Schemathesis v4.30.1 ━━━━━━━━━━━━━━━━━━━━ ✅ Loaded specification from http://0.0.0.0:37503/docs/openapi.json (in 0.18s) Base URL: http://0.0.0.0:37503 Specification: Open API 3.0.3 Operations: 211 selected / 211 total Configuration: /home/stranger6667/data/programming/workbench/target s/unleash/schemathesis.toml Dictionaries: 4 dictionaries / 6 entries ✅ API capabilities: Supports NULL byte in headers: ✘ Accepts backslash and control characters in URL paths: ✓ ❌ Examples (in 2.09s) ✅ 54 passed ❌ 38 failed ⏭ 119 skipped ❌ Coverage (in 22.69s) ✅ 75 passed ❌ 136 failed 🚫 Fuzzing (in 1276.45s) ✅ 76 passed ❌ 134 failed 🚫 1 error ❌ Stateful (in 166.26s) Scenarios: 7264 API Links: 110 covered / 250 selected / 250 total ✅ 6757 passed ❌ 507 failed ==================================== ERRORS ==================================== __________________________ POST /api/admin/playground __________________________ Network Error Connection failed Connection aborted. Remote end closed connection without response Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": [], "context": {"appName": "\ud9e3\ude7e1\udb9a\udc21\ud802\udc4b\u4e3f\u008d"}, "environment": "development"}' http://0.0.0.0:37503/api/admin/playground ____________________________________ Server ____________________________________ Server Unavailable http://0.0.0.0:37503 stopped responding. Last requests before it went away: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": [], "context": {"appName": "\ud9e3\ude7e1\udb9a\udc21\ud802\udc4b\u4e3f\u008d"}, "environment": "development"}' http://0.0.0.0:37503/api/admin/playground curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"context": {"appName": "My cool application."}, "environment": "development"}' http://0.0.0.0:37503/api/admin/playground curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:37503/api/admin/metrics/applications/%10 curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:37503/api/admin/metrics/applications/K%F1%A9%B2%97%F3%AB%8B%A3%C3%A4%C3%96T%5B%C2%B2%C2%9F curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:37503/api/admin/metrics/applications/%C2%80%C2%B3 Tip: If the server crashed, the request that caused it may be older than these. Record every request sent with `--report=har`. Need more help? Join our Discord server: https://discord.gg/R9ASRAmHnA =================================== FAILURES =================================== ___________________ DELETE /api/admin/context/{contextField} ___________________ 1. Test Case ID: 3QOIkw - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"Could not find context field with name 0","details":[{"message":"Could not find context field with name 0"}]}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/context/0 ______ DELETE /api/admin/context/{contextField}/legal-values/{legalValue} ______ 1. Test Case ID: hLo9Ap - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"Could not find context field with name 0","details":[{"message":"Could not find context field with name 0"}]}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/context/0/legal-values/0 __________ DELETE /api/admin/projects/{projectId}/api-tokens/{token} ___________ 1. Test Case ID: ygQ2ZM - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `application/json` [404] Not Found: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/api-tokens/0 ________ DELETE /api/admin/projects/{projectId}/context/{contextField} _________ 1. Test Case ID: lnByaE - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"Could not find context field 0 in project 0","details":[{"message":"Could not find context field 0 in project 0"}]}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/0/context/0 DELETE /api/admin/projects/{projectId}/context/{contextField}/legal-values/{legalValue} 1. Test Case ID: mYITxV - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"Could not find context field 0 in project 0","details":[{"message":"Could not find context field 0 in project 0"}]}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/0/context/0/legal-values/0 _______________ DELETE /api/admin/projects/{projectId}/favorites _______________ 1. Test Case ID: bkW7GF - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 415 Documented: 200, 401, 404 [415] Unsupported Media Type: `{"id":"09e0eecd-c220-49b8-b8f5-691bca0e0f8c","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/favorites ___ DELETE /api/admin/projects/{projectId}/features/{featureName}/favorites ____ 1. Test Case ID: NTxP05 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 415 Documented: 200, 401, 404 [415] Unsupported Media Type: `{"id":"0d4711c3-9182-4924-902d-7bb69fb57864","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/favorites _______________________ DELETE /api/admin/segments/{id} ________________________ 1. Test Case ID: EatDOp - Undocumented HTTP status code Received: 400 Documented: 204, 401, 403, 409 [400] Bad Request: `{"id":"f2e55a7e-0478-479a-ba71-ef5ab9378aa5","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/params/id` property must be integer. You sent \"null,null\".","path":"/params/id"}]}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments/null%2Cnull _____________________ DELETE /api/admin/strategies/{name} ______________________ 1. Test Case ID: 1y2eMp - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"Cannot edit strategy remoteAddress","details":[{"message":"Cannot edit strategy remoteAddress"}]}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/strategies/remoteAddress ______________________ DELETE /api/admin/user-admin/{id} _______________________ 1. Test Case ID: i46HFy - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"id":"0cc8ae4e-5657-45cb-895b-d24192b9bb0c","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/params/id` property must be integer. You sent \"null,null\".","path":"/params/id"}]}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/null%2Cnull ______________________ DELETE /api/admin/user/tokens/{id} ______________________ 1. Test Case ID: e48kfc - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"id":"725f9e34-a2c3-4c94-89d2-13cc85d26cd7","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/params/id` property must be integer. You sent \"null,null\".","path":"/params/id"}]}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user/tokens/null%2Cnull 2. Test Case ID: U6Pvy9 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"Undefined binding(s) detected when compiling DEL. Undefined column(s): [user_id] query: delete from \"personal_access_tokens\" where \"id\" = ? and \"user_id\" = ? returning \"id\", \"description\", \"user_id\", \"expires_at\", \"created_at\", \"seen_at\", \"selector\"","details":[{"message":"Undefined binding(s) detected when compiling DEL. Undefined column(s): [user_id] query: delete from \"personal_access_tokens\" where \"id\" = ? and \"user_id\" = ? returning \"id\", \" // Output truncated...` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user/tokens/0 __________________________ GET /api/admin/addons/{id} __________________________ 1. Test Case ID: WHU5WI - Undocumented HTTP status code Received: 404 Documented: 200, 401 [404] Not Found: `{"name":"NotFoundError","message":"Could not find addon","details":[{"message":"Could not find addon"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/addons/0 2. Test Case ID: P9J3rd - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"id\", \"provider\", \"enabled\", \"description\", \"parameters\", \"events\", \"projects\", \"environments\", \"created_at\" from \"addons\" where \"id\" = $1 limit $2 - invalid input syntax for type integer: \"01M4JVFJEDT0SXVDDAX6RTGA6B\"","details":[{"message":"select \"id\", \"provider\", \"enabled\", \"description\", \"parameters\", \"events\", \"projects\", \"environments\", \"created_at\" from \"addons\" where \"id\" = $1 limit $2 - invalid input syntax for t // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/addons/01M4JVFJEDT0SXVDDAX6RTGA6B ______________________ GET /api/admin/addons/{id}/events _______________________ 1. Test Case ID: g5nEyo - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Invalid integration configuration id","details":[{"message":"Invalid integration configuration id"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/addons/01M4JVFJEDT0SXVDDAX6RTGA6B/events ____________________ GET /api/admin/context/{contextField} _____________________ 1. Test Case ID: gqQ0rI - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"Could not find context field","details":[{"message":"Could not find context field"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/context/0 ____________________________ GET /api/admin/events _____________________________ 1. Test Case ID: fUxPxP - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `{"name":"UnknownError","message":"select count(*) from \"events\" where \"project\" in ($1) limit $2 - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select count(*) from \"events\" where \"project\" in ($1) limit $2 - invalid byte sequence for encoding \"UTF8\": 0x00"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/events?project=%C3%9D%7F%00' ___________________ GET /api/admin/instance-admin/statistics ___________________ 1. Test Case ID: 7ek5DF - Response violates schema Additional properties are not allowed ('serviceAccounts', 'archivedFeatureToggles', 'customRootRoles', 'customRootRolesInUse', 'passwordAuthEnabled', 'SCIMenabled' were unexpected) Validated against the response schema for status code 200. Schema: { "additionalProperties": false, "type": "object", "description": "Information about an instance and statistics about usage ... "required": [ "instanceId" ], "properties": { "instanceId": { "type": "string", "description": "A unique identifier for this instance. Generated ... "example": "ed3861ae-78f9-4e8c-8e57-b57efc15f82b" }, "timestamp": { "anyOf": [ { "type": "string", "format": "date-time", "description": "When these statistics were produced", // Output truncated... } Value: { "OIDCenabled": false, "SAMLenabled": false, "SCIMenabled": false, "activeUsers": { "last30": 0, "last60": 0, "last7": 0, "last90": 0 }, "apiTokens": { "admin": 1, "client": 1, "frontend": 7 }, "archivedFeatureToggles": 1, "clientApps": [ { "count": 0, // Output truncated... } [200] OK: `{"timestamp":"2026-10-10T12:09:42.768Z","instanceId":"c754ed7a-9136-4114-96a4-d305ee1169b2","versionOSS":"8.2.0","versionEnterprise":"","users":3,"serviceAccounts":0,"apiTokens":{"client":1,"admin":1,"frontend":7},"activeUsers":{"last7":0,"last30":0,"last60":0,"last90":0},"licensedUsers":2,"featureToggles":3,"archivedFeatureToggles":1,"projects":1,"contextFields":7,"roles":6,"customRootRoles":0,"customRootRolesInUse":0,"groups":0,"environments":2,"segments":4,"strategies":8,"SAMLenabled":false,"OIDCenabled" // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/instance-admin/statistics __________________ GET /api/admin/invite-link/tokens/{token} ___________________ 1. Test Case ID: bjHmq9 - Undocumented HTTP status code Received: 404 Documented: 200, 401, 403 [404] Not Found: `{"name":"NotFoundError","message":"Could not find public signup token.","details":[{"message":"Could not find public signup token."}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/invite-link/tokens/0 __________________________ GET /api/admin/maintenance __________________________ 1. Test Case ID: IBfBdO - Response violates schema Additional properties are not allowed ('5{6 … ¿', 'operations' were unexpected) Validated against the response schema for status code 200. Schema: { "additionalProperties": false, "type": "object", "description": "The current state of Unleash's maintenance mode feature.", "required": [ "enabled" ], "properties": { "enabled": { "description": "Whether maintenance mode is enabled or not.", "type": "boolean", "example": true } } } Value: { "5{6 \u0085\u00bf": [], "enabled": false, "operations": 65659714443277410 } [200] OK: `{"5{6 … ¿":[],"operations":65659714443277410,"enabled":false}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/maintenance _____________________ GET /api/admin/metrics/applications ______________________ 1. Test Case ID: N5XpsR - Response violates schema (2 violations) Additional properties are not allowed ('createdAt', 'updatedAt', 'createdBy', 'project', 'environment' were unexpected) Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema: { "additionalProperties": false, "type": "object", "description": "Data about an application that's connected to Unleash via... "required": [ "appName" ], "properties": { "appName": { "description": "Name of the application", "type": "string", "example": "accounting" }, "sdkVersion": { "description": "Which SDK and version the application reporting u... "type": "string", "example": "unleash-client-java:8.0.0" }, "strategies": { // Output truncated... } Value: { "appName": "0", "color": "red", "createdAt": "2026-10-10T12:09:25.192Z", "createdBy": null, "description": null, "environment": "*", "icon": "https://github.com/favicon.ico", "project": "*", "strategies": [ "standard", "gradualRollout", "mySpecialCustomStrategy" ], "updatedAt": "2026-10-10T12:09:39.315Z", "url": "https://github.com/Unleash/unleash-proxy-client-js", "usage": [ { "environments": [ // Output truncated... } null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema/properties/description: { "type": "string", "description": "Extra information added about the application reporting t... "example": "Application for reporting page visits" } Value: null [200] OK: `{"applications":[{"appName":"0","createdAt":"2026-10-10T12:09:25.192Z","updatedAt":"2026-10-10T12:09:39.315Z","description":null,"strategies":["standard","gradualRollout","mySpecialCustomStrategy"],"createdBy":null,"url":"https://github.com/Unleash/unleash-proxy-client-js","color":"red","icon":"https://github.com/favicon.ico","project":"*","environment":"*","usage":[{"project":"*","environments":["*"]}]}],"total":1}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/metrics/applications?sortOrder=desc' 2. Test Case ID: f3KiBs - Response violates schema (3 violations) null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema/properties/color: { "type": "string", "description": "The CSS color that is used to color the application's ent... "example": "red" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema/properties/icon: { "type": "string", "description": "An URL to an icon file to be used for the applications's ... "example": "https://github.com/favicon.ico" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema/properties/url: { "type": "string", "description": "A link to reference the application reporting the metrics... "example": "https://github.com/Unleash/unleash-proxy-client-js" } Value: null [200] OK: `{"applications":[{"appName":"0","createdAt":"2026-10-10T12:10:15.158Z","updatedAt":"2026-10-10T12:10:16.002Z","description":null,"strategies":[],"createdBy":null,"url":null,"color":null,"icon":null,"project":"*","environment":"*","usage":[{"project":"*","environments":["*"]}]},{"appName":"00","createdAt":"2026-10-10T12:10:15.238Z","updatedAt":"2026-10-10T12:10:16.041Z","description":null,"strategies":["ʼn񳭐ª󿄒\u0016‘ùHÄ\t×U¤򰁃l<¤!o","🤖%o򎆵󶢧\ta󳾄å‡ÜÕ\u0014񺛬<","Rç©񲬀㗜","","5O","ÈÓ÷|Â","","񇊬","*¿\u001f򓬜¡Ô","failures // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/metrics/applications ________________ GET /api/admin/metrics/applications/{appName} _________________ 1. Test Case ID: QCuxzK - Response violates schema (3 violations) Additional properties are not allowed ('createdAt', 'instances', 'seenToggles', 'links' were unexpected) Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema: { "additionalProperties": false, "type": "object", "description": "Data about an application that's connected to Unleash via... "required": [ "appName" ], "properties": { "appName": { "description": "Name of the application", "type": "string", "example": "accounting" }, "sdkVersion": { "description": "Which SDK and version the application reporting u... "type": "string", "example": "unleash-client-java:8.0.0" }, "strategies": { // Output truncated... } Value: { "appName": "0", "color": "red", "createdAt": "2026-10-10T12:09:25.192Z", "description": null, "icon": "https://github.com/favicon.ico", "instances": [], "links": { "self": "/api/applications/0" }, "seenToggles": [], "strategies": [ { "name": "standard", "notFound": true }, { "name": "gradualRollout", "notFound": true // Output truncated... } null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema/properties/description: { "type": "string", "description": "Extra information added about the application reporting t... "example": "Application for reporting page visits" } Value: null {"name":"standard","notFound":true} is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema/properties/strategies/items: { "type": "string" } Value: { "name": "standard", "notFound": true } [200] OK: `{"appName":"0","createdAt":"2026-10-10T12:09:25.192Z","description":null,"url":"https://github.com/Unleash/unleash-proxy-client-js","color":"red","icon":"https://github.com/favicon.ico","strategies":[{"name":"standard","notFound":true},{"name":"gradualRollout","notFound":true},{"name":"mySpecialCustomStrategy","notFound":true}],"instances":[],"seenToggles":[],"links":{"self":"/api/applications/0"}}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/metrics/applications/0 2. Test Case ID: LOzNWp - Response violates schema (3 violations) null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema/properties/color: { "type": "string", "description": "The CSS color that is used to color the application's ent... "example": "red" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema/properties/icon: { "type": "string", "description": "An URL to an icon file to be used for the applications's ... "example": "https://github.com/favicon.ico" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/applicationSchema/properties/url: { "type": "string", "description": "A link to reference the application reporting the metrics... "example": "https://github.com/Unleash/unleash-proxy-client-js" } Value: null [200] OK: `{"appName":"0","createdAt":"2026-10-10T12:10:15.158Z","description":null,"url":null,"color":null,"icon":null,"strategies":[],"instances":[],"seenToggles":[],"links":{"self":"/api/applications/0"}}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/metrics/applications/0 ______________________ GET /api/admin/personal-dashboard _______________________ 1. Test Case ID: lw4QPP - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"Undefined binding(s) detected when compiling SELECT. Undefined column(s): [features.created_by_user_id] query: select \"name\", \"type\", \"project\", \"created_at\" from \"features\" where \"features\".\"created_by_user_id\" = ? and \"features\".\"archived_at\" is null","details":[{"message":"Undefined binding(s) detected when compiling SELECT. Undefined column(s): [features.created_by_user_id] query: select \"name\", \"type\", \"project\", \"created_at\" from \"features\" // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/personal-dashboard ________________ GET /api/admin/personal-dashboard/{projectId} _________________ 1. Test Case ID: Z4Q9EO - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"Undefined binding(s) detected when compiling SELECT. Undefined column(s): [gu.user_id] query: select \"id\", \"name\", \"type\", \"project\", \"description\" from \"roles\" inner join \"group_role\" as \"gr\" on \"gr\".\"role_id\" = \"id\" inner join \"group_user\" as \"gu\" on \"gu\".\"group_id\" = \"gr\".\"group_id\" where \"gu\".\"user_id\" = ? and (\"gr\".\"project\" = ? or \"type\" = ?)","details":[{"message":"Undefined binding(s) detected when compiling SELECT. Undefi // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/personal-dashboard/default ___________________________ GET /api/admin/projects ____________________________ 1. Test Case ID: 2IMBQO - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403 [400] Bad Request: `{"id":"2f1ba350-123a-45a9-b32b-72dd5f07aa2f","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/query/archived` property must be boolean. You sent [\"null\",\"null\"].","path":"/query/archived"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/projects?archived=null&archived=null' __________ GET /api/admin/projects/{projectId}/context/{contextField} __________ 1. Test Case ID: zrHAvf - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"Could not find context field","details":[{"message":"Could not find context field"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/context/region _________________ GET /api/admin/projects/{projectId}/features _________________ 1. Test Case ID: JDzbNn - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403 [500] Internal Server Error: `{"name":"UnknownError","message":"Cannot read properties of undefined (reading 'some')","details":[{"message":"Cannot read properties of undefined (reading 'some')"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features __________ GET /api/admin/projects/{projectId}/features/{featureName} __________ 1. Test Case ID: E2AnD7 - Response violates schema (4 violations) null is not of type "boolean" Validated against the response schema for status code 200. Schema at /components/schemas/featureEnvironmentSchema/properties/enabled: { "type": "boolean", "example": true, "description": "`true` if the feature is enabled for the environment, oth... } Value: null null is not of type "number" Validated against the response schema for status code 200. Schema at /components/schemas/featureEnvironmentSchema/properties/sortOrder: { "type": "number", "example": 3, "description": "The sort order of the feature environment in the feature ... } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/featureEnvironmentSchema/properties/name: { "type": "string", "example": "my-dev-env", "description": "The name of the environment" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/featureEnvironmentSchema/properties/type: { "type": "string", "example": "development", "description": "The type of the environment" } Value: null [200] OK: `{"environments":[{"name":null,"lastSeenAt":null,"enabled":null,"yes":0,"no":0,"type":null,"sortOrder":null,"strategies":[]}],"name":"search","impressionData":false,"description":null,"project":"default","stale":false,"createdAt":"2026-10-10T12:09:24.165Z","createdBy":{"id":-42,"name":"Unleash Admin Token User","imageUrl":"https://gravatar.com/avatar/3dc16570162d3b0b99d893698516645520622ab41162256213fb7b04eb969d84?s=42&d=retro&r=g"},"type":"operational","archived":false,"dependencies":[],"children":[],"lifec // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features/search GET /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/strategies/{strategyId} 1. Test Case ID: x88crB - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `application/json` [403] Forbidden: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features/search/environments/production/strategies/01M4JVFJCS0AKVHVVQ6964N1BX ______________ GET /api/admin/projects/{projectId}/health-report _______________ 1. Test Case ID: RlAXvN - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"Cannot read properties of undefined (reading 'some')","details":[{"message":"Cannot read properties of undefined (reading 'some')"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/health-report _________________ GET /api/admin/projects/{projectId}/insights _________________ 1. Test Case ID: uW897U - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"Cannot read properties of undefined (reading 'some')","details":[{"message":"Cannot read properties of undefined (reading 'some')"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/insights _________________________ GET /api/admin/search/events _________________________ 1. Test Case ID: Bg4F2q - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"id":"5b457201-29b3-4fab-ad9f-5aa0a6dd8a56","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/query/type` property must match pattern \"^(IS|IS_ANY_OF):(.*?)(,([a-zA-Z0-9_]+))*$\". You sent \"\".","path":"/query/type"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/search/events?type=' 2. Test Case ID: dIBcrD - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"id":"53ef18f2-d220-49b3-a01c-77d002832cba","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/query/project` property must match pattern \"^(IS|IS_ANY_OF):(.*?)(,([a-zA-Z0-9_]+))*$\". You sent \"IS_ANY_OF:ô\\ráۇû󲕛Ð\\u0019\\u0007–󍯏¾Þ𒣡Äì)cӇü򎑁¼ÿ˹ì+񠩪𾫰,0\".","path":"/query/project"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/search/events?project=IS_ANY_OF%3A%C3%B4%0D%C3%A1%C3%9B%C2%87%C3%BB%F3%B2%95%9B%C3%90%19%07%C2%96%F3%8D%AF%8F%C2%BE%C3%9E%F0%92%A3%A1%C3%84%C3%AC%29c%C3%93%C2%87%C3%BC%F2%8E%91%81%C2%BC%C3%BF%C3%8B%C2%B9%C3%AC%2B%F1%A0%A9%AA%F0%BE%AB%B0%2C0' 3. Test Case ID: a0htTG - Server error - Undocumented HTTP status code Received: 500 Documented: 200 [500] Internal Server Error: `{"name":"UnknownError","message":"Invalid time value","details":[{"message":"Invalid time value"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/search/events?environment=IS%3A%2C0%2C_%2C0%2Cv0&limit=&to=IS%3A0000-90-00&type=IS%3A' ________________________ GET /api/admin/search/features ________________________ 1. Test Case ID: tAQyoH - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"id":"70b52d8f-e3cb-4d3a-b6e8-fc4549e30880","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/query/status` property must be array. You sent \"production:enabled\".","path":"/query/status"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/search/features?query=feature_a&project=IS%3Adefault&state=IS%3Aactive&lifecycle=IS%3Ainitial&type=IS%3Arelease&createdBy=IS%3A1&tag=INCLUDE%3Asimple%3Amy_tag&segment=INCLUDE%3Apro-users&offset=50&limit=50&sortBy=type&sortOrder=desc&favoritesFirst=true&archived=IS%3Atrue&favorite=IS%3Atrue&createdAt=IS_ON_OR_AFTER%3A2023-01-28&lastSeenAt=IS_ON_OR_AFTER%3A2023-01-28&status=production%3Aenabled' 2. Test Case ID: 3cXZ93 - Undocumented HTTP status code Received: 429 Documented: 200, 401, 403, 404 [429] Too Many Requests: `Too many requests, please try again later.` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/search/features?createdBy=IS%3A1&archived=IS%3Atrue&createdAt=IS_ON_OR_AFTER%3A2023-01-28' 3. Test Case ID: aWjgol - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"with \"ranked_features\" as (select \"features\".\"name\" as \"feature_name\", \"features\".\"description\" as \"description\", \"features\".\"type\" as \"type\", \"features\".\"archived_at\" as \"archived_at\", \"features\".\"project\" as \"project\", \"features\".\"created_at\" as \"created_at\", \"features\".\"stale\" as \"stale\", \"features\".\"impression_data\" as \"impression_data\", \"feature_environments\".\"enabled\" as \"enabled\", \"feature_environments\".\"envi // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/search/features?createdAt=IS_BEFORE%3A0102-04-08&favoritesFirst=6&lastSeenAt=IS_BEFORE%3A6010-50-00&offset=&query=4&segment=INCLUDE%3A&sortBy=' _________________________ GET /api/admin/segments/{id} _________________________ 1. Test Case ID: U8iBls - Undocumented HTTP status code Received: 400 Documented: 200, 404 [400] Bad Request: `{"id":"33f957e3-a778-4d97-b44f-311a6b53e6cd","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/params/id` property must be integer. You sent \"null,null\".","path":"/params/id"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments/null%2Cnull 2. Test Case ID: 5Dpyit - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"segments\".\"id\", \"segments\".\"name\", \"segments\".\"description\", \"segments\".\"segment_project_id\", \"segments\".\"created_by\", \"segments\".\"created_at\", \"segments\".\"constraints\" from \"segments\" where \"id\" = $1 - value \"17179869185\" is out of range for type integer","details":[{"message":"select \"segments\".\"id\", \"segments\".\"name\", \"segments\".\"description\", \"segments\".\"segment_project_id\", \"segments\".\"created_by\", \"segment // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments/17179869185 ___________________ GET /api/admin/segments/{id}/strategies ____________________ 1. Test Case ID: k1eJzM - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"id":"bad4db2a-e915-4710-9d98-788504c20500","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/params/id` property must be integer. You sent \"null,null\".","path":"/params/id"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments/null%2Cnull/strategies 2. Test Case ID: wb551M - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"No segment exists with ID \"0\"","details":[{"message":"No segment exists with ID \"0\""}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments/0/strategies 3. Test Case ID: Sp7b08 - Server error - Undocumented HTTP status code Received: 500 Documented: 200 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"segments\".\"id\", \"segments\".\"name\", \"segments\".\"description\", \"segments\".\"segment_project_id\", \"segments\".\"created_by\", \"segments\".\"created_at\", \"segments\".\"constraints\" from \"segments\" where \"id\" = $1 - value \"119003686398\" is out of range for type integer","details":[{"message":"select \"segments\".\"id\", \"segments\".\"name\", \"segments\".\"description\", \"segments\".\"segment_project_id\", \"segments\".\"created_by\", \"segmen // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments/119003686398/strategies ___________________________ GET /api/admin/tag-types ___________________________ 1. Test Case ID: HvaAKk - Response violates schema null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/tagTypeSchema/properties/description: { "type": "string", "description": "The description of the tag type.", "example": "A tag type for describing the color of a tag." } Value: null [200] OK: `{"version":1,"tagTypes":[{"name":"team","description":"Seeded","icon":null,"color":null},{"name":"color","description":"A tag type for describing the color of a tag.","icon":"not-really-used","color":"#FFFFFF"},{"name":"false","description":"A tag type for describing the color of a tag.","icon":"not-really-used","color":"#FFFFFF"},{"name":"new-feature","description":"Enable the feature for users who have not logged in before.","icon":null,"color":"#FFFFFF"},{"name":"my-custom-strategy","description":null,"i // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/tag-types _______________________ GET /api/admin/tag-types/{name} ________________________ 1. Test Case ID: skQ8wH - Response violates schema (2 violations) "name" is a required property Validated against the response schema for status code 200. Schema: { "required": [ "name" ], "type": "object", "additionalProperties": false, "description": "A tag type.", "properties": { "name": { "type": "string", "description": "The name of the tag type.", "example": "color" }, "description": { "type": "string", "description": "The description of the tag type.", "example": "A tag type for describing the color of a tag." }, "icon": { // Output truncated... } Value: { "tagType": { "color": "#FFFFFF", "description": "A tag type for describing the color of a tag.", "icon": "not-really-used", "name": "color" }, "version": 1 } Additional properties are not allowed ('version', 'tagType' were unexpected) Validated against the response schema for status code 200. Schema: { "additionalProperties": false, "type": "object", "description": "A tag type.", "required": [ "name" ], "properties": { "name": { "type": "string", "description": "The name of the tag type.", "example": "color" }, "description": { "type": "string", "description": "The description of the tag type.", "example": "A tag type for describing the color of a tag." }, "icon": { // Output truncated... } Value: { "tagType": { "color": "#FFFFFF", "description": "A tag type for describing the color of a tag.", "icon": "not-really-used", "name": "color" }, "version": 1 } [200] OK: `{"version":1,"tagType":{"name":"color","description":"A tag type for describing the color of a tag.","icon":"not-really-used","color":"#FFFFFF"}}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/tag-types/color 2. Test Case ID: MLQUrf - Undocumented HTTP status code Received: 404 Documented: 200, 401, 403 [404] Not Found: `{"name":"NotFoundError","message":"Could not find tag-type","details":[{"message":"Could not find tag-type"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/tag-types/%F3%83%BC%8E%C2%86%3C%C2%A4%2B _____________________________ GET /api/admin/user ______________________________ 1. Test Case ID: JeqLll - Response violates schema (2 violations) "id" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/userSchema: { "required": [ "id" ], "type": "object", "additionalProperties": false, "description": "An Unleash user", "properties": { "id": { "description": "The user id", "type": "integer", "example": 123 }, "name": { "anyOf": [ { "description": "Name of the user", "type": "string", "example": "User" // Output truncated... } Value: { "environment": "*", "internalAdminTokenUserId": -42, "permissions": [ "ADMIN" ], "projects": [ "*" ], "secret": "*:*.workbench0000000000000000000000000000000000000000000000", "type": "admin", "username": "admin" } Additional properties are not allowed ('environment', 'type', 'secret', 'projects', 'internalAdminTokenUserId' were unexpected) Validated against the response schema for status code 200. Schema at /components/schemas/userSchema: { "additionalProperties": false, "type": "object", "description": "An Unleash user", "required": [ "id" ], "properties": { "id": { "description": "The user id", "type": "integer", "example": 123 }, "name": { "anyOf": [ { "description": "Name of the user", "type": "string", "example": "User" // Output truncated... } Value: { "environment": "*", "internalAdminTokenUserId": -42, "permissions": [ "ADMIN" ], "projects": [ "*" ], "secret": "*:*.workbench0000000000000000000000000000000000000000000000", "type": "admin", "username": "admin" } [200] OK: `{"user":{"username":"admin","permissions":["ADMIN"],"environment":"*","type":"admin","secret":"*:*.workbench0000000000000000000000000000000000000000000000","projects":["*"],"internalAdminTokenUserId":-42},"permissions":[{"permission":"ADMIN"}],"feedback":[],"splash":{}}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user _______________________ GET /api/admin/user-admin/search _______________________ 1. Test Case ID: OPQ5Hr - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"id\", \"name\", \"username\", \"email\", \"image_url\", \"seen_at\", \"is_service\", \"scim_id\", \"seat_type\", \"company_role\", \"product_updates_email_consent\" from \"users\" where \"deleted_at\" is null and \"is_service\" = $1 and \"is_system\" = $2 and \"name\" ilike $3 or \"username\" ilike $4 or \"email\" ilike $5 - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select \"id\", \"name\", \"username\", \"email\", \"image_url\", \"s // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/user-admin/search?q=-%00%3By%40N%F3%85%A9%B3%0Du%09%C3%9B%C3%A3%C3%8C%C2%AER%C3%82%C3%9Fi%C3%92lg' ________________________ GET /api/admin/user-admin/{id} ________________________ 1. Test Case ID: frGN3H - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"select * from \"users\" where \"deleted_at\" is null and \"is_service\" = $1 and \"is_system\" = $2 and \"id\" = $3 limit $4 - value \"8911197249\" is out of range for type integer","details":[{"message":"select * from \"users\" where \"deleted_at\" is null and \"is_service\" = $1 and \"is_system\" = $2 and \"id\" = $3 limit $4 - value \"8911197249\" is out of range for type integer"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/8911197249 _________________________ GET /api/admin/user/profile __________________________ 1. Test Case ID: 0yhYCw - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: User id is missing in request user object","details":[{"message":"User id is missing in request user object"}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user/profile __________________________ GET /api/admin/user/roles ___________________________ 1. Test Case ID: VLrMtc - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403 [500] Internal Server Error: `{"name":"UnknownError","message":"Undefined binding(s) detected when compiling SELECT. Undefined column(s): [gu.user_id] query: select \"id\", \"name\", \"type\", \"project\", \"description\" from \"roles\" inner join \"group_role\" as \"gr\" on \"gr\".\"role_id\" = \"id\" inner join \"group_user\" as \"gu\" on \"gu\".\"group_id\" = \"gr\".\"group_id\" where \"gu\".\"user_id\" = ? and (\"gr\".\"project\" = ? or \"type\" = ?)","details":[{"message":"Undefined binding(s) detected when compiling SELECT. Undefi // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/user/roles?projectId=project-y' 2. Test Case ID: waaXM3 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403 [400] Bad Request: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user/roles ___________________________ GET /api/client/features ___________________________ 1. Test Case ID: uGnOwO - Undocumented HTTP status code Received: 403 Documented: 200 [403] Forbidden: `{"message":"invalid token: expected a different token type for this endpoint"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/client/features ____________________ GET /api/client/features/{featureName} ____________________ 1. Test Case ID: Y4Jy0e - Undocumented HTTP status code Received: 403 Documented: 200 [403] Forbidden: `{"message":"invalid token: expected a different token type for this endpoint"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/client/features/0 ______________________________ GET /api/frontend _______________________________ 1. Test Case ID: 6BWnB0 - Undocumented HTTP status code Received: 403 Documented: 200, 401, 404 [403] Forbidden: `{"message":"invalid token: expected a different token type for this endpoint"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/frontend _________________________________ GET /health __________________________________ 1. Test Case ID: v6lxDI - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /health` [200] OK: `{"health":"GOOD"}` Reproduce with: curl -X GET http://0.0.0.0:37503/health __________________________ GET /invite/{token}/signup __________________________ 1. Test Case ID: FzjT2v - Unsupported methods Unsupported method GET returned 200, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [200] OK: ` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/invite/0/validate __________________________________ GET /ready __________________________________ 1. Test Case ID: SdejFC - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /ready` [200] OK: `{"health":"GOOD"}` Reproduce with: curl -X GET http://0.0.0.0:37503/ready _____________________ OPTIONS /api/admin/api-tokens/{name} _____________________ 1. Test Case ID: 9OICkC - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, PUT List exactly the methods this resource supports in `Allow` [200] OK: `GET,HEAD,PUT,DELETE` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/api-tokens/0 ____________________ OPTIONS /api/admin/api-tokens/{token} _____________________ 1. Test Case ID: sLj0mg - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [200] OK: `GET,HEAD,PUT,DELETE` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"expiresAt": "2023-09-04T11:26:24+02:00"}' http://0.0.0.0:37503/api/admin/api-tokens/0 _____________________ OPTIONS /api/admin/context/validate ______________________ 1. Test Case ID: GYZOBY - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PUT List exactly the methods this resource supports in `Allow` [200] OK: `GET,HEAD,PUT,DELETE,POST` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "betaUser"}' http://0.0.0.0:37503/api/admin/context/validate __________________ OPTIONS /api/admin/environments/sort-order __________________ 1. Test Case ID: XFnXto - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [200] OK: `GET,HEAD,PUT` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:37503/api/admin/environments/sort-order ___________ OPTIONS /api/admin/projects/{projectId}/context/validate ___________ 1. Test Case ID: x1fC0k - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PUT List exactly the methods this resource supports in `Allow` [200] OK: `GET,HEAD,PUT,DELETE,POST` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "betaUser"}' http://0.0.0.0:37503/api/admin/projects/default/context/validate OPTIONS /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/strategies/set-sort-order 1. Test Case ID: h4VNNc - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PATCH, PUT List exactly the methods this resource supports in `Allow` [200] OK: `GET,HEAD,POST,PUT,PATCH,DELETE` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"id": "9c40958a-daac-400e-98fb-3bb438567008", "sortOrder": 1}]' http://0.0.0.0:37503/api/admin/projects/0/features/checkout/environments/0/strategies/set-sort-order ____________________ OPTIONS /api/admin/segments/strategies ____________________ 1. Test Case ID: CaTkQ4 - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PUT List exactly the methods this resource supports in `Allow` [200] OK: `POST,DELETE,PUT,GET,HEAD` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"projectId": "red-vista", "strategyId": "15d1e20b-6310-4e17-a0c2-9fb84de3053a", "environmentId": "development", "segmentIds": [1, 5, 6]}' http://0.0.0.0:37503/api/admin/segments/strategies _____________________ OPTIONS /api/admin/segments/validate _____________________ 1. Test Case ID: FvqNbg - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PUT List exactly the methods this resource supports in `Allow` [200] OK: `POST,DELETE,PUT,GET,HEAD` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "betaUser"}' http://0.0.0.0:37503/api/admin/segments/validate ____________________ OPTIONS /api/admin/tag-types/validate _____________________ 1. Test Case ID: NG1fRI - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PUT List exactly the methods this resource supports in `Allow` [200] OK: `POST,GET,HEAD,PUT,DELETE` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#000000", "description": "A tag type for describing the color of a tag.", "icon": null, "name": "color"}' http://0.0.0.0:37503/api/admin/tag-types/validate _____________________ OPTIONS /api/admin/user-admin/access _____________________ 1. Test Case ID: QqLC1w - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, PUT List exactly the methods this resource supports in `Allow` [200] OK: `GET,HEAD,PUT,DELETE` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/access __________________ OPTIONS /api/admin/user-admin/admin-count ___________________ 1. Test Case ID: EJFSvW - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, PUT List exactly the methods this resource supports in `Allow` [200] OK: `GET,HEAD,PUT,DELETE` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/admin-count _________________ OPTIONS /api/admin/user-admin/reset-password _________________ 1. Test Case ID: qylJ3q - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PUT List exactly the methods this resource supports in `Allow` [200] OK: `POST,GET,HEAD,PUT,DELETE` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": "user@example.com"}' http://0.0.0.0:37503/api/admin/user-admin/reset-password ___________________ OPTIONS /api/admin/user-admin/scim-users ___________________ 1. Test Case ID: o3d1O9 - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET, PUT List exactly the methods this resource supports in `Allow` [200] OK: `GET,HEAD,PUT,DELETE` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/scim-users _____________________ OPTIONS /api/admin/user-admin/search _____________________ 1. Test Case ID: 4sG7vG - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, PUT List exactly the methods this resource supports in `Allow` [200] OK: `GET,HEAD,PUT,DELETE` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/user-admin/search?q=' _______________ OPTIONS /api/admin/user-admin/validate-password ________________ 1. Test Case ID: FQ5py6 - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE, GET, PUT List exactly the methods this resource supports in `Allow` [200] OK: `POST,GET,HEAD,PUT,DELETE` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"confirmPassword": "[Filtered]", "oldPassword": "[Filtered]", "password": "[Filtered]"}' http://0.0.0.0:37503/api/admin/user-admin/validate-password ______________________ PATCH /api/admin/context/validate _______________________ 1. Test Case ID: m7zhHr - Unsupported methods Unsupported method PATCH returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"82319577-4332-4a5c-928a-808d5a7876bb","name":"NotFoundError","message":"The path you were looking for (/api/admin/context/validate) is not available.","details":[{"message":"The path you were looking for (/api/admin/context/validate) is not available."}]}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "betaUser"}' http://0.0.0.0:37503/api/admin/context/validate _________ PATCH /api/admin/projects/{projectId}/features/{featureName} _________ 1. Test Case ID: 9yTbfi - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404, 415 [400] Bad Request: `{"id":"9d18da06-8973-4e73-a40d-2153903c36f6","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/0/from` property must be string. You sent {}.","path":"/body/0/from"}]}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"path": "/type", "op": "replace", "from": {}, "value": "kill-switch"}]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout 2. Test Case ID: MEobTR - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - array with invalid items: from: Incorrect type [200] OK: `{"name":"checkout","description":"Controls disabling of the comments section in case of an incident","type":"kill-switch","project":"default","stale":true,"createdAt":"2026-10-10T12:09:24.071Z","impressionData":false,"archivedAt":"2026-10-10T12:09:49.302Z","archived":true}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"path": "/type", "op": "replace", "from": null, "value": "kill-switch"}]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout 3. Test Case ID: qpKe3h - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"type\" must be a string."}]}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"path": "/type", "op": "replace", "from": "/type", "value": 0}]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout 4. Test Case ID: ciiDnC - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"Cannot set properties of undefined (setting 'undefined')","details":[{"message":"Cannot set properties of undefined (setting 'undefined')"}]}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"6\u00dfl~\u00c9\u00f7\u009b\u00ebqOA": [false, null, {"\u00b3K\ud9e8\udef5\u00de\u0084\uda81\udced\u008b\u0091F": false, "\ud88e\udccb\u0097": "\udb9c\udfb2[\ud94c\udf9c]V\uda16\udffa\udbd9\ude6a\u0089D\u0085\u0096\u00a2\udaa9\ude4a"}], "\u00cd\u00ba?\u001c\u00bft\u007f\u00a1\u00ea": 3.8004998675659455e+299, "": [], "path": "", "op": "copy", "from": "8\udafe\udd2c\uda9c\udc45\u008d\u0012\u00d1\u00dc\u00f0j\u00a7C\u00c5"}, {"\u00cc(\u00fa\u0080\u0085": [], "": [null, false, "\u00e3#u\ud861\udd14\u00c3oC"], "path": "\udaea\udd9c\u3be4\u00cc\u00b4f\udb7c\udfe1x\u00f2\u00da\ud870\ude6f", "op": "add"}, {"INF": [], "\u00a1": [[-6.997971826050222e+16, null, 727417830]], "path": "AK", "from": "\u009f\u00b6\ud846\ude4a+", "op": "move"}, {"o\u00a3b\uda22\udde6t\u00e5": [-4.144859508009994e-106, null], "op": "add", "path": "", "from": "v\u00f8\uda0d\udcbf\ud9d2\udde0\u0012\ud863\udfc0\ud8c3\udfc0\u00e1\u00a6\u00f7\ud983\ude6a\u0094\u0084S\u0001"}, {"\u00fe\u0006\n\u00b7\u00f7TO": {"/(\ud8ca\udd6e\u00c7\ud9f5\udf01": [], "U\u00b0T\ud84d\udcc9\ud9d2\ude09@\ud895\udf64\u00d1IX\u00cd\u00bc\u0012\ud809\ude1bK0\udba2\udf0c\t\u0001\u00a4\u00cb\uda51\udcca": [false]}, "\ud991\udf78\ud962\udef9\ud8c4\udfe0ev\ud876\udcc6\u0088": {"@\udbb6\udf4c": {">\u00eaA\u00dax": 1.6662434143231352e+16, "\udb2a\udd2b\u009d\uda23\udfe7\u00b1\ud9fb\udcad\u0090": "\u00fa\u00a7"}, "\u00e0": [-1941, null, -4938]}, "\u00ceCTx\u007f\u001e\u00ad\u00e6/\u0017\udba8\udee9p\u0004\u00a4": [], "\u00b6": {"\ud9a3\udec7": null, "": null, "\ud8dd\udd99": null}, "from": "\udb10\udf49\u0088\ud871\udffb\ud881\udef6\u007f\u00a7\ud8f4\ude79H\u0012\u008c", "path": "\u001b\u00cc\ud92e\udfc5\u001e?\uda1f\udd4aA\u001a|\u0088\u00d6r\u00a3\u00a1UH\u00ea\u00a3\u00c8\udbdc\udf73\u001c@Y,\u0083\ud864\udc74\udac4\udd0d", "op": "add"}, {"op": "add", "from": "\u00e7\udab2\ude5b", "path": "\u00c1\u00fc\udb95\ude89F\u00cc\u0005\u00f0"}]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout PATCH /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/strategies/{strategyId} 1. Test Case ID: XopwSf - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` at /items/properties/path (was string, became number) [200] OK: `{"id":"01M4JVFJCS0AKVHVVQ6964N1BX","name":"flexibleRollout","title":null,"disabled":false,"constraints":[],"parameters":{"groupId":"checkout","rollout":"100","stickiness":"default"},"variants":[],"sortOrder":0,"segments":[1]}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"path": -1.82975070128274e-206, "op": "replace", "from": "\u00c0"}, {"\udaf4\udff4\u0086\u00c7\u00f3 \ud841\ude98e\u0098P": ["(W\udb30\udd25"], "path": 3.0296046206739576e+54, "op": "move"}, {"op": "copy", "path": 9059648929719140.0}, {"\u00f8": [[], null], "path": 2.529641835729112e-155, "from": "82\udbea\udcd4\uda0b\udcc5", "op": "move"}, {"\udaca\udf2e\ud9eb\udf86": {"": {"": "\ud8ed\udd0f\u00c9!\ud90d\udedc\u0086\u00e2", "\ud8fe\udde7\u0093J\u0094": null}, "\u009f\n\u00c4\ud9d8\udfd4\u0013\u00c7": 2956520, "\u00fa\udb18\udfe9C\u00c7\u00b0\u00cc\uda98\udf98\u001bi\ud95f\udefd\u00b0\u0010\ud878\udc2b\u00e8\u00f5": ""}, "from": "", "path": 2.486441439549417e+16, "op": "replace"}, {"op": "copy", "path": -1.7976931348623157e+308, "from": "/\uda96\ude27\u00a4E"}, {"\u00f9*\uda28\udfc0": {"\ud927\udc22\u00ad\u00ea\r\udbe3\udc89\u00e3\ud9e3\uddc7\u0097\u00b91\u0018": {}, "\u009f\udbef\ude35\u00a4\u00b7Bd\u00ef\u00ff\ud9b0\ude81\udb10\udd6c": {"~\u00d5": "\u00bf", "\u009e": 1.5708432340019406e-300, "S\u0015\u0086": -800}, "": {}}, "": {}, "\ud830\udea8\u00c4\u00fd\ud80b\udc9f": {"x\u00a7\u0004}": -1.69806723177712e+16, "\u000f\u00cb\u00fa\ud89e\udf9eY%\u00eb": " \ud9a1\udfc7\u0083\udbbb\udfbf", "\rh\u00f4&{\u00bdR6\u00d5\u0000e\u0005\u00ff\u0090\u00b6\u00b0\u00d6": 9897572960773684.0}, "\u00dcO": {}, "path": -9.306878928509983e+67, "op": "remove"}, {"op": "add", "path": -7.137034851879505e-225}, {"\u0016h": [true, [-1853343, ""], [null, false]], "<\fz\u00b2\u00b25\u00fa;h\u00e1\u00cc": false, "\u0098\u00e5\u00d9\u000b|_\u0004": ["lorem \u0644\u0627 \u0628\u0633\u0645 \u0627\u0644\u0644\u0647 ipsum \u4f60\u597d1234\u4f60\u597d", 4823482, -7.78483990699387e-31], "op": "replace", "path": 3.4293118441333333e+210, "from": "\u00c5\uda04\udf22\u00c8\u00a0"}, {"path": 971944997203743.0, "op": "replace"}, {"path": 9389945002007504.0, "from": "\uda96\udcc0\u00d5\u00a7\udb14\uddfe\u00d5\u001d:M\u00bb\u008a", "op": "replace"}, {"": {"d\u00c8": null, "\u00e0\uda3e\udc5d\uda26\uddb5": 1e-05}, "\u00ab}\u00b8h": {"\uda54\udd84\u00f1": [846, "\u00ba\u00f4\u0090[\uda54\uddc0\u00ee \b\f\u00ae\udb1a\udeae#\u00b3<\u00b3\ud8ae\udc5d\u00b4\u00fe\u00a9\u0098\u00eb\u00ce"], "\ud859\udea0>\u00f4\u009c\u00a3": null, "\u00c0\u00abb\u00eaf'"'"'\u00c2H\u00a8\u00d4\u00fd\uda76\uddf0j": {}}, "*\ud84c\ude362\u0093\ud8ab\udfd1\u008f\ud858\ude09\r\u00be\u00dc\ud86f\ude7btn\ue5c1": {}, "\u001e": [], "\udab7\udea4": {"\u00f0\u00e2\udb7c\udd12": [true, "\u00daX\u0080\u0006i\u00b6"]}, "path": -1.401606156095398e+16, "op": "test", "from": "\ud983\udec7L\u00ca\uda50\udf9f\u00e5\ud945\ude3e9\ud9de\udc37\u00fe\uda60\uddd1"}, {"\u00d4\u0092>\u00b9\u00b3*7\ud9db\ude3fm\u0089\u009f\u0015": [null], "path": -4.9576125856833523e-116, "op": "remove", "from": "\\\u0081P"}, {"": 266808191, "from": "\u00b1\u00cdm", "op": "remove", "path": 5.954497066808872e+16}]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/environments/production/strategies/01M4JVFJCS0AKVHVVQ6964N1BX 2. Test Case ID: GKMd5l - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `application/json` [403] Forbidden: Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"": 8.081990653619316e+142, "\ud85d\udcc1V|m\u0015\r": [null], "\u00c5H\u00f3\u00e2\u00b6\u00f2\u0003!@K\u0018\udbfe\udf36\ud9a3\udd25\u00e8\ud99e\ude4d\uda78\uddeb\u00ff\u00d6\u00d3": {"\u00ddz": {"\ud805\ude85": null, "\u00e0$": null}, "\u00b7f\u00b9\u0001\u00b4\udaa6\udcda)\udb1e\ude3b\ud812\uddf0": 0.0, "\ud8dd\udc39\u000e\u00e1": {"W\ud854\udc92\udac9\udce1\u00e9": 0.0, "\u001dV\u0085\uc1b2\udba0\udef5k": true}}, "\ud8f5\udf17": [-8080, "0\uda35\udd33\u0012\u00bc\udb79\udc44\u00d3\ud84f\udcef>", false], "\uda10\ude6e\u00a6\ud9d9\udc34p\u20ea\u009f\u001dPt\ud995\udcdb": {}, "path": "\u00c7\ud841\uddff\ud9fe\ude70Es\udbc7\udf66\t\u000f\u00e3\u00deg\u0088\u00aa", "op": "copy"}]' http://0.0.0.0:37503/api/admin/projects/default/features/search/environments/development/strategies/01M4JVFJCS0AKVHVVQ6964N1BX 3. Test Case ID: 0dWw8Y - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"Test operation failed\nname: TEST_OPERATION_FAILED\nindex: 3\noperation: {\n \"\": {\n \"\\\"sŠ˜\": [\n \"††\\u0005\",\n null,\n false\n ]\n },\n \"op\": \"test\",\n \"path\": \"\",\n \"from\": \"‘¯\"\n}\ntree: null","details":[{"message":"Test operation failed\nname: TEST_OPERATION_FAILED\nindex: 3\noperation: {\n \"\": {\n \"\\\"sŠ˜\": [\n \"††\\u0005\",\n null,\n false\n ]\n },\n \"op\": \"test\",\n \"path\": \"\",\n // Output truncated...` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"": [4.91653625306008e+16, [], []], "\ud81d\udda4L\u00cd\u00c2\fP\"e\u00ae\u001f\u00b6\u0001\udaf3\udf21\uda40\ude9e\u00d2\u0001\u00a3\r\u00de\u00f7f\u00e6\u0099\u0019\ud969\ude911\udb27\udc5f\u008aRX\u00fd\u00c4\u001d-\udad6\udf67c": false, "\u008a-\u0080Bl": [0.99999, true, {}], "\ud80c\udec9\ud845\udcad\ud871\udfda\ud9a5\udf04\u0087\udbad\uddc3\u00cc)": {}, "_\udb84\udd41\u0001\ud98c\udd05\u00f2\u00da\udaa7\udd0f\u00ffx\udbf7\udd70[\ud8ba\ude5c\u00a8\u00ea\u00a8\u00c9M\uda02\udf59\u00f5": [1.6898105201020405e-260, "X\u00af\n\u00fa\u0015\u00f5\u0088^\ud854\udd86", null], "op": "replace", "path": "\udb3e\udeac\u00a0\udb2a\udfcc\u00e3\u00ae\ud9c4\ude6f\u00f3\u00d5\u00da"}, {"path": "\udbee\udc8d\u00d8\u0004\ub9b0\u0089\u00d2\ud9af\ude51;q\bfe", "from": "", "op": "remove"}, {"\u00df\u00e9": [], "": [false, false, -4169588352], "A\u00a6": {"K\u00cfH\udbb4\ude0a\u00e9\u0004\uda32\ude35\ud852\udddb\u00d5zL\u00d9\u00d1)\u00ff": -3708309654364863.0, "\udb7f\udf60EQ": true, "\u00f2": -5600776484912325.0}, "0": {"\udb59\udc35+(\u00c2D@\u00b7T>`\"\u007fb": null, "S\u00d7\"\u00f6\u0011\u00f1,\u00c9\u00ea\u00fa]\u00c0\u00c2\udb6e\udd49S\u00e6\udac5\ude0d\u00c2\udb2f\uddc7\u00fe>e\udacc\ude03\u00f1\u009c": "L\u00d8\ud8a3\udda4\u0019\u00b6r\u009d\u0080"}, "B\u00eeL\u00a5w": [], "path": "", "op": "remove"}, {"": {"\"s\u008a\u0098": ["\u0086\u0090\u0086\u0005", null, false]}, "op": "test", "path": "", "from": "\u0091\u00af"}, {"\u00a2\uda8a\udfdd\u00f1\u0d01\f": {}, "\u00ba5\u00c9": {"\ud958\uddc8\u00db\ud8b8\udc1a\u00cb\ud887\udf03i\ud8fb\udf99\udbfb\udfe0\u00ae\udb6e\ude15\ud9b8\udf9d\ud9cf\udf38\u0011\ud89f\udc89\u00ea\u0006kz,\u00b7\u0087\ud9fb\udf9f\ud931\udf1d\ud86c\udf52k\u001b\uda08\udc62\u008d1\u00cb\udb0e\uddf2\ud80b\udd60": {"\u00c5": 752}}, "\u00e9": [], "\u0001\u00a5\u00adxQ": [{"\udbc7\udd27P\u00f4\u0094E": null}], "\u00d5|%\u00ee": [{}, [["\ud93e\udd84", null, "\u008f\u00dfw\u00b1m\u1f13\u00e5\ud9ec\uddcc\u00d8\u00ce"], -1.7976931348623157e+308], "Lp\u00c0\ud852\udf84\udb06\udd39q"], "op": "test", "path": "|\u00b3"}, {"\u7bae": [{}, {"": {"\u0006c\ud86b\udf92": "\u0089|", "\u00b0a\u00f3\u0094\u00fd": 1.0894368003134168e+238, "\ud93f\ude53\u00c6\udb28\udded\ud9bd\udd77": null}}, "\u001c\u00b1*": {"+": [], "": -2255}, "op": "copy", "path": "Yr\u00b7\ud894\udf4c"}]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/environments/production/strategies/01M4JVFJCS0AKVHVVQ6964N1BX 4. Test Case ID: OjC8jc - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"path":"undefined","message":"The root object of the request body does not allow additional properties. Your request included the `undefined` property."}]}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"": null, "op": "add", "path": "\udb3e\udeac\u00a0\udb2a\udfcc\u00e3\u00ae\ud9c4\ude6f\u00f3\u00d5\u00da"}, {"C^\udb89\uddf7\u00ddm": [], "\ud803\udf66=*\u00c4\u00e6\u00c2\u00b5": {}, "": {"": false}, "I\u0003": {}, "\u00a8": [[]], "op": "copy", "path": "Yj\udb1f\udceb~\u00dd \u00a6", "from": "\u0013\u0099\ud8b1\ude69\u008a\u00d6\u00b2\udb17\udf2d\ud8a6\uddc9\udacb\ude44\u00efe\u007f"}]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/environments/development/strategies/01M4JVFJCS0AKVHVVQ6964N1BX PATCH /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/variants 1. Test Case ID: hwwJra - Undocumented HTTP status code Received: 415 Documented: 200, 400, 401, 403, 404 [415] Unsupported Media Type: `{"id":"24aeb524-d772-496b-bf76-a5bb7a7679ca","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/0/features/checkout/environments/0/variants _____________________ PATCH /api/admin/tag-types/validate ______________________ 1. Test Case ID: jR4TIX - Unsupported methods Unsupported method PATCH returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"cb6a6232-57e8-447a-b3ec-099e835d6c54","name":"NotFoundError","message":"The path you were looking for (/api/admin/tag-types/validate) is not available.","details":[{"message":"The path you were looking for (/api/admin/tag-types/validate) is not available."}]}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#000000", "description": "A tag type for describing the color of a tag.", "icon": null, "name": "color"}' http://0.0.0.0:37503/api/admin/tag-types/validate ____________________________ POST /api/admin/addons ____________________________ 1. Test Case ID: 0Ghv2K - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: A validation error occurred while processing your request data. Please make sure it conforms to the request data schema.","details":[{"message":"A validation error occurred while processing your request data. Please make sure it conforms to the request data schema."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"provider": "webhook", "description": "This addon posts updates to our internal feature tracking system whenever a feature is created or updated.", "parameters": {"url": "http://localhost:4242/webhook"}, "events": ["feature-created", "feature-updated"], "projects": ["new-landing-project", "signups-v2"], "environments": ["development", "production"], "enabled": false}' http://0.0.0.0:37503/api/admin/addons __________________________ POST /api/admin/api-tokens __________________________ 1. Test Case ID: UZLmCq - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 201, 401, 403, 415 [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Project=project-851 does not exist","details":[{"message":"Project=project-851 does not exist"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"expiresAt": "2023-07-04T11:26:24+02:00", "type": "frontend", "environment": "development", "project": "project-851", "projects": ["project-851", "project-852"], "tokenName": "[Filtered]"}' http://0.0.0.0:37503/api/admin/api-tokens 2. Test Case ID: o0Kv3I - Response header does not conform to the schema "api-tokens" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "api-tokens" [201] Created: `{"tokenName":"token-64522","projects":["*"],"environment":"development","secret":"*:development.2067afd7ee8eca8def62e384be36765e82710b9091f0b3e051c01f92","type":"frontend","alias":null,"project":"*","createdAt":"2026-10-10T12:09:27.116Z","secure":false}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"type": "frontend", "tokenName": "[Filtered]"}' http://0.0.0.0:37503/api/admin/api-tokens 3. Test Case ID: dUXVWG - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` at /oneOf/0/properties/project (was string, became null) [201] Created: `{"tokenName":"g","projects":["*"],"environment":"development","secret":"*:development.16e2e30df39d4a5ad240ad50e3a29328c6b61e939ca5ed89321639ae","type":"client","alias":null,"project":"*","createdAt":"2026-10-10T12:13:10.092Z","secure":false}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u008d&\u00d4": [], "W\u00c0": [null, null], "\uda8d\udce6\udbfb\uddb1\u00c2,\u0018\u00f4\udaf5\udc4e\u0095X\u0086no\u00cd\u0010\u009e\udb02\udfe5c\u00d4\u00cb": [], "\u00f6L\u00067\u00c8": {"\u0083": -8777913709248506.0, "S\uda99\udfe3\ufb32\u0093Z": {}, "\ud9eb\udf44E\ud9ba\udc8a\ud8ed\udc79\u00be\udb39\udccbK": []}, "v\ud869\udf0e": {"": -249}, "type": "clIeNt", "project": null, "tokenName": "[Filtered]"}' http://0.0.0.0:37503/api/admin/api-tokens 4. Test Case ID: uE4OBV - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 403, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"SELECT EXISTS (SELECT 1 FROM environments WHERE name = $1) AS present - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"SELECT EXISTS (SELECT 1 FROM environments WHERE name = $1) AS present - invalid byte sequence for encoding \"UTF8\": 0x00"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u1e70\u033a\u033a\u0315o\u035e \u0337i\u0332\u032c\u0347\u032a\u0359n\u031d\u0317\u0355v\u031f\u031c\u0318\u0326\u035fo\u0336\u0319\u0330\u0320k\u00e8\u035a\u032e\u033a\u032a\u0339\u0331\u0324 \u0316t\u031d\u0355\u0333\u0323\u033b\u032a\u035eh\u033c\u0353\u0332\u0326\u0333\u0318\u0332e\u0347\u0323\u0330\u0326\u032c\u034e \u0322\u033c\u033b\u0331\u0318h\u035a\u034e\u0359\u031c\u0323\u0332\u0345i\u0326\u0332\u0323\u0330\u0324v\u033b\u034de\u033a\u032d\u0333\u032a\u0330-m\u0322i\u0345n\u0316\u033a\u031e\u0332\u032f\u0330d\u0335\u033c\u031f\u0359\u0329\u033c\u0318\u0333 \u031e\u0325\u0331\u0333\u032dr\u031b\u0317\u0318e\u0359p\u0360r\u033c\u031e\u033b\u032d\u0317e\u033a\u0320\u0323\u035fs\u0318\u0347\u0333\u034d\u031d\u0349e\u0349\u0325\u032f\u031e\u0332\u035a\u032c\u035c\u01f9\u032c\u034e\u034e\u031f\u0316\u0347\u0324t\u034d\u032c\u0324\u0353\u033c\u032d\u0358\u0345i\u032a\u0331n\u0360g\u0334\u0349 \u034f\u0349\u0345c\u032c\u031fh\u0361a\u032b\u033b\u032f\u0358o\u032b\u031f\u0316\u034d\u0319\u031d\u0349s\u0317\u0326\u0332.\u0328\u0339\u0348\u0323": {"\ud822\udeaf\u00e6&\u00ac\u0013X\u00b2\u00f5\u00bb\ud807\udd3d\u00b7\u00a6": false}, "\ud8e3\udeb745\u0082\ud992\ude02?\u00fe\u00f8": {"\u00b8g\u00b7\ud8da\udcaa\u00b1": null, "": -1529202953260, "m\u00bb\u00d5": true}, "then": {}, "o\ud9fc\ude55|<": 7.680918493170895e+40, "\u009am\u00b1\ud844\udcf9": [], "tokenName": "[Filtered]", "projects": [".r\ud9fb\udeb6\u00da\u0019\u008b\u00dc\u00fd\u001c", "\u009e!;\u00d3\u00182\u00b0\u0090\u00dd%Z\u001f\u00c6\u0005\ud9fb\udd64\u00c8\u00fbL\u0098Zgl\u00c6", "\u00f3a\u0087\u00ad\u001ax", "\ud8bb\udcdf\udadf\udea4\udad9\udd50\f\uda59\ude59\udab1\ude65\u00b1$\u001e\u001d4\u0005;\ud89c\udd67\u0088", "\u0015\u009e", ".fTx", "c\u008b\ud95a\udf1f\u00c9\u00fe\u00c6", "\u00db\u00b2pL7\u00ad\ud86a\udd19\u000e\ud9d1\udcfb\u00d6", "", "f^\u00fd\u00f3\u0085\u008f\u000ew\uda88\udf4e\u0017\u001c\u00c4\u0085i\u008c\u00df", "", "NIL", "\u00a2Q\u00cd8", "COM1", ""], "environment": "\u00dbTkt\u009fU\u001d\u001c\u0000\u00d0", "expiresAt": "2026-10-10T12:33:25.730Z", "project": ",", "type": "bACKEnd"}' http://0.0.0.0:37503/api/admin/api-tokens _________________ POST /api/admin/archive/revive/{featureName} _________________ 1. Test Case ID: wIM8al - Undocumented HTTP status code Received: 404 Documented: 200, 400, 401, 403 [404] Not Found: `{"name":"NotFoundError","message":"No feature flag found","details":[{"message":"No feature flag found"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/archive/revive/0 _____________________ POST /api/admin/constraints/validate _____________________ 1. Test Case ID: BW61AL - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - value: Incorrect type [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"caseInsensitive": false, "contextName": "appName", "inverted": false, "operator": "IN", "value": false, "values": ["my-app", "my-other-app"]}' http://0.0.0.0:37503/api/admin/constraints/validate 2. Test Case ID: dQ9BQK - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"values[0]\" is not allowed to be empty."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"caseInsensitive": false, "contextName": "appName", "inverted": false, "operator": "IN", "value": "my-app", "values": [""]}' http://0.0.0.0:37503/api/admin/constraints/validate ___________________________ POST /api/admin/context ____________________________ 1. Test Case ID: D4miiH - Server error - Undocumented HTTP status code Received: 500 Documented: 201 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"context_fields\" (\"description\", \"legal_values\", \"name\", \"project\", \"sort_order\", \"stickiness\") values ($1, $2, $3, $4, $5, $6) returning * - insert or update on table \"context_fields\" violates foreign key constraint \"context_fields_project_fkey\"","details":[{"message":"insert into \"context_fields\" (\"description\", \"legal_values\", \"name\", \"project\", \"sort_order\", \"stickiness\") values ($1, $2, $3, $4, $5, $6) returning * - insert or // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "#c154c1", "description": "Deep fuchsia"}], "project": "my-project", "name": "subscriptionTier"}' http://0.0.0.0:37503/api/admin/context 2. Test Case ID: Jzofr9 - Undocumented HTTP status code Received: 415 Documented: 201 [415] Unsupported Media Type: `{"id":"dc6f86f5-4406-49dd-a1e9-b75c19739a68","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/context 3. Test Case ID: 824jOb - Undocumented HTTP status code Received: 400 Documented: 201 [400] Bad Request: `{"id":"35b90ddb-2d4b-44fc-a3fd-916e6d8d06b3","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"path":"/body/name","message":"The `/body/name` property is required. It was not present on the data you sent."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "gold"}, {"value": "silver"}, {"value": "crystal"}], "project": "my-project"}' http://0.0.0.0:37503/api/admin/context 4. Test Case ID: 0VSpFy - Undocumented HTTP status code Received: 409 Documented: 201 [409] Conflict: `{"name":"NameExistsError","message":"A context field with that name already exist","details":[{"message":"A context field with that name already exist"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "gold"}, {"value": "silver"}, {"value": "crystal"}], "project": null, "name": "subscriptionTier"}' http://0.0.0.0:37503/api/admin/context 5. Test Case ID: zgUP62 - Response header does not conform to the schema "context/my-custom-strategy" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "context/my-custom-strategy" [201] Created: `{"name":"my-custom-strategy","description":null,"stickiness":false,"sortOrder":0,"legalValues":[],"createdAt":"2026-10-10T12:09:52.340Z"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "my-custom-strategy"}' http://0.0.0.0:37503/api/admin/context 6. Test Case ID: 3nSXKZ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (``, `À×`, `Õ񵌶È` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"name\" must be URL friendly. You provided \"񸱅\"."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\uda93\udc04^": {"2": {"\u007fl\udbf7\udde3\u00c0\u0002\u0097\u00de": 1e-05, "": true}}, "\uda6a\udda7\u00c2": {}, "\u00c0\u00d7": {"\udbce\udecd": {"\u00eb\u00aa\u00c2\ud91d\udfa5p\u00d2\u00b7": -9.641582004910992e+245}, "X8\u00d1\u00c0N\ud9ec\udd2b": {}}, "\u0018": ["\u00aa\u00a0\ud9c4\udd6fs\ud8bf\uddfa"], "\u00d5\ud994\udf36\u00c8": [5.564089792148897e+16], "name": "\ud9a3\udc45"}' http://0.0.0.0:37503/api/admin/context _______________________ POST /api/admin/context/validate _______________________ 1. Test Case ID: 1JAL8Q - Undocumented HTTP status code Received: 415 Documented: 200 [415] Unsupported Media Type: `{"id":"6cb70942-e2e9-412c-90a5-bb396fe5b074","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/context/validate 2. Test Case ID: ZJupxA - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"id":"3b180e65-49cd-464d-9628-af3a848b4fd2","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/name` property must be string. You sent {}.","path":"/body/name"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": {}}' http://0.0.0.0:37503/api/admin/context/validate 3. Test Case ID: zM54PL - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - name: Incorrect type [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": false}' http://0.0.0.0:37503/api/admin/context/validate 4. Test Case ID: j0047c - Undocumented HTTP status code Received: 409 Documented: 200 [409] Conflict: `{"name":"NameExistsError","message":"A context field with that name already exist","details":[{"message":"A context field with that name already exist"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "my-custom-strategy"}' http://0.0.0.0:37503/api/admin/context/validate 5. Test Case ID: aVqE2j - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"name\" is not allowed to be empty."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": ""}' http://0.0.0.0:37503/api/admin/context/validate _____________ POST /api/admin/context/{contextField}/legal-values ______________ 1. Test Case ID: IsI1QG - Undocumented HTTP status code Received: 415 Documented: 200 [415] Unsupported Media Type: `{"id":"c3f680b0-ec6a-4b10-8848-1617942ffef9","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/context/0/legal-values 2. Test Case ID: POc2o2 - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"id":"4527528a-f0a4-47a8-93ac-055021b579bf","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/description` property must be string. You sent {}.","path":"/body/description"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": {}, "value": "#c154c1"}' http://0.0.0.0:37503/api/admin/context/0/legal-values 3. Test Case ID: ArjAsE - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"Could not find context field with name 0","details":[{"message":"Could not find context field with name 0"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": null, "value": "#c154c1"}' http://0.0.0.0:37503/api/admin/context/0/legal-values 4. Test Case ID: oLMEy7 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` at /properties/value (was string, became integer) [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": 0}' http://0.0.0.0:37503/api/admin/context/region/legal-values 5. Test Case ID: gML3Xb - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"value\" is not allowed to be empty."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": "", "description": "Deep fuchsia"}' http://0.0.0.0:37503/api/admin/context/region/legal-values ___________________ POST /api/admin/environments/sort-order ____________________ 1. Test Case ID: ww0j9w - Unsupported methods Unsupported method POST returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"f4d61896-6319-4cd6-9639-c947b817a007","name":"NotFoundError","message":"The path you were looking for (/api/admin/environments/sort-order) is not available.","details":[{"message":"The path you were looking for (/api/admin/environments/sort-order) is not available."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:37503/api/admin/environments/sort-order ____________________ POST /api/admin/features-batch/export _____________________ 1. Test Case ID: pDT8tR - Undocumented HTTP status code Received: 415 Documented: 200, 404 [415] Unsupported Media Type: `{"id":"88f2c73b-711a-4a54-84b7-4ecc3329f603","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/features-batch/export 2. Test Case ID: ILuR1B - Undocumented HTTP status code Received: 400 Documented: 200, 404 [400] Bad Request: `{"id":"63feb220-be62-414e-a7f1-2e109eccd52c","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"path":"/body/features","message":"The `/body/features` property is required. It was not present on the data you sent."},{"path":"/body/tag","message":"The `/body/tag` property is required. It was not present on the data you sent."},{"message":"The `/body/project` property must be string. You // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environment": "development", "downloadFile": true, "project": {}}' http://0.0.0.0:37503/api/admin/features-batch/export 3. Test Case ID: Auw4r5 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - project: Incorrect type [200] OK: `{"features":[],"featureStrategies":[],"featureEnvironments":[],"contextFields":[],"featureTags":[],"segments":[],"tagTypes":[],"dependencies":[],"links":[]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environment": "development", "downloadFile": true, "project": null}' http://0.0.0.0:37503/api/admin/features-batch/export ____________________ POST /api/admin/features-batch/import _____________________ 1. Test Case ID: lreZ4H - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 404 [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: You can't use an admin token to import features. Please use either a personal access token (https://docs.getunleash.io/concepts/api-tokens-and-client-keys#personal-access-tokens) or a service account (https://docs.getunleash.io/concepts/service-accounts).","details":[{"message":"You can't use an admin token to import features. Please use either a personal access token (https://docs.getunleash.io/co // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"project": "My awesome project", "environment": "development", "data": {"features": [{"name": "disable-comments", "type": "kill-switch", "description": "Controls disabling of the comments section in case of an incident", "archived": true, "project": "dx-squad", "enabled": true, "stale": false, "favorite": true, "impressionData": false, "createdAt": "2023-01-28T15:21:39.975Z", "createdBy": {"id": 123, "name": "User", "imageUrl": "https://example.com/242x200.png"}, "archivedAt": "2023-01-29T15:21:39.975Z", "environments": [{"name": "my-dev-env", "featureName": "disable-comments", "environment": "development", "type": "development", "enabled": true, "sortOrder": 3, "strategies": [{"id": "6b5157cb-343a-41e7-bfa3-7b4ec3044840", "name": "flexibleRollout", "title": "Gradual Rollout 25-Prod", "disabled": false, "featureName": "myAwesomeFeature", "sortOrder": 9999, "segments": [1, 2], "constraints": [{"contextName": "appName", "operator": "IN", "values": ["my-app", "my-other-app"], "value": "my-app", "caseInsensitive": false, "inverted": false}], "variants": [{"name": "blue_group", "weightType": "fix", "stickiness": "custom.context.field", "payload": {"type": "json", "value": "{\"color\": \"red\"}"}, "weight": 0}], "parameters": {}}], "variants": [{"name": "blue_group", "weightType": "variable", "stickiness": "custom.context.field", "payload": {"type": "json", "value": "{\"color\": \"red\"}"}, "overrides": [{"contextName": "userId", "values": ["red", "blue"]}], "weight": 0.0}], "milestoneName": "Phase One", "milestoneOrder": 0, "totalMilestones": 0, "lastSeenAt": "2023-01-28T16:21:39.975Z", "releasePlans": [{"id": "01JB9GGTGQYEQ9D40R17T3YVW2", "discriminator": "plan", "name": "My release plan", "description": "This is my release plan", "featureName": "my-feature", "environment": "production", "createdByUserId": 53, "createdAt": "2022-01-01T00:00:00Z", "activeMilestoneId": "01JB9GGTGQYEQ9D40R17T3YVW1", "milestones": [{"id": "01JB9GGTGQYEQ9D40R17T3YVW1", "name": "My milestone", "sortOrder": 1, "releasePlanDefinitionId": "01JB9GGTGQYEQ9D40R17T3YVW2", "startedAt": "2024-01-01T00:00:00.000Z", "progressionExecutedAt": "2024-01-01T00:00:00.000Z", "pausedAt": "2024-01-01T00:00:00.000Z", "strategies": [{"id": "01JB9GGTGQYEQ9D40R17T3YVW3", "milestoneId": "01JB9GGTGQYEQ9D40R17T3YVW1", "sortOrder": 9999, "title": "Gradual Rollout 25-Prod", "name": "flexibleRollout", "strategyName": "flexibleRollout", "constraints": [{"contextName": "appName", "operator": "IN", "values": ["my-app", "my-other-app"], "value": "my-app", "caseInsensitive": false, "inverted": false}], "variants": [{"name": "blue_group", "weightType": "fix", "stickiness": "custom.context.field", "payload": {"type": "json", "value": "{\"color\": \"red\"}"}, "weight": 0}], "segments": [1, 2], "disabled": false, "parameters": {}}], "transitionCondition": null}], "releasePlanTemplateId": "01JB9GGTGQYEQ9D40R17T3YVW2", "safeguards": [{"id": "01JB9GGTGQYEQ9D40R17T3YVW1", "action": {"type": "pauseReleasePlanProgressions", "id": "01JB9GGTGQYEQ9D40R17T3YVW2"}, "triggerCondition": {"operator": ">", "threshold": 100}, "impactMetric": {"id": "01JB9GGTGQYEQ9D40R17T3YVW1", "metricName": "unleash_counter_feature_toggle_usage_total", "timeRange": "day", "aggregationMode": "rps", "labelSelectors": {"environment": ["development"], "project": ["default"]}, "source": "internal"}}]}], "safeguards": [{"id": "01JB9GGTGQYEQ9D40R17T3YVW1", "action": {"type": "disableFeatureEnvironment", "featureName": "", "environment": "", "project": ""}, "triggerCondition": {"operator": ">", "threshold": 100}, "impactMetric": {"id": "01JB9GGTGQYEQ9D40R17T3YVW1", "metricName": "unleash_counter_feature_toggle_usage_total", "timeRange": "day", "aggregationMode": "rps", "labelSelectors": {"environment": ["development"], "project": ["default"]}, "source": "internal"}}], "yes": 974, "no": 50, "variantCount": 0.0, "changeRequestIds": [], "hasStrategies": false, "hasEnabledStrategies": false}], "tags": [{"value": "a-tag-value", "type": "simple", "color": "#FFFFFF"}], "children": ["some-feature"], "lifecycle": {"stage": "initial", "status": "kept", "enteredStageAt": "2023-01-28T15:21:39.975Z"}, "dependencies": [{"feature": "some-feature", "enabled": true, "variants": ["some-feature-blue-variant"]}], "collaborators": {"users": [{"id": 123, "name": "User", "imageUrl": "https://example.com/242x200.png"}]}, "links": [{"id": "01JTJNCJ5XVP2KPJFA03YRBZCA", "url": "https://github.com/search?q=cleanupReminder&type=code", "title": "Github cleanup", "feature": "disable-comments"}]}], "featureStrategies": [{"name": "flexibleRollout", "id": "924974d7-8003-43ee-87eb-c5f887c06fd1", "featureName": "my-feature", "title": "Rollout 50%", "parameters": {"groupId": "default", "rollout": "50", "stickiness": "random"}, "constraints": [], "disabled": false, "segments": [1]}], "featureEnvironments": [{"name": "my-dev-env", "featureName": "disable-comments", "environment": "development", "type": "development", "enabled": true, "sortOrder": 3, "strategies": [{"id": "6b5157cb-343a-41e7-bfa3-7b4ec3044840", "name": "flexibleRollout", "title": "Gradual Rollout 25-Prod", "disabled": false, "featureName": "myAwesomeFeature", "sortOrder": 9999, "segments": [1, 2], "constraints": [{"contextName": "appName", "operator": "IN", "values": ["my-app", "my-other-app"], "value": "my-app", "caseInsensitive": false, "inverted": false}], "variants": [{"name": "blue_group", "weightType": "fix", "stickiness": "custom.context.field", "payload": {"type": "json", "value": "{\"color\": \"red\"}"}, "weight": 0}], "parameters": {}}], "variants": [{"name": "blue_group", "weightType": "variable", "stickiness": "custom.context.field", "payload": {"type": "json", "value": "{\"color\": \"red\"}"}, "overrides": [{"contextName": "userId", "values": ["red", "blue"]}], "weight": 0.0}], "milestoneName": "Phase One", "milestoneOrder": 0, "totalMilestones": 0, "lastSeenAt": "2023-01-28T16:21:39.975Z", "releasePlans": [{"id": "01JB9GGTGQYEQ9D40R17T3YVW2", "discriminator": "plan", "name": "My release plan", "description": "This is my release plan", "featureName": "my-feature", "environment": "production", "createdByUserId": 53, "createdAt": "2022-01-01T00:00:00Z", "activeMilestoneId": "01JB9GGTGQYEQ9D40R17T3YVW1", "milestones": [{"id": "01JB9GGTGQYEQ9D40R17T3YVW1", "name": "My milestone", "sortOrder": 1, "releasePlanDefinitionId": "01JB9GGTGQYEQ9D40R17T3YVW2", "startedAt": "2024-01-01T00:00:00.000Z", "progressionExecutedAt": "2024-01-01T00:00:00.000Z", "pausedAt": "2024-01-01T00:00:00.000Z", "strategies": [{"id": "01JB9GGTGQYEQ9D40R17T3YVW3", "milestoneId": "01JB9GGTGQYEQ9D40R17T3YVW1", "sortOrder": 9999, "title": "Gradual Rollout 25-Prod", "name": "flexibleRollout", "strategyName": "flexibleRollout", "constraints": [{"contextName": "appName", "operator": "IN", "values": ["my-app", "my-other-app"], "value": "my-app", "caseInsensitive": false, "inverted": false}], "variants": [{"name": "blue_group", "weightType": "fix", "stickiness": "custom.context.field", "payload": {"type": "json", "value": "{\"color\": \"red\"}"}, "weight": 0}], "segments": [1, 2], "disabled": false, "parameters": {}}], "transitionCondition": null}], "releasePlanTemplateId": "01JB9GGTGQYEQ9D40R17T3YVW2", "safeguards": [{"id": "01JB9GGTGQYEQ9D40R17T3YVW1", "action": {"type": "pauseReleasePlanProgressions", "id": "01JB9GGTGQYEQ9D40R17T3YVW2"}, "triggerCondition": {"operator": ">", "threshold": 100}, "impactMetric": {"id": "01JB9GGTGQYEQ9D40R17T3YVW1", "metricName": "unleash_counter_feature_toggle_usage_total", "timeRange": "day", "aggregationMode": "rps", "labelSelectors": {"environment": ["development"], "project": ["default"]}, "source": "internal"}}]}], "safeguards": [{"id": "01JB9GGTGQYEQ9D40R17T3YVW1", "action": {"type": "disableFeatureEnvironment", "featureName": "", "environment": "", "project": ""}, "triggerCondition": {"operator": ">", "threshold": 100}, "impactMetric": {"id": "01JB9GGTGQYEQ9D40R17T3YVW1", "metricName": "unleash_counter_feature_toggle_usage_total", "timeRange": "day", "aggregationMode": "rps", "labelSelectors": {"environment": ["development"], "project": ["default"]}, "source": "internal"}}], "yes": 974, "no": 50, "variantCount": 0.0, "changeRequestIds": [], "hasStrategies": false, "hasEnabledStrategies": false}], "contextFields": [{"name": "appName", "description": "Allows you to constrain on application name", "stickiness": false, "sortOrder": 2, "legalValues": []}], "featureTags": [{"featureName": "my-feature", "tagType": "simple", "tagValue": "user-facing"}], "segments": [{"id": 1, "name": "new-segment-name"}], "tagTypes": [{"name": "simple", "description": "Used to simplify filtering of features", "icon": "#"}], "dependencies": [{"feature": "child_feature", "dependencies": [{"feature": "parent_feature", "enabled": false, "variants": ["variantA", "variantB"]}]}], "links": [{"feature": "child_feature", "links": [{"url": "https://github.com/search?q=cleanupReminder&type=code", "title": "Github cleanup"}]}]}}' http://0.0.0.0:37503/api/admin/features-batch/import 2. Test Case ID: srIudx - Undocumented HTTP status code Received: 415 Documented: 200, 404 [415] Unsupported Media Type: `{"id":"3d7c637b-d30a-406b-b132-4feccfe8480d","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/features-batch/import ___________________ POST /api/admin/features-batch/validate ____________________ 1. Test Case ID: 3Umg4y - Undocumented HTTP status code Received: 415 Documented: 200, 404 [415] Unsupported Media Type: `{"id":"3b914614-03d3-4462-9cdd-232092f86843","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/features-batch/validate 2. Test Case ID: 1itybd - Undocumented HTTP status code Received: 400 Documented: 200, 404 [400] Bad Request: `{"id":"902975c1-7044-4fcd-862c-60dc41d67235","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/data/links/0/links/0/title` property must be string. You sent {}.","path":"/body/data/links/0/links/0/title"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"data": {"contextFields": [{"description": "Allows you to constrain on application name", "legalValues": [], "name": "appName", "sortOrder": 2, "stickiness": false}], "dependencies": [], "featureEnvironments": [{"enabled": true, "environment": "development", "featureName": "my-feature", "name": "variant-testing", "variants": [{"name": "a", "overrides": [], "stickiness": "random", "weight": 500, "weightType": "variable"}, {"name": "b", "overrides": [], "stickiness": "random", "weight": 500, "weightType": "variable"}]}], "featureStrategies": [{"constraints": [], "disabled": false, "featureName": "my-feature", "id": "924974d7-8003-43ee-87eb-c5f887c06fd1", "name": "flexibleRollout", "parameters": {"groupId": "default", "rollout": "50", "stickiness": "random"}, "segments": [1], "title": "Rollout 50%"}], "featureTags": [{"featureName": "my-feature", "tagType": "simple", "tagValue": "user-facing"}], "features": [{"archived": false, "description": "best feature ever", "impressionData": false, "name": "my-feature", "project": "default", "stale": false, "type": "release"}], "links": [{"feature": "child_feature", "links": [{"url": "https://github.com/search?q=cleanupReminder&type=code", "title": {}}]}], "segments": [{"id": 1, "name": "new-segment-name"}], "tagTypes": [{"description": "Used to simplify filtering of features", "icon": "#", "name": "simple"}]}, "environment": "development", "project": "My awesome project"}' http://0.0.0.0:37503/api/admin/features-batch/validate 3. Test Case ID: lBkP7L - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - data -> links -> Array with invalid items: links -> Array with invalid items: title: Incorrect type [200] OK: `{"errors":[{"message":"We detected the following segments that need to be created first:","affectedItems":["new-segment-name"]}],"warnings":[],"permissions":[]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"data": {"contextFields": [{"description": "Allows you to constrain on application name", "legalValues": [], "name": "appName", "sortOrder": 2, "stickiness": false}], "dependencies": [], "featureEnvironments": [{"enabled": true, "environment": "development", "featureName": "my-feature", "name": "variant-testing", "variants": [{"name": "a", "overrides": [], "stickiness": "random", "weight": 500, "weightType": "variable"}, {"name": "b", "overrides": [], "stickiness": "random", "weight": 500, "weightType": "variable"}]}], "featureStrategies": [{"constraints": [], "disabled": false, "featureName": "my-feature", "id": "924974d7-8003-43ee-87eb-c5f887c06fd1", "name": "flexibleRollout", "parameters": {"groupId": "default", "rollout": "50", "stickiness": "random"}, "segments": [1], "title": "Rollout 50%"}], "featureTags": [{"featureName": "my-feature", "tagType": "simple", "tagValue": "user-facing"}], "features": [{"archived": false, "description": "best feature ever", "impressionData": false, "name": "my-feature", "project": "default", "stale": false, "type": "release"}], "links": [{"feature": "child_feature", "links": [{"url": "https://github.com/search?q=cleanupReminder&type=code", "title": false}]}], "segments": [{"id": 1, "name": "new-segment-name"}], "tagTypes": [{"description": "Used to simplify filtering of features", "icon": "#", "name": "simple"}]}, "environment": "development", "project": "My awesome project"}' http://0.0.0.0:37503/api/admin/features-batch/validate 4. Test Case ID: u3CnKT - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"select * from \"features\" where \"name\" in ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15, $16, $17, $18, $19, $20, $21, $22, $23, $24, $25, $26, $27, $28, $29, $30, $31, $32, $33, $34, $35, $36, $37, $38, $39, $40, $41, $42) order by \"name\" asc - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select * from \"features\" where \"name\" in ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15, $16, $17, $18, $19, $ // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"project": "", "data": {"tagTypes": [{"description": "", "icon": "]g\u0011\u00c6", "color": "#ffF368", "name": "N"}, {"color": null, "name": "total"}, {"color": "#0c9A70", "name": "\udba4\udd16\u00a0\ud89b\uddef"}, {"description": "\u00ae\r\udbd8\udca3\u0014\u00e4\u00f6\u00f8/\u00df\udb36\ude17", "name": "K\u009cv\u0099\u00f3\u00c1\u0089\u00c3\u00d0x"}, {"color": null, "description": "\u00f6\u0093w}\udbd7\udc11Q", "icon": "", "name": "d\udb35\udd3f\u00d4\u0081\udb81\udf33\u008f\u0016\u00ad\ud947\udc02\u0095\u00bb\u00ad"}, {"name": "", "color": null, "description": "W\uda33\udc3dr"}, {"color": null, "icon": "\u73e6\u00d9\u00ac\udbd2\uddc8\u00b8\u00d3", "name": "", "description": "\u009f\u00bd\u00d4\u0096\ud9ec\udf8f\u00aa\u0005\u00a0\u0081"}, {"name": "\t\ud93b\udc57\u00af\udbd4\udc44"}, {"description": "\u00cd\u00d9\ud85d\ude8c\u00f3H\u0088", "name": "\uda6d\udc33\u00ba\u0081"}, {"name": "\u00f0", "description": "\u00f5", "icon": "\udad7\udcc09m\u0010\u0090p", "color": null}, {"name": "\u00b5\u00a0\u0097", "color": "#aab0c9", "description": "True", "icon": ""}, {"color": "#cdE1D3", "name": "\u00af+", "description": "\u0002F`5\udb28\udc1en\u00ba\u00c9\u00e7!\u00eea"}, {"name": "", "color": "#A1D5ae", "icon": null, "description": "\u00f6\ud94a\udd9av"}, {"name": "\udb52\udf67lH\u001f\u00f2\udbb5\uddda\udacf\udd85\u000b"}, {"icon": "", "description": "`=j", "name": "\u0011\ud82b\udf0aK\u00b7\ud949\udd1a", "color": null}, {"color": "#9e9a1A", "description": "\u0010(q\u007f\ud9da\udd2d\ud988\udc34\u00d4\u0007\u000e\u00d9\u008e\u0005\u00c02\u00fdz\u007f", "name": "\u00a6", "icon": null}, {"name": "\u00c9", "description": "\ud8ef\ude2f\u00da\u0010", "color": "#F7bFB4"}], "featureStrategies": [{"name": "\ud82c\udcdc\u0094\u0086\u00dd\u00d5\ud899\udc16", "parameters": {"": "\ud88a\udd23Y\u00b4\u00b1\u00dd\ud836\uddf9\u00f1\ud872\udf11`"}, "constraints": [{"inverted": true, "contextName": "", "operator": "SEMVER_LT"}, {"operator": "DATE_BEFORE", "caseInsensitive": true, "inverted": false, "contextName": "\ud89e\udd28", "values": ["\u00a4:\u001e\ud966\udc55E\u00f2"]}, {"contextName": "", "operator": "DATE_AFTER"}], "sortOrder": -2.677150284094183e+216, "disabled": null, "segments": [3.326082532062371e-59, -6.103515625e-05, -1.9, -3.748021331872567e+16, 4.16700571855177e+91, -6.103515625e-05, 1.2035618088356637e-205, -2.1008190731839675e+34, -1.8957685278294757e-192, 6.47405556126122e+68, -5.431800182266422e+16, -8.935519929715416e-178, 988940793540989.0, -1.1930420393274867e+230, -1.463733718554285e+37], "variants": [{"weightType": "fix", "name": "nil", "weight": 0, "stickiness": "\u0011\u009b\u0099g\uda44\udf15\u00e5\u00d2\u0007\u00dfA"}, {"stickiness": "}", "weightType": "variable", "weight": 327, "payload": {"value": "s\u00db\u0002\u000b\u00ab\ud96b\udd66C\u009d\u00f5\u00d37\uda53\udc0chV&\u00d8\u0013QP", "type": "csv"}, "name": ""}, {"name": "0", "weight": 725, "weightType": "fix", "stickiness": "2\u00e4\u9022\ud9ed\ude47\uda99\ude91"}, {"payload": {"+\u00b6\u00a8\u00e8\u000e\u0086\u008d\u0093": -130, "else": [-4697551], "\u00ff\u009cR\u00c0\ud8c9\uddb9": {"]\u00ef\u3c68\u001a\u00ee\u0010nXQ~5\u00b6]S\u00fa\u0096\u00a2": null, "\uda89\udf8d\u00ba": 5928, "": {"\u0099]\u00a0\u008a\t\u00e7\u00b0\u00bb\u001e\u00c7\u00ff\u00d6\u00abb\u00a2\u00fa\udb93\udede8\u0087+\uda83\ude7a\u00c0\b\udac1\ude05\\\ud97e\udf4cW\udb20\uddb3N\ue9a8\u00cf\u00d2\u008c{\u0004\u00cd;!\u00e2\udbc0\udf60": "U\u0080\u00a5\u0093c\u00ee\u00ac\ud943\ude0d4"}}, "type": "number", "value": "\u008c\u00f6\u000fW"}, "name": "L\uda74\udd61\u0098", "weight": 362, "stickiness": "Nh{\udb75\udee9\u00bfIN\u0004\u0098\ud8ff\udd1be\u00f4(\u009d\udba7\udc00", "weightType": "fix"}, {"name": "\u00a0\u00ab`\u000f\u0011\udb98\udf66\u001c\u00b5\uf6b0", "weight": 93, "weightType": "fix", "stickiness": ""}], "featureName": "", "title": null, "id": "\u00c5]\rF\u00c4"}, {"parameters": {"\ud9c8\udee6\u0007\u00d8\u00af\u00cf": "w\udb2e\udf9f\ud9b9\udea8\ud8ef\ude21\udb1b\udd5e\u00cd\u008d\u00ac\udafa\udf88,\u00d3\u0089R\u0018\u0097\ud8ac\udef4=\u00baX8\u00a4"}, "title": null, "name": "\u023e"}, {"sortOrder": -2.499135461176719e+155, "featureName": "\u0015k\u00bb\u0087", "parameters": {"z": "", "": "\u00c1g~\u00faj\u0005\u00b3i{%;gz\udbec\ude50\u00fe\u00dc\udaf5\ude89", "\u00d8\u001d_\u00e5\u0012": "\uda21\ude24", "UndefinedStatusCode": "\u00d7\u0011\u007f\u00c7H\"\u00af\u00c1\u001c", "\u00ba": "\udb74\udcbfN\u00a6"}, "id": "kp\u0010V\udbf0\udce3\u00e2Z\u0002r\ud8fd\udc16", "title": "\u00e2\u0090\u00a4\u00f4", "name": "\n", "segments": [-5.367298987109698e+16, -3.486253600038169e+16, 6.27033630103256e+16, 5.288001840015065e+16, -7.931190630160621e-27], "constraints": [{"contextName": "\u009fP\ud88e\udc39'"'"'[", "operator": "SEMVER_GTE"}, {"value": "\uda58\udcf0\uda92\udf27\u00fa\u00b1\u008f\u0095", "inverted": true, "caseInsensitive": false, "values": ["-Infinity", "", "\ud943\udc41\u00fc&I\u00f9", "iqd\uda07\udf77\u0000\u0019\u00e9m\u0081;\u00f5a\ud8c0\udc81\u00e3R", "&", "", "", "a", "|\u00c5", "\ud876\udff7\u001b\u009f\u00fbE\ud8a4\udc4aXc\u00b17\udb2d\udc55`", "\u009a\u00d4\u00f6\u00ack\u00de"], "operator": "NUM_GTE", "contextName": ""}, {"inverted": true, "contextName": "e", "operator": "NUM_GTE", "value": "Q", "values": ["\u083aW\u0018"], "caseInsensitive": true}, {"operator": "SEMVER_LT", "inverted": true, "contextName": "\u00cf\u00c7\udaaf\udfd3\u00eb>", "values": ["lorem \u0644\u0627 \u0628\u0633\u0645 \u0627\u0644\u0644\u0647 ipsum \u4f60\u597d1234\u4f60\u597d", "\u0007"]}, {"contextName": "\u0017\u00d8\u0082\n)t\u0092\udabd\udd7c\u00f9\u00a3", "operator": "NUM_LTE"}, {"operator": "SEMVER_EQ", "contextName": "\u0091`\ud893\udc95"}], "variants": [{"weight": 307, "stickiness": "", "name": "\u00ad", "weightType": "variable"}, {"weight": 216, "name": "m\ud885\udfc9\ud9ef\udf95#{p\f+", "weightType": "variable", "stickiness": "\udb91\udc62>\u007f\u00f8\u0011\u00cd"}, {"weightType": "variable", "name": "G\u00b9", "weight": 479, "stickiness": "\u0004l", "payload": {"\ud95f\udf05\u008f\u008b\u0004": -1297254, "\u0093\u00b4\u0087\u001a\u00a3\udaaf\udc7f": [], "i\ud838\udf63\u008c\u00f7\u0016)\u009d\ud873\uddb6\ud91f\udf89": {}, "m\f\u0086\u00bd\u0099\ud8d8\udeea!\u00c0c\u00aby|\u0098\u0003]\udab8\uddaa\t\u0091\udbdd\ude4f\ud86c\udd8d": {"": -1.7508679697643525e-221, "\u00d0\u00f4\u00cdg": false}, "7p\u00a1": {}, "type": "csv", "value": "\u00e9\uae65\u00a4\uda54\udda8\ud9b2\udeae\u00b4\ud865\udcb0Zk\u0092\u00b5"}}, {"weightType": "fix", "weight": 235, "name": "\u0080", "payload": {"q": [31598], "\udb99\udc01\u0007\u0085\u0011t": -7.140570948725889e+16, "type": "csv", "value": "\u00d3\u00aef\u00f7\u00b7\u00dc\u00ea-"}, "stickiness": "\u00f9\u00c5\u00e2\udb6c\udc5b"}], "disabled": null}], "features": [], "dependencies": [{"dependencies": [{"feature": ""}], "feature": "x\u00f4=\u0080"}, {"dependencies": [{"feature": "\u00bbA\ud86c\udc4c\u009ey", "variants": ["K\u00ba\ud893\udf27d\u0015\u00eex\u00be\u00a5", "\u0088", "", "\u00f0\u00e8\u008c\u00fd\u00a7", "\u00ca\ud8c2\ude41\"f\ud970\uddac\u00ae\u00cdc\u0003)\ud98d\udde6", "\udb8b\udf9a\u00cf\u60eb\b\u00ba\u0001\ud95a\udd3e\u00db\u00beYW", "\u0002", "c\u000f\u00b8\t\u00d6\udb6e\ude1d\ud885\udf70\u00cf\u001e>Q", "\udacc\uddd3\u0093\b", "ContractViolations", "\u00ff\u00bc\u00f19\u0091\u00f2\ud813\udcff\u00ba\u00cc\udabf\udc64\u00c6\ud927\udf89C\ud8e7\udc21\u0017-\udb5e\udf9a\u00ad\u00c9", "\u9223", "0\u00fe\u008b\u001aZ\u00f0", "Z"], "enabled": false}, {"enabled": false, "feature": ""}], "feature": "\u00bbb\u00f6\ud94d\udf8e\u00fc\u00ac\u00e6"}, {"dependencies": [], "feature": "\udb8c\udd62]\u00eci\u0019\udb50\udfed3%{\udb69\ude55"}, {"feature": "", "dependencies": [{"variants": ["", "", "x+\ud9c9\ude7d\u0007\u008f\ud8db\udeb2a\uda97\udcc2\u00d2v\u00f2", "c", ")2\u00cb\u0011\u0086\u0080\udb19\udf76\u00c2)\u0088\udbc6\uddfd", "^\u0017", "\u0010\u0001", "\ud8a8\udf3fK\u00a3\u00c4\udadf\ude42\ud8e6\udd40"], "feature": "q\u00da\udb31\udd95\u0000\udad5\udc28\ud937\udd8f\u00caz\u00a8\u089f\u00ba", "enabled": true}, {"feature": "\udaad\udc3e\u00aeeAs\u009c\ud9f0\ude9f"}, {"feature": "undefined"}, {"feature": "\ud8e1\udff4-\u0014\u00de\u00ae\u0003", "enabled": false}, {"feature": "\udbfe\udca0\u0099\u00f3s\u00a9\u008e\u001d"}, {"enabled": false, "variants": [" I\ud9c2\udd21\u0098_\ud9a4\udcaa\ud848\udc02\u00b4\ud99c\udc7bsN\ud82d\udfca\ud9eb\udf9f\uda8f\udf52\u00d1\u00cb", "\ud965\ude73\udb32\udf98\u0013j\u00c9\u0080"], "feature": "\n\udac1\udf61\u0018\u00ddE\u0086D\u0012\u00c4\ud913\udcac\uda43\udd1d\u00d6\u00df\u00f11\u00da"}, {"variants": ["\u009b2", "\uda1f\udf2e\ucec483{\u00c5\udb49\udd41C\u00d2\u008d\u00a0\u009d\ud8cc\udcfd\u00eb"], "feature": "", "enabled": false}, {"variants": [], "feature": "\u00f6\u00f9", "enabled": false}, {"feature": ""}, {"feature": "%\u00e8", "enabled": true, "variants": ["\u00c6\u00d4\u0001T\u00e5", "", "\u0003\u008f-\u00a9\u00ec`s\u00e8?", "u\u0018", "lorem \u0644\u0627 \u0628\u0633\u0645 \u0627\u0644\u0644\u0647 ipsum \u4f60\u597d1234\u4f60\u597d"]}, {"enabled": false, "feature": "\u0007\u00b4\u0082?\u00ff", "variants": ["", "i", "Y\u00f3"]}, {"feature": "\u00ded8", "variants": ["Q\u0084", "True"]}, {"feature": "g(\ud924\ude5c"}, {"feature": "", "variants": ["\udb50\ude7df\u00ccM\ud820\udedcH\u0016\u0092L\ud8ac\udc84\b\u00be\u0099\ud802\ude87\u00f0\ud895\ude06", ""], "enabled": true}, {"enabled": false, "feature": "\u0001"}, {"feature": "\u009e\u0007\udbdb\udf95B\u00b2\u00e3\u00da\u001a", "enabled": false}]}, {"dependencies": [{"feature": "", "enabled": true}], "feature": "\udb58\ude65\u00eb\u0019\uda54\udc04\u00af\u0087\u0082"}, {"dependencies": [{"feature": "", "enabled": false}, {"feature": "a\ud87e\ude59[|\u0019\udbf8\udf840X\u00c1\ud8b3\uddb3"}, {"enabled": true, "feature": "\u00ad\ud81a\udecf\ud80b\udf85\f{\u00c9\t", "variants": ["\u0019\u00de", "", "jW", "4\u00ac\ud854\udfa0 \u0093\udb5c\udf9f\u00e3\udb12\udf9d\u0086"]}, {"feature": "m\u00ec\u00bc\ud941\udfc6"}, {"feature": "\udace\udcba\u0015", "variants": ["\u00df>q\u001a\u00eb\udbc6\uddea\u0012", "\u00bdR\u00db\u0088\udbf0\udc1f", "\u00f3\u2acc\u0099\u00d2", "\ud987\udeac\udbb5\udcde\u00a2", "S\udace\udc45G\u0083\u0011\u00c5\udb85\uddcc5\u00d7\u009f\u00ba\ud8d1\udf75\u00d2,", "\u00bc7", "\u00cd1K\u009e\ud93f\udc82\ud845\udec0q\ud975\uddad\u00e1\udb71\udc32\u00c6\u001a\u009f\ud971\ude0c", ">$nG8\u00f9wH\u0099\u00b4\udb13\ude64", "\u0089\udad9\udc6e\f\u00cb", "", "", "\u009c", "", "\ud8d0\ude28\u00f2V\u00cdKY"], "enabled": true}, {"feature": "\u00bb"}, {"variants": [], "enabled": true, "feature": "\udb19\udd3182Cc\u00ad"}, {"variants": [], "feature": "\u00ae\u0019f"}, {"variants": ["\u00ba\ud9e4\ude7b\u0011\ud9d0\udebc\u00a7\u001bU\udb6c\ude17\ud9dc\udc93\ud81b\ude5d\u00fa\u00a5\u008b\u0097\u00a9\u00a9`Z)", "\u009e\u007f\u00c5>\u00a3j\u00df\u00831", "True", "\u000b\u0095*\u00f7\u00a2\ud924\udfb2\u00ba"], "feature": "\udaa1\udd1c\u00a8U\u00a5"}, {"feature": "null", "variants": []}, {"feature": "\u008cM\u00c1\u0000\t\u0015\u0096\u00c5AD\ud870\ude31b\u0088\u0085C8\u00b2>\u0004!n\ud822\udce4\u00e1\u00ca\udac9\udfcaH\u00b1Wz4[[S\udb59\udc9f\uda2e\udee6\u0088\u00e5\u00a9\u0098\u0099\u0016\u00ff"}], "feature": "\ud9bd\udcc1\u00b6\ud8d1\udfa9\ud81d\udce3\u001d\u0017\u0097\ud913\udf95;#"}, {"feature": "\udb1c\udc97\u00f6\u00f0", "dependencies": [{"variants": ["R\u20fb\u00e7H\u00d6${#\u0001\u0007\u00faV\u0085>\u00cf\u009c\u00d9\u00fe\u00cb;\u0085\u00bf\u00e8p\ud9c9\udf6d\u00b1\uda83\ude1a", "\u00c6FW,\udbd6\ude49", "%^", "\udad3\ude70\ud895\udd0a\u00c3\u00ba8\u00e3%=\ud8b3\udddc.", "C\u00da\udb02\udc04\u00a1\u008f\ud8ad\ude64", "%\u00bf", "\u00a9}b\u00c2", "\u00cd", "\u009b\f\u00b8\udb74\uddf5\udac6\udd37\ud95c\udd05\u00d0\u00c7Ap", "\udb27\udc5b\udba4\ude63\u00ad\ud886\udf90", "\u00df", "\ud839\udc74\u0095\ud852\udfce", "\u00ec\udbc0\udc2e\ud98d\udf6f\u00ea", ".", "i", "\ud836\udf29\u0011\u001c\u00c2\u008e\u00da\u00b5\u00fbc", "\u008d!\u0010\u0095", "Z\ud898\udcc5\u00df\t5S\u00ef", "\ud894\udd74R\u00eaa", "", "\u000f\u0082\ud840\ude7dW\u008a\u00ce\udac3\udf8d\u0016", "\u00fe\u008e\u00b1\"\u00d2\ud8ff\udcc0", "H\t\u0089G!\u00f8\u1084\u00c7\u00a8\u0088\u0006\u008c\ub1c08\udbf6\ude98\u008aylT:\u00a1f\udbe0\udd66eYB\u00fd\ud940\udf1e\"\u0092\udac1\udea5"], "enabled": true, "feature": "\ud8d9\udd55\u0085\u00e0rB\u0016\u00b2\udb26\udee3\u0092\u00b1\u0084\udbb9\ude7a\f\n\uda70\uddc97"}, {"variants": ["", "\u00e9H", ":", "\u00d2+u\u00f6\u00aeHYQ", "\u00a7\u0016\u001bx\u00da\ud9ea\uded5\u00da\ud9fd\udef1\ud866\udfaa@\u00a0;\u008c\udb6c\udda1\"\u0083\uda54\udfa9", "-script.pyw", "", "\ud987\uddbem*\u0001\udb02\udcb7\u0012;", "", "\udb36\uddddM\u00e6", ">\u007f#\u00ee\udb59\udff2\u001f\u00caT\ud8cb\udff0\u00ab", "\u00c4\u00ec\ud896\ude79\u00bd\uda50\udedd", "AllowHeaderMismatch", "\u00df\udabf\udde0L\ud97d\udd45\u009c7|\u28c8\u000e\u00d5", "\ud9e2\udef8\u00e0\ud92e\ude92", "\u00c1", "~", "H", "lorem \u0644\u0627 \u0628\u0633\u0645 \u0627\u0644\u0644\u0647 ipsum \u4f60\u597d1234\u4f60\u597d", "", "\u00f0\u00aa\udb70\udc8e\u00ff\u00a2\u00bb\u0004\u0099\u00b7", "\ud958\udcc0u`l\u0004&\u1a1d\u00a9:\u009b"], "feature": "\u6de1\ud865\uddb9\udad0\udf4e.\ud9aa\udcf4", "enabled": true}, {"variants": ["\u008bG\udb7f\udfe0\ud865\udc7e\u00fe\u00d0\u00aa\u00bb\udbfd\udf95\u00d7b\u00b1", "A\u00d3\u00dc\u0004\u0014", "\uda96\udd3c\u0012\u0090", "u\u0004\udbdc\udf43", "\udbf2\ude55\u00be Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "my-feature-3", "projectId": false}' http://0.0.0.0:37503/api/admin/features/validate 2. Test Case ID: g0gFRr - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"name\" must be URL friendly. You provided \"\\u0005\"."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "\u0005", "projectId": "project-y"}' http://0.0.0.0:37503/api/admin/features/validate _________________ POST /api/admin/features/{featureName}/tags __________________ 1. Test Case ID: Q1C37v - Response header does not conform to the schema "checkout/tags" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "checkout/tags" [201] Created: `{"value":"a-tag-value","type":"simple"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": "a-tag-value", "type": "simple", "color": "#FFFFFF"}' http://0.0.0.0:37503/api/admin/features/checkout/tags 2. Test Case ID: id2mJg - Undocumented HTTP status code Received: 415 Documented: 201, 400, 401, 403, 404 [415] Unsupported Media Type: `{"id":"14e06fee-7f27-4ae1-99ce-e79cfa177575","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/features/checkout/tags 3. Test Case ID: ynLmbQ - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - value: Incorrect type [201] Created: `{"type":"simple","value":"false"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#000000", "type": "simple", "value": false}' http://0.0.0.0:37503/api/admin/features/checkout/tags 4. Test Case ID: NxVeGT - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Tag type '0000000000000000000000000000000000000000000000000' does not exist","details":[{"message":"Tag type '0000000000000000000000000000000000000000000000000' does not exist"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#000000", "type": "0000000000000000000000000000000000000000000000000", "value": "a-tag-value"}' http://0.0.0.0:37503/api/admin/features/checkout/tags ___________________________ POST /api/admin/feedback ___________________________ 1. Test Case ID: Rw8G5u - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"user_feedback\" (\"feedback_id\", \"given\", \"nevershow\", \"user_id\") values ($1, $2, $3, DEFAULT) on conflict (\"user_id\", \"feedback_id\") do update set \"feedback_id\" = excluded.\"feedback_id\", \"given\" = excluded.\"given\", \"nevershow\" = excluded.\"nevershow\", \"user_id\" = excluded.\"user_id\" returning \"given\", \"user_id\", \"feedback_id\", \"nevershow\" - null value in column \"user_id\" of relation \"user_feedback\" violates not-null constr // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"neverShow": false, "feedbackId": "pnps"}' http://0.0.0.0:37503/api/admin/feedback 2. Test Case ID: oYAG39 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 3 additional properties not defined in the schema (`úÌ`, `򋳶§•  򐎕и`, `򣦶`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Missing feedbackId","details":[{"message":"Missing feedbackId"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud9ef\udcf6\u00a7\u0095\t\u001d\uda00\udf95\u00d0\u00b8": [null, 4.542774514003113e+16], "\uda4e\uddb6\u0006\u008d": {"\u00fc\udb7e\udc3f\u00ff\u000e": {}, "\u0015t\u00e5": [], ".\u0094\udb14\udd52e\ub7b8\uda10\udc491O\u00fd\u001d\u0002\udbd4\udfee\u00bd\u009aY\u00d25\u0016\u00fb\u00f4x\u00b4\u00f3\u0010\u0014\u00c0\u000e\u0097\u0017": {"\u00aa\u00db\udbcc\udcebJ)": [5.959334020759363e+16], "\ud8e0\udc48\u00a6\ud928\udf1b": [5.959334020759363e+16]}}, "\u00fa\u00cc\u0007": {"\u00cb": -2.7333410995327705e-241}, "feedbackId": ""}' http://0.0.0.0:37503/api/admin/feedback ______________________ POST /api/admin/invite-link/tokens ______________________ 1. Test Case ID: rCZlCU - Undocumented HTTP status code Received: 415 Documented: 201, 400, 401, 403 [415] Unsupported Media Type: `{"id":"e778b467-e86a-4c96-b4ae-b4b3e9652d99","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/invite-link/tokens 2. Test Case ID: lNcitX - Response header does not conform to the schema "tokens/7dc262cc1906e5de9db3f8376596ba6a" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "tokens/7dc262cc1906e5de9db3f8376596ba6a" - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - name: Incorrect type [201] Created: `{"secret":"7dc262cc1906e5de9db3f8376596ba6a","name":"","url":"http://localhost:4242/new-user?invite=7dc262cc1906e5de9db3f8376596ba6a","expiresAt":"2000-01-01T00:00:00.000Z","enabled":true,"createdAt":"2026-10-10T12:09:38.875Z","createdBy":"admin","role":{"id":3,"name":"Viewer","type":"root"},"users":[]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"expiresAt": "2000-01-01T00:00:00Z", "name": null}' http://0.0.0.0:37503/api/admin/invite-link/tokens 3. Test Case ID: pyiumZ - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 401, 403 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"public_signup_tokens\" (\"created_by\", \"expires_at\", \"name\", \"role_id\", \"secret\", \"url\") values ($1, $2, $3, $4, $5, $6) returning \"secret\" - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"insert into \"public_signup_tokens\" (\"created_by\", \"expires_at\", \"name\", \"role_id\", \"secret\", \"url\") values ($1, $2, $3, $4, $5, $6) returning \"secret\" - invalid byte sequence for encoding \"UTF8\": 0x00"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"expiresAt": "2026-10-10T12:13:04.633Z", "name": "\u00f5\u000bIxo\u00b52P\u0000\u00a2\u00c2x\ud962\udda2l"}' http://0.0.0.0:37503/api/admin/invite-link/tokens _________________________ POST /api/admin/maintenance __________________________ 1. Test Case ID: wmvKca - Undocumented HTTP status code Received: 415 Documented: 204, 400, 401, 403 [415] Unsupported Media Type: `{"id":"02ca11ec-8ef9-46c4-a993-b30c5ea8133c","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/maintenance ________________ POST /api/admin/metrics/applications/{appName} ________________ 1. Test Case ID: QXR4mI - Undocumented HTTP status code Received: 415 Documented: 202, 400, 401, 403 [415] Unsupported Media Type: `{"id":"b96cd5ea-cd71-40bd-9b1d-ccd667ec33eb","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/metrics/applications/0 2. Test Case ID: UjR39z - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - icon: Incorrect type [202] Accepted: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"strategies": ["standard", "gradualRollout", "mySpecialCustomStrategy"], "url": "https://github.com/Unleash/unleash-proxy-client-js", "color": "red", "icon": null}' http://0.0.0.0:37503/api/admin/metrics/applications/0 3. Test Case ID: EQwUsm - Server error - Undocumented HTTP status code Received: 500 Documented: 202, 400, 401, 403 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"client_applications\" (\"app_name\", \"color\", \"icon\", \"seen_at\", \"updated_at\", \"url\") values ($1, $2, $3, $4, $5, $6) on conflict (\"app_name\") do update set \"app_name\" = excluded.\"app_name\", \"color\" = excluded.\"color\", \"icon\" = excluded.\"icon\", \"seen_at\" = excluded.\"seen_at\", \"updated_at\" = excluded.\"updated_at\", \"url\" = excluded.\"url\" - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"insert into \" // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"w": [], "e\u00b4\u0093\u008b\udb4d\ude7d\udb62\udc11\ud933\uddc8\u00ae": {}, "k\b\u00be\u0005\ud983\udfc1\u0005`\ud95e\udfbe\u00ca%\uda5c\udce7\u000b{\u00c2\u0087\u00e6\u00bd\u0013": {}, "\u00db\u00f8\u0005": ["\u00ff\ud83f\udee7\u00cb}"], "YX}\udaf6\udd25=\u00cc]": [559173, 100001, null], "icon": "\u00acc\ud896\udc6f\u0082\udb43\udf2b\u00d5U", "color": "W7\uda21\udf20\udb5f\udf73b\u00ff", "url": "\u0000\u00e0\u00dc\u00a0I\u0001.(#\u00d1"}' http://0.0.0.0:37503/api/admin/metrics/applications/%C3%AB%F4%82%B4%89 __________________________ POST /api/admin/playground __________________________ 1. Test Case ID: um2DoI - Undocumented HTTP status code Received: 415 Documented: 200, 400, 401 [415] Unsupported Media Type: `{"id":"e05ba421-8ec8-4cec-b2cb-51a88dd4b5eb","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/playground 2. Test Case ID: LZMBWs - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - context -> userId: Incorrect type [200] OK: `{"input":{"environment":"development","projects":[],"context":{"appName":"My cool application.","currentTime":"2022-07-05T12:56:41+02:00","environment":"","properties":{"customContextField":"this is one!","otherCustomField":"3"},"remoteAddress":"192.168.1.1","sessionId":"b65e7b23-fec0-4814-a129-0e9861ef18fc","userId":""}},"features":[]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environment": "development", "projects": [], "context": {"appName": "My cool application.", "currentTime": "2022-07-05T12:56:41+02:00", "environment": "", "properties": {"customContextField": "this is one!", "otherCustomField": "3"}, "remoteAddress": "192.168.1.1", "sessionId": "[Filtered]", "userId": null}}' http://0.0.0.0:37503/api/admin/playground 3. Test Case ID: 7GsLOy - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"features\".\"name\" as \"name\", \"features\".\"description\" as \"description\", \"features\".\"type\" as \"type\", \"features\".\"project\" as \"project\", \"features\".\"stale\" as \"stale\", \"features\".\"impression_data\" as \"impression_data\", \"features\".\"created_at\" as \"created_at\", \"fe\".\"variants\" as \"variants\", \"fe\".\"enabled\" as \"enabled\", \"fe\".\"environment\" as \"environment\", \"fs\".\"id\" as \"strategy_id\", \"fs\".\"strategy_nam // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"context": {"\u00cf\u0092\u009d<\u00cb\u0086s\ud879\udcb4\u00f2\u00d4^_r5\u008c7\u00f7\u00e9T\u00e5\udb4e\udc95\ud8a2\udd99\u008e:\ud879\ude9a\ud8b2\udec2r\u00ce\t\udb02\udcb8\u00c0{": {"\u0091\udbef\udcd7": true, "\u009a\u00c5\u00f2h\u00b7\udafb\udd1a\u009e\u000e\u00eb\udaa3\ude45\ud8f8\udff9\udb15\udf07\u00d0D\u0014\u00ec": 3162, "\u00ea\u0010\udbf9\udf84:\u00fc\u00a9": -97020637797786}, "environment": "\ud829\udd14", "currentTime": "0309-10-11T07:56:02.000Z", "appName": "\ud9ba\ude17\u001f\u00d7\u00c1\udba0\udc6d", "properties": {}, "userId": "\u0086"}, "projects": ["6", "", "\u00b4\u00e5`_\u0097\u00e9!\u0004\ud816\udfde", "\u00fd\u0081\u0002\u008f\u00ad\u008f", "\u0090\u0003\udb41\uddb7\u0017\u00f4\udadf\udf41\u00b6\u0000\u00b6\u00f4\u00cc", "p):\uda04\ude67\u0090\ud888\udf70", "", "", "\ud9a5\ude73\udb71\udc58", "\u00ce", "\u00dd\uda17\udc92", ""], "environment": "\u00c1\u0002"}' http://0.0.0.0:37503/api/admin/playground 4. Test Case ID: wf4Gpf - Response violates schema Additional properties are not allowed ('impressionData', 'enabled', 'description', 'project', 'stale', 'type' were unexpected) Validated against the response schema for status code 200. Schema at /components/schemas/playgroundFeatureSchema: { "additionalProperties": false, "description": "A simplified feature flag model intended for the Unleash ... "type": "object", "required": [ "name", "projectId", "isEnabled", "isEnabledInCurrentEnvironment", "variant", "variants", "strategies" ], "properties": { "name": { "type": "string", "example": "my-feature", "description": "The feature's name." }, // Output truncated... } Value: { "description": null, "enabled": false, "hasUnsatisfiedDependency": false, "impressionData": false, "isEnabled": false, "isEnabledInCurrentEnvironment": false, "name": "1323", "project": "default", "projectId": "default", "stale": false, "strategies": { "data": [], "result": false }, "type": "permission", "variant": { "enabled": false, "feature_enabled": false, // Output truncated... } [200] OK: `{"input":{"context":{"appName":"My cool application."},"environment":"development"},"features":[{"isEnabled":false,"isEnabledInCurrentEnvironment":false,"hasUnsatisfiedDependency":false,"variant":{"name":"disabled","enabled":false,"feature_enabled":false},"variants":[],"impressionData":false,"enabled":false,"description":null,"project":"default","stale":false,"type":"permission","name":"1323","projectId":"default","strategies":{"result":false,"data":[]}},{"isEnabled":false,"isEnabledInCurrentEnvironment":fa // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"context": {"appName": "My cool application."}, "environment": "development"}' http://0.0.0.0:37503/api/admin/playground _____________________ POST /api/admin/playground/advanced ______________________ 1. Test Case ID: qFmlxl - Undocumented HTTP status code Received: 415 Documented: 200, 400, 401 [415] Unsupported Media Type: `{"id":"43dac047-203e-47e1-944c-c0b1e809af42","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/playground/advanced 2. Test Case ID: xMJR6q - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - context -> userId: Incorrect type [200] OK: `{"features":[],"input":{"environments":["development","production"],"projects":[],"context":{"appName":"My cool application.","currentTime":"2022-07-05T12:56:41+02:00","environment":"","properties":{"customContextField":"this is one!","otherCustomField":"3"},"remoteAddress":"192.168.1.1","sessionId":"b65e7b23-fec0-4814-a129-0e9861ef18fc","userId":""}}}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environments": ["development", "production"], "projects": [], "context": {"appName": "My cool application.", "currentTime": "2022-07-05T12:56:41+02:00", "environment": "", "properties": {"customContextField": "this is one!", "otherCustomField": "3"}, "remoteAddress": "192.168.1.1", "sessionId": "[Filtered]", "userId": null}}' http://0.0.0.0:37503/api/admin/playground/advanced 3. Test Case ID: X0iJLf - Response violates schema (2 violations) Additional properties are not allowed ('hasUnsatisfiedDependency' was unexpected) Validated against the response schema for status code 200. Schema at /components/schemas/advancedPlaygroundEnvironmentFeatureSchema: { "additionalProperties": false, "description": "A simplified feature flag model intended for the Unleash ... "type": "object", "required": [ "name", "environment", "context", "projectId", "isEnabled", "isEnabledInCurrentEnvironment", "variant", "variants", "strategies" ], "properties": { "name": { "type": "string", "example": "my-feature", // Output truncated... } Value: { "context": { "appName": "My cool application.", "currentTime": "2022-07-05T12:56:41+02:00", "customContextField": "this is one!", "environment": "", "otherCustomField": "3", "remoteAddress": "192.168.1.1", "sessionId": "b65e7b23-fec0-4814-a129-0e9861ef18fc", "userId": "username@provider.com" }, "environment": "development", "hasUnsatisfiedDependency": false, "isEnabled": true, "isEnabledInCurrentEnvironment": true, "name": "search", "projectId": "default", "strategies": { "data": [ // Output truncated... } {"enabled":false,"featureEnabled":true,"feature_enabled":true,"name":"disabled"} is not valid under any of the schemas listed in the 'anyOf' keyword Validated against the response schema for status code 200. Schema at /components/schemas/advancedPlaygroundEnvironmentFeatureSchema/properties/variant: { "anyOf": [ { "description": "The feature variant you receive based on the prov... "type": "object", "additionalProperties": false, "required": [ "name", "enabled" ], "properties": { "name": { "type": "string", "description": "The variant's name. If there is no varian... "example": "red-variant" }, "enabled": { "type": "boolean", "description": "Whether the variant is enabled or not. If... // Output truncated... } Value: { "enabled": false, "featureEnabled": true, "feature_enabled": true, "name": "disabled" } [200] OK: `{"features":[{"name":"search","projectId":"default","environments":{"development":[{"isEnabled":true,"isEnabledInCurrentEnvironment":true,"hasUnsatisfiedDependency":false,"variant":{"feature_enabled":true,"featureEnabled":true,"name":"disabled","enabled":false},"context":{"currentTime":"2022-07-05T12:56:41+02:00","environment":"","customContextField":"this is one!","otherCustomField":"3","remoteAddress":"192.168.1.1","sessionId":"b65e7b23-fec0-4814-a129-0e9861ef18fc","userId":"username@provider.com","appNam // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environments": ["development", "production"], "projects": "*", "context": {"appName": "My cool application.", "currentTime": "2022-07-05T12:56:41+02:00", "environment": "", "properties": {"customContextField": "this is one!", "otherCustomField": "3"}, "remoteAddress": "192.168.1.1", "sessionId": "[Filtered]", "userId": "username@provider.com"}}' http://0.0.0.0:37503/api/admin/playground/advanced 4. Test Case ID: 6ZGGXc - Response violates schema "" is shorter than 1 character Validated against the response schema for status code 200. Schema at /components/schemas/sdkFlatContextSchema/properties/appName: { "minLength": 1, "type": "string", "example": "My cool application.", "description": "The name of the application." } Value: "" [200] OK: `{"features":[{"name":"0","projectId":"default","environments":{"Qv0iAM_mv0bmB":[{"isEnabled":false,"isEnabledInCurrentEnvironment":false,"hasUnsatisfiedDependency":false,"variant":{"name":"disabled","enabled":false,"feature_enabled":false},"context":{"environment":"æ𱃵„􋘱d","":":ÿÓ","\u000b\u0017\b0":"","… Ñ,v(ÿ\u0005":"򫶕¿€F𩄡f","󫯕":"\u0002®","񧆓":"򣋓Ô󞌣ã񁟓©","userId":"\u0012>\u001fng","appName":"$Àšr«\u0017Ú񇯅¿򾶞G"},"variants":[],"name":"0","environment":"Qv0iAM_mv0bmB","projectId":"default","strategies":{"result": // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u0097\u0081%\ud9eb\udcd3\u0089": [null], "\u0014\u0010\u00b1": {}, "\u00f3\u00c9s=\u00d9\u00dd\u0007\udb90\ude38\u00b5\ud846\uddb8": {"\udaf8\udfcaV\u0093\u00fc\udaed\udf66\u001e": [], "\udbde\udc9a\u00cb\uda4c\udedcN": -58826, "\udbb7\udee8\uda7f\udfe5\u0011\u00fd\u00c3\u00ba\u008d": [4.025424445903101e+16]}, "\u009c,": -17357, "@": -524289, "context": {"\ud83a\udf4a\u00b1\u0092\u00ff\u00fe\u0015\u00fd\u00cd": [null], "$T\u00fc": false, "2": -9007199254740992.0, "\u00c1\u00ea\u00fc\u000b\u001c\ud85d\udec3\u00e11\u0080": {}, "\u00c4\u00df/": -83840483287, "environment": "\u00e6\ud884\udcf5\u0084\udbed\ude31d", "appName": "$\u00c0\u009ar\u00ab\u0090\u0017\u00da\ud8de\udfc5\u00bf\udabb\udd9eG,", "properties": {"": ":\u00ff\u00d3", "\u000b\u0017\b0": "", "\u0085\u00d1,v(\u00ff\u0005": "\uda6f\udd95\u00bf\u0080F\ud864\udd21f", "\udb6e\udfd5": "\u0002\u00ae", "\ud95c\udd93": "\uda4c\uded3\u00d4\udb38\udf23\u00e3\ud8c5\udfd3\u00a9"}, "userId": "\u0012>\u001fng"}, "environments": ["Qv0iAM_mv0bmB", "FC-7N", "-mLxW"]}' http://0.0.0.0:37503/api/admin/playground/advanced _______________ POST /api/admin/projects/{projectId}/api-tokens ________________ 1. Test Case ID: OhegD2 - Response header does not conform to the schema "api-tokens" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "api-tokens" [201] Created: `{"environment":"development","expiresAt":"2023-10-01T00:00:00.000Z","tokenName":"some-user","projects":["default"],"secret":"default:development.35762b16221b146c2702afc27601b6b710861191b6f7aeea5913e827","type":"frontend","alias":null,"project":"default","createdAt":"2026-10-10T12:09:25.926Z","secure":false}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"type": "frontend", "environment": "development", "expiresAt": "2023-10-01T00:00:00Z", "tokenName": "[Filtered]"}' http://0.0.0.0:37503/api/admin/projects/default/api-tokens 2. Test Case ID: zKHsFx - Undocumented HTTP status code Received: 415 Documented: 201, 400, 401, 403, 404 [415] Unsupported Media Type: `{"id":"dadeb957-837a-4164-8d85-be48b6029faf","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/api-tokens 3. Test Case ID: xZwizz - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - tokenName: Incorrect type [201] Created: `{"environment":"development","expiresAt":"2023-10-01T00:00:00.000Z","tokenName":"false","projects":["default"],"secret":"default:development.34804b5d866de0f3fc12ce49241957f8d0602a6d1715d9b5941cd68e","type":"frontend","alias":null,"project":"default","createdAt":"2026-10-10T12:09:43.973Z","secure":false}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"type": "frontend", "environment": "development", "expiresAt": "2023-10-01T00:00:00Z", "tokenName": "[Filtered]"}' http://0.0.0.0:37503/api/admin/projects/default/api-tokens 4. Test Case ID: NbLfoc - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Environment=default does not exist","details":[{"message":"Environment=default does not exist"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"type": "frontend", "environment": "default", "expiresAt": "2023-10-01T00:00:00Z", "tokenName": "[Filtered]"}' http://0.0.0.0:37503/api/admin/projects/default/api-tokens _________________ POST /api/admin/projects/{projectId}/archive _________________ 1. Test Case ID: gNjYen - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - features -> Array with invalid items: Incorrect type [202] Accepted: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": [null]}' http://0.0.0.0:37503/api/admin/projects/default/archive 2. Test Case ID: b8e9m3 - Server error - Undocumented HTTP status code Received: 500 Documented: 202, 400, 401, 403, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"select * from \"features\" where \"name\" in ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15) order by \"name\" asc - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select * from \"features\" where \"name\" in ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15) order by \"name\" asc - invalid byte sequence for encoding \"UTF8\": 0x00"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\udbb1\udfe7w;{\ud9fb\udf26H": {"\u00f0a\u00dc\u00fa\u00bbA\u00b0\u00ad": {"/\u00fd\ud929\udfa1": null, "y~\udb42\udd50\u00f09": [], "E\uda07\udcc2d": -1138}, "ServerError": [[]], "\u009c\u00fb\ud884\udd02\u00f5": null}, "features": ["MalformedMediaType", "\u00e5", "*", "\u00fd\u00d2", "", "ms6\u00f6b&Qbq\u0000\udb7f\udd9d", "Ly\u987d\u00e7", "\ud8d9\udcd7\u0016\u0003\u001cJ\u00f65\u00ffU", "{4\udb17\udcfe\u00a6", "", "\u0099\u0015H\u00ab\u00cc\ud8f3\ude83\u0091\ud942\udf95\u00d9\u0089\u00b5\udb3a\uddb5\u00a7", "N^\u00dc\udbc0\udc9dy\n\u00c7", "\u0002", "\u0000\ud862\udef3\uda3b\udf11\udac2\uddf5?", "\u009d\u0097\u00f3\udbcd\ude7a\udb58\udf83\u00c0\u00f9\u009e\u0007\ud9c3\udea3\u00fao\uda08\ude5a\u0083\u00c9\u00ef\ud8b7\udec0"]}' http://0.0.0.0:37503/api/admin/projects/default/archive ____________ POST /api/admin/projects/{projectId}/archive/validate _____________ 1. Test Case ID: zHFIpa - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - features -> Array with invalid items: Incorrect type [200] OK: `{"parentsWithChildFeatures":[],"hasDeletedDependencies":false}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": [null]}' http://0.0.0.0:37503/api/admin/projects/default/archive/validate 2. Test Case ID: 7FqFea - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"select * from \"dependent_features\" where \"parent\" in ($1, $2) or \"child\" in ($3, $4) limit $5 - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select * from \"dependent_features\" where \"parent\" in ($1, $2) or \"child\" in ($3, $4) limit $5 - invalid byte sequence for encoding \"UTF8\": 0x00"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u0098\u00ca\uda9f\udd8d\u008d,\u00b4Kl\u0007.^\ud899\udd6d": {}, "\u169b\u1684\u1693\u1690\u168b\u1692\u1684\u1680\u1691\u1684\u1682\u1691\u168f\u1685\u169c": false, "": [], "\u0088": {"\u00b0\u00ac": "\u00d8*\uda2b\udd99d\b\u0092\u00f0\u009e\u0081\u0015\udb07\ude8ej\u0013\udac2\udd16C\udb2b\udc30"}, "\udbf2\udd27\u00e4\ud867\udfd3\u00a9\ud994\ude25\udb17\udea7\u00cc8^\u00d8\u0089\ud933\udd9f\u00cd": [], "features": ["\u0000\u000e\u0080c", "\u00f5\u0000\u00b8\u00d7\rh\u0082\u0015"]}' http://0.0.0.0:37503/api/admin/projects/default/archive/validate POST /api/admin/projects/{projectId}/bulk_features/environments/{environment}/on 1. Test Case ID: 143jkd - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404, 413, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"SELECT EXISTS (SELECT 1 FROM feature_environments WHERE feature_name = $1 AND environment = $2) AS present - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"SELECT EXISTS (SELECT 1 FROM feature_environments WHERE feature_name = $1 AND environment = $2) AS present - invalid byte sequence for encoding \"UTF8\": 0x00"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": {"": 4239, "\u008f\u00ff\u00e6\u001f\u00866^pp": "", "\udb88\udf91\u00f4\ud487\udbdf\udcc8\u00dd\u00c5\ud827\udfba": -6.554545541023455e+93}, "\u00d2\ud945\udf2e\ta\u00fd\ud91f\ude94q\uda7e\udfda": "\u0007", "\u00c8&C+\u0010e": {}, "features": ["\u00f1\u00ea\u00fa\udaa3\udc73\u00c5[\u00aec1\udb21\udd094\u0000yb\u00db\u001a\u00a2", "!\u0093\udbf1\udf4cd\ud8e1\ude77\udbcb\udcfe/", "", "\u008cg\u001cv", "COM1", "9"]}' http://0.0.0.0:37503/api/admin/projects/default/bulk_features/environments/production/on _________________ POST /api/admin/projects/{projectId}/context _________________ 1. Test Case ID: 8PLOnw - Response header does not conform to the schema "context/subscriptionTier" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "context/subscriptionTier" [201] Created: `{"name":"subscriptionTier","description":"The user's subscription tier","stickiness":false,"sortOrder":2,"legalValues":[{"value":"#c154c1","description":"Deep fuchsia"}],"createdAt":"2026-10-10T12:09:26.032Z","project":"default"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "#c154c1", "description": "Deep fuchsia"}], "project": "my-project", "name": "subscriptionTier"}' http://0.0.0.0:37503/api/admin/projects/default/context 2. Test Case ID: ctalwE - Undocumented HTTP status code Received: 409 Documented: 201 [409] Conflict: `{"name":"NameExistsError","message":"A context field with that name already exist","details":[{"message":"A context field with that name already exist"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "gold"}, {"value": "silver"}, {"value": "crystal"}], "project": "my-project", "name": "subscriptionTier"}' http://0.0.0.0:37503/api/admin/projects/default/context 3. Test Case ID: F4CUYi - Undocumented HTTP status code Received: 415 Documented: 201 [415] Unsupported Media Type: `{"id":"477d43d5-124e-4458-bc17-76818093a42d","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/context 4. Test Case ID: No9X7q - Undocumented HTTP status code Received: 400 Documented: 201 [400] Bad Request: `{"id":"e4a099b0-8b9b-4f6a-b48e-0f9c8dbb7508","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"path":"/body/name","message":"The `/body/name` property is required. It was not present on the data you sent."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "gold"}, {"value": "silver"}, {"value": "crystal"}], "project": "my-project"}' http://0.0.0.0:37503/api/admin/projects/default/context 5. Test Case ID: IKEGZj - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - name: Incorrect type [201] Created: `{"name":"false","description":"The user's subscription tier","stickiness":false,"sortOrder":2,"legalValues":[{"value":"gold"},{"value":"silver"},{"value":"crystal"}],"createdAt":"2026-10-10T12:09:44.192Z","project":"default"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "gold"}, {"value": "silver"}, {"value": "crystal"}], "project": "my-project", "name": false}' http://0.0.0.0:37503/api/admin/projects/default/context 6. Test Case ID: KhoXis - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"name\" must be URL friendly. You provided \"Rollout percentage\"."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "Rollout percentage"}' http://0.0.0.0:37503/api/admin/projects/project-y/context 7. Test Case ID: JwCFLe - Server error - Undocumented HTTP status code Received: 500 Documented: 201 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"context_fields\" (\"description\", \"legal_values\", \"name\", \"project\", \"sort_order\", \"stickiness\") values ($1, $2, $3, $4, $5, $6) returning * - value \"2381125902\" is out of range for type integer","details":[{"message":"insert into \"context_fields\" (\"description\", \"legal_values\", \"name\", \"project\", \"sort_order\", \"stickiness\") values ($1, $2, $3, $4, $5, $6) returning * - value \"2381125902\" is out of range for type integer"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00a6\u00b9": {"\u0088\uda65\udea9\u00a4J\udb45\udf4c": true, "": [-3.370246926654684e+16], "Rf\ud9a1\udfcf<": {}}, "}\ud912\udddb": [], " \u00ba\u00c0\uda58\udc05\f\u00a0": {"\ud9b8\udcf7\u00f5\u7b7f\u00ccy\ud85d\udc63\u00d4%\uda59\udf78\ud93f\udd450": false}, "description": "\u0083", "name": "emojiIcon", "sortOrder": 2381125902, "stickiness": true}' http://0.0.0.0:37503/api/admin/projects/default/context ____________ POST /api/admin/projects/{projectId}/context/validate _____________ 1. Test Case ID: VjbUTp - Undocumented HTTP status code Received: 415 Documented: 200 [415] Unsupported Media Type: `{"id":"f0bca941-9d09-421c-90ef-e5017a0beae5","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/context/validate 2. Test Case ID: 3K43Jd - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"id":"60809c03-1d75-47b6-809c-a9c186393cd8","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/name` property must be string. You sent {}.","path":"/body/name"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": {}}' http://0.0.0.0:37503/api/admin/projects/default/context/validate 3. Test Case ID: MudLRO - Undocumented HTTP status code Received: 409 Documented: 200 [409] Conflict: `{"name":"NameExistsError","message":"A context field with that name already exist","details":[{"message":"A context field with that name already exist"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": false}' http://0.0.0.0:37503/api/admin/projects/default/context/validate 4. Test Case ID: O8wyk8 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"name\" must be URL friendly. You provided \"ó㰗\\u000e?¹\"."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "\u00f3\u00e3\u00b0\u0097\u000e?\u00b9"}' http://0.0.0.0:37503/api/admin/projects/default/context/validate 5. Test Case ID: XmX0My - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` at /properties/name (was string, became number) [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": -1.192092896e-07}' http://0.0.0.0:37503/api/admin/projects/default/context/validate ___ POST /api/admin/projects/{projectId}/context/{contextField}/legal-values ___ 1. Test Case ID: WgZSDy - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"Could not find context field region in project default","details":[{"message":"Could not find context field region in project default"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"value": "#c154c1", "description": "Deep fuchsia"}' http://0.0.0.0:37503/api/admin/projects/default/context/region/legal-values 2. Test Case ID: Yr5xFC - Undocumented HTTP status code Received: 415 Documented: 200 [415] Unsupported Media Type: `{"id":"f3f93fd6-2ecc-4b4c-9014-98145416b823","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/context/0/legal-values 3. Test Case ID: VPxW1m - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"id":"a6fa877c-0014-43db-9c35-5e96dbfaa39d","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/description` property must be string. You sent {}.","path":"/body/description"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": {}, "value": "#c154c1"}' http://0.0.0.0:37503/api/admin/projects/default/context/0/legal-values 4. Test Case ID: CbWsVa - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - description: Incorrect type [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": null, "value": "#c154c1"}' http://0.0.0.0:37503/api/admin/projects/default/context/0/legal-values _________________ POST /api/admin/projects/{projectId}/delete __________________ 1. Test Case ID: qPAV3r - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - features -> Array with invalid items: Incorrect type [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": [null]}' http://0.0.0.0:37503/api/admin/projects/default/delete 2. Test Case ID: do9pcs - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403 [500] Internal Server Error: `{"name":"UnknownError","message":"select * from \"features\" where \"name\" in ($1, $2, $3, $4) order by \"name\" asc - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select * from \"features\" where \"name\" in ($1, $2, $3, $4) order by \"name\" asc - invalid byte sequence for encoding \"UTF8\": 0x00"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": [{"": [3497478671779146760192, 6.17727792032033e+16, false]}], "-C]\u00dc\ud970\udc79\u00f6\u00e9f\udb49\udefc\udb44\udc49K\u00d0": "\uda24\udd71", "O\u00f8": [-2.7029115820818624e+16, 5.98513742856718e+16, "W\u00c3\u008d\u00bf"], ",./;'"'"'[]\\-=<>?:\"{}|_+!@#$%^&*()`~": [], "\u00dftQ\u00fc*\uc074o\ud973\udf67": {}, "features": ["\ud847\ude4eg", "\u00a4\u00f6\ud9d0\ude52!\u0087 \u00de\ud8c0\udffb\u0016\u00aaW\udb38\udfb7\ud946\udd24\udaba\udc77", "\u00e1\ud980\udea1r\u0089\u0000\u00f3", "\ud8e7\udd30\u00cb\u00a8\u00c2\u00de\u00fb.\u00b6\u00c6\u00f2\ud935\udf9f\u00fd\u00f2(\u0013\ud9eb\udd4e"]}' http://0.0.0.0:37503/api/admin/projects/default/delete ______________ POST /api/admin/projects/{projectId}/environments _______________ 1. Test Case ID: 4oyr5k - Undocumented HTTP status code Received: 415 Documented: 200, 401, 403, 409 [415] Unsupported Media Type: `{"id":"e05d7907-7574-4d86-8159-2025ac0651b9","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/environments 2. Test Case ID: UEP6Ql - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 409 [400] Bad Request: `{"id":"f3ed4bae-53ec-4437-b5a0-10f1959226ac","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/defaultStrategy/segments/0` property must be number. You sent {}.","path":"/body/defaultStrategy/segments/0"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"changeRequestsEnabled": true, "defaultStrategy": {"name": "flexibleRollout", "title": null, "disabled": null, "sortOrder": 9999, "constraints": [{"values": ["1", "2"], "inverted": false, "operator": "IN", "contextName": "appName", "caseInsensitive": false}], "variants": [], "parameters": {}, "segments": [{}]}, "environment": "development"}' http://0.0.0.0:37503/api/admin/projects/default/environments 3. Test Case ID: SftxYG - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Environment does not exist","details":[{"message":"Environment does not exist"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environment": ""}' http://0.0.0.0:37503/api/admin/projects/default/environments 4. Test Case ID: pgJuhf - Undocumented HTTP status code Received: 404 Documented: 200, 401, 403, 409 [404] Not Found: `{"name":"NotFoundError","message":"No project found","details":[{"message":"No project found"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"changeRequestsEnabled": false, "environment": "\u00dd\udb7a\udddf\u00cd", "defaultStrategy": {"sortOrder": 6.053690060772204e+16, "name": "my-custom-strategy", "parameters": {"6": "\ud87f\udf7f\ud85c\ude42\ud8e4\udcd8\u0092\u00ba\u001fb\u00c8^xl1B", "\u0081qJ\u00c0\u00e2\ud8c3\udf6e\u00ad\u0089\u00e1I:)\u00ad\ud830\udec8\u00caq<\ud890\udf85": "O\u0017\udb4a\ude06R\u00b0\u00eb\udb55\udf42!\u00de\udae7\udd9b\u00ae\ud97a\udd79\ud8d6\ude0f\ud8f3\uddc7", "H": "\ud8ee\udcae\u0093\u00a4J\ud987\udf85", "\ud945\udcfb\u0005\ud30b\u0002]\u00a0\u00a0M\udb73\udfab": "n\u008dr\u00c6"}, "title": null}}' http://0.0.0.0:37503/api/admin/projects/L%C3%A7%F2%AA%AB%91x%C3%9Ch%28e/environments POST /api/admin/projects/{projectId}/environments/{environment}/default-strategy 1. Test Case ID: uKKy5P - Undocumented HTTP status code Received: 415 Documented: 200, 400 [415] Unsupported Media Type: `{"id":"f2e77ae7-a6fe-47b0-8cc6-247a5d3d688b","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/environments/development/default-strategy 2. Test Case ID: Fmk5aE - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - segments -> Array with invalid items: Incorrect type [200] OK: `{"name":"flexibleRollout","title":null,"disabled":null,"segments":[0],"variants":[],"sortOrder":9999,"parameters":{},"constraints":[{"values":["1","2"],"inverted":false,"operator":"IN","contextName":"appName","caseInsensitive":false}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "flexibleRollout", "title": null, "disabled": null, "sortOrder": 9999, "constraints": [{"values": ["1", "2"], "inverted": false, "operator": "IN", "contextName": "appName", "caseInsensitive": false}], "variants": [], "parameters": {}, "segments": [null]}' http://0.0.0.0:37503/api/admin/projects/default/environments/development/default-strategy 3. Test Case ID: vTTtsE - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Only \"flexibleRollout\" strategy can be used as a default strategy for an environment","details":[{"message":"Only \"flexibleRollout\" strategy can be used as a default strategy for an environment"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "my-custom-strategy"}' http://0.0.0.0:37503/api/admin/projects/project-y/environments/production/default-strategy ________________ POST /api/admin/projects/{projectId}/favorites ________________ 1. Test Case ID: C4PHgZ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 415 Documented: 200, 401, 404 [415] Unsupported Media Type: `{"id":"eb95a43b-454e-4a89-895f-9b5820a64526","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/favorites ________________ POST /api/admin/projects/{projectId}/features _________________ 1. Test Case ID: 2piV35 - Undocumented HTTP status code Received: 201 Documented: 200, 401, 403, 404, 415 [201] Created: `{"name":"disable-comments","description":"Controls disabling of the comments section in case of an incident","type":"release","project":"default","stale":false,"createdAt":"2026-10-10T12:09:26.176Z","impressionData":false,"archived":false}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "disable-comments", "type": "release", "description": "Controls disabling of the comments section in case of an incident", "impressionData": false, "tags": [{"value": "a-tag-value", "type": "simple", "color": "#FFFFFF"}]}' http://0.0.0.0:37503/api/admin/projects/default/features 2. Test Case ID: yk7b1H - Undocumented HTTP status code Received: 409 Documented: 200, 401, 403, 404, 415 [409] Conflict: `{"name":"NameExistsError","message":"A flag with that name already exists","details":[{"message":"A flag with that name already exists"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "disable-comments", "type": "release", "description": "Controls disabling of the comments section in case of an incident", "impressionData": false, "tags": [{"value": "a-tag-value", "type": "simple", "color": "#FFFFFF"}]}' http://0.0.0.0:37503/api/admin/projects/default/features 3. Test Case ID: hmKBH3 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404, 415 [400] Bad Request: `{"id":"1c849fea-1ada-4d6e-9f79-7bf22ed3dd00","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/tags/0/color` property must match pattern \"^#[0-9A-Fa-f]{6}$\". You sent \"AAA\".","path":"/body/tags/0/color"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "disable-comments", "type": "release", "description": null, "impressionData": false, "tags": [{"color": "AAA", "type": "simple", "value": "a-tag-value"}]}' http://0.0.0.0:37503/api/admin/projects/default/features 4. Test Case ID: NHd0kk - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - name: Incorrect type [201] Created: `{"name":"false","description":null,"type":"release","project":"default","stale":false,"createdAt":"2026-10-10T12:09:45.428Z","impressionData":false,"archived":false}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": false, "type": "release", "description": null, "impressionData": false, "tags": []}' http://0.0.0.0:37503/api/admin/projects/default/features 5. Test Case ID: 90RzI4 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (`4`, `eÑα0`, ` ¥®Ü񋼚BO󼮥jÔ򉜠lÓ` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"name\" is not allowed to be empty."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{" \u00a5\u00ae\u0012\u00dc\ud8ef\udf1aBO\udbb2\udfa5j\u00d4\u0001\ud9e5\udf20l\u00d3": {}, "\u4c2a\udb1c\udfb7\ud8a8\udcff\ud970\udc47\u00c2\u00db}\u000b": [true, 3.166580574153051e+16], "\u0014e\u00d1\u00ce\u00b10": {}, "\u0083\ud9b8\udd20": {"started_at": [1.7976931348623157e+308]}, "\u00064": null, "name": ""}' http://0.0.0.0:37503/api/admin/projects/default/features ______ POST /api/admin/projects/{projectId}/features/{child}/dependencies ______ 1. Test Case ID: duqEGg - Undocumented HTTP status code Received: 415 Documented: 200, 401, 403, 404 [415] Unsupported Media Type: `{"id":"33d65212-0f96-4a58-a817-faece5675deb","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features/0/dependencies 2. Test Case ID: 4tzykm - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"id":"7394c697-622f-4c8c-81b7-044db8dbe97c","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/variants/0` property must be string. You sent {}.","path":"/body/variants/0"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"feature": "parent_feature", "enabled": false, "variants": [{}]}' http://0.0.0.0:37503/api/admin/projects/default/features/0/dependencies 3. Test Case ID: OUa48c - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - feature: Incorrect type [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"feature": false, "enabled": false, "variants": ["variantA", "variantB"]}' http://0.0.0.0:37503/api/admin/projects/default/features/0/dependencies ______ POST /api/admin/projects/{projectId}/features/{featureName}/clone _______ 1. Test Case ID: spT9yr - Undocumented HTTP status code Received: 201 Documented: 200, 401, 403, 404, 415 [201] Created: `{"name":"new-feature","description":"Seeded","type":"release","project":"default","stale":false,"createdAt":"2026-10-10T12:09:26.511Z","impressionData":false,"archived":false}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "new-feature", "replaceGroupId": true}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/clone 2. Test Case ID: iO5sSP - Undocumented HTTP status code Received: 409 Documented: 200, 401, 403, 404, 415 [409] Conflict: `{"name":"NameExistsError","message":"A flag with that name already exists","details":[{"message":"A flag with that name already exists"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "new-feature", "replaceGroupId": true}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/clone 3. Test Case ID: afDPFZ - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404, 415 [400] Bad Request: `{"id":"eb2057bf-fa37-42e9-9d07-aaa8f3fea26a","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"path":"/body/name","message":"The `/body/name` property is required. It was not present on the data you sent."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/clone 4. Test Case ID: FcUCIv - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (`é𸏇Ϫò`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"name\" must be URL friendly. You provided \"*Ì­`µf1\\u0010±RàªíD¸,#\"."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00e9\ud8a0\udfc7\u00cf\u00aa\u00c3\u00b2": [], "name": "*\u00cc\u00ad\u008d`\u00b5f1\u0010\u00b1R\u00e0\u00aa\u00edD\u00b8,#\u007f", "replaceGroupId": true}' http://0.0.0.0:37503/api/admin/projects/default/features/search/clone 5. Test Case ID: cXSQ4S - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"feature_environments\" (\"enabled\", \"environment\", \"feature_name\", \"variants\") values ($1, $2, $3, $4) on conflict (\"feature_name\", \"environment\") do update set \"variants\" = excluded.\"variants\" - null value in column \"environment\" of relation \"feature_environments\" violates not-null constraint","details":[{"message":"insert into \"feature_environments\" (\"enabled\", \"environment\", \"feature_name\", \"variants\") values ($1, $2, $3, $4) on // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u0083\ud9de\udd5a\u00e46~;\b\u00f2": {}, "\u00c6": true, "": {"\u00d5\u00b0H\ud8b8\udf5cf\u00c5\ud91c\udd28": "", "Y\u00a0\u0080": {}, "`": ""}, "\u00cd\u00c6": [[null, 0.5, true], true], "\u00aa~W\u00fb\u0088": [], "name": "production"}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/clone POST /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/strategies 1. Test Case ID: xHyUXH - Undocumented HTTP status code Received: 415 Documented: 200, 401, 403, 404 [415] Unsupported Media Type: `{"id":"a514c0fc-411f-4362-bd3c-3c92d5187ded","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/0/features/checkout/environments/0/strategies 2. Test Case ID: AItXAO - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"id":"e1776fb9-4b71-49be-bbbd-bcdf55d54770","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/segments/0` property must be number. You sent {}.","path":"/body/segments/0"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "flexibleRollout", "title": null, "disabled": null, "sortOrder": 9999, "constraints": [{"values": ["1", "2"], "inverted": false, "operator": "IN", "contextName": "appName", "caseInsensitive": false}], "variants": [], "parameters": {}, "segments": [{}]}' http://0.0.0.0:37503/api/admin/projects/0/features/checkout/environments/0/strategies 3. Test Case ID: BNR4SJ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Could not find strategy type with name l","details":[{"message":"Could not find strategy type with name l"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "l"}' http://0.0.0.0:37503/api/admin/projects/default/features/search/environments/development/strategies 4. Test Case ID: 519WIw - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"segments\".\"id\", \"segments\".\"name\", \"segments\".\"description\", \"segments\".\"segment_project_id\", \"segments\".\"created_by\", \"segments\".\"created_at\", \"segments\".\"constraints\" from \"segments\" where \"id\" = $1 - value \"-23341597679853690\" is out of range for type integer","details":[{"message":"select \"segments\".\"id\", \"segments\".\"name\", \"segments\".\"description\", \"segments\".\"segment_project_id\", \"segments\".\"created_by\", \" // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": {}, "variants": [{"&^H\u0013\ue031": {"a\u0017\u00d1\ud9ed\udfe39c\udb6a\udd275": [null], "\u000e\u0002": [null, 690]}, "\u00c9\u008e[\u00a8\u001f\u0012\u00b2\u00bd\u00b2n\u00c9C\u00952\u00de": {}, "": {"\udb7a\ude15\u00bd": null, "M\u00f6\u00ab": 1.4605445670951643e+64}, "\u00d2W+": {"\u00af": ["4;\ud830\udf24\u00e6\u00ac\u0006\u0016", "\u001f", true]}, "\u0015\"J": [true, "\ud847\udc6f\udb1c\udf80\u00b0"], "stickiness": "\\/7Y\u00df", "weightType": "variable", "weight": 903, "name": "\u00f4"}, {"D\u00f0\u0004": 2743071, "kK\u0094\u00a7~\u0098\u00e8\udbb7\udfd1\u0085\u00a2\u00fa\u00da-": {"Nd\u00d3\u00c0\u00ee\u0099\u0013)\ud866\udd54\u00de\u00fb\u00a8\u009c\udb76\udc53}\ud8f0\udedf\u0014\u00c6\u00d6\ud841\udeba\u0096r\ud843\ude1d\u00e3\u00d6": [-14001374249]}, "weight": 423, "name": "\u0086\b", "weightType": "variable", "stickiness": "\u00fd\u00ff|"}], "segments": [-2.334159767985369e+16, -5.2514786034489986e+132, -1.695470686314633e+233], "title": null, "name": "k", "disabled": null, "sortOrder": 1.1462242286867434e+122, "parameters": {"xY\u0017": "\u0012\u001f\udab5\udf13\ud9be\udcf2\u00ab\u00f1.\ud895\udf2aT\u0096", "\u008a\udbdd\udf40": "\ud9ac\udcfa"}, "constraints": []}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/environments/development/strategies POST /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/strategies/set-sort-order 1. Test Case ID: eS9oIO - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: trying to change strategies for environment via update sortOrder","details":[{"message":"trying to change strategies for environment via update sortOrder"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"id": "9c40958a-daac-400e-98fb-3bb438567008", "sortOrder": 1}]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/environments/development/strategies/set-sort-order 2. Test Case ID: zewrI4 - Undocumented HTTP status code Received: 415 Documented: 200, 400, 401, 403 [415] Unsupported Media Type: `{"id":"8a8ce6ab-7482-41f4-82d5-7db9fb61bba0","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/0/features/checkout/environments/0/strategies/set-sort-order 3. Test Case ID: RlomGg - Undocumented HTTP status code Received: 404 Documented: 200, 400, 401, 403 [404] Not Found: `{"name":"NotFoundError","message":"Feature checkout does not have environment 0","details":[{"message":"Feature checkout does not have environment 0"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"id": "9c40958a-daac-400e-98fb-3bb438567008", "sortOrder": null}]' http://0.0.0.0:37503/api/admin/projects/0/features/checkout/environments/0/strategies/set-sort-order ____ POST /api/admin/projects/{projectId}/features/{featureName}/favorites _____ 1. Test Case ID: KAoJ03 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 415 Documented: 200, 401, 404 [415] Unsupported Media Type: `{"id":"aa8746bf-de85-4a1f-abba-993f72420e42","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/favorites POST /api/admin/projects/{projectId}/features/{featureName}/lifecycle/complete 1. Test Case ID: ukXHZc - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"id":"e3cf0eb2-00e0-47c9-a5a7-f636a5fe0f07","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"path":"/body/status","message":"The `/body/status` property is required. It was not present on the data you sent."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/lifecycle/complete 2. Test Case ID: mBuo08 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - statusValue: Incorrect type [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"status": "kept", "statusValue": null}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/lifecycle/complete 3. Test Case ID: 3w0N6t - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"feature_lifecycles\" (\"created_at\", \"feature\", \"stage\", \"status\", \"status_value\") values ($1, $2, $3, $4, $5) on conflict (\"feature\", \"stage\") do nothing returning * - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"insert into \"feature_lifecycles\" (\"created_at\", \"feature\", \"stage\", \"status\", \"status_value\") values ($1, $2, $3, $4, $5) on conflict (\"feature\", \"stage\") do nothing returning * - invalid byte // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"status": "discarded", "statusValue": "\udbca\ude25\u0000\u0016\uda03\udce1\ud84d\udc50\u0097\ud95a\udc67t\ud9d3\udd42\u0090"}' http://0.0.0.0:37503/api/admin/projects/default/features/search/lifecycle/complete _______ POST /api/admin/projects/{projectId}/features/{featureName}/link _______ 1. Test Case ID: lIrsiF - Undocumented HTTP status code Received: 404 Documented: 204, 400, 401, 403, 415 [404] Not Found: `{"name":"NotFoundError","message":"Could not find feature with name checkout","details":[{"message":"Could not find feature with name checkout"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"url": "https://github.com/search?q=cleanupReminder&type=code", "title": false}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/link 2. Test Case ID: OXymtu - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` at /properties/url (was string, became number) - violates `type` at /properties/title/anyOf/0 (was string, became number) [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"title": -5.009396657905272e+16, "url": 0.0}' http://0.0.0.0:37503/api/admin/projects/default/features/search/link 3. Test Case ID: 9LuBOP - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 3 additional properties not defined in the schema (``, `񣔖󆤧`, `󟼀ށ”`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Invalid URL: ÎW񛸨","details":[{"message":"Invalid URL: ÎW񛸨"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\udb3f\udf00\u008e\u0081\u0094": {"\u00d4\u008f\u0085": [10000000.0, "\u00e1B\u00daT\u008f\u00c8"]}, "": [true, -5.960464477539063e-08], "\ud94d\udd16\udada\udd27": [null, null], "url": "\u00ceW\ud92f\ude28"}' http://0.0.0.0:37503/api/admin/projects/%F0%98%A9%AC8d%C2%91B/features/search/link _________________ POST /api/admin/projects/{projectId}/revive __________________ 1. Test Case ID: zVTGHh - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - features -> Array with invalid items: Incorrect type [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": [null]}' http://0.0.0.0:37503/api/admin/projects/default/revive 2. Test Case ID: FBVRWT - Undocumented HTTP status code Received: 404 Documented: 200, 400, 401, 403 [404] Not Found: `{"name":"NotFoundError","message":"Active project with id \u0010Ó6½(6 does not exist","details":[{"message":"Active project with id \u0010Ó6½(6 does not exist"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"1/0": null, "\u00e3z\udbc5\udf9dj\u00d4\u00f6@\u009a": null, "echoes": null, "\u008f": null, "\udb5c\udf67\ud855\ude3a-G\ud8c8\ude5a\ud8eb\ude79~+\u0007\u008d\u0002\u0093\u00d2\u009d\u00e5\u0097,": null, "features": []}' http://0.0.0.0:37503/api/admin/projects/%10%C3%936%C2%BD%286/revive 3. Test Case ID: ermYcY - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403 [500] Internal Server Error: `{"name":"UnknownError","message":"select * from \"features\" where \"name\" in ($1, $2, $3, $4, $5, $6, $7, $8) order by \"name\" asc - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select * from \"features\" where \"name\" in ($1, $2, $3, $4, $5, $6, $7, $8) order by \"name\" asc - invalid byte sequence for encoding \"UTF8\": 0x00"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": ["\u0012\ud993\udd1e", "\u00ae\u0001\u00eat\u00fa\u00d4\ud879\udee7\u00c9\u00bd\u0000A", "P\uda35\ude6c\ud8bc\ude8a\u00f2", "", "", "\u00a3\u009aH\u00d5\u00ef", "\u009a\u008e\u00b5\u00a3\u00b5\u0003\u00a7\u00aeTZ\u001e\u001aM", ";\udb91\udc0a<5\ua4ddP1\udb7e\ude4b\ud93d\udf1c\u000b\u00d5\u0004\u0007KHSy"]}' http://0.0.0.0:37503/api/admin/projects/default/revive __________________ POST /api/admin/projects/{projectId}/stale __________________ 1. Test Case ID: 8SkaNb - Undocumented HTTP status code Received: 400 Documented: 202, 401, 403, 415 [400] Bad Request: `{"id":"823640dc-ceea-4d75-b1ce-a9946a3dd4e1","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/stale` property must be boolean. You sent {}.","path":"/body/stale"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": ["my-feature-1", "my-feature-2", "my-feature-3"], "stale": {}}' http://0.0.0.0:37503/api/admin/projects/default/stale 2. Test Case ID: UlAzTr - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - stale: Incorrect type [202] Accepted: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": ["my-feature-1", "my-feature-2", "my-feature-3"], "stale": null}' http://0.0.0.0:37503/api/admin/projects/default/stale 3. Test Case ID: OS2e9y - Server error - Undocumented HTTP status code Received: 500 Documented: 202, 401, 403, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"select * from \"features\" where \"name\" in ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15, $16) order by \"name\" asc - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select * from \"features\" where \"name\" in ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15, $16) order by \"name\" asc - invalid byte sequence for encoding \"UTF8\": 0x00"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud91e\uddc0,\ud8ac\ude21\uda91\udf98`M\udba3\uded3m\u00f9#\u00dd\u0006": {">\u00b9\udb25\udfbeT\udb72\udf8fM%": [[]]}, "\u00eb\u00c4\u00a2\ud9ec\udfe5:1": {}, "AL\udafe\udcdd?Y\u0080n\u00b3\u001e/^m\udb11\udcc3x\u00fa\u00adt\u00ae\u008b\udbdc\udc1dtP\u00be\u00c1\u00a4\u00e7\u00cf\udb54\udc38'"'"'\u00b1": [], "": [[], null, {"": [null]}], "\u001a\u00ec": ["Infinity"], "stale": false, "features": ["t\u00c4F\u00ad\ud909\udd05\u00fc", "\u0000\u00af\u0087\udbe2\udee3\u00eb\u0004", "\u00e7y\u00e0\u00e1\u00a4/\u00b0", "", "\u00e6\u0153\u00c6\u0152\ufb00\u02a4\u02a8\u00df", "\udb43\ude82\u00db\u00f7", "", "", "\u00a8\"", "0..0", "l\u00dd\u00ca", "", "\u00b6\u0004t\u00bb\u00ee", "\u008bT\udafc\udf22", "\u00e1\u00c0Y\u00c4", "\u0096\u00a3\u0080\u0018C"]}' http://0.0.0.0:37503/api/admin/projects/project-y/stale _______________________ POST /api/admin/record-ui-error ________________________ 1. Test Case ID: gGpfw5 - Undocumented HTTP status code Received: 415 Documented: 204, 401, 403 [415] Unsupported Media Type: `{"id":"d0bea222-8cd8-44d8-ada0-e9b8c5a603eb","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/record-ui-error 2. Test Case ID: ROK4VX - Undocumented HTTP status code Received: 400 Documented: 204, 401, 403 [400] Bad Request: `{"id":"4c6f56d7-d19b-46ea-8744-c0331aeb78b7","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/errorStack` property must be string. You sent {}.","path":"/body/errorStack"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"errorMessage": "", "errorStack": {}}' http://0.0.0.0:37503/api/admin/record-ui-error 3. Test Case ID: UpKsrL - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - errorStack: Incorrect type [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"errorMessage": "", "errorStack": null}' http://0.0.0.0:37503/api/admin/record-ui-error ___________________________ POST /api/admin/segments ___________________________ 1. Test Case ID: aL29Bi - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 401, 403, 409, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"segments\" (\"constraints\", \"created_by\", \"description\", \"id\", \"name\", \"segment_project_id\") values ($1, $2, $3, DEFAULT, $4, $5) returning \"id\", \"name\", \"description\", \"segment_project_id\", \"created_by\", \"created_at\", \"constraints\" - insert or update on table \"segments\" violates foreign key constraint \"segments_segment_project_id_fkey\"","details":[{"message":"insert into \"segments\" (\"constraints\", \"created_by\", \"description // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "beta-users", "description": "Users willing to help us test and build new features.", "project": "red-vista", "constraints": [{"contextName": "appName", "operator": "IN", "values": ["my-app", "my-other-app"], "value": "my-app", "caseInsensitive": false, "inverted": false}]}' http://0.0.0.0:37503/api/admin/segments 2. Test Case ID: JjzjX3 - Response header does not conform to the schema "segments/3" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "segments/3" - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - constraints -> Array with invalid items: value: Incorrect type [201] Created: `{"id":3,"name":"beta-users","description":null,"constraints":[{"value":"false","values":["my-app","my-other-app"],"inverted":false,"operator":"IN","contextName":"appName","caseInsensitive":false}],"createdBy":"admin","createdAt":"2026-10-10T12:09:39.761Z"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "beta-users", "description": null, "project": null, "constraints": [{"caseInsensitive": false, "contextName": "appName", "inverted": false, "operator": "IN", "value": false, "values": ["my-app", "my-other-app"]}]}' http://0.0.0.0:37503/api/admin/segments 3. Test Case ID: VuZEP9 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"constraints[0].values[0]\" is not allowed to be empty."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "beta-users", "description": null, "project": null, "constraints": [{"caseInsensitive": false, "contextName": "appName", "inverted": false, "operator": "IN", "value": "my-app", "values": [""]}]}' http://0.0.0.0:37503/api/admin/segments _____________________ POST /api/admin/segments/strategies ______________________ 1. Test Case ID: Y7GLS9 - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 401, 403, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"feature_strategy_segment\" (\"feature_strategy_id\", \"segment_id\") values ($1, $2) - insert or update on table \"feature_strategy_segment\" violates foreign key constraint \"feature_strategy_segment_feature_strategy_id_fkey\"","details":[{"message":"insert into \"feature_strategy_segment\" (\"feature_strategy_id\", \"segment_id\") values ($1, $2) - insert or update on table \"feature_strategy_segment\" violates foreign key constraint \"feature_strategy_segme // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"projectId": "red-vista", "strategyId": "15d1e20b-6310-4e17-a0c2-9fb84de3053a", "environmentId": "development", "segmentIds": [1, 5, 6]}' http://0.0.0.0:37503/api/admin/segments/strategies 2. Test Case ID: iW3xbA - Response header does not conform to the schema "strategies/" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "strategies/" [201] Created: `{"":null,"¦":null,"ÖD":238048499111,"¥񸾩":{},"environmentId":"","projectId":"project-y","segmentIds":[],"strategyId":""}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": null, "\u00a6": null, "\u00d6D": 238048499111, "\u00a5\ud9a3\udfa9": {}, "environmentId": "", "projectId": "project-y", "segmentIds": [], "strategyId": ""}' http://0.0.0.0:37503/api/admin/segments/strategies 3. Test Case ID: lwq3pg - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (`÷V;äã𿶳`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Strategies may not have more than 5 segments","details":[{"message":"Strategies may not have more than 5 segments"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00f7V;\u00e4\u009d\u00e3\ud8bf\uddb3": {"": false, "9\u00e4\u0080\ud950\ude08\u00efn\udbee\udf19%\u9023\u00bf": null, "\uda00\udf37\udacd\udc23\u00f5": false}, "environmentId": "\u00d8\u00dc\u00b8\ud8c7\udd2e\udbbc\udfa3\u008f\u00b0\u00b8\ud8ce\ude31A9\u00c9x!\udb50\udf98\u0085", "projectId": "project-y", "segmentIds": [2055766723, 15979, 2821770, 11230, 53, 2022628, 23093], "strategyId": ""}' http://0.0.0.0:37503/api/admin/segments/strategies 4. Test Case ID: 7U2Vti - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` at /properties/strategyId (was string, became integer) [201] Created: `{"environmentId":"k%","projectId":"","segmentIds":[],"strategyId":"4"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environmentId": "k%", "projectId": "", "segmentIds": [], "strategyId": 4}' http://0.0.0.0:37503/api/admin/segments/strategies ______________________ POST /api/admin/segments/validate _______________________ 1. Test Case ID: qZ0IDV - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 400, 401, 409, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"segments\".\"id\", \"segments\".\"name\", \"segments\".\"description\", \"segments\".\"segment_project_id\", \"segments\".\"created_by\", \"segments\".\"created_at\", \"segments\".\"constraints\" from \"segments\" where \"name\" = $1 - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select \"segments\".\"id\", \"segments\".\"name\", \"segments\".\"description\", \"segments\".\"segment_project_id\", \"segments\".\"created_by\", \"segments\" // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "\u0000\u008c"}' http://0.0.0.0:37503/api/admin/segments/validate 2. Test Case ID: nMKtCW - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Segment name cannot be empty","details":[{"message":"Segment name cannot be empty"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": ""}' http://0.0.0.0:37503/api/admin/segments/validate 3. Test Case ID: kpl223 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` at /properties/name (was string, became boolean) [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": false}' http://0.0.0.0:37503/api/admin/segments/validate _________________________ POST /api/admin/splash/{id} __________________________ 1. Test Case ID: V8QvKY - Response violates schema "userId" is a required property Validated against the response schema for status code 200. Schema: { "required": [ "userId", "splashId", "seen" ], "type": "object", "description": "Data related to a user having seen a splash screen.", "properties": { "userId": { "type": "integer", "description": "The ID of the user that was shown the splash scre... "example": 1 }, "splashId": { "type": "string", "description": "The ID of the splash screen that was shown.", "example": "new-splash-screen" }, // Output truncated... } Value: { "seen": true, "splashId": "0" } [200] OK: `{"splashId":"0","seen":true}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/splash/0 __________________________ POST /api/admin/strategies __________________________ 1. Test Case ID: EDUIep - Response header does not conform to the schema "strategies/my-custom-strategy" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "strategies/my-custom-strategy" [201] Created: `{"displayName":null,"name":"my-custom-strategy","editable":true,"description":"Enable the feature for users who have not logged in before.","parameters":[{"name":"Rollout percentage","type":"percentage","description":"How many percent of users should see this feature?","required":false}],"deprecated":false,"title":"My awesome strategy"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "my-custom-strategy", "title": "My awesome strategy", "description": "Enable the feature for users who have not logged in before.", "editable": false, "deprecated": true, "parameters": [{"name": "Rollout percentage", "type": "percentage", "description": "How many percent of users should see this feature?", "required": false}]}' http://0.0.0.0:37503/api/admin/strategies 2. Test Case ID: veQIKp - Undocumented HTTP status code Received: 400 Documented: 201, 401, 403, 409, 415 [400] Bad Request: `{"id":"db4bf10f-a2b0-47e4-9115-68a13e9f5241","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/parameters/0/required` property must be boolean. You sent {}.","path":"/body/parameters/0/required"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "my-custom-strategy", "title": "My awesome strategy", "description": "Enable the feature for users who have not logged in before.", "editable": false, "deprecated": true, "parameters": [{"name": "Rollout percentage", "type": "percentage", "description": "How many percent of users should see this feature?", "required": {}}]}' http://0.0.0.0:37503/api/admin/strategies 3. Test Case ID: epyJq1 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - name: Incorrect type [201] Created: `{"displayName":null,"name":"false","editable":true,"description":"Enable the feature for users who have not logged in before.","parameters":[],"deprecated":false,"title":"My awesome strategy"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": false, "title": "My awesome strategy", "description": "Enable the feature for users who have not logged in before.", "editable": false, "deprecated": true, "parameters": []}' http://0.0.0.0:37503/api/admin/strategies 4. Test Case ID: N1Lbpe - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"name\" must be URL friendly. You provided \"Rollout percentage\"."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"parameters": [], "name": "Rollout percentage", "deprecated": false}' http://0.0.0.0:37503/api/admin/strategies __________________________ POST /api/admin/tag-types ___________________________ 1. Test Case ID: bSujcr - Response header does not conform to the schema "tag-types/color" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "tag-types/color" [201] Created: `{"name":"color","description":"A tag type for describing the color of a tag.","icon":"not-really-used","color":"#FFFFFF"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "color", "description": "A tag type for describing the color of a tag.", "icon": "not-really-used", "color": "#FFFFFF"}' http://0.0.0.0:37503/api/admin/tag-types 2. Test Case ID: pv1CrD - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - name: Incorrect type [201] Created: `{"color":"#000000","description":"A tag type for describing the color of a tag.","icon":null,"name":"false"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#000000", "description": "A tag type for describing the color of a tag.", "icon": null, "name": false}' http://0.0.0.0:37503/api/admin/tag-types 3. Test Case ID: CWrmj3 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"name\" length must be at least 2 characters long. You provided \"p\"."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "p", "description": "Transition between technical implementations with minimal risk. Expected lifetime: ~7 days", "icon": "Y\udaaa\udcc9\u0084"}' http://0.0.0.0:37503/api/admin/tag-types ______________________ POST /api/admin/tag-types/validate ______________________ 1. Test Case ID: sumkyt - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"name\" must be URL friendly. You provided \")âwA4\"."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": ")\u00e2wA4", "icon": null}' http://0.0.0.0:37503/api/admin/tag-types/validate 2. Test Case ID: TTI3zD - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` at /properties/name (was string, became integer) - violates `type` at /properties/description (was string, became integer) [200] OK: `{"valid":true,"tagType":{"color":"#0aB14F","name":"-9702","description":"2520","icon":"5"}}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#0aB14F", "name": -9702, "description": 2520, "icon": "5"}' http://0.0.0.0:37503/api/admin/tag-types/validate _____________________________ POST /api/admin/tags _____________________________ 1. Test Case ID: kRJIJl - Response header does not conform to the schema "tags/false/a-tag-value" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "tags/false/a-tag-value" - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - type: Incorrect type [201] Created: `{"version":1,"tag":{"type":"false","value":"a-tag-value"}}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#000000", "type": false, "value": "a-tag-value"}' http://0.0.0.0:37503/api/admin/tags 2. Test Case ID: dFw0ST - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 401, 403, 409, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"tags\" (\"type\", \"value\") values ($1, $2) - insert or update on table \"tags\" violates foreign key constraint \"tags_type_fkey\"","details":[{"message":"insert into \"tags\" (\"type\", \"value\") values ($1, $2) - insert or update on table \"tags\" violates foreign key constraint \"tags_type_fkey\""}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#000000", "type": "0000000000000000000000000000000000000000000000000", "value": "a-tag-value"}' http://0.0.0.0:37503/api/admin/tags 3. Test Case ID: lkJh6Q - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"type\" must be URL friendly. You provided \"\\u0005󍨮𧢶Ù񢽶I§`\\t^iô–—§\\u0018®~’õA˜򏊢񝧦\\\"°񻭈G\\u001b\\u000e\\u001c1ë5\"."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"type": "\u0005\udaf6\ude2e\ud85e\udcb6\u00d9\ud94b\udf76I\u00a7`\t^i\u00f4\u0096\u0097\u00a7\u0018\u00ae~\u0092\u00f5A\u0098\ud9fc\udea2\ud936\udde6\"\u00b0\ud9ae\udf48G\u001b\u000e\u001c1\u00eb5", "value": "false"}' http://0.0.0.0:37503/api/admin/tags ________________________ POST /api/admin/ui-config/cors ________________________ 1. Test Case ID: jEDZzB - Undocumented HTTP status code Received: 415 Documented: 204 [415] Unsupported Media Type: `{"id":"7b2c3180-0279-44b0-8958-958a2d5b727b","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/ui-config/cors 2. Test Case ID: 4hKYmO - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"id":"2c2d35ab-2d72-4917-96ce-60f281f1eea9","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/frontendApiOrigins/0` property must be string. You sent {}.","path":"/body/frontendApiOrigins/0"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"frontendApiOrigins": [{}]}' http://0.0.0.0:37503/api/admin/ui-config/cors 3. Test Case ID: mEWCEn - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Invalid origin: ","details":[{"message":"Invalid origin: "}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"frontendApiOrigins": [""]}' http://0.0.0.0:37503/api/admin/ui-config/cors 4. Test Case ID: vW69sa - Undocumented HTTP status code Received: 404 Documented: 204 [404] Not Found: `{"name":"NotFoundError","message":"The requested resource could not be found","details":[{"message":"The requested resource could not be found"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:37503/api/admin/ui-config/cors __________________________ POST /api/admin/user-admin __________________________ 1. Test Case ID: 2gtTmV - Response header does not conform to the schema "3" is not a "uri" Schema: { "format": "uri", "type": "string" } Value: "3" [201] Created: `{"accountType":"User","id":3,"name":"Sam Seawright","username":"hunter","email":"user@example.com","imageUrl":"https://gravatar.com/avatar/b4c9a289323b21a01c3e940f150eb9b8c542587f1abfd8f0e1cc1ffc5e475514?s=42&d=retro&r=g","seenAt":null,"loginAttempts":0,"createdAt":"2026-10-10T12:09:25.361Z","scimId":null,"seatType":null,"companyRole":null,"productUpdatesEmailConsent":null,"rootRole":"Admin","inviteLink":"http://localhost:4242/new-user?token=$2b$10$sUEEQGfnekuIxobO2sthb.CcvAA9RzVVNeccNK.SKR6CVlUdm2hnu","ema // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"username": "hunter", "email": "user@example.com", "name": "Sam Seawright", "password": "[Filtered]", "rootRole": "Admin", "sendEmail": false}' http://0.0.0.0:37503/api/admin/user-admin 2. Test Case ID: O0oqw7 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: User already exists","details":[{"message":"User already exists"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"username": "hunter", "email": "user@example.com", "name": "Sam Seawright", "password": "[Filtered]", "rootRole": 1, "sendEmail": false}' http://0.0.0.0:37503/api/admin/user-admin 3. Test Case ID: 4DyI0f - Undocumented HTTP status code Received: 415 Documented: 201, 400, 401, 403 [415] Unsupported Media Type: `{"id":"ae8a09af-51d1-4aec-b325-c9091ffe4548","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin 4. Test Case ID: IAc8AN - Undocumented HTTP status code Received: 429 Documented: 201, 400, 401, 403 [429] Too Many Requests: `Too many requests, please try again later.` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"email": "user@example.com", "name": "Sam Seawright", "password": "[Filtered]", "rootRole": 0, "sendEmail": false, "username": "hunter"}' http://0.0.0.0:37503/api/admin/user-admin __________________ POST /api/admin/user-admin/inactive/delete __________________ 1. Test Case ID: VhcVxr - Undocumented HTTP status code Received: 404 Documented: 200, 400, 401, 403 [404] Not Found: `{"name":"NotFoundError","message":"No user found","details":[{"message":"No user found"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"ids": [12, 212]}' http://0.0.0.0:37503/api/admin/user-admin/inactive/delete 2. Test Case ID: pdCzOB - Undocumented HTTP status code Received: 429 Documented: 200, 400, 401, 403 [429] Too Many Requests: `Too many requests, please try again later.` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/inactive/delete __________________ POST /api/admin/user-admin/reset-password ___________________ 1. Test Case ID: 5tarTY - Undocumented HTTP status code Received: 429 Documented: 200, 400, 401, 403, 404 [429] Too Many Requests: `Too many requests, please try again later.` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/reset-password _________________ POST /api/admin/user-admin/validate-password _________________ 1. Test Case ID: H93I5C - Undocumented HTTP status code Received: 429 Documented: 200, 400, 401, 415 [429] Too Many Requests: `Too many requests, please try again later.` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/validate-password _______________ POST /api/admin/user-admin/{id}/change-password ________________ 1. Test Case ID: vP6vGY - Undocumented HTTP status code Received: 429 Documented: 200, 400, 401, 403 [429] Too Many Requests: `Too many requests, please try again later.` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/1/change-password _____________________ POST /api/admin/user/change-password _____________________ 1. Test Case ID: v6ckgz - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401 [500] Internal Server Error: `{"name":"UnknownError","message":"Undefined binding(s) detected when compiling FIRST. Undefined column(s): [id] query: select \"password_hash\" from \"users\" where \"deleted_at\" is null and \"is_service\" = ? and \"is_system\" = ? and \"id\" = ? limit ?","details":[{"message":"Undefined binding(s) detected when compiling FIRST. Undefined column(s): [id] query: select \"password_hash\" from \"users\" where \"deleted_at\" is null and \"is_service\" = ? and \"is_system\" = ? and \"id\" = ? limit ?"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"password": "[Filtered]", "oldPassword": "[Filtered]", "confirmPassword": "[Filtered]"}' http://0.0.0.0:37503/api/admin/user/change-password 2. Test Case ID: jrveOc - Undocumented HTTP status code Received: 415 Documented: 200, 400, 401 [415] Unsupported Media Type: `{"id":"274c2dc6-8f43-4d3e-83ae-49a9e2a4bba1","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user/change-password 3. Test Case ID: jCq65n - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"password": "[Filtered]"}' http://0.0.0.0:37503/api/admin/user/change-password _________________________ POST /api/admin/user/tokens __________________________ 1. Test Case ID: jJBbaB - Undocumented HTTP status code Received: 415 Documented: 201, 401, 403, 404 [415] Unsupported Media Type: `{"id":"389a610a-f371-4e06-b393-0dcdfb2fad85","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user/tokens 2. Test Case ID: GXF3Gl - Undocumented HTTP status code Received: 400 Documented: 201, 401, 403, 404 [400] Bad Request: `{"id":"66750635-2d77-47ae-8eb4-59214a212adc","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/expiresAt` property must match format \"date-time\". You sent \"\".","path":"/body/expiresAt"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "user:xyzrandomstring", "expiresAt": ""}' http://0.0.0.0:37503/api/admin/user/tokens ___________________________ POST /api/client/metrics ___________________________ 1. Test Case ID: izNBPw - Undocumented HTTP status code Received: 403 Documented: 202, 204, 400 [403] Forbidden: `{"message":"invalid token: expected a different token type for this endpoint"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"appName": "insurance-selector", "instanceId": "application-name-dacb1234", "sdkVersion": "unleash-client-java:7.0.0", "platformName": ".NET Core", "platformVersion": "3.1", "yggdrasilVersion": "1.0.0", "specVersion": "3.0.0", "sdkFlavor": "unleash-openfeature-node-provider", "sdkFlavorVersion": "1.0.1", "bucket": {"start": 1690449593, "stop": 1690449593, "toggles": {"myCoolToggle": {"yes": 25, "no": 42, "variants": {"blue": 6, "green": 15, "red": 46}}, "myOtherToggle": {"yes": 0, "no": 100}}}}' http://0.0.0.0:37503/api/client/metrics ________________________ POST /api/client/metrics/bulk _________________________ 1. Test Case ID: bijc2T - Undocumented HTTP status code Received: 403 Documented: 202, 400, 413, 415 [403] Forbidden: `{"message":"invalid token: expected a different token type for this endpoint"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"applications": [{"connectVia": [{"appName": "unleash-edge", "instanceId": "edge-pod-bghzv5"}], "appName": "Ingress load balancer", "environment": "development", "instanceId": "application-name-dacb1234", "interval": 10, "started": 1690449593, "strategies": ["standard", "gradualRollout"], "projects": ["projectA", "projectB"], "sdkVersion": "unleash-client-java:8.0.0", "sdkType": "backend", "sdkFlavor": "unleash-openfeature-node-provider", "sdkFlavorVersion": "1.0.1"}], "metrics": [{"featureName": "my.special.feature", "appName": "accounting", "environment": "development", "timestamp": 1690449593, "yes": 974, "no": 50, "variants": {"variantA": 15, "variantB": 25, "variantC": 5}}], "impactMetrics": [{"name": "my-histogram", "help": "Measures request duration", "type": "histogram", "samples": [{"count": 100, "sum": 1500, "buckets": [{"le": 0.5, "count": 30}], "labels": {"application": "my-app", "environment": "production"}}]}], "seenTokens": ["[Filtered]"]}' http://0.0.0.0:37503/api/client/metrics/bulk __________________________ POST /api/client/register ___________________________ 1. Test Case ID: vF5U0a - Undocumented HTTP status code Received: 403 Documented: 202 [403] Forbidden: `{"message":"invalid token: expected a different token type for this endpoint"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"appName": "example-app", "instanceId": "b77f3d13-5f48-4a7b-a3f4-a449b97ce43a", "sdkVersion": "unleash-client-java:7.0.0", "platformName": ".NET Core", "platformVersion": "3.1", "yggdrasilVersion": "1.0.0", "specVersion": "3.0.0", "sdkFlavor": "unleash-openfeature-node-provider", "sdkFlavorVersion": "1.0.1", "interval": 10, "started": "2023-06-13T16:35:00.000Z", "strategies": ["default", "gradualRollout", "remoteAddress"]}' http://0.0.0.0:37503/api/client/register 2. Test Case ID: S2Jm0a - Undocumented HTTP status code Received: 400 Documented: 202 [400] Bad Request: `{"message":"Unexpected token '�', \"�U\" is not valid JSON"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '�U' http://0.0.0.0:37503/api/client/register ______________________________ POST /api/frontend ______________________________ 1. Test Case ID: bd8ULB - Undocumented HTTP status code Received: 403 Documented: 200, 401, 404 [403] Forbidden: `{"message":"invalid token: expected a different token type for this endpoint"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"context": {"appName": "My cool application.", "currentTime": "2022-07-05T12:56:41+02:00", "properties": {"customContextField": "this is one!", "otherCustomField": "3"}, "remoteAddress": "192.168.1.1", "sessionId": "[Filtered]", "userId": "username@provider.com", "environment": ""}}' http://0.0.0.0:37503/api/frontend 2. Test Case ID: wtV3tR - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `{"message":"Unexpected token '�', \"�A\" is not valid JSON"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '�A' http://0.0.0.0:37503/api/frontend ______________________ POST /api/frontend/client/metrics _______________________ 1. Test Case ID: WXrpvW - Undocumented HTTP status code Received: 403 Documented: 200, 204, 400, 401, 404 [403] Forbidden: `{"message":"invalid token: expected a different token type for this endpoint"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"appName": "insurance-selector", "instanceId": "application-name-dacb1234", "sdkVersion": "unleash-client-java:7.0.0", "platformName": ".NET Core", "platformVersion": "3.1", "yggdrasilVersion": "1.0.0", "specVersion": "3.0.0", "sdkFlavor": "unleash-openfeature-node-provider", "sdkFlavorVersion": "1.0.1", "bucket": {"start": 1690449593, "stop": 1690449593, "toggles": {"myCoolToggle": {"yes": 25, "no": 42, "variants": {"blue": 6, "green": 15, "red": 46}}, "myOtherToggle": {"yes": 0, "no": 100}}}}' http://0.0.0.0:37503/api/frontend/client/metrics ______________________ POST /api/frontend/client/register ______________________ 1. Test Case ID: uxwAQZ - Undocumented HTTP status code Received: 403 Documented: 200, 400, 401, 404 [403] Forbidden: `{"message":"invalid token: expected a different token type for this endpoint"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environment": "development", "appName": "", "instanceId": "", "sdkVersion": "", "interval": 0.0, "started": 0.0, "strategies": []}' http://0.0.0.0:37503/api/frontend/client/register __________________________ POST /auth/reset/password ___________________________ 1. Test Case ID: qUMgSq - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 415 [400] Bad Request: `{"name":"OwaspValidationError","message":"The password must contain at least one uppercase letter.","details":[{"validationErrors":["The password must contain at least one uppercase letter.","The password must contain at least one number."],"message":"The password must contain at least one uppercase letter."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"token": "[Filtered]", "password": "[Filtered]"}' http://0.0.0.0:37503/auth/reset/password _______________________ POST /auth/reset/password-email ________________________ 1. Test Case ID: q8gQY9 - Undocumented HTTP status code Received: 429 Documented: 200, 401, 404, 415 [429] Too Many Requests: `Too many requests, please try again later.` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/auth/reset/password-email 2. Test Case ID: sJRtXS - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404, 415 [400] Bad Request: `{"message":"Unexpected token '\u0000', \"\u0000\" is not valid JSON"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:37503/auth/reset/password-email 3. Test Case ID: 6pif8k - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"Can only find users with id, username or email.","details":[{"message":"Can only find users with id, username or email."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"email": ""}' http://0.0.0.0:37503/auth/reset/password-email ______________________ POST /auth/reset/validate-password ______________________ 1. Test Case ID: vvAi4Z - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"OwaspValidationError","message":"The password must be at least 10 characters long.","details":[{"validationErrors":["The password must be at least 10 characters long.","The password must contain at least one uppercase letter.","The password must contain at least one special character."],"message":"The password must be at least 10 characters long."}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"password": "[Filtered]"}' http://0.0.0.0:37503/auth/reset/validate-password 2. Test Case ID: CRexlk - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `POST /auth/reset/validate-password` [200] OK: Reproduce with: curl -X POST -H 'Content-Type: application/json' -d '{"password": "[Filtered]"}' http://0.0.0.0:37503/auth/reset/validate-password ___________________________ POST /auth/simple/login ____________________________ 1. Test Case ID: UzLx9l - Undocumented HTTP status code Received: 415 Documented: 200, 401 [415] Unsupported Media Type: `{"id":"1dc8b724-c63c-4f46-bb63-b89ca9b95266","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/auth/simple/login 2. Test Case ID: Hl3DyI - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `{"id":"0ab135b5-19b2-4d07-95dc-4bd7d0d9f3df","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/password` property must be string. You sent {}.","path":"/body/password"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"password": "[Filtered]", "username": "user"}' http://0.0.0.0:37503/auth/simple/login 3. Test Case ID: L37uUJ - Undocumented HTTP status code Received: 429 Documented: 200, 401 [429] Too Many Requests: `Too many requests, please try again later.` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"password": "[Filtered]", "username": "user"}' http://0.0.0.0:37503/auth/simple/login ____________________________ POST /edge/issue-token ____________________________ 1. Test Case ID: 6TuofG - Undocumented HTTP status code Received: 401 Documented: 200, 400, 403, 413, 415 [401] Unauthorized: `{"error":"Missing HMAC authorization header"}` Reproduce with: curl -X POST -H 'Content-Type: application/json' -d '{"tokens": ["[Filtered]"]}' http://0.0.0.0:37503/edge/issue-token _____________________________ POST /edge/validate ______________________________ 1. Test Case ID: OI7Iz4 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - tokens -> Array with invalid items: Incorrect type [200] OK: `{"tokens":[]}` Reproduce with: curl -X POST -H 'Content-Type: application/json' -d '{"tokens": ["[Filtered]"]}' http://0.0.0.0:37503/edge/validate 2. Test Case ID: 0utAEI - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 413, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"tokens\".\"secret\", \"username\", \"token_name\", \"type\", \"expires_at\", \"created_at\", \"alias\", \"seen_at\", \"environment\", \"token_project_link\".\"project\" from \"api_tokens\" as \"tokens\" left join \"api_token_project\" as \"token_project_link\" on \"tokens\".\"secret\" = \"token_project_link\".\"secret\" where \"tokens\".\"secret\" = $1 - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select \"tokens\".\"secret\", \"userna // Output truncated...` Reproduce with: curl -X POST -H 'Content-Type: application/json' -d '{"": {"e?J\u0095\nU\u0094": "\u00f4\ud9e8\udf21+\u0085\u00e3@\u00c0#\ud814\udd24", "\u00b3A\u00c4\u008b": null}, "\ud873\udf3aw": {"\u00a9C\u0017\u00d9": null}, "tokens": ["[Filtered]"]}' http://0.0.0.0:37503/edge/validate _________________________ POST /invite/{token}/signup __________________________ 1. Test Case ID: mjYups - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `application/json` - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"username": "Hunter", "email": "hunter@example.com", "name": "Hunter Burgan", "password": "[Filtered]"}' http://0.0.0.0:37503/invite/0/signup 2. Test Case ID: UqjKou - Undocumented HTTP status code Received: 415 Documented: 200, 400, 409 [415] Unsupported Media Type: `{"id":"a3cc33ff-fe25-467d-8b49-cf44b2e75882","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:37503/invite/0/signup ____________________________ PUT /api/admin/addons _____________________________ 1. Test Case ID: nghidS - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"aeef8fd4-add4-4601-b10b-bbf7087e004a","name":"NotFoundError","message":"The path you were looking for (/api/admin/addons) is not available.","details":[{"message":"The path you were looking for (/api/admin/addons) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"provider": "webhook", "description": "This addon posts updates to our internal feature tracking system whenever a feature is created or updated.", "enabled": false, "parameters": {"url": "http://localhost:4242/webhook"}, "events": ["feature-created", "feature-updated"], "projects": ["new-landing-project", "signups-v2"], "environments": ["development", "production"]}' http://0.0.0.0:37503/api/admin/addons __________________________ PUT /api/admin/addons/{id} __________________________ 1. Test Case ID: joCtPa - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404, 413, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"id\", \"provider\", \"enabled\", \"description\", \"parameters\", \"events\", \"projects\", \"environments\", \"created_at\" from \"addons\" where \"id\" = $1 limit $2 - invalid input syntax for type integer: \"01M4JVFJEDT0SXVDDAX6RTGA6B\"","details":[{"message":"select \"id\", \"provider\", \"enabled\", \"description\", \"parameters\", \"events\", \"projects\", \"environments\", \"created_at\" from \"addons\" where \"id\" = $1 limit $2 - invalid input syntax for t // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"enabled": false, "events": [], "parameters": {"0": null}, "provider": ""}' http://0.0.0.0:37503/api/admin/addons/01M4JVFJEDT0SXVDDAX6RTGA6B __________________________ PUT /api/admin/api-tokens ___________________________ 1. Test Case ID: LPBH7P - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"0b119bbf-ee13-494a-a99c-45f64e798fc6","name":"NotFoundError","message":"The path you were looking for (/api/admin/api-tokens) is not available.","details":[{"message":"The path you were looking for (/api/admin/api-tokens) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"expiresAt": "2023-07-04T11:26:24+02:00", "type": "frontend", "environment": "development", "project": "project-851", "projects": ["project-851", "project-852"], "tokenName": "[Filtered]"}' http://0.0.0.0:37503/api/admin/api-tokens ______________________ PUT /api/admin/api-tokens/{token} _______________________ 1. Test Case ID: r87pPj - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 415 [400] Bad Request: `{"id":"9ec93879-c68a-4984-9138-5e69c8c3bc90","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/expiresAt` property must match format \"date-time\". You sent \"\".","path":"/body/expiresAt"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"expiresAt": ""}' http://0.0.0.0:37503/api/admin/api-tokens/0 _____________________ PUT /api/admin/constraints/validate ______________________ 1. Test Case ID: I4j1ee - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"364038a9-b94a-44b5-b704-9a925c997f85","name":"NotFoundError","message":"The path you were looking for (/api/admin/constraints/validate) is not available.","details":[{"message":"The path you were looking for (/api/admin/constraints/validate) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"caseInsensitive": false, "contextName": "appName", "inverted": false, "operator": "IN", "value": "my-app", "values": ["my-app", "my-other-app"]}' http://0.0.0.0:37503/api/admin/constraints/validate ____________________________ PUT /api/admin/context ____________________________ 1. Test Case ID: gKwH5T - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"2ef51676-ae66-4448-88e1-440cb74f97c7","name":"NotFoundError","message":"The path you were looking for (/api/admin/context) is not available.","details":[{"message":"The path you were looking for (/api/admin/context) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "gold"}, {"value": "silver"}, {"value": "crystal"}], "project": "my-project", "name": "subscriptionTier"}' http://0.0.0.0:37503/api/admin/context ____________________ PUT /api/admin/context/{contextField} _____________________ 1. Test Case ID: x3bmc3 - Server error - Undocumented HTTP status code Received: 500 Documented: 200 [500] Internal Server Error: `{"name":"UnknownError","message":"update \"context_fields\" set \"name\" = $1, \"description\" = $2, \"stickiness\" = $3, \"sort_order\" = $4, \"legal_values\" = $5, \"project\" = $6 where \"name\" = $7 returning * - insert or update on table \"context_fields\" violates foreign key constraint \"context_fields_project_fkey\"","details":[{"message":"update \"context_fields\" set \"name\" = $1, \"description\" = $2, \"stickiness\" = $3, \"sort_order\" = $4, \"legal_values\" = $5, \"project\" = $6 where \"name\ // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "#c154c1", "description": "Deep fuchsia"}], "project": "my-project"}' http://0.0.0.0:37503/api/admin/context/region 2. Test Case ID: L1o0lb - Undocumented HTTP status code Received: 415 Documented: 200 [415] Unsupported Media Type: `{"id":"691952b5-9165-4faa-bb94-d187b687204d","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/context/0 3. Test Case ID: 2fLPOO - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"id":"f8015786-8c86-478e-94ce-6ece55f5be11","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/project` property must be string. You sent {}.","path":"/body/project"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "gold"}, {"value": "silver"}, {"value": "crystal"}], "project": {}}' http://0.0.0.0:37503/api/admin/context/0 4. Test Case ID: HbveZx - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"Could not find context field with name 0","details":[{"message":"Could not find context field with name 0"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "gold"}, {"value": "silver"}, {"value": "crystal"}], "project": null}' http://0.0.0.0:37503/api/admin/context/0 5. Test Case ID: oCy1Rv - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` at /properties/stickiness (was boolean, became null) [200] OK: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"stickiness": null}' http://0.0.0.0:37503/api/admin/context/region _________________________ PUT /api/admin/environments __________________________ 1. Test Case ID: kPlYW1 - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"842761bb-8f16-4ee3-b2bc-d693ad8f1609","name":"NotFoundError","message":"The path you were looking for (/api/admin/environments) is not available.","details":[{"message":"The path you were looking for (/api/admin/environments) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/environments ____________________ PUT /api/admin/environments/sort-order ____________________ 1. Test Case ID: WsdGvV - Undocumented HTTP status code Received: 415 Documented: 200, 401, 403, 404 [415] Unsupported Media Type: `{"id":"db6dbfa3-9718-4555-bcfe-644854fb378f","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/environments/sort-order 2. Test Case ID: iplmSr - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"id":"2b2914a4-fbd1-4df7-9195-cf6ec610cee9","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/x-schemathesis-additional` property must be integer. You sent {}.","path":"/body/x-schemathesis-additional"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"x-schemathesis-additional": {}}' http://0.0.0.0:37503/api/admin/environments/sort-order 3. Test Case ID: TCIjML - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - object with invalid additional property: Incorrect type [200] OK: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"x-schemathesis-additional": null}' http://0.0.0.0:37503/api/admin/environments/sort-order 4. Test Case ID: WD7nL1 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"update \"environments\" set \"sort_order\" = $1 where \"name\" = $2 - value \"-9134886710\" is out of range for type integer","details":[{"message":"update \"environments\" set \"sort_order\" = $1 where \"name\" = $2 - value \"-9134886710\" is out of range for type integer"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00ee": 145159, "": 230, "C\u00f6d\uda43\udd4d2": -9134886710}' http://0.0.0.0:37503/api/admin/environments/sort-order 5. Test Case ID: usKnCm - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 3 additional properties not defined in the schema (``, `ò`, `𗀝^}Û0󳱞`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"ò\" must be a safe number. You provided 36893488147419103000."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": -414, "\ud81c\udc1d^}\u00db\u00100\udb8f\udc5e\u0081": 500916, "\u00f2": 36893488147419103232}' http://0.0.0.0:37503/api/admin/environments/sort-order ________________________ PUT /api/admin/event-creators _________________________ 1. Test Case ID: LXlQUj - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"47313ce7-402a-4dfc-b8ec-eac31e14bab4","name":"NotFoundError","message":"The path you were looking for (/api/admin/event-creators) is not available.","details":[{"message":"The path you were looking for (/api/admin/event-creators) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/event-creators ____________________________ PUT /api/admin/events _____________________________ 1. Test Case ID: JwyHMo - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"e15f1959-a8b7-4811-8b82-29e12c705fb3","name":"NotFoundError","message":"The path you were looking for (/api/admin/events) is not available.","details":[{"message":"The path you were looking for (/api/admin/events) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/events?project=' _________________________ PUT /api/admin/feature-types _________________________ 1. Test Case ID: tmq9El - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"12be45aa-2b19-4867-a49f-ddec01f77d0c","name":"NotFoundError","message":"The path you were looking for (/api/admin/feature-types) is not available.","details":[{"message":"The path you were looking for (/api/admin/feature-types) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/feature-types __________________ PUT /api/admin/feature-types/{id}/lifetime __________________ 1. Test Case ID: pfmI3u - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - lifetimeDays: Incorrect type [200] OK: `{"id":"release","name":"Release","description":"Roll out new or incomplete features. Expected lifetime ~40 days","lifetimeDays":null}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"lifetimeDays": false}' http://0.0.0.0:37503/api/admin/feature-types/release/lifetime _____________________ PUT /api/admin/features-batch/export _____________________ 1. Test Case ID: Li2ZH1 - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"5619afe0-e85a-446b-bb71-5c4ed48ef00e","name":"NotFoundError","message":"The path you were looking for (/api/admin/features-batch/export) is not available.","details":[{"message":"The path you were looking for (/api/admin/features-batch/export) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environment": "development", "downloadFile": true, "features": ["MyAwesomeFeature"]}' http://0.0.0.0:37503/api/admin/features-batch/export _____________________ PUT /api/admin/features-batch/import _____________________ 1. Test Case ID: L3qMCe - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"e73867f0-f9e1-4390-baa4-aa4486323667","name":"NotFoundError","message":"The path you were looking for (/api/admin/features-batch/import) is not available.","details":[{"message":"The path you were looking for (/api/admin/features-batch/import) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"data": {"contextFields": [{"description": "Allows you to constrain on application name", "legalValues": [], "name": "appName", "sortOrder": 2, "stickiness": false}], "dependencies": [], "featureEnvironments": [{"enabled": true, "environment": "development", "featureName": "my-feature", "name": "variant-testing", "variants": [{"name": "a", "overrides": [], "stickiness": "random", "weight": 500, "weightType": "variable"}, {"name": "b", "overrides": [], "stickiness": "random", "weight": 500, "weightType": "variable"}]}], "featureStrategies": [{"constraints": [], "disabled": false, "featureName": "my-feature", "id": "924974d7-8003-43ee-87eb-c5f887c06fd1", "name": "flexibleRollout", "parameters": {"groupId": "default", "rollout": "50", "stickiness": "random"}, "segments": [1], "title": "Rollout 50%"}], "featureTags": [{"featureName": "my-feature", "tagType": "simple", "tagValue": "user-facing"}], "features": [{"archived": false, "description": "best feature ever", "impressionData": false, "name": "my-feature", "project": "default", "stale": false, "type": "release"}], "links": [], "segments": [{"id": 1, "name": "new-segment-name"}], "tagTypes": [{"description": "Used to simplify filtering of features", "icon": "#", "name": "simple"}]}, "environment": "development", "project": "My awesome project"}' http://0.0.0.0:37503/api/admin/features-batch/import ____________________ PUT /api/admin/features-batch/validate ____________________ 1. Test Case ID: S072zC - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"29276c77-d487-4446-92ac-19573498c819","name":"NotFoundError","message":"The path you were looking for (/api/admin/features-batch/validate) is not available.","details":[{"message":"The path you were looking for (/api/admin/features-batch/validate) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"data": {"contextFields": [{"description": "Allows you to constrain on application name", "legalValues": [], "name": "appName", "sortOrder": 2, "stickiness": false}], "dependencies": [], "featureEnvironments": [{"enabled": true, "environment": "development", "featureName": "my-feature", "name": "variant-testing", "variants": [{"name": "a", "overrides": [], "stickiness": "random", "weight": 500, "weightType": "variable"}, {"name": "b", "overrides": [], "stickiness": "random", "weight": 500, "weightType": "variable"}]}], "featureStrategies": [{"constraints": [], "disabled": false, "featureName": "my-feature", "id": "924974d7-8003-43ee-87eb-c5f887c06fd1", "name": "flexibleRollout", "parameters": {"groupId": "default", "rollout": "50", "stickiness": "random"}, "segments": [1], "title": "Rollout 50%"}], "featureTags": [{"featureName": "my-feature", "tagType": "simple", "tagValue": "user-facing"}], "features": [{"archived": false, "description": "best feature ever", "impressionData": false, "name": "my-feature", "project": "default", "stale": false, "type": "release"}], "links": [], "segments": [{"id": 1, "name": "new-segment-name"}], "tagTypes": [{"description": "Used to simplify filtering of features", "icon": "#", "name": "simple"}]}, "environment": "development", "project": "My awesome project"}' http://0.0.0.0:37503/api/admin/features-batch/validate _______________________ PUT /api/admin/features/validate _______________________ 1. Test Case ID: TcS6oV - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"f5f4a31d-5fb9-4045-8b69-79bf4d91bbb4","name":"NotFoundError","message":"The path you were looking for (/api/admin/features/validate) is not available.","details":[{"message":"The path you were looking for (/api/admin/features/validate) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "my-feature-3", "projectId": "project-y"}' http://0.0.0.0:37503/api/admin/features/validate __________________ PUT /api/admin/features/{featureName}/tags __________________ 1. Test Case ID: EHm0tC - Undocumented HTTP status code Received: 415 Documented: 200, 400, 401, 403, 404 [415] Unsupported Media Type: `{"id":"d48092da-d5be-4d75-b874-401a2a351960","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/features/checkout/tags 2. Test Case ID: 54iY72 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - removedTags -> Array with invalid items: type: Incorrect type [200] OK: `{"version":1,"tags":[{"type":"simple","value":"00","color":"#FFFFFF"},{"type":"simple","value":"000","color":"#FFFFFF"},{"type":"simple","value":"0000000000000000000000000000000000000000000000000","color":"#FFFFFF"},{"type":"simple","value":"00000000000000000000000000000000000000000000000000","color":"#FFFFFF"},{"type":"simple","value":"a-tag-value","color":"#FFFFFF"},{"type":"simple","value":"false","color":"#FFFFFF"},{"type":"simple","value":"tag-to-add","color":"#FFFFFF"},{"type":"simple","value":"workbe // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"addedTags": [{"value": "tag-to-add", "type": "simple"}], "removedTags": [{"color": "#000000", "type": false, "value": "a-tag-value"}]}' http://0.0.0.0:37503/api/admin/features/checkout/tags 3. Test Case ID: Pf6bmj - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Tag type '0000000000000000000000000000000000000000000000000' does not exist","details":[{"message":"Tag type '0000000000000000000000000000000000000000000000000' does not exist"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"addedTags": [{"color": "#000000", "type": "0000000000000000000000000000000000000000000000000", "value": "a-tag-value"}], "removedTags": [{"value": "tag-to-remove", "type": "simple"}]}' http://0.0.0.0:37503/api/admin/features/checkout/tags ___________________________ PUT /api/admin/feedback ____________________________ 1. Test Case ID: Jg4FRl - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"84c0a8b3-56e4-49eb-8201-6351cfb54883","name":"NotFoundError","message":"The path you were looking for (/api/admin/feedback) is not available.","details":[{"message":"The path you were looking for (/api/admin/feedback) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"neverShow": false, "feedbackId": "pnps"}' http://0.0.0.0:37503/api/admin/feedback _________________________ PUT /api/admin/feedback/{id} _________________________ 1. Test Case ID: uLAa6j - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"user_feedback\" (\"feedback_id\", \"given\", \"nevershow\", \"user_id\") values ($1, $2, $3, DEFAULT) on conflict (\"user_id\", \"feedback_id\") do update set \"feedback_id\" = excluded.\"feedback_id\", \"given\" = excluded.\"given\", \"nevershow\" = excluded.\"nevershow\", \"user_id\" = excluded.\"user_id\" returning \"given\", \"user_id\", \"feedback_id\", \"nevershow\" - null value in column \"user_id\" of relation \"user_feedback\" violates not-null constr // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"userId": 2, "neverShow": false, "given": "2023-07-06T08:29:21.282Z"}' http://0.0.0.0:37503/api/admin/feedback/0 ___________________ PUT /api/admin/instance-admin/statistics ___________________ 1. Test Case ID: Io4G2R - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"c910fd3a-fefb-4b6d-9e23-010818a3b2fb","name":"NotFoundError","message":"The path you were looking for (/api/admin/instance-admin/statistics) is not available.","details":[{"message":"The path you were looking for (/api/admin/instance-admin/statistics) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/instance-admin/statistics _________________ PUT /api/admin/instance-admin/statistics/csv _________________ 1. Test Case ID: PxbHUz - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"a53c4995-19f9-45fc-9e26-56ada2099b31","name":"NotFoundError","message":"The path you were looking for (/api/admin/instance-admin/statistics/csv) is not available.","details":[{"message":"The path you were looking for (/api/admin/instance-admin/statistics/csv) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/instance-admin/statistics/csv ______________________ PUT /api/admin/invite-link/tokens _______________________ 1. Test Case ID: L8qd2l - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"915304cb-3d8c-4d88-b0ad-6cc19d43f532","name":"NotFoundError","message":"The path you were looking for (/api/admin/invite-link/tokens) is not available.","details":[{"message":"The path you were looking for (/api/admin/invite-link/tokens) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"expiresAt": "2000-01-01T00:00:00Z", "name": ""}' http://0.0.0.0:37503/api/admin/invite-link/tokens __________________ PUT /api/admin/invite-link/tokens/{token} ___________________ 1. Test Case ID: AQxxyy - Undocumented HTTP status code Received: 404 Documented: 200, 400, 401, 403 [404] Not Found: `{"name":"NotFoundError","message":"Could not find public signup token.","details":[{"message":"Could not find public signup token."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"expiresAt": "2023-04-11T15:46:56Z", "enabled": true}' http://0.0.0.0:37503/api/admin/invite-link/tokens/0 2. Test Case ID: 2exnZj - Undocumented HTTP status code Received: 415 Documented: 200, 400, 401, 403 [415] Unsupported Media Type: `{"id":"c2d9fe30-8c8c-4b20-a315-8a65001216aa","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/invite-link/tokens/0 3. Test Case ID: kuRzRg - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `application/json` - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:37503/api/admin/invite-link/tokens/0 ________________________ PUT /api/admin/lifecycle/count ________________________ 1. Test Case ID: Fdrgve - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"ca0d186e-5a77-400f-9fd1-7f11c009ae5f","name":"NotFoundError","message":"The path you were looking for (/api/admin/lifecycle/count) is not available.","details":[{"message":"The path you were looking for (/api/admin/lifecycle/count) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/lifecycle/count __________________________ PUT /api/admin/maintenance __________________________ 1. Test Case ID: gelgQZ - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"08de21be-70c6-4da2-b403-a93ed5df7b23","name":"NotFoundError","message":"The path you were looking for (/api/admin/maintenance) is not available.","details":[{"message":"The path you were looking for (/api/admin/maintenance) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"enabled": true}' http://0.0.0.0:37503/api/admin/maintenance _____________________ PUT /api/admin/metrics/applications ______________________ 1. Test Case ID: 0SDM2O - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"092a80d8-1edc-4370-baa4-d9a7ae182259","name":"NotFoundError","message":"The path you were looking for (/api/admin/metrics/applications) is not available.","details":[{"message":"The path you were looking for (/api/admin/metrics/applications) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/metrics/applications?query=first_app&offset=50&limit=50&sortBy=type&sortOrder=desc' _____________________ PUT /api/admin/metrics/sdks/outdated _____________________ 1. Test Case ID: TmfRJP - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"130a4a18-fcce-4171-8e7e-71129c0e8e51","name":"NotFoundError","message":"The path you were looking for (/api/admin/metrics/sdks/outdated) is not available.","details":[{"message":"The path you were looking for (/api/admin/metrics/sdks/outdated) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/metrics/sdks/outdated _____________________ PUT /api/admin/metrics/unknown-flags _____________________ 1. Test Case ID: THctW8 - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"04dcf80e-9198-4039-8e3f-f5b48103a94e","name":"NotFoundError","message":"The path you were looking for (/api/admin/metrics/unknown-flags) is not available.","details":[{"message":"The path you were looking for (/api/admin/metrics/unknown-flags) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/metrics/unknown-flags ______________________ PUT /api/admin/personal-dashboard _______________________ 1. Test Case ID: 1INdFg - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"27bbc6ad-4be2-421f-adfa-34b7acafe953","name":"NotFoundError","message":"The path you were looking for (/api/admin/personal-dashboard) is not available.","details":[{"message":"The path you were looking for (/api/admin/personal-dashboard) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/personal-dashboard __________________________ PUT /api/admin/playground ___________________________ 1. Test Case ID: JkXL8g - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"d669cefe-bfa0-4f21-b95c-b3a81280f8c2","name":"NotFoundError","message":"The path you were looking for (/api/admin/playground) is not available.","details":[{"message":"The path you were looking for (/api/admin/playground) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environment": "development", "projects": [], "context": {"appName": "My cool application.", "currentTime": "2022-07-05T12:56:41+02:00", "environment": "", "properties": {"customContextField": "this is one!", "otherCustomField": "3"}, "remoteAddress": "192.168.1.1", "sessionId": "[Filtered]", "userId": "username@provider.com"}}' http://0.0.0.0:37503/api/admin/playground ______________________ PUT /api/admin/playground/advanced ______________________ 1. Test Case ID: zAjwj0 - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"c14fdec6-fc1f-4550-9c7f-af9f5aa94460","name":"NotFoundError","message":"The path you were looking for (/api/admin/playground/advanced) is not available.","details":[{"message":"The path you were looking for (/api/admin/playground/advanced) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"environments": ["development", "production"], "projects": [], "context": {"appName": "My cool application.", "currentTime": "2022-07-05T12:56:41+02:00", "environment": "", "properties": {"customContextField": "this is one!", "otherCustomField": "3"}, "remoteAddress": "192.168.1.1", "sessionId": "[Filtered]", "userId": "username@provider.com"}}' http://0.0.0.0:37503/api/admin/playground/advanced ___________________________ PUT /api/admin/projects ____________________________ 1. Test Case ID: JIjmes - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"23d9db3a-ac90-497e-baf3-239e2ec5c758","name":"NotFoundError","message":"The path you were looking for (/api/admin/projects) is not available.","details":[{"message":"The path you were looking for (/api/admin/projects) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/projects?archived=true' __________ PUT /api/admin/projects/{projectId}/context/{contextField} __________ 1. Test Case ID: UO7QuU - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"name":"NotFoundError","message":"Could not find context field region in project default","details":[{"message":"Could not find context field region in project default"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "#c154c1", "description": "Deep fuchsia"}], "project": "my-project"}' http://0.0.0.0:37503/api/admin/projects/default/context/region 2. Test Case ID: QjGIF7 - Undocumented HTTP status code Received: 415 Documented: 200 [415] Unsupported Media Type: `{"id":"0591e1e5-cf4b-469d-85b9-7468215dfca0","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/context/0 3. Test Case ID: wDl1wR - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"id":"2b82f306-01e8-40f9-84f6-b98189607da3","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/project` property must be string. You sent {}.","path":"/body/project"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "gold"}, {"value": "silver"}, {"value": "crystal"}], "project": {}}' http://0.0.0.0:37503/api/admin/projects/default/context/0 4. Test Case ID: ImV8q1 - Server error - Undocumented HTTP status code Received: 500 Documented: 200 [500] Internal Server Error: `{"name":"UnknownError","message":"update \"context_fields\" set \"name\" = $1, \"description\" = $2, \"stickiness\" = $3, \"sort_order\" = $4, \"legal_values\" = $5, \"project\" = $6 where \"name\" = $7 returning * - insert or update on table \"context_fields\" violates foreign key constraint \"context_fields_project_fkey\"","details":[{"message":"update \"context_fields\" set \"name\" = $1, \"description\" = $2, \"stickiness\" = $3, \"sort_order\" = $4, \"legal_values\" = $5, \"project\" = $6 where \"name\ // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The user'"'"'s subscription tier", "stickiness": false, "sortOrder": 2, "legalValues": [{"value": "gold"}, {"value": "silver"}, {"value": "crystal"}], "project": false}' http://0.0.0.0:37503/api/admin/projects/default/context/0 __________ PUT /api/admin/projects/{projectId}/features/{featureName} __________ 1. Test Case ID: ti8L05 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404, 415 [400] Bad Request: `{"id":"448017b8-4466-4783-a4e9-ed08d252db09","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/impressionData` property must be boolean. You sent {}.","path":"/body/impressionData"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "Controls disabling of the comments section in case of an incident", "type": "kill-switch", "stale": true, "archived": true, "impressionData": {}}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout 2. Test Case ID: A9LrVL - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - impressionData: Incorrect type [200] OK: `{"name":"checkout","description":"Controls disabling of the comments section in case of an incident","type":"kill-switch","project":"default","stale":true,"createdAt":"2026-10-10T12:09:24.071Z","impressionData":false,"archivedAt":"2026-10-10T12:09:48.631Z","archived":true}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "Controls disabling of the comments section in case of an incident", "type": "kill-switch", "stale": true, "archived": true, "impressionData": null}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout PUT /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/strategies/{strategyId} 1. Test Case ID: NI5IhM - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 3 additional properties not defined in the schema (``, `¨ 󱻩¸`, `󬧏`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"[0].name\" is not allowed to be empty."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00a8\t\udb87\udee9\u00b8": {"\u00a9|L\u0087\ud920\udcd6+8`4": [], "j": {"\ud87e\ude34\u00ae\u009d\ud89f\udc0a\u00af0+\u00ba3\u00e6\ud813\udc16\udb35\udd6e\u0097\ud96b\udf3f\ud895\uddfd\u0003\u008a\ud84a\udd2f": -3752199405014682, "\u00c6\u00e1\udbf9\udecf": -246484554, "\u0014": "\u0011\u00f4\u0016\u000f\u00c8\udbf4\udc60\uda9a\udc98\u00eb;\u0088]\u008b"}, "": [-2.00001]}, "\udb72\uddcf": {"C": "\udaa4\udcaf\u00e6\r\u0093", "": 7.27730183839217e+304, "\u00e9\ud9cf\udd24\ud9ae\udf79\u00e2": -7242}, "": {"\u0080\u00bc": [-17400], "": ["\udb08\udc72", 36028797018963968, false], "\u0099e\ud97e\uddaf\u008c\udafc\ude24\u0083\u00c7": {"\ud99c\udc1a8Y": "W"}}, "variants": [{"weight": 413, "weightType": "variable", "name": "", "stickiness": "\u0098#\u0083K\u00cbm"}, {"stickiness": "5-X\u008f\u00f1", "weightType": "variable", "weight": 383, "payload": {"value": "\u00ed\udacf\udf82\u00bb\u00ab\u0016\u8251\u00b7\udb59\udeeca\u0088\u00dc", "type": "number"}, "name": ""}, {"weightType": "fix", "weight": 186, "stickiness": "\u00cb", "name": ""}], "segments": []}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/environments/production/strategies/01M4JVFJCS0AKVHVVQ6964N1BX 2. Test Case ID: BmJezL - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"segments\".\"id\", \"segments\".\"name\", \"segments\".\"description\", \"segments\".\"segment_project_id\", \"segments\".\"created_by\", \"segments\".\"created_at\", \"segments\".\"constraints\" from \"segments\" where \"id\" = $1 - invalid input syntax for type integer: \"1.8248917860813357e-292\"","details":[{"message":"select \"segments\".\"id\", \"segments\".\"name\", \"segments\".\"description\", \"segments\".\"segment_project_id\", \"segments\".\"created_by\ // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"W2": [{"UndefinedContentType": -1.2221428842916592e-17, "\u00f5": true}, 234373612659158.0, [-5.546753203986575e+16]], "": 665, "\ud8a9\udc6e\u00b4\u009a\u00f8\u00a1'"'"'\u0004\u0011\u00b6\u000fQ": [], ",h\u0016": -2215153818962209.0, "999999999999999999999999999999": "\u00b8f\u0083", "segments": [1.8248917860813357e-292], "constraints": [{"operator": "SEMVER_GT", "values": ["\u00d8\r}\u00e6\u00ff\u00b8", "\"8\u008f\uda8a\udda9"], "contextName": "\ud930\udd7f>]\uda1e\ude48z"}, {"values": ["\u00ab\ud809\udef9A\u00c0\udaf2\udd00", "\ud8b0\udff3D\u00ee\u0013", "4\ud992\udf27\u000eb\u00d9\u009c\u009f\u00f2\u009c", "\u00e3", "", "", "|\u001c)\ud936\uddce", "\u0082'"'"'O\u00f0\u00c9\ud888\udf12\u00ba\u0005m(R", "\u00b5\u00e6", "\ud805\udeb0\u0001", "", ""], "caseInsensitive": true, "contextName": "\u00a2", "operator": "STR_ENDS_WITH", "value": "\ud969\udcf2\u00b4\udb61\udd96", "inverted": false}, {"contextName": "1h\uda66\udf95\u0010k\u008b", "value": "\u0084~`\u0017\u00cc\udb46\udf7c\u0080\udae0\udd59\u00b2\u00d2\u00d9", "operator": "SEMVER_LT"}]}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/environments/development/strategies/01M4JVMM2V76P66GQBFCVG118C 3. Test Case ID: GxXlNM - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `anyOf` at /properties/title [200] OK: `{"id":"01M4JVMKYW8A7QWPMC8VBFT71N","name":"appName","title":"false","disabled":false,"constraints":[],"parameters":{},"variants":[],"sortOrder":0,"segments":[]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00d4\udb47\ude83\u00b6\u00c1y/\udb2f\udfff\u00e8\uda71\udf49\u00df\u001a": [], "T\n\u00e8.\u00d4\u0002\ud800\udee7\u00ab\u00c3\u00fd\udac0\udd90\u00b4\u00a8\u00cdTO\u009e": {"\udb9f\udcf5\u0088\r,!\udb46\udfee\u00c9": true, "\u00c3\u0004[e\u00a3": "\u00e0", "K\ud915\udd90\u008b\u00c7\u00dc\ud87f\ude33\b\u009fE\u000f\u00e8\u0006n\ud84f\ude0e\ud8d0\udca3%\u00c1\ud8c3\udc09\u00f8`\u00eb\u000f_\u00cb\u00a3": "Security"}, "": {}, "\u0011U\u0000": 437, "title": false}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/environments/development/strategies/01M4JVMKYW8A7QWPMC8VBFT71N PUT /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/variants 1. Test Case ID: W3uPxp - Undocumented HTTP status code Received: 415 Documented: 200, 400, 401, 403 [415] Unsupported Media Type: `{"id":"3386f563-c3ff-4d9e-9b3b-4ef92b9d5e51","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/0/features/0/environments/0/variants 2. Test Case ID: XKEtOM - Undocumented HTTP status code Received: 404 Documented: 200, 400, 401, 403 [404] Not Found: `{"name":"NotFoundError","message":"There's no feature named \"0\" in project \"0\", but there's a feature with that name in project \"default\"","details":[{"message":"There's no feature named \"0\" in project \"0\", but there's a feature with that name in project \"default\""}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"name": "blue_group", "overrides": [{"contextName": "userId", "values": [null]}], "payload": {"type": "json", "value": "{\"color\": \"red\"}"}, "stickiness": "custom.context.field", "weight": 0.0, "weightType": "variable"}]' http://0.0.0.0:37503/api/admin/projects/0/features/0/environments/0/variants ___ PUT /api/admin/projects/{projectId}/features/{featureName}/link/{linkId} ___ 1. Test Case ID: udkHW6 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (`3`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Invalid URL: 6„W\u001f¬򤌏","details":[{"message":"Invalid URL: 6„W\u001f¬򤌏"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"3": [[1.7155203002150696e+16, 1.7155203002150696e+16]], "title": "false", "url": "6\u0084W\u001f\u00ac\uda50\udf0f"}' http://0.0.0.0:37503/api/admin/projects/default/features/J/link/%C3%82%C2%AA __ PUT /api/admin/projects/{projectId}/features/{featureName}/variants-batch ___ 1. Test Case ID: fmBYVC - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: No environments provided","details":[{"message":"No environments provided"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"variants": [{"name": "blue_group", "weightType": "variable", "stickiness": "custom.context.field", "payload": {"type": "json", "value": "{\"color\": \"red\"}"}, "overrides": [{"contextName": "userId", "values": ["red", "blue"]}], "weight": 0.0}], "environments": []}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/variants-batch 2. Test Case ID: JQgnTm - Undocumented HTTP status code Received: 415 Documented: 200, 400, 401, 403 [415] Unsupported Media Type: `{"id":"8d820855-e7c5-42ea-a714-72a17e3adeb0","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/variants-batch 3. Test Case ID: KncLkB - Undocumented HTTP status code Received: 404 Documented: 200, 400, 401, 403 [404] Not Found: `{"name":"NotFoundError","message":"Could not find checkout in ","details":[{"message":"Could not find checkout in "}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"variants": [], "environments": [null]}' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/variants-batch 4. Test Case ID: nekWRe - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403 [500] Internal Server Error: `{"name":"UnknownError","message":"SELECT EXISTS(SELECT 1\n FROM change_request_settings\n WHERE environment = $1\n and project = $2) AS present - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"SELECT EXISTS(SELECT 1\n FROM change_request_settings\n WHERE environment = $1\n and project = $2) AS present - invalid byte sequenc // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"MP": [], "environments": ["", "s\udb0f\udff6\udb03\udf05H\u00f8q", "L\uda06\udf9eG\ud9b0\udc19\u9f57\uda66\ude79\u0002\u0018\u00e9\u0091\u00fe[rj~\u0092\u00a8e\u00ccR\u00d8\ud942\udfb0\u00a8Y\u00a3K\u0080\u00de)\u00f0/]h\u00ad\u00d1\udb05\udf99\u00cf9\u00fbSpA\u00e3b6\u00ca\u00df@\u00c4\u00b2", "s", "0", "e\u008b\u0019E", "\u0089\u00fc\u0088\u001a\u0011\u0097", "\u00c7\u009a", "\r5", "\ud9ef\udd17\u00c7\udb0d\uddd7\u0082\\T\u0000\u00d5\u00d9\ud926\udcde>\ud8cc\udc37\r"]}' http://0.0.0.0:37503/api/admin/projects/default/features/sourceTypeName/variants-batch ___________________ PUT /api/admin/projects/{projectId}/tags ___________________ 1. Test Case ID: lJS5A4 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404, 415 [400] Bad Request: `{"id":"d20d6b7b-e80a-404a-b342-5966f8a45127","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/tags/removedTags/0/color` property must match pattern \"^#[0-9A-Fa-f]{6}$\". You sent \"AAA\".","path":"/body/tags/removedTags/0/color"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": [], "tags": {"addedTags": [{"value": "tag-to-add", "type": "simple"}], "removedTags": [{"color": "AAA", "type": "simple", "value": "a-tag-value"}]}}' http://0.0.0.0:37503/api/admin/projects/default/tags 2. Test Case ID: n1Rwxf - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - tags -> removedTags -> Array with invalid items: type: Incorrect type [200] OK: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": [], "tags": {"addedTags": [{"value": "tag-to-add", "type": "simple"}], "removedTags": [{"color": "#000000", "type": false, "value": "a-tag-value"}]}}' http://0.0.0.0:37503/api/admin/projects/default/tags 3. Test Case ID: p69cCp - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Tag type 'Other' does not exist","details":[{"message":"Tag type 'Other' does not exist"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": ["\u00f7\u00ea\u00c4P", "\u0012$", "\u0097\u000f\ua96b\u00b0", "\u00ea", " \udb86\udcc3\ud93c\udc0a\r4", "\u008f\ud9eb\udd3c\u00c2:", "7\u00fc", "\u000f\udbd3\ude47"], "tags": {"addedTags": [{"value": "\u00fd\ud9c7\udfe1m\u00e0\u00d1\udb7b\ude53P\u00d8\udb80\udf55", "type": "Other"}], "removedTags": [{"value": " \u00f5", "type": "\u00f5\u008c\u0018\u00cf", "color": "#afBEe4"}, {"value": "\u008a5", "type": "\u00c4A\uda1b\udd26"}]}}' http://0.0.0.0:37503/api/admin/projects/default/tags 4. Test Case ID: BJPyuI - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"feature_tag\" (\"created_by_user_id\", \"feature_name\", \"tag_type\", \"tag_value\") values ($1, $2, $3, $4), ($5, $6, $7, $8), ($9, $10, $11, $12), ($13, $14, $15, $16) on conflict (\"feature_name\", \"tag_type\", \"tag_value\") do nothing returning \"feature_name\", \"tag_type\", \"tag_value\" - insert or update on table \"feature_tag\" violates foreign key constraint \"feature_tag_feature_name_fkey\"","details":[{"message":"insert into \"feature_tag\" (\"c // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"features": ["\ud875\udf1ct", "\u008b\u00ebQ;\u00a3\t\u008e\u00d4\udaa1\udedd "], "tags": {"removedTags": [{"value": "e\u0099>", "type": "\u00f6\u00c8\ud982\udfb3\u0086\u00b6\udb6c\udf3b\u00ad\u00dc\u00f1\udbaa\udfa1\u00f8\u000el\u009f\u0014\ud833\uddf8>\u001b"}], "addedTags": [{"value": "\u0082\ud850\udc4b[\u00f5\uda9f\ude84", "type": "\udac7\udc34P\b\u00d4\u00b4\\\u00ca\udbdb\udcb3", "color": "#DC02f1"}, {"value": "\u0093E", "color": null, "type": "\uda30\udd7f\u00ad\u00a9\u001f"}]}}' http://0.0.0.0:37503/api/admin/projects/default/tags ________________________ PUT /api/admin/record-ui-error ________________________ 1. Test Case ID: oqhZEl - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"589e123c-9737-40d3-873c-e3e9447e56d6","name":"NotFoundError","message":"The path you were looking for (/api/admin/record-ui-error) is not available.","details":[{"message":"The path you were looking for (/api/admin/record-ui-error) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"errorMessage": "", "errorStack": ""}' http://0.0.0.0:37503/api/admin/record-ui-error _________________________ PUT /api/admin/search/events _________________________ 1. Test Case ID: ioXFDQ - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"b9fc6a2b-51f5-424f-b2ea-dbdc19fb3fa0","name":"NotFoundError","message":"The path you were looking for (/api/admin/search/events) is not available.","details":[{"message":"The path you were looking for (/api/admin/search/events) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/search/events?query=admin%40example.com&id=IS%3A123&groupId=IS%3A123&feature=IS%3Amyfeature&project=IS%3Adefault&type=IS%3Achange-added&createdBy=IS%3A2&from=IS%3A2024-01-01&to=IS%3A2024-01-31&offset=50&limit=50&environment=IS%3Aproduction' ___________________________ PUT /api/admin/segments ____________________________ 1. Test Case ID: oPwjG5 - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"da594fa0-aead-4ca5-b71b-c6d51fd6a476","name":"NotFoundError","message":"The path you were looking for (/api/admin/segments) is not available.","details":[{"message":"The path you were looking for (/api/admin/segments) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "beta-users", "description": null, "project": null, "constraints": []}' http://0.0.0.0:37503/api/admin/segments ______________________ PUT /api/admin/segments/strategies ______________________ 1. Test Case ID: rGa3xm - Unsupported methods Unsupported method PUT returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `{"id":"2f5740b4-4360-41ea-85c0-559fe90c8f0f","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/params/id` property must be integer. You sent \"strategies\".","path":"/params/id"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"projectId": "red-vista", "strategyId": "15d1e20b-6310-4e17-a0c2-9fb84de3053a", "environmentId": "development", "segmentIds": [1, 5, 6]}' http://0.0.0.0:37503/api/admin/segments/strategies _______________________ PUT /api/admin/segments/validate _______________________ 1. Test Case ID: ClTSBL - Unsupported methods Unsupported method PUT returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `{"id":"9be05ceb-5cbb-4bd6-b3d6-8e7b8dca9477","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/params/id` property must be integer. You sent \"validate\".","path":"/params/id"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "betaUser"}' http://0.0.0.0:37503/api/admin/segments/validate _________________________ PUT /api/admin/segments/{id} _________________________ 1. Test Case ID: 7qfB7F - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Invalid project. Segment is being used by strategies in other projects: default","details":[{"message":"Invalid project. Segment is being used by strategies in other projects: default"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "beta-users", "description": "Users willing to help us test and build new features.", "project": "red-vista", "constraints": [{"contextName": "appName", "operator": "IN", "values": ["my-app", "my-other-app"], "value": "my-app", "caseInsensitive": false, "inverted": false}]}' http://0.0.0.0:37503/api/admin/segments/1 2. Test Case ID: G7UbMT - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - name: Incorrect type [204] No Content: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": false, "description": null, "project": null, "constraints": []}' http://0.0.0.0:37503/api/admin/segments/4 3. Test Case ID: 0gnTZb - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 400, 401, 403, 409, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"update \"segments\" set \"name\" = $1, \"description\" = $2, \"segment_project_id\" = $3, \"constraints\" = $4 where \"id\" = $5 returning \"id\", \"name\", \"description\", \"segment_project_id\", \"created_by\", \"created_at\", \"constraints\" - insert or update on table \"segments\" violates foreign key constraint \"segments_segment_project_id_fkey\"","details":[{"message":"update \"segments\" set \"name\" = $1, \"description\" = $2, \"segment_project_id\" = $3, \"constr // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": [null, {}, {"\u00b6g": null}], "\udabf\udf4a\u00eb\ud863\udc99\u00aa": [{"M\u008b": null, "z\u0013\u0081q": null}], "description": "\uda18\udc34\u00886s{\u0084\u00dc\ud99c\udfa3\u000f", "project": "\u00bc\uda62\udefc\u0010\u00ad\u0017\u00b9Q\u00a6\u00c5\udaae\udcd3\u00ed", "constraints": [], "name": "migration"}' http://0.0.0.0:37503/api/admin/segments/7 __________________________ PUT /api/admin/strategies ___________________________ 1. Test Case ID: kM0Ucs - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"bc9aef05-cd82-4260-9f19-bbeac4a536a5","name":"NotFoundError","message":"The path you were looking for (/api/admin/strategies) is not available.","details":[{"message":"The path you were looking for (/api/admin/strategies) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"name": "my-custom-strategy", "title": "My awesome strategy", "description": "Enable the feature for users who have not logged in before.", "editable": false, "deprecated": true, "parameters": []}' http://0.0.0.0:37503/api/admin/strategies _______________________ PUT /api/admin/strategies/{name} _______________________ 1. Test Case ID: LLaX5P - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404, 415 [400] Bad Request: `{"id":"2c43ff6d-e3d7-49fa-8649-4260e232c521","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/body/parameters/0/required` property must be boolean. You sent {}.","path":"/body/parameters/0/required"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "Enable the feature for users who have not logged in before.", "parameters": [{"name": "Rollout percentage", "type": "percentage", "description": "How many percent of users should see this feature?", "required": {}}]}' http://0.0.0.0:37503/api/admin/strategies/false 2. Test Case ID: dBEJtB - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - parameters -> Array with invalid items: required: Incorrect type [200] OK: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "Enable the feature for users who have not logged in before.", "parameters": [{"name": "Rollout percentage", "type": "percentage", "description": "How many percent of users should see this feature?", "required": null}]}' http://0.0.0.0:37503/api/admin/strategies/false 3. Test Case ID: wGazvu - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"Cannot edit strategy applicationHostname","details":[{"message":"Cannot edit strategy applicationHostname"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"(\u009d\u00ad\u0093\udae5\uddb9\u00ac\u00e2": [{"\udaf7\ude95\ud813\ude0f\ud8db\udd45C\u00e6\n": true, ">\uda55\udf01\u00a3\udac6\udc53\u0083\u00ae": false, "\u0091\u0094c": 0.0}], "": [{"\u00ec\u00d4": null, "\u00ca\u0085\u00f4\ud86c\udc29\ud9b8\udec4\ud9ed\udca5\ud9e6\ude20*\udb0a\ude57": null, "\u0093": 4.16462690047552e+16}, null, [-2.3642426757012024e+294]], "parameters": [{"name": "ids", "type": "list", "description": "", "required": false}]}' http://0.0.0.0:37503/api/admin/strategies/applicationHostname 4. Test Case ID: e7wVPf - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"\"parameters[0].name\" is not allowed to be empty."},{"message":"\"parameters[2].name\" is not allowed to be empty."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u0084&!a\u00a5": [], "parameters": [{"required": true, "name": "", "type": "list", "description": "\u008e\u00e3\f"}, {"S": [true], "\udb1b\uddf5\u00ee^Xl": [[], [{"\u00a3\u00a7\u0004n\u0018?\ud887\udfd0\u00cei\udb9a\udf5e\uda9e\udfdd\udae7\udfb2": "\u0081_\udb0f\udfaf\ud874\ude92\u0086", "": ", \u00e3\uda88\udd43\u00cb", "0": "\u00c2V&o_\u00df\ud8f7\udcec%\ud885\ude5d\ud950\udd85\u00db"}]], "\u00b3": 63624, "4\u00c41": [[-144115188075855872, "\u00f5"], {"\u0093\u0019\udb5b\udc6c\u00ael\u00db\u00ce\udbfc\ude05X\u00e2\u8fd6\u7681": "\ud991\udff4"}, []], "s\u00ee\udb3d\ude66": [], "name": "\u00ae", "type": "string"}, {"(\u00d3:\ud826\udc2a\uda19\udc39k\udb70\udf614\u00d2\u0083\udaaa\udf97q": {"\u00cb\u00ed\u00b0E\u00a4\udb58\udccb\uda80\udcce\u001a": -6.542685176980732e+16, "\u0080\u001f/`\ud814\ude34Un7\u00f4\u00af\u009f\u00ef\u0004\u00d1": "\u00b3\u00a5\u0081\u00ff"}, "\ud971\udf70": {"": -523, "\u009b=&\u0095\\)b\u00ef\ud943\udfe5\u00a8": "\t\ud882\udeb0\u00d2\u008c<:\u001c)", "\u009d\udb2d\ude6d\u00ae\u0007\ud9fa\ude91G\ud9d0\udc6a\u0095": 1125899906842625}, "uq\u00b3\u001a6\u0089\u009fs": [-1.7976931348623157e+308, -16717579], "2\u001e\uda86\udf54++\uda57\udd19\u008e": [], "a\u0089": {"\u009b\uc18c\u00a0\u00ba\u008c\udb55\uddf2V\u00d8": [true]}, "required": false, "name": "", "type": "number"}, {".exe": ["fP"], "\ud8c5\udfba\udac1\udc02": [], "}": [[null, -400, true], {"\u00a4\u00de\u0000\u00c4": "\udbb3\udcd9\ud910\udcb86C\u00c4y\u00ban\u00ea\u0007\u00f59\u0016\u00d3"}], "\ud9e5\udfa4\u0018[\ud837\udc93\u00af": {}, "\u00de\u00a8\u00e3\udb4e\udd6e\u00b5|?j\u00b4": ["\u00bc"], "name": "\u0010\u0017\ud8ef\udc20z\ud92e\udf71\u0096\u008d\u00f4B", "type": "boolean", "description": "J"}, {"type": "percentage", "name": "\u0097(@"}, {"MalformedMediaType": [], "name": "\u0013\u00e3\u00a3\u0094\u00e6\ud99d\udeba", "type": "boolean", "description": "\uda1a\udf88\udba5\udffb2\u0003<\u00c0\u0087P,\uda0a\udeabsZE\u00c3\u00d3\u00e0\u008e"}, {"type": "number", "name": "\u008b"}, {"\udb4c\ude46#R\udae9\udfc8S\u009d\u009f-\uda86\udea2l": {}, "]\u001e\u0098z\ud8d0\udd2f\u00be\u008a": [{}], "": ["b", {"false": -369777163314169600, "\ud948\udc39\u00b2": 9876894518816681230336}, {"\ud8d4\udc0d\u00d7QbB": {"O\u0084\u00a1\u0086\u0098S": 3.9508396209609375e+297}, "\u0081\u0017f\u00ad\u00c1": false}], "\u001e~": {"\u008f": "dw"}, "\u008c\u00f01mZ\u00d6$\u2d07\u00e0\udba3\udc2f": {}, "required": true, "description": "\u00ad\u00a4\u00a7;\udb7f\udc19{\r\u00cf\u77f7\u00f35\u00ddo", "name": "`\u00ce\udbad\ude83\u00bb\ud857\udf39\ud8e2\udd99)\u00f2\u00bd\udb06\udfbb;1", "type": "percentage"}, {"M": [], "\u0084\udaa4\udc4c\u00a1": {"\udaff\udd44\u00e1\udb2c\udde3\ud947\udc4e\udbb8\udec0\udb4c\udfdf\u00f2\udbcb\udf80": 133000508401851296, "/\u00b7\u000e\u0091\u00c7.X\u00e6%\u00fc\uc753\ud8e1\udff3": false, "\u00b8": "\ud8c8\udd80\u00d6"}, "\u00c0\u00d5\u00a5": {}, "\t\u009aR\u00bb.\ud8a7\udc17\u00ac\ud844\udcd7\u008c\\": -4.30879709473158e+74, "\u00c4\u00a4\ud927\udebd\u00f0": {"": {}, "\u00de\u007fm4\udbe7\ude9b\u00d6": {}, "\u00ddg": true}, "name": "\u009cQk", "type": "number"}, {"\uca8fR\ud913\udf5d\u0000\udbb3\udfbc\u00d8#h\u001c>\u0083?&\u00c9M": [2.7313107169438135e+20, true, 528098], "": [213, [], {}], "name": "\u00a3\u001f\u00c6\ud858\udd07S\uda2d\uddc42\u00c1", "required": true, "type": "boolean", "description": "\u0001\ud91a\udd0bo"}, {"": false, "RejectedPositiveData": {}, "\u0005\ud961\udc34\u0090\u00f9\u00ed{\u00d7\u00e2": [" Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "A tag type for describing the color of a tag.", "icon": null, "color": "#FFFFFF"}' http://0.0.0.0:37503/api/admin/tag-types/false 3. Test Case ID: ImbYpP - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"Empty .update() call detected! Update data does not contain any values to update. This will result in a faulty query. Table: tag_types. Columns: description,icon,color.","details":[{"message":"Empty .update() call detected! Update data does not contain any values to update. This will result in a faulty query. Table: tag_types. Columns: description,icon,color."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:37503/api/admin/tag-types/false _____________________________ PUT /api/admin/tags ______________________________ 1. Test Case ID: 6IHOlN - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"ac72ca82-9022-4506-a4c7-f1ee6254e1eb","name":"NotFoundError","message":"The path you were looking for (/api/admin/tags) is not available.","details":[{"message":"The path you were looking for (/api/admin/tags) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"color": "#000000", "type": "simple", "value": "a-tag-value"}' http://0.0.0.0:37503/api/admin/tags ______________________ PUT /api/admin/telemetry/settings _______________________ 1. Test Case ID: h3x222 - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"ac11667b-390a-477c-9a5e-bbe164b2d422","name":"NotFoundError","message":"The path you were looking for (/api/admin/telemetry/settings) is not available.","details":[{"message":"The path you were looking for (/api/admin/telemetry/settings) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/telemetry/settings ___________________________ PUT /api/admin/ui-config ___________________________ 1. Test Case ID: Utcls7 - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"0d37360a-f0f7-4b92-8f73-64b32590003d","name":"NotFoundError","message":"The path you were looking for (/api/admin/ui-config) is not available.","details":[{"message":"The path you were looking for (/api/admin/ui-config) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/ui-config ________________________ PUT /api/admin/ui-config/cors _________________________ 1. Test Case ID: u7RSF7 - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"81dfe32c-d8d6-44ec-a6e8-8447703884fe","name":"NotFoundError","message":"The path you were looking for (/api/admin/ui-config/cors) is not available.","details":[{"message":"The path you were looking for (/api/admin/ui-config/cors) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"frontendApiOrigins": ["*"]}' http://0.0.0.0:37503/api/admin/ui-config/cors _____________________________ PUT /api/admin/user ______________________________ 1. Test Case ID: IgpGNO - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"75f66c66-1fcc-4361-a00a-69d9fed2de91","name":"NotFoundError","message":"The path you were looking for (/api/admin/user) is not available.","details":[{"message":"The path you were looking for (/api/admin/user) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user __________________________ PUT /api/admin/user-admin ___________________________ 1. Test Case ID: cvCUWD - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"837b1186-33cd-40a2-bcaf-3d21d1330aac","name":"NotFoundError","message":"The path you were looking for (/api/admin/user-admin) is not available.","details":[{"message":"The path you were looking for (/api/admin/user-admin) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"email": "user@example.com", "name": "Sam Seawright", "password": "[Filtered]", "rootRole": 0, "sendEmail": false, "username": "hunter"}' http://0.0.0.0:37503/api/admin/user-admin _______________________ PUT /api/admin/user-admin/access _______________________ 1. Test Case ID: 1VyasQ - Unsupported methods Unsupported method PUT returned 415, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [415] Unsupported Media Type: `{"id":"09f8f5e0-056c-4550-8f48-e77707c9212f","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/access ____________________ PUT /api/admin/user-admin/admin-count _____________________ 1. Test Case ID: bTqoJz - Unsupported methods Unsupported method PUT returned 415, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [415] Unsupported Media Type: `{"id":"63039baf-1f1b-45a0-a078-741da5a30793","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/admin-count ______________________ PUT /api/admin/user-admin/inactive ______________________ 1. Test Case ID: 6sUZeU - Unsupported methods Unsupported method PUT returned 415, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [415] Unsupported Media Type: `{"id":"46218366-e2ae-4a47-a4c4-c20fe265e93f","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/inactive __________________ PUT /api/admin/user-admin/inactive/delete ___________________ 1. Test Case ID: trApTB - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"70a0a032-412a-4961-9d69-00f783cdbd7b","name":"NotFoundError","message":"The path you were looking for (/api/admin/user-admin/inactive/delete) is not available.","details":[{"message":"The path you were looking for (/api/admin/user-admin/inactive/delete) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"ids": [12, 212]}' http://0.0.0.0:37503/api/admin/user-admin/inactive/delete ___________________ PUT /api/admin/user-admin/reset-password ___________________ 1. Test Case ID: zRslb3 - Unsupported methods Unsupported method PUT returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `{"id":"cf86dac3-9785-4d03-85d4-0e089733b1c1","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/params/id` property must be integer. You sent \"reset-password\".","path":"/params/id"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": "user@example.com"}' http://0.0.0.0:37503/api/admin/user-admin/reset-password _____________________ PUT /api/admin/user-admin/scim-users _____________________ 1. Test Case ID: TlhD72 - Unsupported methods Unsupported method PUT returned 415, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [415] Unsupported Media Type: `{"id":"6d929eb3-b852-4bb5-9a72-ef6fb05ce7af","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/scim-users _______________________ PUT /api/admin/user-admin/search _______________________ 1. Test Case ID: o8FxPQ - Unsupported methods Unsupported method PUT returned 415, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [415] Unsupported Media Type: `{"id":"3c1c344d-fa31-45bf-9215-42f243fd8a58","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/user-admin/search?q=' _________________ PUT /api/admin/user-admin/validate-password __________________ 1. Test Case ID: OWfddb - Unsupported methods Unsupported method PUT returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `{"id":"0366339b-30be-4c76-b287-c8e0bb3a1523","name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data. Refer to the `details` list for more information.","details":[{"message":"The `/params/id` property must be integer. You sent \"validate-password\".","path":"/params/id"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"confirmPassword": "[Filtered]", "oldPassword": "[Filtered]", "password": "[Filtered]"}' http://0.0.0.0:37503/api/admin/user-admin/validate-password ________________________ PUT /api/admin/user-admin/{id} ________________________ 1. Test Case ID: BhRSQX - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"update \"users\" set \"name\" = $1, \"email\" = $2 where \"deleted_at\" is null and \"is_service\" = $3 and \"is_system\" = $4 and \"id\" = $5 - duplicate key value violates unique constraint \"users_email_key\"","details":[{"message":"update \"users\" set \"name\" = $1, \"email\" = $2 where \"deleted_at\" is null and \"is_service\" = $3 and \"is_system\" = $4 and \"id\" = $5 - duplicate key value violates unique constraint \"users_email_key\""}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"email": "user@example.com", "name": "Sam Seawright", "rootRole": "Admin"}' http://0.0.0.0:37503/api/admin/user-admin/1 2. Test Case ID: DYSnbR - Undocumented HTTP status code Received: 415 Documented: 200, 400, 401, 403, 404 [415] Unsupported Media Type: `{"id":"9fbf20fe-56dc-4cca-a23d-b87eecdd1e5d","name":"ContentTypeError","message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format.","details":[{"message":"We do not accept the content-type you provided (you didn't provide one). Try using one of the content-types we do accept instead (application/json) and make sure the body is in the corresponding format." // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user-admin/3 3. Test Case ID: FmiYmv - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - rootRole: Incorrect type [200] OK: `{"accountType":"User","id":3,"name":"Sam Seawright","username":"hunter","email":"user@example.com","imageUrl":"https://gravatar.com/avatar/b4c9a289323b21a01c3e940f150eb9b8c542587f1abfd8f0e1cc1ffc5e475514?s=42&d=retro&r=g","seenAt":null,"loginAttempts":0,"createdAt":"2026-10-10T12:09:25.361Z","scimId":null,"seatType":null,"companyRole":null,"productUpdatesEmailConsent":null,"rootRole":0}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"email": "user@example.com", "name": "Sam Seawright", "rootRole": null}' http://0.0.0.0:37503/api/admin/user-admin/3 4. Test Case ID: yB4Dam - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"name":"BadDataError","message":"Request validation failed: your request body or params contain invalid data: Could not find rootRole=Reader","details":[{"message":"Could not find rootRole=Reader"}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"email": "user@example.com", "name": "Sam Seawright", "rootRole": "Reader"}' http://0.0.0.0:37503/api/admin/user-admin/3 _____________________ PUT /api/admin/user/change-password ______________________ 1. Test Case ID: st7TKL - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"7830c5b0-8b87-48ad-a26d-26f5bec62aa4","name":"NotFoundError","message":"The path you were looking for (/api/admin/user/change-password) is not available.","details":[{"message":"The path you were looking for (/api/admin/user/change-password) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"confirmPassword": "[Filtered]", "oldPassword": "[Filtered]", "password": "[Filtered]"}' http://0.0.0.0:37503/api/admin/user/change-password _________________________ PUT /api/admin/user/profile __________________________ 1. Test Case ID: KdjoUj - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"d36a0062-ad49-4b4d-91ed-8e0b16b17662","name":"NotFoundError","message":"The path you were looking for (/api/admin/user/profile) is not available.","details":[{"message":"The path you were looking for (/api/admin/user/profile) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/user/profile __________________________ PUT /api/admin/user/roles ___________________________ 1. Test Case ID: ZXpKDD - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"0ab48179-91b1-4119-86f2-691a82bbeef1","name":"NotFoundError","message":"The path you were looking for (/api/admin/user/roles) is not available.","details":[{"message":"The path you were looking for (/api/admin/user/roles) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' 'http://0.0.0.0:37503/api/admin/user/roles?projectId=project-y' __________________________ PUT /api/admin/user/tokens __________________________ 1. Test Case ID: 4ZAqy7 - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"id":"2d2cdebd-6b68-4dd3-9b93-41b3108b9f46","name":"NotFoundError","message":"The path you were looking for (/api/admin/user/tokens) is not available.","details":[{"message":"The path you were looking for (/api/admin/user/tokens) is not available."}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "user:xyzrandomstring", "expiresAt": "2023-04-19T08:15:14.000Z"}' http://0.0.0.0:37503/api/admin/user/tokens ___________________________ PUT /auth/reset/password ___________________________ 1. Test Case ID: LD8s6Y - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: ` Error
Cannot PUT /auth/reset/password
` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"password": "[Filtered]", "token": "[Filtered]"}' http://0.0.0.0:37503/auth/reset/password ________________________ PUT /auth/reset/password-email ________________________ 1. Test Case ID: 0Ad7ia - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: ` Error
Cannot PUT /auth/reset/password-email
` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"email": "test@example.com"}' http://0.0.0.0:37503/auth/reset/password-email ___________________________ PUT /auth/reset/validate ___________________________ 1. Test Case ID: zIoJvX - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: ` Error
Cannot PUT /auth/reset/validate
` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/auth/reset/validate ______________________ PUT /auth/reset/validate-password _______________________ 1. Test Case ID: wcEogX - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: ` Error
Cannot PUT /auth/reset/validate-password
` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"password": "[Filtered]"}' http://0.0.0.0:37503/auth/reset/validate-password ____________________________ PUT /auth/simple/login ____________________________ 1. Test Case ID: 200D7W - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: ` Error
Cannot PUT /auth/simple/login
` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"password": "[Filtered]", "username": "user"}' http://0.0.0.0:37503/auth/simple/login ____________________________ PUT /edge/issue-token _____________________________ 1. Test Case ID: yzZu9R - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: ` Error
Cannot PUT /edge/issue-token
` Reproduce with: curl -X PUT -H 'Content-Type: application/json' -d '{"tokens": ["[Filtered]"]}' http://0.0.0.0:37503/edge/issue-token ______________________________ PUT /edge/validate ______________________________ 1. Test Case ID: k7yvwX - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: ` Error
Cannot PUT /edge/validate
` Reproduce with: curl -X PUT -H 'Content-Type: application/json' -d '{"tokens": ["[Filtered]"]}' http://0.0.0.0:37503/edge/validate _________________________________ PUT /health __________________________________ 1. Test Case ID: 4mhEmK - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: ` Error
Cannot PUT /health
` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/health __________________________________ PUT /ready __________________________________ 1. Test Case ID: 8vdXfB - Unsupported methods Unsupported method PUT returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: ` Error
Cannot PUT /ready
` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:37503/ready ________________________________ Stateful tests ________________________________ 1. Test Case ID: LEapDy - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"id\", \"provider\", \"enabled\", \"description\", \"parameters\", \"events\", \"projects\", \"environments\", \"created_at\" from \"addons\" where \"id\" = $1 limit $2 - invalid input syntax for type integer: \"01M4JVFJEDT0SXVDDAX6RTGA6B\"","details":[{"message":"select \"id\", \"provider\", \"enabled\", \"description\", \"parameters\", \"events\", \"projects\", \"environments\", \"created_at\" from \"addons\" where \"id\" = $1 limit $2 - invalid input syntax for t // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/addons curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/addons/01M4JVFJEDT0SXVDDAX6RTGA6B 2. Test Case ID: lWLcVL - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404, 415 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"feature_tag\" (\"created_by_user_id\", \"feature_name\", \"tag_type\", \"tag_value\") values ($1, $2, $3, $4), ($5, $6, $7, $8), ($9, $10, $11, $12) on conflict (\"feature_name\", \"tag_type\", \"tag_value\") do nothing returning \"feature_name\", \"tag_type\", \"tag_value\" - insert or update on table \"feature_tag\" violates foreign key constraint \"feature_tag_tag_type_tag_value_fkey\"","details":[{"message":"insert into \"feature_tag\" (\"created_by_user_i // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud9ee\udf35\uda38\udcfc": true, "description": "Slack tag used by the slack-addon to specify the slack channel.", "name": "blue_group", "impressionData": false, "type": "kill-switch", "tags": [{"value": "~Z\u00ae", "color": null, "type": "\u0088l\u00e1\u00da\udb13\udd20\uda87\udcfb"}, {"value": "\u0017\u0094HD\u0082\udb15\udce5s`PI\u001a\u00f8\ud89d\udf5d\u0017\u008a\ud89c\udc987\u0001", "type": "\udb4f\udd53\ud889\udfab\udbc7\udfd0\u009bK"}, {"value": "\u00c2l\u009a", "type": "\u00b12\u00ce\ud97c\udd15", "color": "#953097"}]}' http://0.0.0.0:37503/api/admin/projects/default/features 3. Test Case ID: sIKjJt - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 404 [500] Internal Server Error: `{"name":"UnknownError","message":"select \"name\", \"description\", \"type\", \"project\", \"stale\", \"created_at\", \"impression_data\", \"archived_at\" from \"features\" where \"project\" = $1 and \"archived_at\" is null - invalid byte sequence for encoding \"UTF8\": 0x00","details":[{"message":"select \"name\", \"description\", \"type\", \"project\", \"stale\", \"created_at\", \"impression_data\", \"archived_at\" from \"features\" where \"project\" = $1 and \"archived_at\" is null - invalid byte sequenc // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": [], "a\uda40\udd35N\u009a\u0019\u0002f\u0085\u00fe'"'"'\u0098\u00af\udb45\udc7d\u00e9\ud92f\udf7d'"'"'\udb0c\udc20": [], "\u00a08\udbca\udc42": {"\uda35\udd9d\u00fbk\u00e3\udba3\udf030\u00038\u009b\ud5b3": null}, "\u00fd+\udb4d\udeb3w\uecb0\u6e83\u00d9i": [], "project": "\u00f4\u0000L\u008c", "environment": false}' http://0.0.0.0:37503/api/admin/features-batch/export 4. Test Case ID: tnSVK1 - Undocumented HTTP status code Received: 404 Documented: 200, 401, 403 [404] Not Found: `{"name":"NotFoundError","message":"Could not find tag-type","details":[{"message":"Could not find tag-type"}]}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "The emoji_icon to use when posting messages to slack. Defaults to \":unleash:\".", "name": "webhook", "color": "#eaAceb"}' http://0.0.0.0:37503/api/admin/tag-types/validate curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/tag-types/webhook 5. Test Case ID: 5rm2zT - Undocumented HTTP status code Received: 404 Documented: 204, 401, 403, 409 [404] Not Found: `{"name":"NotFoundError","message":"No segment exists with ID \"4\"","details":[{"message":"No segment exists with ID \"4\""}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments/4 6. Test Case ID: vedGyO - Response violates schema [{"constraints":[],"disabled":false,"id":"01M4JVFJCS0AKVHVVQ6964N1BX","milestoneId":null,"name":"flexibleRollout","parameters":{"groupId":"checkout","rollout":"100","stickiness":"default"},"segments":[1],"sortOrder":0,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM2186JVM6YVPM2FNCVE","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":17,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM2EYDZ06HEY92GKW9A3","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":18,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM2V76P66GQBFCVG118C","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":19,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM39WA21R4R31A6Y2T95","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":20,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM3PE6Z26E341JRFH5PS","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":21,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM44DJPK0WHT161W4V3H","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":22,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM4GPG9ZCYBH7TV3AZ8A","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":23,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM4WRYWMR71FS89KPE4K","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":24,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM599NQ78J6HZEXDYEAG","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":25,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM5QWWN3ZT4V9Y9H7G12","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":26,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM64P5K7M3V2P91GMY9J","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":27,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM6JNCBZFEAXAY71143C","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":28,"title":null,"variants":[]},{"constraints":[],"disabled":false,"id":"01M4JVMM70PW6RX03TF0PFKZE7","milestoneId":null,"name":"appName","parameters":{},"segments":[],"sortOrder":29,"title":null,"variants":[]}] is not of type "object" Validated against the response schema for status code 200. Schema at /components/schemas/featureStrategySchema: { "type": "object", "description": "A single activation strategy configuration schema for a f... "additionalProperties": false, "required": [ "name" ], "properties": { "id": { "type": "string", "description": "A uuid for the feature strategy", "example": "6b5157cb-343a-41e7-bfa3-7b4ec3044840" }, "name": { "type": "string", "description": "The name or type of strategy", "example": "flexibleRollout" }, "title": { // Output truncated... } Value: [ { "constraints": [], "disabled": false, "id": "01M4JVFJCS0AKVHVVQ6964N1BX", "milestoneId": null, "name": "flexibleRollout", "parameters": { "groupId": "checkout", "rollout": "100", "stickiness": "default" }, "segments": [ 1 ], "sortOrder": 0, "title": null, "variants": [] }, // Output truncated... ] [200] OK: `[{"id":"01M4JVFJCS0AKVHVVQ6964N1BX","name":"flexibleRollout","constraints":[],"parameters":{"groupId":"checkout","rollout":"100","stickiness":"default"},"variants":[],"title":null,"disabled":false,"sortOrder":0,"milestoneId":null,"segments":[1]},{"id":"01M4JVMM2186JVM6YVPM2FNCVE","name":"appName","constraints":[],"parameters":{},"variants":[],"title":null,"disabled":false,"sortOrder":17,"milestoneId":null,"segments":[]},{"id":"01M4JVMM2EYDZ06HEY92GKW9A3","name":"appName","constraints":[],"parameters":{},"va // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/feature-types curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/client-metrics/features/Operational curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features/checkout/environments/development/strategies 7. Test Case ID: Q7fmXX - Undocumented HTTP status code Received: 404 Documented: 204, 400, 401, 403, 409, 415 [404] Not Found: `{"name":"NotFoundError","message":"No segment exists with ID \"293790\"","details":[{"message":"No segment exists with ID \"293790\""}]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\uda4c\ude2e": [], "NaN": {"\u00fe\u00ea\udbec\uddd4o\udac0\udc92\udaca\udd4c\u00c0\u00a9F\u00ee\u00b6\u00e3": 5329121, "IgnoredAuth": "[Filtered]", "": 2479745}, "1I\u3b41\u00ad\u00c3\u007fa": {"!K}\u00c6\u00a5\u00e4": 1.401298464324817e-45, "\u00d7\u0087\u00f5": [null, true, 4109985222027942.0]}, "\u0093\uda7c\udd7f\u00ecw\udac4\uddeet\u00e9\udafb\ude3b\r\u008c\u00e6\u0006WS": false, "\u00c7": {}, "name": "\udbe1\udc93\"\u00a3\u0081r=\u00db\ud9c2\ude75\u00cc:", "constraints": []}' http://0.0.0.0:37503/api/admin/segments/293790 8. Test Case ID: Uky1yd - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `application/json` [409] Conflict: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/segments/1 9. Test Case ID: Z4k7pY - Use after free The API did not return a `HTTP 404 Not Found` response (got `HTTP 200 OK`) for a resource that was previously deleted. The resource was deleted with `DELETE /api/admin/projects/default/features/search` [200] OK: `{"name":"search","description":"񝞝","type":"release","project":"default","stale":false,"createdAt":"2026-10-10T12:09:24.165Z","impressionData":false,"archivedAt":"2026-10-10T12:21:59.574Z","archived":true}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud91c\udedc\u00fa\u00ce[\u00e3\u00a6\udb3b\udf36": null, "\u00be\u0002\u00af\u00bb1t\u007fZ\udba0\uddcd\u00ce\u00c1\u00f1\u00b9\u0093\u00da\udafe\ude98\u00a7": [["\u0015h\ud859\udf71", 177702735517561, 6.058885144923726e+16]], "": [], "\u00a7": "\u00b9V\ud8a2\ude89\u008b\u00b6B", "environment": "40\u0014s", "downloadFile": false, "project": "j"}' http://0.0.0.0:37503/api/admin/features-batch/export curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:37503/api/admin/projects/default/features/search curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[]' http://0.0.0.0:37503/api/admin/projects/default/features/search 10. Test Case ID: 0DOO1e - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 401, 403 [500] Internal Server Error: `{"name":"UnknownError","message":"insert into \"users\" (\"company_role\", \"created_at\", \"email\", \"email_hash\", \"image_url\", \"name\", \"product_updates_email_consent\", \"username\") values (DEFAULT, $1, $2, encode(sha256($3::bytea), 'hex'), DEFAULT, $4, DEFAULT, $5) returning \"id\", \"name\", \"username\", \"email\", \"image_url\", \"seen_at\", \"is_service\", \"scim_id\", \"seat_type\", \"company_role\", \"product_updates_email_consent\", \"login_attempts\", \"created_at\" - duplicate key value // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"email": "workbench@example.com", "sendEmail": true, "username": "hunter", "password": "[Filtered]", "name": "remoteAddress", "rootRole": 0}' http://0.0.0.0:37503/api/admin/user-admin 11. Test Case ID: fi2MfU - Response violates schema null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/tagTypeSchema/properties/description: { "type": "string", "description": "The description of the tag type.", "example": "A tag type for describing the color of a tag." } Value: null [200] OK: `{"features":[{"name":"-34310821","description":null,"type":"release","project":"default","stale":false,"impressionData":false,"archived":false},{"name":"78284168","description":null,"type":"release","project":"default","stale":false,"impressionData":true,"archived":false},{"name":"Admin","description":"0/0","type":"release","project":"default","stale":false,"impressionData":false,"archived":false},{"name":"Default","description":null,"type":"operational","project":"default","stale":false,"impressionData":fa // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": {"Ac\u008d": -4407858}, "\u00b9\udbc3\udc6c\u0003\u00e4\uda20\udfdbC": {"": {}}, "\udae5\ude3e": {"\u00f8\u00b9\u0007\u008e\u0015": "Other", "\u00a2\u00ef\udaa6\udfa1h\u00bc\r/\u0019": ""}, "environment": "\ud80e\udd93\u00fc", "features": []}' http://0.0.0.0:37503/api/admin/features-batch/export =================================== WARNINGS =================================== Authentication failed: 16 operations returned authentication errors 403 Forbidden (13 operations): - GET /api/admin/user/tokens - GET /api/client/features - GET /api/client/features/{featureName} - GET /api/frontend - PATCH /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/variants - POST /api/admin/user/tokens - POST /api/client/metrics - POST /api/client/metrics/bulk - POST /api/client/register - POST /api/frontend - POST /api/frontend/client/metrics - POST /api/frontend/client/register - PUT /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/variants 401 Unauthorized (3 operations): - GET /auth/reset/validate - POST /auth/simple/login - POST /edge/issue-token 💡 Ensure valid authentication credentials are set via --auth or -H Rate limited: 7 operations mostly returned 429 Too Many Requests, leaving the logic behind them untested - GET /api/admin/search/features - POST /api/admin/user-admin/inactive/delete - POST /api/admin/user-admin/reset-password - POST /api/admin/user-admin/validate-password - POST /api/admin/user-admin/{id}/change-password - POST /auth/reset/password-email - POST /auth/simple/login 💡 Send requests no faster than the API allows with --rate-limit, e.g. --rate-limit=100/m Missing test data: 16 operations repeatedly returned 404 Not Found, preventing tests from reaching your API's core logic No links point to these operations (2 operations): - GET /api/admin/tags/{type}/{value} - POST /auth/reset/password-email 💡 Provide realistic parameter values in your config file so tests can access existing resources Reachable via links, but stateful testing never reached it: - DELETE /api/admin/user-admin/{id} 💡 Raise `phases.stateful.max-steps` or run longer so stateful testing reaches these operations Reached via links, but the linked data was not usable (13 operations): - DELETE /api/admin/addons/{id} - DELETE /api/admin/projects/{projectId}/features/{child}/dependencies - DELETE /api/admin/projects/{projectId}/features/{child}/dependencies/{parent} - DELETE /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/strategies/{strategyId} - DELETE /api/admin/projects/{projectId}/features/{featureName}/link/{linkId} - GET /api/admin/projects/{projectId}/features/{featureName}/environments/{environment} - GET /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/strategies - GET /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/variants - PATCH /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/variants - POST /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/off - POST /api/admin/projects/{projectId}/features/{featureName}/environments/{environment}/on - PUT /api/admin/addons/{id} - PUT /api/admin/projects/{projectId}/features/{featureName}/link/{linkId} 💡 Check the operations that create this data - their responses do not yield usable identifiers Schema validation mismatch: 3 operations mostly rejected generated data due to validation errors, indicating schema constraints don't match API validation - POST /api/admin/projects/{projectId}/environments - POST /api/admin/tag-types/validate - POST /api/admin/tags 💡 Check your schema constraints - API validation may be stricter than documented =================================== SUMMARY ==================================== API Operations: Selected: 211/211 Tested: 211 Test Phases: ❌ Examples ❌ Coverage 🚫 Fuzzing ❌ Stateful Failures: ❌ API accepts requests without authentication: 3 ❌ Server error: 58 ❌ Use after free: 1 ❌ Response header does not conform to the schema: 12 ❌ Response violates schema: 29 ❌ API accepted schema-violating request: 48 ❌ API rejected schema-compliant request: 56 ❌ Invalid Allow header: 15 ❌ JSON deserialization error: 7 ❌ Missing Content-Type header: 7 ❌ Undocumented HTTP status code: 196 ❌ Unsupported methods: 63 Errors: 🚫 Network Error: 1 🚫 Server Unavailable: 1 Warnings: ⚠️ Missing authentication: 16 operations returned only 401/403 responses ⚠️ Rate limited: 7 operations mostly returned 429 responses ⚠️ Missing valid test data: 16 operations repeatedly returned 404 responses ⚠️ Schema validation mismatch: 3 operations mostly rejected generated data Test cases: 211716 generated, 401 found 495 unique failures, 8 errored, 982 skipped Seed: 251312374787886113515466957632245890878 ================ 495 failures, 2 errors, 4 warnings in 1467.68s ================