Skip to content

Document role-scoped OpenAPI spec downloads on RBAC-gated docs sites - #7216

Open
fern-api[bot] wants to merge 3 commits into
mainfrom
2026-10-01-fern-ai-1fb7a4-30109a6f
Open

fern-api[bot] wants to merge 3 commits into
mainfrom
2026-10-01-fern-ai-1fb7a4-30109a6f

Conversation

@fern-api

@fern-api fern-api Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

On docs sites that use authentication with role-based access control, the downloadable OpenAPI/AsyncAPI spec endpoints now return specs scoped to the signed-in viewer's roles. A viewer gets only the APIs and endpoints their roles can see, and APIs outside their roles return 404. Before this change, any signed-in viewer could download a spec containing endpoints their role couldn't see, so gated content could leak through the spec download.

Implements docs for: feat(docs): 404 guessed spec URLs and serve role-scoped specs on gated sites (fern-api/fern-platform#15393)

Changed pages

  • fern/products/docs/pages/developer-tools/openapi-spec.mdx: added a sentence to the existing authentication <Note> stating that RBAC sites serve role-scoped specs (only permitted APIs and endpoints) and return 404 for APIs outside the viewer's roles, linking to the RBAC page. The existing 401 statement for unauthenticated requests is unchanged.

The bot's original draft also mentioned a fallback to request-time generation above four role-requirement combinations. That's an internal implementation detail with no customer-visible effect, so it was removed.

Link to Devin session: https://app.devin.ai/sessions/e8a2323b525848d0a3b54a7f7037a419
Open in Devin Desktop: https://app.devin.ai/desktop/session/e8a2323b525848d0a3b54a7f7037a419?variant=devin

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

🌿 Preview your docs: https://fern-preview-2026-10-01-fern-ai-1fb7a4-30109a6f.docs.buildwithfern.com/learn

Here are the markdown pages you've updated:

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration devin-ai-integration Bot changed the title Document RBAC-scoped spec download behavior on openapi-spec page Document role-scoped OpenAPI spec downloads on RBAC-gated docs sites Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants