read", "repo.ext_issues": "none", "repo.ext_wiki": "none", "repo.issues": "write", "repo.packages": "read", "repo.projects": "none", "repo.pulls": "owner", "repo.releases": "none", "repo.wiki": "admin"}, "visibility": "public"}' http://0.0.0.0:43007/api/v1/orgs/0/teams 3. Test Case ID: UBZubr - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 404, 422 [500] Internal Server Error: `{"message":"constraint failed: UNIQUE constraint failed: team_unit.team_id, team_unit.type (2067)","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud8a1\uddd4*": null, "W\u0081": [null], "": {}, "\u0011\"\u00d4i": [[], [0.75]], "\udbf2\udd70\u0082]\u0087\u0089": {"#": "", "\u00d0\u000e\udb81\udd80\udad3\udfb73][": "", "\u009dM\u0099": "\u0088W\u00ac("}, "units": ["\u00ce\u00bc\u009d\u000e\u00f0s", "text/xml", "A\u000e\u00ace\u0083\u00df", "\u0090E", "wealth", "", "w", "7\u394c\u8676\ud848\ude3f\u00ad>I\u00f1"], "name": "A"}' http://0.0.0.0:43007/api/v1/orgs/workbench/teams 4. Test Case ID: ir7hp0 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 3 additional properties not defined in the schema (`‘á􀛗*Ñæ`, `Κ`, `񉫨`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. - Undocumented HTTP status code Received: 400 Documented: 201, 404, 422 [400] Bad Request: `{"message":"no permission specified","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u0091\u00e1\udbc1\uded7*\u001a\u00d1\u00e6": {}, "\ud8e6\udee8": {"\u00fa\u00af": null}, "\u00ce\u009a": [null, 5.2499852933430596e-182], "can_create_org_repo": false, "name": "BSD-2-Clause"}' http://0.0.0.0:43007/api/v1/orgs/workbench/teams 5. Test Case ID: qNmys4 - Response violates schema (2 violations) null is not of type "array" Validated against the response schema for status code 201. Schema at /definitions/Team/properties/units: { "type": "array", "description": "Deprecated: This variable should be replaced by UnitsMap ... "items": { "type": "string" }, "x-deprecated": true, "x-go-name": "Units", "example": [ "repo.code", "repo.issues", "repo.ext_issues", "repo.wiki", "repo.pulls", "repo.releases", "repo.projects", "repo.ext_wiki" ] } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/Team/properties/units_map: { "type": "object", "additionalProperties": { "type": "string" }, "x-go-name": "UnitsMap", "example": { "repo.code": "read", "repo.ext_issues": "none", "repo.ext_wiki": "none", "repo.issues": "write", "repo.projects": "none", "repo.pulls": "owner", "repo.releases": "none", "repo.wiki": "admin" } } Value: null [201] Created: `{"id":5,"name":"archive_cleanup","description":"","organization":{"id":3,"name":"S","full_name":"","email":"","avatar_url":"http://0.0.0.0:43007/avatars/1f303fd10424e23d36ee4dbd6af13c4d735f75bfe318b1259474fa53863403ba","description":"","website":"","location":"","visibility":"public","repo_admin_change_team_access":false,"username":"S"},"includes_all_repositories":true,"permission":"read","units":null,"units_map":null,"can_create_org_repo":false,"visibility":"private"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"includes_all_repositories": true, "name": "archive_cleanup", "permission": "read"}' http://0.0.0.0:43007/api/v1/orgs/workbench/teams ___________ POST /packages/{owner}/{type}/{name}/-/link/{repo_name} ____________ 1. Test Case ID: eUsyQn - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/packages/0/0/0/-/link/demo 2. Test Case ID: ERrPXH - Undocumented HTTP status code Received: 403 Documented: 201, 404 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X POST -H 'Sudo: m' -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/packages/admin/lock/%C2%A4/-/link/demo 3. Test Case ID: LRJ4wV - Undocumented HTTP status code Received: 401 Documented: 201, 404 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/packages/admin/lock/%C2%A4/-/link/demo ________________ POST /packages/{owner}/{type}/{name}/-/unlink _________________ 1. Test Case ID: zQ5cmT - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/packages/0/0/0/-/unlink _____________________________ POST /repos/migrate ______________________________ 1. Test Case ID: RxfgSS - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[CloneAddr]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"auth_password": "[Filtered]", "auth_token": "[Filtered]", "auth_username": "[Filtered]", "aws_access_key_id": "[Filtered]", "aws_secret_access_key": "[Filtered]", "clone_addr": "", "description": "", "issues": false, "labels": false, "lfs": false, "lfs_endpoint": "", "milestones": false, "mirror": false, "mirror_interval": "", "private": false, "pull_requests": false, "releases": false, "repo_name": "", "repo_owner": "", "service": "git", "uid": 0, "wiki": false}' http://0.0.0.0:43007/api/v1/repos/migrate 2. Test Case ID: xwQ0pk - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"auth_password": "[Filtered]", "auth_token": "[Filtered]", "auth_username": "[Filtered]", "aws_access_key_id": "[Filtered]", "aws_secret_access_key": "[Filtered]", "clone_addr": "", "description": "", "issues": false, "labels": false, "lfs": false, "lfs_endpoint": "", "milestones": false, "mirror": false, "mirror_interval": "", "private": false, "pull_requests": false, "releases": false, "repo_name": "", "repo_owner": "", "service": "git", "uid": 0, "wiki": false}' http://0.0.0.0:43007/api/v1/repos/migrate ________ POST /repos/{owner}/{repo}/actions/runners/registration-token _________ 1. Test Case ID: oVV850 - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/0/0/actions/runners/registration-token 2. Test Case ID: ClFTaR - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/actions/runners/registration-token ____________ POST /repos/{owner}/{repo}/actions/runs/{run}/approve _____________ 1. Test Case ID: 4EuaOt - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/actions/runs/0/approve _____________ POST /repos/{owner}/{repo}/actions/runs/{run}/cancel _____________ 1. Test Case ID: UikEAQ - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/actions/runs/0/cancel __________ POST /repos/{owner}/{repo}/actions/runs/{run}/force-cancel __________ 1. Test Case ID: gYEmJd - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/actions/runs/0/force-cancel ______ POST /repos/{owner}/{repo}/actions/runs/{run}/jobs/{job_id}/rerun _______ 1. Test Case ID: qTUrn0 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/actions/runs/0/jobs/0/rerun _____________ POST /repos/{owner}/{repo}/actions/runs/{run}/rerun ______________ 1. Test Case ID: Ys23mr - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/actions/runs/0/rerun 2. Test Case ID: fMWhQV - Undocumented HTTP status code Received: 401 Documented: 201, 400, 403, 404, 409, 422 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/runs/118331/rerun _______ POST /repos/{owner}/{repo}/actions/runs/{run}/rerun-failed-jobs ________ 1. Test Case ID: jTniUP - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/actions/runs/0/rerun-failed-jobs _________ POST /repos/{owner}/{repo}/actions/variables/{variablename} __________ 1. Test Case ID: ttIbzD - Undocumented HTTP status code Received: 404 Documented: 201, 400, 409, 500 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "value": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/actions/variables/0 2. Test Case ID: cvdfN4 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"description": "", "value": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/actions/variables/0 3. Test Case ID: BT7lmo - Undocumented HTTP status code Received: 422 Documented: 201, 400, 409, 500 [422] Unprocessable Content: `{"message":"[]: jsontext: invalid character '\\x00' at start of value","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables/0 4. Test Case ID: abTdvh - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Value]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables/0 5. Test Case ID: AVQA4P - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 3 additional properties not defined in the schema (`9Z+`, `£ Ðè´򢶁 `, `򇬄`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"message":"name must start with a letter or underscore and contain only letters, numbers, and underscores","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud9de\udf04": {}, "\u00a3\r\u00d0\u00e8\u00b4\uda4b\udd81\u001c": [], "9Z+": [{"!\u00bf\ud9f5\udea5h\u00e4;\u00fd\u008a7": "\udba9\udf71", ",\u00ec\t": null, "\u00ec\u001433,\u0014w\u00d6\u0084\udb33\udc22+\ud897\udfcb\u00fb\u00c5": null}, [-101931678407036239872]], "value": "q"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables/%F0%9D%90%93%F0%9D%90%A1%F0%9D%90%9E%20%F0%9D%90%AA%F0%9D%90%AE%F0%9D%90%A2%F0%9D%90%9C%F0%9D%90%A4%20%F0%9D%90%9B%F0%9D%90%AB%F0%9D%90%A8%F0%9D%90%B0%F0%9D%90%A7%20%F0%9D%90%9F%F0%9D%90%A8%F0%9D%90%B1%20%F0%9D%90%A3%F0%9D%90%AE%F0%9D%90%A6%F0%9D%90%A9%F0%9D%90%AC%20%F0%9D%90%A8%F0%9D%90%AF%F0%9D%90%9E%F0%9D%90%AB%20%F0%9D%90%AD%F0%9D%90%A1%F0%9D%90%9E%20%F0%9D%90%A5%F0%9D%90%9A%F0%9D%90%B3%F0%9D%90%B2%20%F0%9D%90%9D%F0%9D%90%A8%F0%9D%90%A0 6. Test Case ID: 0FSdtp - Missing Content-Type header The following media types are documented in the schema: - `application/json` [201] Created: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\udb7f\udea0Q\t\u00d1\u00db. ": {"$": [], "|\udb9d\udca6\u000e": -2.9891084130090904e+16, "1e100": "M\u001d"}, "\u0017": {"\u00ab\ud8d8\udf38\u00c3*\u00bf\uda7d\udd18i": 2.2907520557693417e+78}, "\u0001\ud972\udf76\u009b\u0007\udbb9\udf3d\u00a4": ["#\ufb2c", -2.9835061950713565e-108, "\udb8d\udd9bTo\u00f7\u008f\udb18\udf11"], "[": {}, "\u00c6": [{"\u00df": true, "\u00fe\u0099\u00c6\u00d7e\u00a7": "v\u00a6\ud85a\uddb7", "": null}], "description": "1\u00a7", "value": "\udb09\udcbd\uda03\udcf8\u0081\u00ffTp\udb2a\udd2d\u0011\u00f9"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables/u ____ POST /repos/{owner}/{repo}/actions/workflows/{workflow_id}/dispatches _____ 1. Test Case ID: XLcuXG - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"inputs": {}, "ref": "refs/heads/main"}' 'http://0.0.0.0:43007/api/v1/repos/0/0/actions/workflows/0/dispatches?return_run_details=true&scoped_workflow_source_repo_id=-9223372036854775808' 2. Test Case ID: rYwivI - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Ref]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"ref": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/workflows/0/dispatches ______________________ POST /repos/{owner}/{repo}/avatar _______________________ 1. Test Case ID: kxUe74 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"image": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/avatar 2. Test Case ID: uqeBHC - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 204, 404 [422] Unprocessable Content: `{"message":"[Image]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/avatar 3. Test Case ID: 43MVL5 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204, 404 [400] Bad Request: `{"message":"illegal base64 data at input byte 0","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"image": "\u00db\u00c1\u00a7\u00a3\u008e}\u00f3\udbfd\udcd0\u00fd"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/avatar ________________ POST /repos/{owner}/{repo}/branch_protections _________________ 1. Test Case ID: 923r5Z - Response violates schema null is not of type "array" Validated against the response schema for status code 201. Schema at /properties/status_check_contexts: { "type": "array", "items": { "type": "string" }, "x-go-name": "StatusCheckContexts" } Value: null [201] Created: `{"branch_name":"¤","rule_name":"¤","priority":1,"enable_push":false,"enable_push_whitelist":false,"push_whitelist_usernames":[],"push_whitelist_teams":[],"push_whitelist_deploy_keys":false,"enable_force_push":false,"enable_force_push_allowlist":false,"force_push_allowlist_usernames":[],"force_push_allowlist_teams":[],"force_push_allowlist_deploy_keys":false,"enable_merge_whitelist":false,"merge_whitelist_usernames":[],"merge_whitelist_teams":[],"enable_bypass_allowlist":false,"bypass_allowlist_usernames":[] // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"branch_name": "\u00a4"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/branch_protections 2. Test Case ID: iP7dES - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 2 additional properties not defined in the schema (``, `­u󾄂`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. - Undocumented HTTP status code Received: 400 Documented: 201, 403, 404, 422, 423 [400] Bad Request: `{"message":"both rule_name and branch_name are empty","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00ad\u0003u\udbb8\udd02": {}, "": {}, "ignore_stale_approvals": true, "block_on_official_review_requests": false}' http://0.0.0.0:43007/api/v1/repos/admin/demo/branch_protections 3. Test Case ID: KK84FL - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/branch_protections ____________ POST /repos/{owner}/{repo}/branch_protections/priority ____________ 1. Test Case ID: e3uQzY - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"ids": []}' http://0.0.0.0:43007/api/v1/repos/0/0/branch_protections/priority 2. Test Case ID: M87AGB - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/branch_protections/priority 3. Test Case ID: RdEVyG - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/branch_protections/priority _____________________ POST /repos/{owner}/{repo}/branches ______________________ 1. Test Case ID: goIgNr - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"new_branch_name": "", "old_branch_name": "", "old_ref_name": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/branches 2. Test Case ID: uZgCxb - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 403, 404, 409, 423 [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/branches 3. Test Case ID: OiWNk4 - Response violates schema (4 violations) null is not of type "array" Validated against the response schema for status code 201. Schema at /definitions/PayloadCommit/properties/added: { "type": "array", "description": "List of files added in this commit", "items": { "type": "string" }, "x-go-name": "Added" } Value: null null is not of type "array" Validated against the response schema for status code 201. Schema at /definitions/PayloadCommit/properties/modified: { "type": "array", "description": "List of files modified in this commit", "items": { "type": "string" }, "x-go-name": "Modified" } Value: null null is not of type "array" Validated against the response schema for status code 201. Schema at /definitions/PayloadCommit/properties/removed: { "type": "array", "description": "List of files removed in this commit", "items": { "type": "string" }, "x-go-name": "Removed" } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/PayloadUser: { "type": "object", "description": "PayloadUser represents the author or committer of a commit", "properties": { "email": { "type": "string", "format": "email", "x-go-name": "Email" }, "name": { "description": "Full name of the commit author", "type": "string", "x-go-name": "Name" }, "username": { "description": "username of the user", "type": "string", "x-go-name": "UserName" } // Output truncated... } Value: null [201] Created: `{"name":"a§𕕮񍀦","commit":{"id":"83e0599c2e9d180479e163ad6e7fb7eb32b851a2","message":"Initial commit\n","url":"http://localhost:3000/admin/demo/commit/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","author":{"name":"admin","email":"admin@example.com","username":"admin"},"committer":{"name":"admin","email":"admin@example.com","username":"admin"},"verification":{"verified":false,"reason":"gpg.error.not_signed_commit","signature":"","signer":null,"payload":""},"timestamp":"2026-10-10T09:54:25Z","added":null,"removed" // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00a2F\u00ddE\ud915\udde1\ua0d3\udb4a\udde1\u009c\u0093]\u009b\u009a\u00cf=\udbd4\udf01\u00f9\ud98c\udf34\udbd3\udc42m\u001d\ud9d7\udd13\u00ab\udbc0\uddd7\ud8c6\udebb\uda49\udda5\u009e\u00a5\u0097\udb82\udee0J\udbf0\ude18": [["c", true, null]], "\u00d6f\u0088}\ud896\udd7bD\ud939\udeaf\u00ec": [true, null], "\u0014\u001a\u0087\u0090\u00ad\u00b7\ud997\udcd7_w", "operation": "create"}]}' http://0.0.0.0:43007/api/v1/repos/admin/demo/contents 4. Test Case ID: Z0REFv - Response violates schema (2 violations) null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/ContentsResponse/properties/submodule_git_url: { "type": "string", "description": "`submodule_git_url` is populated when `type` is `submodul... "x-go-name": "SubmoduleGitURL" } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/ContentsResponse/properties/target: { "type": "string", "description": "`target` is populated when `type` is `symlink`, otherwise... "x-go-name": "Target" } Value: null [201] Created: `{"files":[{"name":"}®S򒪨","path":"}®S򒪨","sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","last_commit_sha":"b603fee3f38a9646bbe91fd622eca778d2614980","last_committer_date":"2026-10-10T09:59:21Z","last_author_date":"2026-10-10T09:59:21Z","type":"file","mode":"100644","size":0,"encoding":"base64","content":"","target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/%7D%C2%AES%F2%92%AA%A8?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/%7D%C2%AES%F2%92%AA%A8","git_url":" // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": true, "files": [{"\ud8b8\ude74": {}, "\udb1a\uddb5\u00f9": 6.478437553581995e+16, "": [null, "\u00b9\u00bd", null], "path": "}\u00aeS\uda0a\udea8", "from_path": "%\ud911\udc99a\ud898\udc57Y", "operation": "create"}], "message": "Initial commit\n", "new_branch": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/contents ________________ POST /repos/{owner}/{repo}/contents/{filepath} ________________ 1. Test Case ID: DcZmrr - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"author": "[Filtered]", "branch": "", "committer": {"email": "0@0.com", "name": ""}, "content": "", "dates": {"author": "[Filtered]", "committer": "2000-01-01T00:00:00Z"}, "force_push": false, "message": "", "new_branch": "", "signoff": false}' http://0.0.0.0:43007/api/v1/repos/0/0/contents/0 2. Test Case ID: HxF16f - Response violates schema (3 violations) null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/PayloadUser: { "type": "object", "description": "PayloadUser represents the author or committer of a commit", "properties": { "email": { "type": "string", "format": "email", "x-go-name": "Email" }, "name": { "description": "Full name of the commit author", "type": "string", "x-go-name": "Name" }, "username": { "description": "username of the user", "type": "string", "x-go-name": "UserName" } // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/ContentsResponse/properties/submodule_git_url: { "type": "string", "description": "`submodule_git_url` is populated when `type` is `submodul... "x-go-name": "SubmoduleGitURL" } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/ContentsResponse/properties/target: { "type": "string", "description": "`target` is populated when `type` is `symlink`, otherwise... "x-go-name": "Target" } Value: null [201] Created: `{"content":{"name":"0","path":"0","sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","last_commit_sha":"aa7cbf35920bb549090447015c53b2426900df88","last_committer_date":"2026-10-10T09:59:22Z","last_author_date":"2026-10-10T09:59:22Z","type":"file","mode":"100644","size":0,"encoding":"base64","content":"","target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/0?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/0","git_url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/gi // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"content": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/contents/0 3. Test Case ID: Svh4GJ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"repository file already exists [path: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"content": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/contents/0 _____________________ POST /repos/{owner}/{repo}/diffpatch _____________________ 1. Test Case ID: keNmNS - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"author": "[Filtered]", "branch": "", "committer": {"email": "0@0.com", "name": ""}, "content": "", "dates": {"author": "[Filtered]", "committer": "2000-01-01T00:00:00Z"}, "force_push": false, "message": "", "new_branch": "", "signoff": false}' http://0.0.0.0:43007/api/v1/repos/0/0/diffpatch 2. Test Case ID: DOYkhg - Undocumented HTTP status code Received: 422 Documented: 200, 404, 423 [422] Unprocessable Content: `{"message":"[]: jsontext: invalid character '\\x00' at start of value","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:43007/api/v1/repos/admin/demo/diffpatch 3. Test Case ID: cadNb9 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 404, 423 [500] Internal Server Error: `{"message":"git apply error: exit status 128 - error: No valid patches in input (allow with \"--allow-empty\")","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"content": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/diffpatch 4. Test Case ID: hyTuFW - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[BranchName]: GitRefName","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u5087\ud97c\udf1a\u0084\u00d9\udbd8\ude94\u00b9": [{}, false], "\u00a9\ud96c\udcda": {"j": {}, "\udb52\udd93\u00ce\u00da\udaf8\ude51\udbd4\udfcf\u00e8\u008c\u00b9\\\udbff\udce0g\ud994\udff2o\udbaa\udf20M\u009d\u00cc\udb1e\udc00": {"\udb85\udcbc\u00b0\ud8aa\udebc\udbbd\udffec": true, "\u00c8\udb75\ude6f": 77004, "j": false}, "\u00a9\u0090X\u0098\ud8c4\ude9b\ud990\udeaa\u00f7\u0085\u009d\u0018": false}, "message": "\u00d4\ud842\ude06\ud84c\udff0", "new_branch": "E\u00db\udbde\udf90", "committer": {"": 0.95, "email": "workbench@example.com"}, "signoff": true, "author": "[Filtered]", "branch": "\u0003\u00d3", "content": "\u00d1\u0005)\u00f9", "dates": {"u\udbee\udd0ff\u00ce\uda6a\udd51\u00bc\u00e3\udaab\udea9": ["", -1.8714516553956126e+269, null]}, "force_push": true}' http://0.0.0.0:43007/api/v1/repos/admin/demo/diffpatch ___________________ POST /repos/{owner}/{repo}/file-contents ___________________ 1. Test Case ID: uobarQ - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"files": []}' 'http://0.0.0.0:43007/api/v1/repos/0/0/file-contents?ref=' 2. Test Case ID: tPXHKm - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 200, 404 [422] Unprocessable Content: `{"message":"[Files]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/file-contents 3. Test Case ID: nvkZOu - Response violates schema (5 violations) null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/content: { "type": "string", "description": "`content` is populated when `type` is `file`, otherwise n... "x-go-name": "Content" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/download_url: { "type": "string", "description": "DownloadURL is the direct download URL for this file", "x-go-name": "DownloadURL" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/encoding: { "type": "string", "description": "`encoding` is populated when `type` is `file`, otherwise ... "x-go-name": "Encoding" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/submodule_git_url: { "type": "string", "description": "`submodule_git_url` is populated when `type` is `submodul... "x-go-name": "SubmoduleGitURL" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse/properties/target: { "type": "string", "description": "`target` is populated when `type` is `symlink`, otherwise... "x-go-name": "Target" } Value: null [200] OK: `[{"name":"","path":"","sha":"a129b1479c8a60937cb586d39ce71d3c7341b35b","last_commit_sha":"81fd78e7708f93ca17ba2ebde334ba4566b26bca","last_committer_date":"2026-10-10T09:59:25Z","last_author_date":"2026-10-10T09:59:25Z","type":"dir","mode":"40000","size":0,"encoding":null,"content":null,"target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/","git_url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/git/blobs/a129b1479c // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"files": [""]}' http://0.0.0.0:43007/api/v1/repos/admin/demo/file-contents 4. Test Case ID: AQl8pW - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `POST /repos/{owner}/{repo}/file-contents` [200] OK: `[{"name":"","path":"","sha":"a129b1479c8a60937cb586d39ce71d3c7341b35b","last_commit_sha":"81fd78e7708f93ca17ba2ebde334ba4566b26bca","last_committer_date":"2026-10-10T09:59:25Z","last_author_date":"2026-10-10T09:59:25Z","type":"dir","mode":"40000","size":0,"encoding":null,"content":null,"target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/","git_url":"http://0.0.0.0:43007/api/v1/repos/admin/demo/git/blobs/a129b1479c // Output truncated...` Reproduce with: curl -X POST -H 'Content-Type: application/json' -d '{"files": [""]}' http://0.0.0.0:43007/api/v1/repos/admin/demo/file-contents 5. Test Case ID: L5YAVH - Response violates schema null is not of type "object" Validated against the response schema for status code 200. Schema at /definitions/ContentsResponse: { "type": "object", "description": "ContentsResponse contains information about a repo's entr... "properties": { "_links": { "$ref": "#/components/schemas/FileLinksResponse" }, "content": { "description": "`content` is populated when `type` is `file`, oth... "type": "string", "x-go-name": "Content" }, "download_url": { "description": "DownloadURL is the direct download URL for this f... "type": "string", "x-go-name": "DownloadURL" }, "encoding": { "description": "`encoding` is populated when `type` is `file`, ot... // Output truncated... } Value: null [200] OK: `[null,null]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"files": ["red", "\u00d4\u001bf}\u00d7\udaef\udcc5\u00dd\u0016\"S"]}' http://0.0.0.0:43007/api/v1/repos/admin/demo/file-contents _______________________ POST /repos/{owner}/{repo}/forks _______________________ 1. Test Case ID: 4XLCHi - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"name": "", "organization": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/forks 2. Test Case ID: 3SQlHE - Server error - Undocumented HTTP status code Received: 500 Documented: 202, 403, 404, 409, 422 [500] Internal Server Error: `{"message":"name is invalid []: must be valid alpha or numeric or dash(-_) or dot characters","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/forks 3. Test Case ID: 5epycR - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/forks _______________________ POST /repos/{owner}/{repo}/hooks _______________________ 1. Test Case ID: IZ6mn4 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"active": false, "authorization_header": "[Filtered]", "branch_filter": "", "config": {}, "events": [], "name": "", "type": "dingtalk"}' http://0.0.0.0:43007/api/v1/repos/0/0/hooks 2. Test Case ID: UvDoNv - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 404 [422] Unprocessable Content: `{"message":"Missing config option: url","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"config": {}, "type": "gogs"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/hooks _________________ POST /repos/{owner}/{repo}/hooks/{id}/tests __________________ 1. Test Case ID: QAF9LW - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' 'http://0.0.0.0:43007/api/v1/repos/0/0/hooks/-9223372036854775808/tests?ref=' ______________________ POST /repos/{owner}/{repo}/issues _______________________ 1. Test Case ID: 1CsMMu - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"assignee": "", "assignees": [], "body": "", "closed": false, "due_date": "2000-01-01T00:00:00Z", "labels": [], "milestone": 0, "projects": [], "ref": "", "title": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/issues 2. Test Case ID: Vl1nq6 - Response violates schema (7 violations) null is not of type "array" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/assignees: { "type": "array", "items": { "$ref": "#/components/schemas/User" }, "x-go-name": "Assignees" } Value: null null is not of type "array" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/projects: { "type": "array", "items": { "$ref": "#/components/schemas/Project" }, "x-go-name": "Projects" } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/Milestone: { "type": "object", "description": "Milestone milestone is a collection of issues on one repo... "properties": { "closed_at": { "type": "string", "format": "date-time", "x-go-name": "Closed" }, "closed_issues": { "description": "ClosedIssues is the number of closed issues in th... "type": "integer", "format": "int64", "x-go-name": "ClosedIssues" }, "created_at": { "type": "string", "format": "date-time", "x-go-name": "Created" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/PullRequestMeta: { "type": "object", "description": "PullRequestMeta PR info if an issue is a PR", "properties": { "draft": { "type": "boolean", "x-go-name": "IsWorkInProgress" }, "html_url": { "type": "string", "x-go-name": "HTMLURL" }, "merged": { "type": "boolean", "x-go-name": "HasMerged" }, "merged_at": { "type": "string", "format": "date-time", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/due_date: { "type": "string", "format": "date-time", "x-go-name": "Deadline" } Value: null [201] Created: `{"id":2,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/2","html_url":"http://0.0.0.0:43007/admin/demo/issues/2","number":2,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricte // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"title": "h\u00a2T\udae3\ude8d\ud992\udd2a\u00af%W\u00da\u0083\ud843\udc66\u00af\u00c5"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues 3. Test Case ID: k4iRIk - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 2 additional properties not defined in the schema (`C¨ ó򷓭`, `𛬉^򰬞Âö©򙖒`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [422] Unprocessable Content: `{"message":"Assignee does not exist: [name: user does not exist [uid: 0, name: ÌQ򮟓ù􆞫r񬅮\u0004]sö񠖊]]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"C\u00a8\t\u00f3\uda9d\udced": {}, "\ud82e\udf09^\uda82\udf1e\u00c2\u00f6\u00a9\uda25\udd92": null, "assignees": ["\u00ccQ\uda79\udfd3\u00f9\u008f\udbd9\udfab\uf2cer\ud970\udd6e\u0004]s\u00f6\ud941\udd8a", "\"\u00c6M\u0080\u00e9\u00b5\u00d7\\\u0087\u00af\u009f\u00b5", "_\u0013"], "title": "\u00dc(JoJ\u00a1\udb74\udd01\u0004\u0007f\u00f5WS\u00c6\u00f7\ud9ab\udd88"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues ____________ POST /repos/{owner}/{repo}/issues/comments/{id}/assets ____________ 1. Test Case ID: qY8FUK - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' 'http://0.0.0.0:43007/api/v1/repos/0/0/issues/comments/-9223372036854775808/assets?name=' 2. Test Case ID: rJzpfO - Server error - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json - Undocumented HTTP status code Received: 500 Documented: 201, 400, 403, 404, 413, 422, 423 [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data; boundary=7f4d8b3e82af2014aff8c6203db9dfeb' -d $'--7f4d8b3e82af2014aff8c6203db9dfeb\r\n\xf1\x97\xb0\x86LâÀ--7f4d8b3e82af2014aff8c6203db9dfeb--\r\n' 'http://0.0.0.0:43007/api/v1/repos/%C3%B5J/%C2%A7%F3%B1%81%A4%C3%80%F1%9A%AF%9D/issues/comments/null/assets?name=cleanup_hook_task_table' __________ POST /repos/{owner}/{repo}/issues/comments/{id}/reactions ___________ 1. Test Case ID: RFEN6d - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"content": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/issues/comments/-9223372036854775808/reactions 2. Test Case ID: uTySYg - Undocumented HTTP status code Received: 422 Documented: 200, 201, 403, 404 [422] Unprocessable Content: `{"message":"[]: jsontext: invalid character '\\x10' at start of value","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x10>e2(`1�' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/comments/1/reactions 3. Test Case ID: kwEJfq - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/comments/5/reactions _______________ POST /repos/{owner}/{repo}/issues/{index}/assets _______________ 1. Test Case ID: gqTSNb - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' 'http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/assets?name=' 2. Test Case ID: YElkPH - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"This file cannot be uploaded or modified due to a forbidden file extension or type.","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data; boundary=1d7f1a0bfa1c159ce1e236dc4ddc7d3f' -d $'--1d7f1a0bfa1c159ce1e236dc4ddc7d3f\r\nContent-Disposition: form-data; name="attachment"; filename="attachment"\r\n\r\n�6j\r\n--1d7f1a0bfa1c159ce1e236dc4ddc7d3f--\r\n' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/assets 3. Test Case ID: kC2Tlf - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 404, 413, 422, 423 [500] Internal Server Error: `{"message":"http: no such file","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data; boundary=c637e12e2b1a998d80d1b087531af51c' -d $'--c637e12e2b1a998d80d1b087531af51c--\r\n' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/assets?name=repo_health_check' _____________ POST /repos/{owner}/{repo}/issues/{index}/assignees ______________ 1. Test Case ID: PxBzcS - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"assignees": []}' http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/assignees 2. Test Case ID: hWzT6O - Response violates schema (7 violations) null is not of type "array" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/assignees: { "type": "array", "items": { "$ref": "#/components/schemas/User" }, "x-go-name": "Assignees" } Value: null null is not of type "array" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/projects: { "type": "array", "items": { "$ref": "#/components/schemas/Project" }, "x-go-name": "Projects" } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/Milestone: { "type": "object", "description": "Milestone milestone is a collection of issues on one repo... "properties": { "closed_at": { "type": "string", "format": "date-time", "x-go-name": "Closed" }, "closed_issues": { "description": "ClosedIssues is the number of closed issues in th... "type": "integer", "format": "int64", "x-go-name": "ClosedIssues" }, "created_at": { "type": "string", "format": "date-time", "x-go-name": "Created" // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/PullRequestMeta: { "type": "object", "description": "PullRequestMeta PR info if an issue is a PR", "properties": { "draft": { "type": "boolean", "x-go-name": "IsWorkInProgress" }, "html_url": { "type": "string", "x-go-name": "HTMLURL" }, "merged": { "type": "boolean", "x-go-name": "HasMerged" }, "merged_at": { "type": "string", "format": "date-time", // Output truncated... } Value: null null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/User: { "type": "object", "description": "User represents a user", "properties": { "active": { "description": "Is user active", "type": "boolean", "x-go-name": "IsActive" }, "avatar_url": { "description": "URL to the user's avatar", "type": "string", "x-go-name": "AvatarURL" }, "created": { "type": "string", "format": "date-time", "x-go-name": "Created" }, // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/Issue/properties/due_date: { "type": "string", "format": "date-time", "x-go-name": "Deadline" } Value: null [201] Created: `{"id":1,"url":"http://localhost:3000/api/v1/repos/admin/demo/issues/1","html_url":"http://0.0.0.0:43007/admin/demo/issues/1","number":1,"user":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":true,"last_login":"1970-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricte // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/assignees 3. Test Case ID: X3q7n7 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 3 additional properties not defined in the schema (``, ` 󑐩􏬩Ÿ`, `ã† '-𰉍ä5`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [422] Unprocessable Content: `{"message":"user does not exist [uid: 0, name: —)\u000eF]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u000b\udb05\udc29\udbfe\udf29\u009f": [{"i\u0082$\u008e)": ""}, [true]], "\u0081\u00e3\u0086\u001d'"'"'-\ud880\ude4d\u00e45": [], "": {"\u00cf": {"": null, "\udbec\udeb7": true}, "": {"&\u00ff5G\u0086\udaeb\udc85)": "\u001fp\u000ez\ud9df\ude3fB"}, "\u00c1\u00f7{s\u0092": {"4\u00db\ud969\udc4b\ud82b\udf26": -2.9800481253795016e+16, "3\uda6c\ude86\"L\u00e2|": "\ud9d8\ude00\ud85a\uddeb\u00f9"}}, "assignees": ["\u0097)\u000eF", ""]}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/assignees _______________ POST /repos/{owner}/{repo}/issues/{index}/blocks _______________ 1. Test Case ID: VrmzvK - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"index": 0, "owner": "", "repo": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/issues/0/blocks 2. Test Case ID: 4UEDNx - Undocumented HTTP status code Received: 422 Documented: 201, 404 [422] Unprocessable Content: `{"message":"[]: json: cannot unmarshal JSON object into Go string within \"/owner\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00a7\u00a8\u000b\uda6f\ude1a5\u008d": {"\u0012\u001a\ud983\udf67 \u00e3A\uef55": []}, "": ["\ud809\udd2aX\u001a\u00eb\u0014"], "Y!\u001cyT\u0001\ud98d\udc0d\u001e\u00b1K\u0002\u0091\u00fe": [5.736630988425057e-283], "\u00eb\u00a7\uda82\udcea\u009a\udb25\udc8c\u001e": [{"O=\ud960\uddc6o\u0000+\uda7c\udf1a\ud855\udd62\u00f3": null, "i\u009e\ud887\udf8e\u00ff": null}, [null, 5388295]], "[]\u00cc\uda05\udf6fH\u00d8": {}, "owner": {}}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/%3C%C2%B7%C3%9A%C2%86%E9%86%B3%C3%B1%C2%AD%F1%84%AC%80%C2%B5/blocks 3. Test Case ID: ASX777 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/%C3%89%C2%9DX%F2%94%95%A5%F0%A0%8E%ABoT%C2%BB/blocks ______________ POST /repos/{owner}/{repo}/issues/{index}/comments ______________ 1. Test Case ID: H3q57b - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"body": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/comments 2. Test Case ID: Ppupa9 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 2 additional properties not defined in the schema (`0񙞋 V–m6qx§Ädˆ􎅓򖝠􍢆`, `กา`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. - Undocumented HTTP status code Received: 422 Documented: 201, 403, 404, 423 [422] Unprocessable Content: `{"message":"[Body]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"0\ud925\udf8b\u00a0V\u0096\u0015m6qx\u00a7\u00c4d\u00c2\u0016\u0088\udbf8\udd53\uda19\udf60\udbf6\udc86": "\u00c6tm\u00a2\u00d8", "\u0e01\u0e32": null, "body": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/comments 3. Test Case ID: ynlYP8 - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 403, 404, 423 [500] Internal Server Error: `{"message":"issue does not exist [id: 0, repo_id: 0, index: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"body": "Workbench"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/-61533759/comments ______________ POST /repos/{owner}/{repo}/issues/{index}/deadline ______________ 1. Test Case ID: 9NhIlS - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"due_date": "2000-01-01T00:00:00Z"}' http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/deadline 2. Test Case ID: kTga17 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 403, 404 [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/deadline ____________ POST /repos/{owner}/{repo}/issues/{index}/dependencies ____________ 1. Test Case ID: PWpSrp - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"index": 0, "owner": "", "repo": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/issues/0/dependencies 2. Test Case ID: bbsXPe - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 404, 423 [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/u%F3%AC%96%8C%F2%98%8A%A8%C2%90/dependencies _______________ POST /repos/{owner}/{repo}/issues/{index}/labels _______________ 1. Test Case ID: GuFEex - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"labels": []}' http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/labels 2. Test Case ID: 3zrR5v - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 200, 403, 404 [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/labels 3. Test Case ID: cl3uF5 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (``). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. - Undocumented HTTP status code Received: 400 Documented: 200, 403, 404 [400] Bad Request: `{"message":"a label must be an integer or a string","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": {}, "labels": [{}, 6752700582831932.0, {}, [null, -4703180360, null], {"\udaa8\udc1a \u00ec\u00d3ol\u00f5": null}, [], [-17173, -13620, "\u00b0\u00e3\u0088\u00e7\u00e8\u00fa"]]}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/labels ________________ POST /repos/{owner}/{repo}/issues/{index}/pin _________________ 1. Test Case ID: CEPcSJ - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/pin 2. Test Case ID: NzWyUP - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/pin 3. Test Case ID: WqR1hK - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 403, 404 [500] Internal Server Error: `{"message":"constraint failed: UNIQUE constraint failed: issue_pin.repo_id, issue_pin.issue_id (2067)","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/pin _____________ POST /repos/{owner}/{repo}/issues/{index}/reactions ______________ 1. Test Case ID: FY3o8o - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"content": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/reactions 2. Test Case ID: uVZ3lb - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 200, 201, 403, 404 [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/reactions __________ POST /repos/{owner}/{repo}/issues/{index}/stopwatch/start ___________ 1. Test Case ID: Og0BEH - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/stopwatch/start 2. Test Case ID: 5sFWsl - Missing Content-Type header The following media types are documented in the schema: - `application/json` [201] Created: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/stopwatch/start ___________ POST /repos/{owner}/{repo}/issues/{index}/stopwatch/stop ___________ 1. Test Case ID: cJZFav - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/stopwatch/stop 2. Test Case ID: jGc8xS - Missing Content-Type header The following media types are documented in the schema: - `application/json` [201] Created: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/stopwatch/stop _______________ POST /repos/{owner}/{repo}/issues/{index}/times ________________ 1. Test Case ID: sJvIGG - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"created": "2000-01-01T00:00:00Z", "time": 0, "user_name": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/issues/-9223372036854775808/times 2. Test Case ID: C4IoR0 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 200, 400, 403, 404 [422] Unprocessable Content: `{"message":"[Time]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"time": 0, "user_name": "A"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/times _______________________ POST /repos/{owner}/{repo}/keys ________________________ 1. Test Case ID: XZNndl - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"key": "[Filtered]", "read_only": false, "title": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/keys 2. Test Case ID: c5Hzdo - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/keys ____________________ POST /repos/{owner}/{repo}/keys/tokens ____________________ 1. Test Case ID: CR1tdi - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"read_only": false, "title": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/keys/tokens 2. Test Case ID: 8GuTsI - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/keys/tokens ______________________ POST /repos/{owner}/{repo}/labels _______________________ 1. Test Case ID: ct34sF - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Name]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#00aabb", "exclusive": false, "is_archived": false, "description": "", "name": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/labels 2. Test Case ID: F7Is4b - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"color": "#00aabb", "description": "", "exclusive": false, "is_archived": false, "name": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/labels __________________ POST /repos/{owner}/{repo}/merge-upstream ___________________ 1. Test Case ID: IOY2V2 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"branch": "", "ff_only": false}' http://0.0.0.0:43007/api/v1/repos/0/0/merge-upstream 2. Test Case ID: GEhqi2 - Server error - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json - Undocumented HTTP status code Received: 500 Documented: 200, 400, 404, 409 [500] Internal Server Error: `PANIC: runtime error: invalid memory address or nil pointer dereference /usr/local/go/src/runtime/panic.go:859 (0x492004) /go/src/gitea.dev/modules/web/routing/logger_manager.go:87 (0x157033b) /usr/local/go/src/runtime/panic.go:859 (0x492004) /usr/local/go/src/runtime/panic.go:336 (0x494eb4) /usr/local/go/src/runtime/signal_unix.go:931 (0x494e85) /go/src/gitea.dev/models/repo/repo.go:369 (0x18e22ea) /go/src/gitea.dev/models/perm/access/repo_permission.go:434 (0x1aac80b) /go/src/gitea.dev/models/perm/access/ // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/merge-upstream 3. Test Case ID: 8s9KWU - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 200, 400, 404, 409 [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/merge-upstream ____________________ POST /repos/{owner}/{repo}/milestones _____________________ 1. Test Case ID: ifZAPq - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"description": "", "due_on": "2000-01-01T00:00:00Z", "state": "open", "title": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/milestones 2. Test Case ID: zwERTU - Response violates schema (2 violations) null is not of type "string" Validated against the response schema for status code 201. Schema at /properties/closed_at: { "type": "string", "format": "date-time", "x-go-name": "Closed" } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /properties/due_on: { "type": "string", "format": "date-time", "x-go-name": "Deadline" } Value: null [201] Created: `{"id":2,"title":"","description":"","state":"open","open_issues":0,"closed_issues":0,"created_at":"2026-10-10T10:00:10Z","updated_at":"2026-10-10T10:00:10Z","closed_at":null,"due_on":null}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/milestones 3. Test Case ID: AFwK1A - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 404 [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/milestones ____________________ POST /repos/{owner}/{repo}/mirror-sync ____________________ 1. Test Case ID: YilxZ1 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/mirror-sync 2. Test Case ID: NRtD5B - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 403, 404 [400] Bad Request: `{"message":"Repository is not a mirror","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/mirror-sync _____________________ POST /repos/{owner}/{repo}/projects ______________________ 1. Test Case ID: Yr7GFC - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"card_type": "", "description": "", "template_type": "", "title": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/projects 2. Test Case ID: M9kmgm - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (``, `󿾜±`, `¤` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [422] Unprocessable Content: `{"message":"invalid template_type \"\\U0009331fÝí\\u009e\\U000b3bd6Ç\" (expected none, basic_kanban, bug_triage)","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00a4\u00ca\u00c4": {"\u00b3\u009d\ud973\udea4`": false, "*BR\u00be\u0011}|\ud9a4\udf0eGE \u00a3*5": 640, "\ud990\udf56": -2978}, "\u001f\udbbf\udf9c\u00b1": {"\u008a\u00f1\udb57\ude5a\u009c": {"pZH\u00ba\u00f4": false}}, "\u00a4": [{}, {}], "\ud977\udc80\u00e9": [], "": 30.0, "description": "8\udb71\uddda\u000f,\u00db", "title": "h\u00a2T\udae3\ude8d\ud992\udd2a\u00af%W\u00da\u0083\ud843\udc66\u00af\u00c5", "card_type": "\u00c0\ud83d\udcce\u001d\udb54\udc34\u00bc\u00e0", "template_type": "\uda0c\udf1f\u00dd\u00ed\u009e\uda8e\udfd6\u00c7"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/projects _______________ POST /repos/{owner}/{repo}/projects/{id}/columns _______________ 1. Test Case ID: CYTlKY - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"color": "", "title": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/projects/-9223372036854775808/columns 2. Test Case ID: N7EcKj - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (`1e100`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [422] Unprocessable Content: `{"message":"[Title]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"1e100": [], "title": "", "color": "2h\u00cf\u00c8"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/projects/1/columns ____________ POST /repos/{owner}/{repo}/projects/{id}/columns/move _____________ 1. Test Case ID: fyZ6J3 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"column_ids": []}' http://0.0.0.0:43007/api/v1/repos/0/0/projects/-9223372036854775808/columns/move 2. Test Case ID: jMn8R5 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"column_ids must list every column of the project exactly once","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"column_ids": [-1590327312979, -438820005115, 232303819342, 1575, 1688932412, 79, -205090034, -1201714, -4295, 2538, -311, 1923, -1030763675703922560, -2295, -1945, -329404447640]}' http://0.0.0.0:43007/api/v1/repos/admin/demo/projects/123/columns/move 3. Test Case ID: 0TUJ1e - Undocumented HTTP status code Received: 401 Documented: 204, 403, 404, 422, 423 [401] Unauthorized: `{"message":"token is required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: q,"OJE Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/push_mirrors-sync _____________________ POST /repos/{owner}/{repo}/releases ______________________ 1. Test Case ID: 2cVuNl - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"body": "", "draft": false, "name": "", "prerelease": false, "tag_message": "", "tag_name": "", "target_commitish": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/releases 2. Test Case ID: Gc3Fiq - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[TagName]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"tag_name": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/releases 3. Test Case ID: 9NrvQx - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 404, 409, 422 [500] Internal Server Error: `{"message":"release tag name is not valid [tag_name: ¾R񛱹w񡕬‡\u0017ë„hEQÕß]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"#\u0012HJ2\u0082>\u00b4\u00d6\u00d1\u001e\u0084t\u0015\u00f8w\uda31\ude15\u0082": {"\u0089\ud972\udc10%": []}, "tag_name": "\u00beR\ud92f\udc79w\ud945\udd6c\u0087\u0017\u00eb\u0084hEQ\u00d5\u00df"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/releases 4. Test Case ID: a5RZF1 - Response violates schema null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/Release/properties/published_at: { "type": "string", "format": "date-time", "x-go-name": "PublishedAt" } Value: null [201] Created: `{"id":4,"tag_name":"ö򞭸񱱱¶𵰀øa񉎽:","target_commitish":"main","name":"","body":"","url":"http://localhost:3000/api/v1/repos/admin/demo/releases/4","html_url":"http://localhost:3000/admin/demo/releases/tag/%C3%B6%F2%9E%AD%B8%F1%B1%B1%B1%C2%B6%F0%B5%B0%80%C3%B8a%F1%89%8E%BD:","tarball_url":"http://localhost:3000/admin/demo/archive/%C3%B6%F2%9E%AD%B8%F1%B1%B1%B1%C2%B6%F0%B5%B0%80%C3%B8a%F1%89%8E%BD:.tar.gz","zipball_url":"http://localhost:3000/admin/demo/archive/%C3%B6%F2%9E%AD%B8%F1%B1%B1%B1%C2%B6%F0%B5%B0%80%C3%B // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"Y": 3.3149870105088916e+16, "\udbe5\udeef\u00a1\u00ef": {"": 1215781, "\u008d": -36893488147419103233}, "tag_message": "N", "tag_name": "\u00f6\uda3a\udf78\ud987\udc71\u00b6\ud897\udc00\u00f8a\ud8e4\udfbd:", "draft": true}' http://0.0.0.0:43007/api/v1/repos/admin/demo/releases _______________ POST /repos/{owner}/{repo}/releases/{id}/assets ________________ 1. Test Case ID: m5JaS6 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' 'http://0.0.0.0:43007/api/v1/repos/0/0/releases/-9223372036854775808/assets?name=' 2. Test Case ID: 6Ba6J1 - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 404, 413 [500] Internal Server Error: `{"message":"http: no such file","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data; boundary=c637e12e2b1a998d80d1b087531af51c' -d $'--c637e12e2b1a998d80d1b087531af51c--\r\n' http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/1/assets 3. Test Case ID: nlES6D - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data; boundary=a222103b9b30b1f9e8be6882ecedb1d2' -d $'--a222103b9b30b1f9e8be6882ecedb1d2\r\n[]--a222103b9b30b1f9e8be6882ecedb1d2--\r\n' http://0.0.0.0:43007/api/v1/repos/admin/demo/releases/1/assets __________________ POST /repos/{owner}/{repo}/statuses/{sha} ___________________ 1. Test Case ID: 3sM1AJ - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"context": "", "description": "", "state": "pending", "target_url": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/statuses/0 2. Test Case ID: lx5Sv1 - Response violates schema "" is not one of "pending", "success" or 4 other candidates Validated against the response schema for status code 201. Schema at /definitions/CommitStatus/properties/status: { "enum": [ "pending", "success", "error", "failure", "warning", "skipped" ], "description": "State represents the status state (pending, success, erro... "type": "string", "x-go-enum-desc": "pending CommitStatusPending is for when the CommitStat... "x-go-name": "State" } Value: "" [201] Created: `{"id":1,"status":"","target_url":"","description":"","url":"http://localhost:3000/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2","context":"","creator":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"","email":"1+admin@noreply.localhost","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00 // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/statuses/83e0599c2e9d180479e163ad6e7fb7eb32b851a2 3. Test Case ID: knPiEc - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 404 [500] Internal Server Error: `{"message":"GetCommit[ê\tÇ󥡏\u0016¡¶񓾭Þ\th… ]: object does not exist [id: ê\tÇ󥡏\u0016¡¶񓾭Þ\th… , rel_path: ]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"g\u0016\u00a8\udabf\udc8d\u00d2\u00ae4\u008a\u00e9\ud9bc\udc9a\udb42\udd99": [{}, {"\b1\u00e9\ud8d2\uded9\u00f8\ud9d3\ude36H%/6": 43386807083676319744}], "\uda83\ude19]Z\u008f`\ud9b9\uddd0\ud806\udc3d": false, "state": "failure", "description": "D\u00a9\u001a\u0016(", "context": "\u00c5x\t\udbc6\udc95", "target_url": "\u0096"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/statuses/%C3%AA%09%C3%87%F3%A5%A1%8F%16%C2%A1%C2%B6%F1%93%BE%AD%C3%9E%09h%C2%85 4. Test Case ID: 3baoJL - Undocumented HTTP status code Received: 422 Documented: 201, 400, 404 [422] Unprocessable Content: `{"message":"[]: json: cannot unmarshal JSON boolean into Go structs.CreateStatusOption","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d false http://0.0.0.0:43007/api/v1/repos/admin/demo/statuses/categories 5. Test Case ID: cKVZWY - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/statuses/f03ced9f5d13512a8268a8ff3f37a6c18131afbf __________________ POST /repos/{owner}/{repo}/tag_protections __________________ 1. Test Case ID: RXiAhd - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"name_pattern": "", "whitelist_teams": [], "whitelist_usernames": []}' http://0.0.0.0:43007/api/v1/repos/0/0/tag_protections 2. Test Case ID: xfHOaI - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 201, 403, 404, 422, 423 [400] Bad Request: `{"message":"name_pattern are empty","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/tag_protections 3. Test Case ID: ubebY1 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"user does not exist [uid: 0, name: ÔEÜÍ]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": {"\u00a6v\u7fc2": 3.0232064946250332e+16, "\uc420\u000f]\u00f2\u0091\uda7d\udc23\u0081\u0093\u00a3J\uda81\ude84H\u00c2": -88555881, "\u00c9\ud888\udfd0\u00ef\u0083\u0000\u00df\u001b\udaa9\ude7d\ud9e6\udc17N\u00ef?_\u00e7\udaa0\ude44\u00a72\udb62\udc70": false}, "name_pattern": "\u1e70\u033a\u033a\u0315o\u035e \u0337i\u0332\u032c\u0347\u032a\u0359n\u031d\u0317\u0355v\u031f\u031c\u0318\u0326\u035fo\u0336\u0319\u0330\u0320k\u00e8\u035a\u032e\u033a\u032a\u0339\u0331\u0324 \u0316t\u031d\u0355\u0333\u0323\u033b\u032a\u035eh\u033c\u0353\u0332\u0326\u0333\u0318\u0332e\u0347\u0323\u0330\u0326\u032c\u034e \u0322\u033c\u033b\u0331\u0318h\u035a\u034e\u0359\u031c\u0323\u0332\u0345i\u0326\u0332\u0323\u0330\u0324v\u033b\u034de\u033a\u032d\u0333\u032a\u0330-m\u0322i\u0345n\u0316\u033a\u031e\u0332\u032f\u0330d\u0335\u033c\u031f\u0359\u0329\u033c\u0318\u0333 \u031e\u0325\u0331\u0333\u032dr\u031b\u0317\u0318e\u0359p\u0360r\u033c\u031e\u033b\u032d\u0317e\u033a\u0320\u0323\u035fs\u0318\u0347\u0333\u034d\u031d\u0349e\u0349\u0325\u032f\u031e\u0332\u035a\u032c\u035c\u01f9\u032c\u034e\u034e\u031f\u0316\u0347\u0324t\u034d\u032c\u0324\u0353\u033c\u032d\u0358\u0345i\u032a\u0331n\u0360g\u0334\u0349 \u034f\u0349\u0345c\u032c\u031fh\u0361a\u032b\u033b\u032f\u0358o\u032b\u031f\u0316\u034d\u0319\u031d\u0349s\u0317\u0326\u0332.\u0328\u0339\u0348\u0323", "whitelist_usernames": ["\u00d4E\u00dc\u00cd"]}' http://0.0.0.0:43007/api/v1/repos/admin/demo/tag_protections _______________________ POST /repos/{owner}/{repo}/tags ________________________ 1. Test Case ID: D8cnu1 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"message": "", "tag_name": "", "target": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/tags 2. Test Case ID: OIoGbl - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/tags 3. Test Case ID: dP10BG - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 404, 405, 409, 422, 423 [500] Internal Server Error: `{"message":"release tag name is not valid [tag_name: »Û󷟿?񂣓¸񄄂á?񰏟ã콊d󢫛«E㊓󘛼]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud87b\ude99": 3517, "T\u000e\udb5a\udd1b\u0011]Z": [], "NaN": 1.7976931348623155e+308, "\u0096": [], "tag_name": "\u00bb\u00db\udb9d\udfff?\ud8ca\udcd3\u00b8\ud8d0\udd02\u00e1?\ud980\udfdf\u00e3\ucf4ad\udb4a\udedb\u00abE\u3293\udb21\udefc"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/tags _____________________ POST /repos/{owner}/{repo}/transfer ______________________ 1. Test Case ID: eCCwe7 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"new_owner": "", "team_ids": []}' http://0.0.0.0:43007/api/v1/repos/0/0/transfer __________________ POST /repos/{owner}/{repo}/transfer/accept __________________ 1. Test Case ID: 2r97UD - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/transfer/accept __________________ POST /repos/{owner}/{repo}/transfer/reject __________________ 1. Test Case ID: by59Qn - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/repos/0/0/transfer/reject 2. Test Case ID: 1ARV5V - Undocumented HTTP status code Received: 401 Documented: 200, 403, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/transfer/reject?token=%5BFiltered%5D&sudo=X%C3%87%C3%A3u%C2%BD&access_token=%5BFiltered%5D' _____________________ POST /repos/{owner}/{repo}/wiki/new ______________________ 1. Test Case ID: nJMXcn - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"content_base64": "", "message": "", "title": ""}' http://0.0.0.0:43007/api/v1/repos/0/0/wiki/new 2. Test Case ID: BWOBah - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 400, 403, 404, 423 [422] Unprocessable Content: `{"message":"[Title]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/wiki/new 3. Test Case ID: kdEMgH - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (`… .򋧎På𡿪&7¢Ñ󇅜e `). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"message":"illegal base64 data at input byte 0","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u0085.\ud9ee\uddceP\u00e5\ud847\udfea&7\u00a2\u00d1\udadc\udd5ce\r": {"\u0007+\u00bc\ud87c\udf5b\u00c5\u00c4\u00ee\ud83b\ude85G\u00a9": -2.095950228783177e+16, "C\uda33\udc27": null, "": 272330}, "title": "\"\u00b3", "content_base64": "\u00d6\u00be\u00d8C", "message": "Add \u0011\u0086\n"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/wiki/new 4. Test Case ID: TBGiMQ - Undocumented HTTP status code Received: 401 Documented: 201, 400, 403, 404, 423 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/wiki/new?access_token=%5BFiltered%5D' ____________ POST /repos/{template_owner}/{template_repo}/generate _____________ 1. Test Case ID: uJTcWb - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"avatar": false, "default_branch": "", "description": "", "git_content": false, "git_hooks": false, "labels": false, "name": "", "owner": "", "private": false, "protected_branch": false, "topics": false, "webhooks": false}' http://0.0.0.0:43007/api/v1/repos/0/0/generate ________________ POST /user/actions/runners/registration-token _________________ 1. Test Case ID: LmT30P - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/user/actions/runners/registration-token _________________ POST /user/actions/variables/{variablename} __________________ 1. Test Case ID: ZLI6SC - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 400, 409 [422] Unprocessable Content: `{"message":"[Value]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "value": ""}' http://0.0.0.0:43007/api/v1/user/actions/variables/0 2. Test Case ID: rgRqle - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"description": "", "value": ""}' http://0.0.0.0:43007/api/v1/user/actions/variables/0 3. Test Case ID: aPSHVI - Missing Content-Type header The following media types are documented in the schema: - `application/json` [201] Created: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"x[\u008d": [true, null], "6": true, "\u0017\u00d6K\u0088A": [false], "\ua0cc": {"\uda78\udc36g\u00c3\u0098": [], "\u0015\u00e3'"'"'\u0093\u00ba\u00ef\u00f7z\u00f9\rG\ud88b\uddce\u00be\u009d": null, "\u0096\u00db}\u00b4'"'"'x\"\uda74\udef2\udb83\udd43": -615}, "\r\ud85c\udd3e": {}, "description": "\ud854\ude2e\u009d\u0017Q\udb40\udd11\u0000\u6330U\u0085\u0093\u00f7\b\n\u00d99", "value": "\u00fa@"}' http://0.0.0.0:43007/api/v1/user/actions/variables/u 4. Test Case ID: hhHzAA - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"name must start with a letter or underscore and contain only letters, numbers, and underscores","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": "total", "description": "\u00bf"}' http://0.0.0.0:43007/api/v1/user/actions/variables/b%F2%88%A8%B7%22%C3%9F%C2%A1%F2%92%B2%BA%F3%80%BA%8E%C3%86%0D%C3%A6 5. Test Case ID: 1fVMEJ - Undocumented HTTP status code Received: 401 Documented: 201, 400, 409 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H $'Sudo: e\tm$' -H 'X-GITEA-OTP: w' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"workbench_output": [-698132028793439, null], "": {"\u00a1+6m*": 4111888, "\u00e6\u00c9\t\u0004": -185}, "\u00d89\u00b4`\u00a0/\u00e9\u00ebM\ud9f9\udf0c\udbbe\ude96\u0084\u00c5\u0014\u000e\u9153,f\ud89c\udf6d\u00de\u00fd\u008a": [], "XbL\uda09\udc61": -8.068787850989715e-257, "+\u00d3": "\u001c\u00b2g", "value": ""}' 'http://0.0.0.0:43007/api/v1/user/actions/variables/false?sudo=%C2%B3o%C3%AC%F0%95%90%9F%3B%7B%F2%B7%98%B7%C3%9F&token=%5BFiltered%5D' ________________________ POST /user/applications/oauth2 ________________________ 1. Test Case ID: lZoalh - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 400 [422] Unprocessable Content: `{"message":"[Name]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"confidential_client": false, "name": "", "redirect_uris": [], "skip_secondary_authorization": "[Filtered]"}' http://0.0.0.0:43007/api/v1/user/applications/oauth2 2. Test Case ID: 8no22S - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"confidential_client": false, "name": "", "redirect_uris": [], "skip_secondary_authorization": "[Filtered]"}' http://0.0.0.0:43007/api/v1/user/applications/oauth2 3. Test Case ID: ejRuPl - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"invalid redirect URI: ´\u0019ϼ”3","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"confidential_client": false, "redirect_uris": ["\u00b4\u0019\u00cf\u00bc\u00943"], "name": "\ud865\udc1c\ud932\udc56W\u00bd"}' http://0.0.0.0:43007/api/v1/user/applications/oauth2 ______________________________ POST /user/avatar _______________________________ 1. Test Case ID: eE2YnK - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 204 [422] Unprocessable Content: `{"message":"[Image]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"image": ""}' http://0.0.0.0:43007/api/v1/user/avatar 2. Test Case ID: 8uuc6v - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"image": ""}' http://0.0.0.0:43007/api/v1/user/avatar 3. Test Case ID: AAjGzB - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 2 additional properties not defined in the schema (`aB򷱛/ù`, `}`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"message":"illegal base64 data at input byte 0","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"}": null, "aB\u001f\uda9f\udc5b/\u00f9": {}, "image": "\ud9dc\udd22~W"}' http://0.0.0.0:43007/api/v1/user/avatar ______________________________ POST /user/emails _______________________________ 1. Test Case ID: GA3xVf - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"Email list empty","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"emails": []}' http://0.0.0.0:43007/api/v1/user/emails 2. Test Case ID: aUZMJN - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"email address is invalid: ","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"emails": [""]}' http://0.0.0.0:43007/api/v1/user/emails 3. Test Case ID: 6YnJsQ - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"emails": []}' http://0.0.0.0:43007/api/v1/user/emails __________________________ POST /user/gpg_key_verify ___________________________ 1. Test Case ID: 8wCam8 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/gpg_key_verify 2. Test Case ID: ESGeIq - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/user/gpg_key_verify _____________________________ POST /user/gpg_keys ______________________________ 1. Test Case ID: 7j3XmO - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[ArmoredKey]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"armored_public_key": "[Filtered]", "armored_signature": ""}' http://0.0.0.0:43007/api/v1/user/gpg_keys 2. Test Case ID: n65arB - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"armored_public_key": "[Filtered]", "armored_signature": ""}' http://0.0.0.0:43007/api/v1/user/gpg_keys _______________________________ POST /user/hooks _______________________________ 1. Test Case ID: lienE1 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201 [422] Unprocessable Content: `{"message":"Missing config option: url","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"active": false, "authorization_header": "[Filtered]", "branch_filter": "", "config": {}, "events": [], "name": "", "type": "dingtalk"}' http://0.0.0.0:43007/api/v1/user/hooks 2. Test Case ID: Shd3Ji - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"active": false, "authorization_header": "[Filtered]", "branch_filter": "", "config": {}, "events": [], "name": "", "type": "dingtalk"}' http://0.0.0.0:43007/api/v1/user/hooks _______________________________ POST /user/keys ________________________________ 1. Test Case ID: 4sBgzM - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Title]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"key": "[Filtered]", "read_only": false, "title": ""}' http://0.0.0.0:43007/api/v1/user/keys 2. Test Case ID: CWAtIA - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"key": "[Filtered]", "read_only": false, "title": ""}' http://0.0.0.0:43007/api/v1/user/keys _____________________________ POST /user/projects ______________________________ 1. Test Case ID: nPipOc - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Title]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"card_type": "", "description": "", "template_type": "", "title": ""}' http://0.0.0.0:43007/api/v1/user/projects 2. Test Case ID: 8m6eMv - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"card_type": "", "description": "", "template_type": "", "title": ""}' http://0.0.0.0:43007/api/v1/user/projects _______________________ POST /user/projects/{id}/columns _______________________ 1. Test Case ID: UzuMO8 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Title]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "", "title": ""}' http://0.0.0.0:43007/api/v1/user/projects/-9223372036854775808/columns 2. Test Case ID: 3A1UPp - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"color": "", "title": ""}' http://0.0.0.0:43007/api/v1/user/projects/-9223372036854775808/columns ____________________ POST /user/projects/{id}/columns/move _____________________ 1. Test Case ID: GfXtKY - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"column_ids": []}' http://0.0.0.0:43007/api/v1/user/projects/-9223372036854775808/columns/move 2. Test Case ID: B9c1rk - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/projects/1/columns/move _____________ POST /user/projects/{id}/columns/{column_id}/default _____________ 1. Test Case ID: 6LWZJ2 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/user/projects/-9223372036854775808/columns/-9223372036854775808/default 2. Test Case ID: TGAa45 - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/projects/229/columns/3/default ________ POST /user/projects/{id}/columns/{column_id}/issues/{issue_id} ________ 1. Test Case ID: OQq5G0 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' http://0.0.0.0:43007/api/v1/user/projects/-9223372036854775808/columns/-9223372036854775808/issues/1 2. Test Case ID: fmaKoL - Undocumented HTTP status code Received: 401 Documented: 201, 403, 404, 422, 423 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'X-GITEA-OTP: OI)B]g3' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/projects/1/columns/4194303/issues/9223372036854775806?token=%5BFiltered%5D' _______________ POST /user/projects/{id}/issues/{issue_id}/move ________________ 1. Test Case ID: 3HIUKX - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[ColumnID]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"column_id": 0, "sorting": 0}' http://0.0.0.0:43007/api/v1/user/projects/-9223372036854775808/issues/1/move 2. Test Case ID: w1RX5Y - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"column_id": 0, "sorting": 0}' http://0.0.0.0:43007/api/v1/user/projects/-9223372036854775808/issues/1/move _______________________________ POST /user/repos _______________________________ 1. Test Case ID: JIDv7t - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Name]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"auto_init": false, "default_branch": "", "description": "", "gitignores": "", "issue_labels": "", "license": "", "name": "", "object_format_name": "sha1", "private": false, "readme": "", "template": false, "trust_model": "default"}' http://0.0.0.0:43007/api/v1/user/repos 2. Test Case ID: ZU1g3Y - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"auto_init": false, "default_branch": "", "description": "", "gitignores": "", "issue_labels": "", "license": "", "name": "", "object_format_name": "sha1", "private": false, "readme": "", "template": false, "trust_model": "default"}' http://0.0.0.0:43007/api/v1/user/repos ________________________ POST /users/{username}/tokens _________________________ 1. Test Case ID: UhZbmE - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 400, 403 [422] Unprocessable Content: `{"message":"[Name]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"scopes": ["all", "read:activitypub", "read:issue", "write:misc", "read:notification", "read:organization", "read:package", "read:repository", "read:user"], "name": ""}' http://0.0.0.0:43007/api/v1/users/admin/tokens 2. Test Case ID: gKeRZ1 - Server error on unexpected Content-Type `Content-Type: multipart/form-data` without a boundary returned 500, expected 400 Bad Request or 415 Unsupported Media Type Reject a malformed `Content-Type` before parsing the request body [500] Internal Server Error: `failed to parse request multipart form` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data' -d '{"name": "", "scopes": ["all", "read:activitypub", "read:issue", "write:misc", "read:notification", "read:organization", "read:package", "read:repository", "read:user"]}' http://0.0.0.0:43007/api/v1/users/workbench-user/tokens 3. Test Case ID: C6x7i6 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"access token must have a scope","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "\u00ed\u00d6\u00bc#\udae1\udfc2\u000b\uda5b\udd6eX"}' http://0.0.0.0:43007/api/v1/users/admin/tokens 4. Test Case ID: zC3BKX - Undocumented HTTP status code Received: 404 Documented: 201, 400, 403 [404] Not Found: `{"message":"user redirect does not exist [name: (”􊘫\u001f]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00fa\u007f\u008c": {}, "\u023e": {"": [[804385392]], "\u00b1\u00a6\n": [], "\u00f1\u0093\u001dt\ud9fe\udefc\f": {"w\u0015\ud9e1\udcbd+\u00de\uda7c\udf25\udba3\udc0b\u0094\udb57\ude9f\u00d3y\u009d8\u00ae": [true, 403429, -8479404], "\u00fd\u0080\u00f2\udbda\udc47": []}}, "\u00ab^'"'"'\u00af": [], "": {"\u0088\u00d6": 20146001178}, "scopes": ["\u00ac\ud8b8\udc98\udbfe\udff7\ud856\udebf\udb08\uddac\u0015\u0084-", "\u001f_\u00c5!"], "name": "update_migration_poster_id"}' http://0.0.0.0:43007/api/v1/users/%28%C2%94%F4%8A%98%AB%1F/tokens ______________________________ PUT /notifications ______________________________ 1. Test Case ID: rsHEMv - Undocumented HTTP status code Received: 400 Documented: 205 [400] Bad Request: `{"message":"parsing time \"null\" as \"2006-01-02T15:04:05Z07:00\": cannot parse \"null\" as \"2006\"","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/notifications?last_read_at=null&last_read_at=null' 2. Test Case ID: 5L4IDa - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `last_read_at` in query - violates `format` at /properties/last_read_at [205] Reset Content: `[]` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/notifications?last_read_at=' _________________ PUT /orgs/{org}/actions/secrets/{secretname} _________________ 1. Test Case ID: U5vREw - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"data": ""}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/secrets/0 2. Test Case ID: zU3YCm - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"name must start with a letter or underscore and contain only letters, numbers, and underscores","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"data": "\u00a3\ud898\ude85_\u00a7\u007fA\u00c0\u00ef\u008b"}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/secrets/0 3. Test Case ID: YUi5hR - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 4 additional properties not defined in the schema (`False`, `\񄬒󯕁8á󄞦YŠ𾘡Š󗁎`򧱬񒎉򏌂|†`, `©񔥃` and 1 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. - Undocumented HTTP status code Received: 422 Documented: 201, 204, 400, 404 [422] Unprocessable Content: `{"message":"[Data]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"False": [null], "\u00e2\u009d\u0017\udac0\udf92\u0099k\u00a2@\ue1ad\u0084": {}, "\\\ud8d2\udf12\udb7d\udd418\u00e1\udad1\udfa6Y\u008a\ud8b9\ude21\u008a\udb1c\udc4e`\uda5f\udc6c\ud908\udf89\u0004\ud9fc\udf02|\u0019\u0086": null, "\u00a9\ud912\udd43": {"\u00c4/~K\u0015\u001a\u00db\u0091\u00d1": {}, "\ud9b6\udcf7\u00ef\uda7c\udf1e\u00c4\ud9a1\uddea\u0011\u00b1\u000b\u00d4\uda1f\ude02\u009f\u0082\u00c4.": [-62706, -72, null], "\u00a5": [":t\u00c7\ud883\udcae0\uda5f\udf61\u00c0\u0016\u00e8", -2.7554417081896427e+158]}, "data": ""}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/secrets/%5B%C3%81o 4. Test Case ID: NbgNkF - Missing Content-Type header The following media types are documented in the schema: - `application/json` [201] Created: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u008e": {"": -2.00001, "5": 2.35266732207496e+16, "\u0015O\u0084WO\u00d2\u0091\u00d8c\ud8c4\ude7f": -37991469475537640}, "\u00a8-\u00ab\u00c7": {}, "data": "7\u0012\u00c8"}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/secrets/o _______________ PUT /orgs/{org}/actions/variables/{variablename} _______________ 1. Test Case ID: a84Pgd - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": ""}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/u 2. Test Case ID: FuUeVA - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 204, 400, 404 [422] Unprocessable Content: `{"message":"[Value]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": ""}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/false 3. Test Case ID: RJsvvr - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": "\u00c0"}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/false 4. Test Case ID: jJlJMV - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (``, `Fk`, `Kr‚Ÿ` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"message":"name must start with a letter or underscore and contain only letters, numbers, and underscores","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00a7\u00e9E\u00ebo;\u0006F\u00b5\u0086\udb11\udfee\u00eb": {"\u0099\u00ee\u00eb\u00ae:[\u00f5\u00e9\u0001\u00e1": []}, "\u00e7\u00fc\u009b\u00f9": {}, "K\u0001r\u0082\u009f": {}, "": [null, 68773233], "\u0018Fk": -3455418343, "name": "attachment.gif", "value": "\u008aS.\u00cf\u00861\udbbf\udfa1\u00ddi\u0002", "description": "\uda01\udfb0UO\ud976\udd76\u009b\u00c5"}' http://0.0.0.0:43007/api/v1/orgs/workbench/actions/variables/false ______________________ PUT /orgs/{org}/blocks/{username} _______________________ 1. Test Case ID: am8bIM - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/blocks/admin 2. Test Case ID: hoLHD5 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204, 404, 422 [400] Bad Request: `{"message":"cannot block the user","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/blocks/admin __________________ PUT /orgs/{org}/public_members/{username} ___________________ 1. Test Case ID: jdJQI0 - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/orgs/workbench/public_members/admin ____________ PUT /repos/{owner}/{repo}/actions/secrets/{secretname} ____________ 1. Test Case ID: Y3oZHG - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 204, 400, 404 [422] Unprocessable Content: `{"message":"[Data]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"data": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/secrets/0 2. Test Case ID: UETiPc - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 2 additional properties not defined in the schema (`0¿t񕡂`, `􀼹󓀤`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"message":"name must start with a letter or underscore and contain only letters, numbers, and underscores","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\udbc3\udf39\udb0c\udc24": {}, "0\u00bf\u0012t\ud916\udc42\u0011\u0014": {"\u00b9\ud859\ude715\ud88a\uddda\u009c\u00f6\u00ba\u009d": {"": 6.015317590074307e+16, "\ud92a\udd7c\u00ed": 4.845712345974803e-213}, "": {}}, "data": "\u00c3"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/secrets/y%C3%8F%F2%8A%AD%935 3. Test Case ID: 7lAgYs - Missing Content-Type header The following media types are documented in the schema: - `application/json` [201] Created: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u000e": [[], {"\udbb3\udc7f": "\u0015\u00ef\u00d3\u00ac", "\u0088\u00df": 2.3610795649219907e+306}, null], "-\ud838\udcbc\udaa7\udf11\u00b2\ud9a2\udfc5\u00cbO": {"?\u001d\u00ff\u00ff\u00e6\u00dc\ud904\uddf3`\u00e6\ud8a9\udc8f\udb8e\udcdc\u00b2\u00a0z\u00b80N\uda07\ude09\ud8fd\ude2a\udbc6\udec9\u00b1{\u00abV": true, "": -30797, "y": {}}, "\uda58\udf0f": "6\u00e65\u0090\udb8c\ude05\u00c1\ud84b\ude8a\u00dc\ud944\udcdc{\uda5b\udf76\f!\u00cd\u00c1\u00cf\u00a8<\n\ud9cc\ude4f\udb1a\udf83Y", "": [[]], "\u00a8": {}, "data": "\u00a3\ud898\ude85_\u00a7\u007fA\u00c0\u00ef\u008b"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/secrets/o __________ PUT /repos/{owner}/{repo}/actions/variables/{variablename} __________ 1. Test Case ID: ca8sJC - Undocumented HTTP status code Received: 422 Documented: 201, 204, 400, 404 [422] Unprocessable Content: `{"message":"[]: jsontext: invalid character '.' at start of value","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d .q http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables/u 2. Test Case ID: RL7AO2 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"[Value]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables/u 3. Test Case ID: Ko3Y15 - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud94c\udd4e\ud87c\udd00": {}, "value": "\u00ad"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables/u 4. Test Case ID: IlEisl - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (``, `6`, `ª¹ÑIm󍵦ž` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"message":"name must start with a letter or underscore and contain only letters, numbers, and underscores","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00aa\u00b9\u00d1I\u008dm\udaf7\udd66\u009e": "}\udbe5\udd66#", "\u00fc\u0086\u78cf": -6.20996786542638e+16, "6\u001b": false, "": {"\udb65\udfcf": null, "\u0087\u00dee\u000e\u00cf\u0013\u00e7a\u00d7\u0013\udb99\udfd1\u00d3\u009c\u008a": "_", "\u00a9\u00ad\u000fME\u0081\u00b4": -8.840841874923337e+261}, "\ud932\udfd1\u00fbh\u00a0w": true, "value": "started_at", "description": "\u0098\u0012\u00a0\u00cf\u00e9", "name": "\ud90d\udfa6*R\u00f2\u0014\u00f6\ud9e4\udcf7\u008c\u0007\u00a8\u00e3"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/variables/u _______ PUT /repos/{owner}/{repo}/actions/workflows/{workflow_id}/enable _______ 1. Test Case ID: QAHPfz - Undocumented HTTP status code Received: 401 Documented: 204, 400, 403, 404, 409, 422 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Sudo;' -H 'Authorization: [Filtered]' -H 'X-GITEA-OTP: j' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/actions/workflows/0/enable?sudo=%F1%AE%8C%A9V&access_token=%5BFiltered%5D&token=%5BFiltered%5D' _________________ PUT /repos/{owner}/{repo}/branches/{branch} __________________ 1. Test Case ID: 4pJROf - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"branch commit does not match [expected: 80d813304cce7ce1e538097133572f371a018407, given: 83e0599c2e9d180479e163ad6e7fb7eb32b851a2]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"new_commit_id": "80d813304cce7ce1e538097133572f371a018407", "old_commit_id": "80d813304cce7ce1e538097133572f371a018407"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/branches/0 2. Test Case ID: OMTAuM - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"new_commit_id": "83e0599c2e9d180479e163ad6e7fb7eb32b851a2", "old_commit_id": "83e0599c2e9d180479e163ad6e7fb7eb32b851a2"}' http://0.0.0.0:43007/api/v1/repos/admin/demo/branches/0 ____________ PUT /repos/{owner}/{repo}/collaborators/{collaborator} ____________ 1. Test Case ID: rZjfVZ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"user does not exist [uid: 0, name: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/collaborators/0 ________________ PUT /repos/{owner}/{repo}/contents/{filepath} _________________ 1. Test Case ID: b9bnIs - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"repository file already exists [path: 0]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"content": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/contents/0 2. Test Case ID: kYaFBK - Response violates schema (3 violations) null is not of type "object" Validated against the response schema for status code 201. Schema at /definitions/PayloadUser: { "type": "object", "description": "PayloadUser represents the author or committer of a commit", "properties": { "email": { "type": "string", "format": "email", "x-go-name": "Email" }, "name": { "description": "Full name of the commit author", "type": "string", "x-go-name": "Name" }, "username": { "description": "username of the user", "type": "string", "x-go-name": "UserName" } // Output truncated... } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/ContentsResponse/properties/submodule_git_url: { "type": "string", "description": "`submodule_git_url` is populated when `type` is `submodul... "x-go-name": "SubmoduleGitURL" } Value: null null is not of type "string" Validated against the response schema for status code 201. Schema at /definitions/ContentsResponse/properties/target: { "type": "string", "description": "`target` is populated when `type` is `symlink`, otherwise... "x-go-name": "Target" } Value: null [201] Created: `{"content":{"name":"§Ú","path":"§Ú","sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","last_commit_sha":"44a5848b3c5e4d7c96965b013568014133b21ccf","last_committer_date":"2026-10-10T10:07:47Z","last_author_date":"2026-10-10T10:07:47Z","type":"file","mode":"100644","size":0,"encoding":"base64","content":"","target":null,"url":"http://localhost:3000/api/v1/repos/admin/demo/contents/%C2%A7%C3%9A?ref=main","html_url":"http://0.0.0.0:43007/admin/demo/src/branch/main/%C2%A7%C3%9A","git_url":"http://0.0.0.0:43007/ap // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"content": ""}' http://0.0.0.0:43007/api/v1/repos/admin/demo/contents/%C2%A7%C3%9A _______________ PUT /repos/{owner}/{repo}/issues/{index}/labels ________________ 1. Test Case ID: pyyjpB - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (`q`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. - Undocumented HTTP status code Received: 400 Documented: 200, 403, 404 [400] Bad Request: `{"message":"a label must be an integer or a string","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"q": [{}], "labels": [{"T": null}, [-1895, [-1.573582482216178e+300, -16, "m$"], {"\u00e6\u0084\udae9\udcf2": -286551}], {}, "g\n\u009c", "\u00b5KR7\u0094\u00e5\u001b", {}, "\ud84d\udcf4\udbbd\udc8c\u0096-\\$\udadf\udd6b"]}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/labels 2. Test Case ID: qyBmly - Undocumented HTTP status code Received: 422 Documented: 200, 403, 404 [422] Unprocessable Content: `{"message":"[]: jsontext: invalid character '\\x00' at start of value","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/161356625/labels ________________ PUT /repos/{owner}/{repo}/issues/{index}/lock _________________ 1. Test Case ID: acCxKA - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/lock 2. Test Case ID: xC5ZSQ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 204, 403, 404 [422] Unprocessable Content: `{"message":"[]: Unsupported Content-Type","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/issues/1/lock ___________________ PUT /repos/{owner}/{repo}/notifications ____________________ 1. Test Case ID: qnsdmY - Undocumented HTTP status code Received: 404 Documented: 205 [404] Not Found: `{"message":"not found","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/0/0/notifications?all=&status-types=&to-status=&last_read_at=2000-01-01T00%3A00%3A00Z' 2. Test Case ID: EmxzIu - Undocumented HTTP status code Received: 403 Documented: 205 [403] Forbidden: `{"message":"Only administrators allowed to sudo."}` Reproduce with: curl -X PUT -H 'X-GITEA-OTP;' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/notifications?sudo=%5B%C2%B0H' ____________________ PUT /repos/{owner}/{repo}/subscription ____________________ 1. Test Case ID: EKlBAF - Undocumented HTTP status code Received: 401 Documented: 200, 403, 404 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/repos/admin/demo/subscription?access_token=%5BFiltered%5D' _______________________ PUT /repos/{owner}/{repo}/topics _______________________ 1. Test Case ID: gOUv94 - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43007/api/v1/repos/admin/demo/topics 2. Test Case ID: FdBe89 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 4 additional properties not defined in the schema (`¥«cí­Û󇳴£I񕽱¤`, `Ž´P^®`, `zeg` and 1 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [422] Unprocessable Content: `{"invalidTopics":["l°򤩕o–","𝕍ð","\u0019q\u0017򩥍","r򋃕","􉒦"],"message":"Topic names are invalid"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u0004\u00a5\u00abc\u00ed\u00ad\u00db\udadf\udcf4\u00a3I\ud917\udf71\u00a4": {}, "\u0012\u008e\u00b4P^\u00ae": {}, "\u00c2_1\u0005 \udad5\ude5a\udac9\udc7d\u0017\u00e7": [null], "zeg": {"|\u00d3\ud80a\udf99\ud80c\udfb7\udae5\udc3c\u00eaO\uda7a\uddb7\ud85f\udc7f\u00d5": 1.9277766240616456e-94, "+)(3\udbd5\ude68\ud860\uddcf": {}, "\u00eeU\u0095\u00fe$^": true}, "topics": ["L\u00b0\uda52\ude55O\u0096", "\ud835\udd4d\u00d0", "\u0019Q\u0017\uda66\udd4d", "", "1", "R\ud9ec\udcd5", "\udbe5\udca6"]}' http://0.0.0.0:43007/api/v1/repos/admin/demo/topics ___________________ PUT /repos/{owner}/{repo}/topics/{topic} ___________________ 1. Test Case ID: tHLevW - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/topics/0 2. Test Case ID: sFQuMT - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [422] Unprocessable Content: `{"message":"Topic name is invalid","invalidTopics":"򴡆8񇱾"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/repos/admin/demo/topics/%C2%90%F2%B4%A1%868%F1%87%B1%BE ____________________ PUT /user/actions/secrets/{secretname} ____________________ 1. Test Case ID: DdK96J - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 204, 400, 404 [422] Unprocessable Content: `{"message":"[Data]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"data": "", "description": ""}' http://0.0.0.0:43007/api/v1/user/actions/secrets/0 2. Test Case ID: BXT5xP - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 2 additional properties not defined in the schema (`Î`, `ßVæ§"`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"message":"name must start with a letter or underscore and contain only letters, numbers, and underscores","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00dfV\u00e6\u00a7\"": true, "\u00ce": [{}, {"\u00a0\u00d4\udba1\ude1c\u0088\u00b0f\udb48\udd3c": false}], "data": ")\u00de_\u000f"}' http://0.0.0.0:43007/api/v1/user/actions/secrets/%C2%980%0C%C2%A8%C2%B4%C3%97%21 3. Test Case ID: ZEQFlG - Missing Content-Type header The following media types are documented in the schema: - `application/json` [201] Created: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"data": "\u00f4=\ud928\udc8d\u0019\uda7e\udec0\udb93\udd81\u00a2\f\u0013\ud979\uddb1\u00b5P\u001d\u001d\u0007\u009e\uda86\udd39\u00cc\u00c32\u008f"}' http://0.0.0.0:43007/api/v1/user/actions/secrets/affected __________________ PUT /user/actions/variables/{variablename} __________________ 1. Test Case ID: MO3DyK - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 422 Documented: 201, 204, 400, 404 [422] Unprocessable Content: `{"message":"[Value]: Required","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "name": "", "value": ""}' http://0.0.0.0:43007/api/v1/user/actions/variables/0 2. Test Case ID: jjaOdD - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": "#\u00c1\u00b9\u00f8\ud911\udfcc"}' http://0.0.0.0:43007/api/v1/user/actions/variables/u 3. Test Case ID: CBmW08 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"name must start with a letter or underscore and contain only letters, numbers, and underscores","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": "\ud8eb\udd11pS\udb3b\udfed\u00e6\u00a1\u00abL", "description": "\udad8\udd60\f", "name": "attachment.pdf"}' http://0.0.0.0:43007/api/v1/user/actions/variables/u _________________________ PUT /user/blocks/{username} __________________________ 1. Test Case ID: dpQZ4W - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204, 404, 422 [400] Bad Request: `{"message":"cannot block the user","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/blocks/admin ________________________ PUT /user/following/{username} ________________________ 1. Test Case ID: HB3xEZ - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/following/admin _______________________ PUT /user/starred/{owner}/{repo} _______________________ 1. Test Case ID: PbWG7u - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/starred/admin/demo ________________________________ Stateful tests ________________________________ 1. Test Case ID: 0RrxQK - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `[{"id":2,"owner":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"\rÝ𑀮°𓚒­뜸#œÔ򛝠Í𴳓ÑێB","website":"","description":"˜\u0012  // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/subscriptions?limit=16919190477&page=-777' 2. Test Case ID: zRyBi8 - Response violates schema "" is not a "email" Validated against the response schema for status code 200. Schema at /definitions/User/properties/email: { "format": "email", "type": "string", "x-go-name": "Email" } Value: "" [200] OK: `[{"id":5,"owner":{"id":1,"login":"admin","type":"User","login_name":"","source_id":0,"full_name":"admin/demo","email":"admin@example.com","avatar_url":"http://0.0.0.0:43007/avatars/d0557e4b4e83732824a59f34458ed3b93e59497f2fa6617ba649a0cfe3dc3f12","html_url":"http://0.0.0.0:43007/admin","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2026-10-10T09:54:25Z","restricted":false,"active":false,"prohibit_login":false,"location":"\rÝ𑀮°𓚒­뜸#œÔ򛝠Í𴳓ÑێB","website":"","description":"˜\u0012  // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/repos 3. Test Case ID: MjHLcq - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/followers?page=-3423442' curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"]": [{}, {"\u001c|\u0007Y": [], "": -3.169329924418736e+236}, {}], "": {"\u0084<\u00ba": {"\u00c7s\u0010\u001d\u0080": "", "\u0081\u00de\u0083E\uda45\ude92\u00ce": true}}, "8\"\u008b\udbd6\udea6g\u00e6\u00ae\u009b": [1.4631088000632174e+16, -1048577, [null, "\u0091V\u00d3"]], "\f\u00c2\udb4f\udee3@\u0011\u00c2n\ud997\udd4c_": {}, "\u001b\udb0e\udf65\u000bc\u0098\udb25\udf70hd\ud9ae\udc51": ["Y\u00e9\u009e[\u00d9\u00ec\ud990\udeac\u00f3\u00f9\u00e4\u00df"], "email": "p\ud8d3\udf03\u00af\u00cd\udb95\ude4e", "visibility": "private", "description": "\u00f7\u00c4\udb0c\ude0e", "full_name": "admin/update_mirrors", "repo_admin_change_team_access": false, "website": "", "location": "-Infinity", "username": ""}' http://0.0.0.0:43007/api/v1/admin/users/workbench/orgs 4. Test Case ID: Tiv5Xv - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/following?limit=-81412633334325&page=549755813887' curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/users/workbench/subscriptions?page=-862288' 5. Test Case ID: LfnTGA - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'X-GITEA-OTP: ~'"'"'y' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user/emails?token=%5BFiltered%5D&access_token=%5BFiltered%5D' 6. Test Case ID: GRfIEo - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/actions/runs?event=Ky%F2%A5%A1%BA%2F%C2%89%F4%8E%A2%B4%F4%80%8C%B1%09%C3%A8%C2%91%C2%BFA%C2%AF_' curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/admin/users/workbench 7. Test Case ID: Asf8W2 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"message":"readme template does not exist, available templates: [Default]","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"readme": "none", "default_branch": "main", "template": false, "issue_labels": "\u00db\ud88f\udc3c\u00b6\u00b9\udade\udf5a\"\u00e7\u00d2", "name": "repo_health_check", "object_format_name": "sha1", "private": false, "auto_init": true, "trust_model": "default", "license": "\ud94d\udf63J\u00bc\u00a7\u00c6\u001d\"\u00aa\u00a5\f\u0098", "gitignores": "*\u009d"}' http://0.0.0.0:43007/api/v1/admin/users/workbench-user/repos 8. Test Case ID: k3NAVE - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/teams curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/teams/3/members/admin 9. Test Case ID: 5vtRqX - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /label/templates/{name}` [200] OK: `[{"name":"Kind/Bug","exclusive":false,"color":"ee0701","description":"Something is not working"},{"name":"Kind/Feature","exclusive":false,"color":"0288d1","description":"New functionality"},{"name":"Kind/Enhancement","exclusive":false,"color":"84b6eb","description":"Improve existing functionality"},{"name":"Kind/Security","exclusive":false,"color":"9c27b0","description":"This is security issue"},{"name":"Kind/Testing","exclusive":false,"color":"795548","description":"Issue or pull request related to testing // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/label/templates curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/label/templates/Advanced curl -X GET http://0.0.0.0:43007/api/v1/label/templates/Advanced 10. Test Case ID: 9eJiiC - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/projects curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"{\udaa0\udcee": {"": [], "\ud853\udc16": 5.769428965827904e+16, "\ud9b7\udd06\uda93\udd42\uc6fd}$\u00fb\r\u00f6\udac3\udc60O": [null]}, "K\udaae\udcee\udaf8\ude02\u00bbG": {"\u009a\u00e5\u00e2y?\udaf0\ude36y\u00bb": {}, "\ud9ce\udd06\u007f\u00b7\u0097\u00ca\ud939\udcce\u00d2\u00f5": ["K\u00b2\udb14\udcbc\udbfb\udc97\u00ef", true, null], "\u00af\udaff\udcb4\u00bb\u0090\u00b0\u00f1\u0010\udbbd\udd57T\u00a7": {"]\u008e9\udb54\udcff\u00a1": null}}, "\u009b": {"8\uda3b\udf73\u00dd\uda82\udf35\u00bf\uda69\udd94f\ud81d\ude0a\u00db\udaa2\udc41\u00f8\u00a0": 563994027274888960}, "<\ud8b6\udfef'"'"'\u0007\u00f3ac\u009d\u00e0\u0095\r\u00b1": [[], "\u0000J\u00c3"], "column_ids": []}' http://0.0.0.0:43007/api/v1/user/projects/225/columns/move 11. Test Case ID: fWncPY - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json [404] Not Found: `user does not exist` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/packages?limit=-986271459&type=conda' curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": {"\u00a7\u00da\u00ed\u00b7'"'"'\u00c7": ["JN\u00ca=\u009e\udb54\udd39\u00c6-JC\u00e91\udbaf\udcb6", "auto_init": true, "license": "q", "default_branch": "main", "name": "demo", "gitignores": "\u00a5\u0081bt\u0010X", "private": true, "trust_model": "default"}' http://0.0.0.0:43007/api/v1/user/repos 13. Test Case ID: L8Basn - Missing Content-Type header The following media types are documented in the schema: - `application/json` [204] No Content: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/projects curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43007/api/v1/user/projects/345 14. Test Case ID: WAmUAM - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 409, 422 [500] Internal Server Error: `{"message":"initRepository: prepareRepoCommit: getLicense[q]: GetLicense[q]: file does not exist","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"template": true, "auto_init": true, "name": "AFFECTED", "default_branch": "\ud911\udd62", "private": false, "description": "Need some help", "license": "q"}' http://0.0.0.0:43007/api/v1/user/repos 15. Test Case ID: 2cCqqp - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Sudo: s`} !_NF' -H 'X-GITEA-OTP: bCr_' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/user?token=%5BFiltered%5D&access_token=%5BFiltered%5D&sudo=%F3%BF%8A%A4%F2%AE%AB%86C%16%C2%93%C2%9Bq%C2%B0%F0%A0%9C%BB%C3%8A' 16. Test Case ID: usJO69 - Undocumented HTTP status code Received: 401 Documented: 200, 403, 422 [401] Unauthorized: `{"message":"invalid username, password or token","url":"http://localhost:3000/api/swagger"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43007/api/v1/admin/users?is_admin=false&access_token=%5BFiltered%5D&sort=&visibility=&login_name=' =================================== WARNINGS =================================== Authentication failed: 4 operations returned authentication errors 403 Forbidden (4 operations): - DELETE /repos/{owner}/{repo}/hooks/git/{id} - GET /repos/{owner}/{repo}/hooks/git/{id} - PATCH /repos/{owner}/{repo}/hooks/git/{id} - PUT /repos/{owner}/{repo}/teams/{team} 💡 Ensure valid authentication credentials are set via --auth or -H Missing test data: 385 operations repeatedly returned 404 Not Found, preventing tests from reaching your API's core logic No links point to these operations (138 operations): - DELETE /repos/{owner}/{repo}/avatar - DELETE /repos/{owner}/{repo}/contents/{filepath} - DELETE /repos/{owner}/{repo}/issues/{index} - DELETE /repos/{owner}/{repo}/issues/{index}/assignees - DELETE /repos/{owner}/{repo}/issues/{index}/blocks - DELETE /repos/{owner}/{repo}/issues/{index}/dependencies - DELETE /repos/{owner}/{repo}/issues/{index}/labels - DELETE /repos/{owner}/{repo}/issues/{index}/lock - DELETE /repos/{owner}/{repo}/issues/{index}/pin - DELETE /repos/{owner}/{repo}/issues/{index}/reactions - DELETE /repos/{owner}/{repo}/issues/{index}/stopwatch/delete - DELETE /repos/{owner}/{repo}/issues/{index}/subscriptions/{user} - DELETE /repos/{owner}/{repo}/issues/{index}/times - DELETE /repos/{owner}/{repo}/pulls/{index}/merge - DELETE /repos/{owner}/{repo}/pulls/{index}/requested_reviewers - DELETE /repos/{owner}/{repo}/subscription - DELETE /user/starred/{owner}/{repo} - GET /repos/{owner}/{repo}/actions/artifacts - GET /repos/{owner}/{repo}/actions/jobs - GET /repos/{owner}/{repo}/actions/runners - GET /repos/{owner}/{repo}/actions/runs - GET /repos/{owner}/{repo}/actions/secrets - GET /repos/{owner}/{repo}/actions/tasks - GET /repos/{owner}/{repo}/actions/variables - GET /repos/{owner}/{repo}/actions/workflows - GET /repos/{owner}/{repo}/activities/feeds - GET /repos/{owner}/{repo}/assignees - GET /repos/{owner}/{repo}/collaborators - GET /repos/{owner}/{repo}/commits - GET /repos/{owner}/{repo}/commits/{ref}/status - GET /repos/{owner}/{repo}/commits/{ref}/statuses - GET /repos/{owner}/{repo}/compare/{basehead} - GET /repos/{owner}/{repo}/contents - GET /repos/{owner}/{repo}/contents-ext/{filepath} - GET /repos/{owner}/{repo}/contents/{filepath} - GET /repos/{owner}/{repo}/editorconfig/{filepath} - GET /repos/{owner}/{repo}/file-contents - GET /repos/{owner}/{repo}/forks - GET /repos/{owner}/{repo}/git/blobs/{sha} - GET /repos/{owner}/{repo}/git/notes/{sha} - GET /repos/{owner}/{repo}/git/refs - GET /repos/{owner}/{repo}/git/tags/{sha} - GET /repos/{owner}/{repo}/git/trees/{sha} - GET /repos/{owner}/{repo}/hooks - GET /repos/{owner}/{repo}/hooks/git - GET /repos/{owner}/{repo}/issue_config - GET /repos/{owner}/{repo}/issue_config/validate - GET /repos/{owner}/{repo}/issue_templates - GET /repos/{owner}/{repo}/issues - GET /repos/{owner}/{repo}/issues/comments - GET /repos/{owner}/{repo}/issues/pinned - GET /repos/{owner}/{repo}/issues/{index} - GET /repos/{owner}/{repo}/issues/{index}/assets - GET /repos/{owner}/{repo}/issues/{index}/blocks - GET /repos/{owner}/{repo}/issues/{index}/comments - GET /repos/{owner}/{repo}/issues/{index}/dependencies - GET /repos/{owner}/{repo}/issues/{index}/labels - GET /repos/{owner}/{repo}/issues/{index}/reactions - GET /repos/{owner}/{repo}/issues/{index}/subscriptions - GET /repos/{owner}/{repo}/issues/{index}/subscriptions/check - GET /repos/{owner}/{repo}/issues/{index}/timeline - GET /repos/{owner}/{repo}/issues/{index}/times - GET /repos/{owner}/{repo}/labels - GET /repos/{owner}/{repo}/languages - GET /repos/{owner}/{repo}/licenses - GET /repos/{owner}/{repo}/milestones - GET /repos/{owner}/{repo}/new_pin_allowed - GET /repos/{owner}/{repo}/projects - GET /repos/{owner}/{repo}/pulls - GET /repos/{owner}/{repo}/pulls/pinned - GET /repos/{owner}/{repo}/pulls/{base}/{head} - GET /repos/{owner}/{repo}/pulls/{index} - GET /repos/{owner}/{repo}/pulls/{index}/commits - GET /repos/{owner}/{repo}/pulls/{index}/files - GET /repos/{owner}/{repo}/pulls/{index}/merge - GET /repos/{owner}/{repo}/pulls/{index}/reviews - GET /repos/{owner}/{repo}/push_mirrors - GET /repos/{owner}/{repo}/releases - GET /repos/{owner}/{repo}/releases/latest - GET /repos/{owner}/{repo}/reviewers - GET /repos/{owner}/{repo}/stargazers - GET /repos/{owner}/{repo}/statuses/{sha} - GET /repos/{owner}/{repo}/subscribers - GET /repos/{owner}/{repo}/subscription - GET /repos/{owner}/{repo}/tags - GET /repos/{owner}/{repo}/teams - GET /repos/{owner}/{repo}/times - GET /repos/{owner}/{repo}/times/{user} - GET /repos/{owner}/{repo}/topics - GET /repos/{owner}/{repo}/wiki/pages - GET /repos/{owner}/{repo}/wiki/revisions/{pageName} - GET /user/starred/{owner}/{repo} - PATCH /repos/{owner}/{repo}/issues/{index}/pin/{position} - POST /admin/cron/{task} - POST /admin/unadopted/{owner}/{repo} - POST /repos/{owner}/{repo}/avatar - POST /repos/{owner}/{repo}/branches - POST /repos/{owner}/{repo}/contents - POST /repos/{owner}/{repo}/contents/{filepath} - POST /repos/{owner}/{repo}/diffpatch - POST /repos/{owner}/{repo}/file-contents - POST /repos/{owner}/{repo}/forks - POST /repos/{owner}/{repo}/hooks - POST /repos/{owner}/{repo}/issues - POST /repos/{owner}/{repo}/issues/{index}/assets - POST /repos/{owner}/{repo}/issues/{index}/assignees - POST /repos/{owner}/{repo}/issues/{index}/blocks - POST /repos/{owner}/{repo}/issues/{index}/comments - POST /repos/{owner}/{repo}/issues/{index}/deadline - POST /repos/{owner}/{repo}/issues/{index}/dependencies - POST /repos/{owner}/{repo}/issues/{index}/labels - POST /repos/{owner}/{repo}/issues/{index}/pin - POST /repos/{owner}/{repo}/issues/{index}/reactions - POST /repos/{owner}/{repo}/issues/{index}/stopwatch/start - POST /repos/{owner}/{repo}/issues/{index}/stopwatch/stop - POST /repos/{owner}/{repo}/keys - POST /repos/{owner}/{repo}/keys/tokens - POST /repos/{owner}/{repo}/labels - POST /repos/{owner}/{repo}/merge-upstream - POST /repos/{owner}/{repo}/milestones - POST /repos/{owner}/{repo}/mirror-sync - POST /repos/{owner}/{repo}/projects - POST /repos/{owner}/{repo}/pulls - POST /repos/{owner}/{repo}/pulls/{index}/requested_reviewers - POST /repos/{owner}/{repo}/pulls/{index}/update - POST /repos/{owner}/{repo}/push_mirrors-sync - POST /repos/{owner}/{repo}/statuses/{sha} - POST /repos/{owner}/{repo}/tag_protections - POST /repos/{owner}/{repo}/transfer/accept - POST /repos/{owner}/{repo}/transfer/reject - POST /repos/{owner}/{repo}/wiki/new - POST /repos/{template_owner}/{template_repo}/generate - PUT /repos/{owner}/{repo}/issues/{index}/labels - PUT /repos/{owner}/{repo}/issues/{index}/lock - PUT /repos/{owner}/{repo}/issues/{index}/subscriptions/{user} - PUT /repos/{owner}/{repo}/subscription - PUT /repos/{owner}/{repo}/topics - PUT /user/starred/{owner}/{repo} 💡 Provide realistic parameter values in your config file so tests can access existing resources No links point to this operation - GET /repos/{owner}/{repo}/commits appears to supply the data it needs: - POST /repos/{owner}/{repo}/pulls/{index}/reviews 💡 Add a link from GET /repos/{owner}/{repo}/commits, or supply the identifiers it returns in your config file No links point to these operations - POST /repos/{owner}/{repo}/branch_protections appears to supply the data they need (3 operations): - DELETE /repos/{owner}/{repo}/branch_protections/{name} - GET /repos/{owner}/{repo}/branch_protections/{name} - PATCH /repos/{owner}/{repo}/branch_protections/{name} 💡 Add a link from POST /repos/{owner}/{repo}/branch_protections, or supply the identifiers it returns in your config file No links point to these operations - POST /repos/{owner}/{repo}/branches appears to supply the data they need (2 operations): - DELETE /repos/{owner}/{repo}/branches/{branch} - GET /repos/{owner}/{repo}/branches/{branch} 💡 Add a link from POST /repos/{owner}/{repo}/branches, or supply the identifiers it returns in your config file No links point to these operations - POST /repos/{owner}/{repo}/push_mirrors appears to supply the data they need (2 operations): - DELETE /repos/{owner}/{repo}/push_mirrors/{name} - GET /repos/{owner}/{repo}/push_mirrors/{name} 💡 Add a link from POST /repos/{owner}/{repo}/push_mirrors, or supply the identifiers it returns in your config file No links point to these operations - nothing in the schema appears to supply the data they need (45 operations): - DELETE /orgs/{org} - DELETE /orgs/{org}/avatar - DELETE /orgs/{org}/repos - DELETE /repos/{owner}/{repo}/actions/runs/{run} - DELETE /repos/{owner}/{repo}/hooks/git/{id} - DELETE /repos/{owner}/{repo}/wiki/page/{pageName} - GET /orgs/{org} - GET /orgs/{org}/actions/jobs - GET /orgs/{org}/actions/runners - GET /orgs/{org}/actions/runs - GET /orgs/{org}/actions/secrets - GET /orgs/{org}/actions/variables - GET /orgs/{org}/activities/feeds - GET /orgs/{org}/hooks - GET /orgs/{org}/labels - GET /orgs/{org}/members - GET /orgs/{org}/projects - GET /orgs/{org}/public_members - GET /orgs/{org}/repos - GET /orgs/{org}/teams - GET /orgs/{org}/teams/search - GET /repos/{owner}/{repo}/actions/runs/{run} - GET /repos/{owner}/{repo}/actions/runs/{run}/artifacts - GET /repos/{owner}/{repo}/actions/runs/{run}/attempts/{attempt} - GET /repos/{owner}/{repo}/actions/runs/{run}/attempts/{attempt}/jobs - GET /repos/{owner}/{repo}/actions/runs/{run}/jobs - GET /repos/{owner}/{repo}/archive/{archive} - GET /repos/{owner}/{repo}/assignees/{assignee} - GET /repos/{owner}/{repo}/hooks/git/{id} - GET /repos/{owner}/{repo}/issues/{index}/assignees/{assignee} - GET /repos/{owner}/{repo}/wiki/page/{pageName} - PATCH /orgs/{org} - PATCH /repos/{owner}/{repo}/hooks/git/{id} - PATCH /repos/{owner}/{repo}/wiki/page/{pageName} - POST /repos/{owner}/{repo}/actions/runs/{run}/approve - POST /repos/{owner}/{repo}/actions/runs/{run}/cancel - POST /repos/{owner}/{repo}/actions/runs/{run}/force-cancel - POST /repos/{owner}/{repo}/actions/runs/{run}/rerun - POST /repos/{owner}/{repo}/actions/runs/{run}/rerun-failed-jobs - POST /repos/{owner}/{repo}/branch_protections/priority - POST /repos/{owner}/{repo}/pulls/{index}/merge - PUT /orgs/{org}/public_members/{username} - PUT /repos/{owner}/{repo}/collaborators/{collaborator} - PUT /repos/{owner}/{repo}/topics/{topic} - PUT /user/following/{username} 💡 Schemathesis found no operation that creates this data - create it outside the test run and supply the identifiers in your config file Reachable via links, but stateful testing never reached them (110 operations): - DELETE /orgs/{org}/actions/secrets/{secretname} - DELETE /orgs/{org}/actions/variables/{variablename} - DELETE /orgs/{org}/blocks/{username} - DELETE /orgs/{org}/hooks/{id} - DELETE /orgs/{org}/members/{username} - DELETE /orgs/{org}/projects/{id} - DELETE /orgs/{org}/public_members/{username} - DELETE /packages/{owner}/{type}/{name} - DELETE /repos/{owner}/{repo} - DELETE /repos/{owner}/{repo}/actions/artifacts/{artifact_id} - DELETE /repos/{owner}/{repo}/actions/secrets/{secretname} - DELETE /repos/{owner}/{repo}/actions/variables/{variablename} - DELETE /repos/{owner}/{repo}/collaborators/{collaborator} - DELETE /repos/{owner}/{repo}/hooks/{id} - DELETE /repos/{owner}/{repo}/issues/comments/{id} - DELETE /repos/{owner}/{repo}/issues/comments/{id}/assets/{attachment_id} - DELETE /repos/{owner}/{repo}/issues/{index}/assets/{attachment_id} - DELETE /repos/{owner}/{repo}/issues/{index}/comments/{id} - DELETE /repos/{owner}/{repo}/issues/{index}/labels/{id} - DELETE /repos/{owner}/{repo}/keys/{id} - DELETE /repos/{owner}/{repo}/labels/{id} - DELETE /repos/{owner}/{repo}/projects/{id}/columns/{column_id} - DELETE /repos/{owner}/{repo}/pulls/{index}/reviews/{id} - DELETE /repos/{owner}/{repo}/releases/tags/{tag} - DELETE /repos/{owner}/{repo}/releases/{id} - DELETE /repos/{owner}/{repo}/tag_protections/{id} - DELETE /repos/{owner}/{repo}/tags/{tag} - DELETE /repos/{owner}/{repo}/topics/{topic} - DELETE /teams/{id} - DELETE /user/actions/secrets/{secretname} - DELETE /user/actions/variables/{variablename} - DELETE /user/blocks/{username} - DELETE /user/following/{username} - GET /orgs/{org}/actions/variables/{variablename} - GET /orgs/{org}/blocks/{username} - GET /orgs/{org}/hooks/{id} - GET /orgs/{org}/labels/{id} - GET /orgs/{org}/members/{username} - GET /orgs/{org}/projects/{id} - GET /orgs/{org}/projects/{id}/columns - GET /orgs/{org}/projects/{id}/columns/{column_id}/issues - GET /orgs/{org}/public_members/{username} - GET /repos/{owner}/{repo} - GET /repos/{owner}/{repo}/actions/artifacts/{artifact_id} - GET /repos/{owner}/{repo}/actions/artifacts/{artifact_id}/zip - GET /repos/{owner}/{repo}/actions/variables/{variablename} - GET /repos/{owner}/{repo}/actions/workflows/{workflow_id} - GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs - GET /repos/{owner}/{repo}/collaborators/{collaborator} - GET /repos/{owner}/{repo}/collaborators/{collaborator}/permission - GET /repos/{owner}/{repo}/commits/{sha}/pull - GET /repos/{owner}/{repo}/git/commits/{sha} - GET /repos/{owner}/{repo}/git/refs/{ref} - GET /repos/{owner}/{repo}/hooks/{id} - GET /repos/{owner}/{repo}/issues/comments/{id} - GET /repos/{owner}/{repo}/issues/comments/{id}/assets - GET /repos/{owner}/{repo}/issues/comments/{id}/reactions - GET /repos/{owner}/{repo}/issues/{index}/assets/{attachment_id} - GET /repos/{owner}/{repo}/keys - GET /repos/{owner}/{repo}/keys/{id} - GET /repos/{owner}/{repo}/projects/{id} - GET /repos/{owner}/{repo}/projects/{id}/columns - GET /repos/{owner}/{repo}/projects/{id}/columns/{column_id}/issues - GET /repos/{owner}/{repo}/pulls/{index}/reviews/{id} - GET /repos/{owner}/{repo}/pulls/{index}/reviews/{id}/comments - GET /repos/{owner}/{repo}/releases/tags/{tag} - GET /repos/{owner}/{repo}/releases/{id} - GET /repos/{owner}/{repo}/releases/{id}/assets - GET /repos/{owner}/{repo}/releases/{id}/assets/{attachment_id} - GET /repos/{owner}/{repo}/tag_protections/{id} - GET /repos/{owner}/{repo}/tags/{tag} - GET /teams/{id}/members - GET /teams/{id}/members/{username} - GET /user/actions/variables/{variablename} - GET /user/blocks/{username} - GET /user/following/{username} - GET /user/gpg_keys/{id} - PATCH /orgs/{org}/hooks/{id} - PATCH /orgs/{org}/projects/{id} - PATCH /repos/{owner}/{repo} - PATCH /repos/{owner}/{repo}/branches/{branch} - PATCH /repos/{owner}/{repo}/hooks/{id} - PATCH /repos/{owner}/{repo}/issues/comments/{id} - PATCH /repos/{owner}/{repo}/issues/{index}/comments/{id} - PATCH /repos/{owner}/{repo}/labels/{id} - PATCH /repos/{owner}/{repo}/milestones/{id} - PATCH /repos/{owner}/{repo}/projects/{id}/columns/{column_id} - PATCH /repos/{owner}/{repo}/pulls/{index} - PATCH /repos/{owner}/{repo}/releases/{id} - PATCH /repos/{owner}/{repo}/tag_protections/{id} - POST /orgs/{org}/projects/{id}/columns - POST /orgs/{org}/projects/{id}/columns/move - POST /orgs/{org}/repos - POST /repos/{owner}/{repo}/actions/workflows/{workflow_id}/dispatches - POST /repos/{owner}/{repo}/branch_protections - POST /repos/{owner}/{repo}/hooks/{id}/tests - POST /repos/{owner}/{repo}/projects/{id}/columns/move - POST /repos/{owner}/{repo}/pulls/comments/{id}/resolve - POST /repos/{owner}/{repo}/pulls/comments/{id}/unresolve - POST /repos/{owner}/{repo}/push_mirrors - PUT /orgs/{org}/actions/secrets/{secretname} - PUT /orgs/{org}/actions/variables/{variablename} - PUT /orgs/{org}/blocks/{username} - PUT /repos/{owner}/{repo}/actions/secrets/{secretname} - PUT /repos/{owner}/{repo}/actions/variables/{variablename} - PUT /repos/{owner}/{repo}/actions/workflows/{workflow_id}/disable - PUT /repos/{owner}/{repo}/actions/workflows/{workflow_id}/enable - PUT /repos/{owner}/{repo}/branches/{branch} - PUT /repos/{owner}/{repo}/contents/{filepath} - PUT /user/blocks/{username} 💡 Raise `phases.stateful.max-steps` or run longer so stateful testing reaches these operations Reached via links, but the linked data was not usable (84 operations): - DELETE /admin/actions/runners/{runner_id} - DELETE /admin/users/{username}/keys/{id} - DELETE /orgs/{org}/actions/runners/{runner_id} - DELETE /orgs/{org}/labels/{id} - DELETE /orgs/{org}/projects/{id}/columns/{column_id} - DELETE /orgs/{org}/projects/{id}/columns/{column_id}/issues/{issue_id} - DELETE /packages/{owner}/{type}/{name}/{version} - DELETE /repos/{owner}/{repo}/actions/runners/{runner_id} - DELETE /repos/{owner}/{repo}/issues/comments/{id}/reactions - DELETE /repos/{owner}/{repo}/issues/{index}/times/{id} - DELETE /repos/{owner}/{repo}/milestones/{id} - DELETE /repos/{owner}/{repo}/projects/{id} - DELETE /repos/{owner}/{repo}/projects/{id}/columns/{column_id}/issues/{issue_id} - DELETE /repos/{owner}/{repo}/releases/{id}/assets/{attachment_id} - DELETE /repos/{owner}/{repo}/teams/{team} - DELETE /teams/{id}/members/{username} - DELETE /teams/{id}/repos/{org}/{repo} - DELETE /user/actions/runners/{runner_id} - DELETE /user/keys/{id} - DELETE /user/projects/{id}/columns/{column_id} - DELETE /user/projects/{id}/columns/{column_id}/issues/{issue_id} - DELETE /users/{username}/tokens/{token} - GET /admin/actions/runners/{runner_id} - GET /label/templates/{name} - GET /notifications/threads/{id} - GET /orgs/{org}/actions/runners/{runner_id} - GET /orgs/{org}/projects/{id}/columns/{column_id} - GET /packages/{owner}/{type}/{name} - GET /packages/{owner}/{type}/{name}/-/latest - GET /packages/{owner}/{type}/{name}/{version} - GET /packages/{owner}/{type}/{name}/{version}/files - GET /repos/{owner}/{repo}/actions/jobs/{job_id} - GET /repos/{owner}/{repo}/actions/jobs/{job_id}/logs - GET /repos/{owner}/{repo}/actions/runners/{runner_id} - GET /repos/{owner}/{repo}/issues/comments/{id}/assets/{attachment_id} - GET /repos/{owner}/{repo}/labels/{id} - GET /repos/{owner}/{repo}/milestones/{id} - GET /repos/{owner}/{repo}/projects/{id}/columns/{column_id} - GET /repos/{owner}/{repo}/teams/{team} - GET /teams/{id}/repos/{org}/{repo} - GET /user/actions/runners/{runner_id} - GET /user/keys/{id} - GET /user/projects/{id}/columns/{column_id} - GET /user/projects/{id}/columns/{column_id}/issues - GET /users/{username}/following/{target} - GET /users/{username}/orgs/{org}/permissions - PATCH /admin/actions/runners/{runner_id} - PATCH /notifications/threads/{id} - PATCH /orgs/{org}/actions/runners/{runner_id} - PATCH /orgs/{org}/labels/{id} - PATCH /orgs/{org}/projects/{id}/columns/{column_id} - PATCH /repos/{owner}/{repo}/actions/runners/{runner_id} - PATCH /repos/{owner}/{repo}/issues/comments/{id}/assets/{attachment_id} - PATCH /repos/{owner}/{repo}/issues/{index} - PATCH /repos/{owner}/{repo}/issues/{index}/assets/{attachment_id} - PATCH /repos/{owner}/{repo}/projects/{id} - PATCH /repos/{owner}/{repo}/releases/{id}/assets/{attachment_id} - PATCH /user/actions/runners/{runner_id} - PATCH /user/projects/{id}/columns/{column_id} - POST /orgs/{org}/projects/{id}/columns/{column_id}/default - POST /orgs/{org}/projects/{id}/columns/{column_id}/issues/{issue_id} - POST /orgs/{org}/projects/{id}/issues/{issue_id}/move - POST /packages/{owner}/{type}/{name}/-/unlink - POST /repos/{owner}/{repo}/actions/runs/{run}/jobs/{job_id}/rerun - POST /repos/{owner}/{repo}/issues/comments/{id}/assets - POST /repos/{owner}/{repo}/issues/comments/{id}/reactions - POST /repos/{owner}/{repo}/issues/{index}/times - POST /repos/{owner}/{repo}/projects/{id}/columns - POST /repos/{owner}/{repo}/projects/{id}/columns/{column_id}/default - POST /repos/{owner}/{repo}/projects/{id}/columns/{column_id}/issues/{issue_id} - POST /repos/{owner}/{repo}/pulls/{index}/comments/{id}/replies - POST /repos/{owner}/{repo}/pulls/{index}/reviews/{id} - POST /repos/{owner}/{repo}/pulls/{index}/reviews/{id}/dismissals - POST /repos/{owner}/{repo}/pulls/{index}/reviews/{id}/undismissals - POST /repos/{owner}/{repo}/releases - POST /repos/{owner}/{repo}/releases/{id}/assets - POST /repos/{owner}/{repo}/tags - POST /repos/{owner}/{repo}/transfer - POST /user/projects/{id}/columns/move - POST /user/projects/{id}/columns/{column_id}/default - POST /user/projects/{id}/columns/{column_id}/issues/{issue_id} - PUT /repos/{owner}/{repo}/teams/{team} - PUT /teams/{id}/members/{username} - PUT /teams/{id}/repos/{org}/{repo} 💡 Check the operations that create this data - their responses do not yield usable identifiers =================================== SUMMARY ==================================== API Operations: Selected: 537/537 Tested: 537 Test Phases: ❌ Examples ❌ Coverage ❌ Fuzzing ❌ Stateful Failures: ❌ API accepts requests without authentication: 83 ❌ Server error: 32 ❌ Server error on unexpected Content-Type: 117 ❌ Unexpected response to a request without authentication: 1 ❌ Response violates schema: 157 ❌ API accepted schema-violating request: 100 ❌ API rejected schema-compliant request: 170 ❌ Invalid Allow header: 25 ❌ JSON deserialization error: 4 ❌ Missing Content-Type header: 58 ❌ Undocumented Content-Type: 67 ❌ Undocumented HTTP status code: 260 Warnings: ⚠️ Missing authentication: 4 operations returned only 401/403 responses ⚠️ Missing valid test data: 385 operations repeatedly returned 404 responses Test cases: 174058 generated, 886 found 1074 unique failures, 5 errored, 2769 skipped Seed: 168468500604608369489449774947616937683 ==================== 1074 failures, 2 warnings in 3600.02s =====================