Cisco Secure Client · API Governance Rules

Cisco Secure Client API Rules

Spectral linting rules defining API design standards and conventions for Cisco Secure Client.

5 Rules error 3 warn 2
View Rules File View on GitHub

Rule Categories

csc

Rules

error
csc-https-only
All Secure Client management API servers MUST use HTTPS.
$.servers[*].url
error
csc-security-required
API MUST define security schemes for token, OAuth, or HMAC auth.
$.components.securitySchemes
error
csc-operation-id
Operations MUST have an operationId.
$.paths[*][get,post,put,delete,patch]
warn
csc-tag-required
Operations MUST be tagged for security domain grouping.
$.paths[*][get,post,put,delete,patch].tags
warn
csc-info-contact
API info MUST contain a contact for security disclosures.
$.info

Spectral Ruleset

cisco-secure-client-rules.yml Raw ↑
extends:
  - spectral:oas
rules:
  csc-https-only:
    description: All Secure Client management API servers MUST use HTTPS.
    severity: error
    given: $.servers[*].url
    then:
      function: pattern
      functionOptions:
        match: '^https://'
  csc-security-required:
    description: API MUST define security schemes for token, OAuth, or HMAC auth.
    severity: error
    given: $.components.securitySchemes
    then:
      function: truthy
  csc-operation-id:
    description: Operations MUST have an operationId.
    severity: error
    given: $.paths[*][get,post,put,delete,patch]
    then:
      field: operationId
      function: truthy
  csc-tag-required:
    description: Operations MUST be tagged for security domain grouping.
    severity: warn
    given: $.paths[*][get,post,put,delete,patch].tags
    then:
      function: truthy
  csc-info-contact:
    description: API info MUST contain a contact for security disclosures.
    severity: warn
    given: $.info
    then:
      field: contact
      function: truthy