Skip to content

fix(spec): define network zone asns/locations as arrays instead of allOf wrappers - #601

Open
BinoyOza-okta wants to merge 1 commit into
masterfrom
OKTA-1236525
Open

BinoyOza-okta wants to merge 1 commit into
masterfrom
OKTA-1236525

Conversation

@BinoyOza-okta

Copy link
Copy Markdown
Contributor

Fix ValidationError in list_network_zones() for Dynamic and Enhanced Dynamic zones

Summary

Fixes a Pydantic ValidationError raised by NetworkZoneApi.list_network_zones() and get_network_zone() when a response contains a DYNAMIC or DYNAMIC_V2 zone with asns or locations values. This includes the empty list [] the API returns for Enhanced Dynamic zones with no ASNs configured.

Problem

pydantic_core.ValidationError: 1 validation error for EnhancedDynamicNetworkZoneAllOfAsnsInclude
  Input should be a valid dictionary or instance of EnhancedDynamicNetworkZoneAllOfAsnsInclude
  [type=model_type, input_value=[], input_type=list]

Because a single bad zone fails deserialization, the whole paginated list call fails.

Root cause

openapi/api.yaml declared these fields by wrapping an array schema in allOf:

include:
  allOf:
    - $ref: '#/components/schemas/NetworkZoneAsns'   # type: array
    - description: An array of ASNs to include ...

OpenAPI Generator 7.7.0 treats this wrapper as a new object type, so it generated empty models with no fields instead of List[...]. Pydantic correctly rejects a list for an object type. This isn't caused by Pydantic v2 strictness or by empty lists: populated lists fail too, and the empty models would drop the data anyway.

The pattern appeared in 6 places:

Model Field Before After
DynamicNetworkZone asns DynamicNetworkZoneAllOfAsns List[StrictStr]
DynamicNetworkZone locations DynamicNetworkZoneAllOfLocations List[NetworkZoneLocation]
EnhancedDynamicNetworkZoneAllOfAsns include / exclude ...AsnsInclude / ...AsnsExclude List[StrictStr]
EnhancedDynamicNetworkZoneAllOfLocations include / exclude ...LocationsInclude / ...LocationsExclude List[NetworkZoneLocation]

IP zones (gateways / proxies) are not affected.

Changes

  • openapi/api.yaml: replaced the 6 allOf wrappers with inline array definitions. Descriptions are kept, and maximum: 75 / nullable: true are copied from the referenced components.
  • Regenerated: dynamic_network_zone.py, enhanced_dynamic_network_zone_all_of_asns.py, enhanced_dynamic_network_zone_all_of_locations.py, their docs, and the lazy import maps in okta/__init__.py and okta/models/__init__.py.
  • Removed: the 6 obsolete wrapper models, their docs, and their links in okta/DOC_GUIDE.md.
  • Tests: added tests/test_network_zone_arrays.py.

Breaking change note

The 6 wrapper classes are removed (DynamicNetworkZoneAllOfAsns, DynamicNetworkZoneAllOfLocations, EnhancedDynamicNetworkZoneAllOf{Asns,Locations}{Include,Exclude}).
They had no fields and could never hold data, so no working code could have depended on them. The on-wire JSON shape is unchanged.

Testing

  • tests/test_network_zone_arrays.py: 48 tests covering empty, populated, and null payloads, discrimination through NetworkZone.from_dict, to_dict / JSON round trips, _links, proxyType validation, and regression guards for the removed models.
  • 39 of the 48 tests fail against the pre-fix models, confirming they catch the bug.
  • Coverage of the 4 changed models is 97%. The 5 uncovered lines are generator else branches for dict-valued nested fields, which can't be reached with Pydantic v2 validation on.
  • Existing unit tests and the network zone integration tests pass.

…lOf wrappers

Replace the `allOf: [$ref: <array schema>, description: ...]` wrappers on the network zone `asns` and `locations` fields in `openapi/api.yaml` with inline array definitions:

- DynamicNetworkZone: asns, locations
- EnhancedDynamicNetworkZone: asns.include, asns.exclude, locations.include, locations.exclude

Root cause: OpenAPI Generator 7.7.0 treats an allOf wrapper around an array $ref as a new object type. It generated six empty, field-less models (e.g. EnhancedDynamicNetworkZoneAllOfAsnsInclude), so any list returned by the API, including an empty one, raised a pydantic ValidationError. A single DYNAMIC or DYNAMIC_V2 zone with ASNs or locations was enough to fail the whole list_network_zones() call.

The inline definitions keep the original descriptions. The fields now generate as Optional[List[StrictStr]] and Optional[List[NetworkZoneLocation]].

- Regenerated the affected models and docs.
- Removed the six obsolete wrapper models, their docs, and their DOC_GUIDE.md links.
- Added tests/test_network_zone_arrays.py (48 tests).

The on-wire JSON shape is unchanged. This is a spec-accuracy fix.
@BinoyOza-okta BinoyOza-okta self-assigned this Oct 6, 2026

@dhiwakar-okta dhiwakar-okta left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants