Changes for version 0.02 - 2026-08-04

  • Security: components.securitySchemes are now enforced. to_app takes a security => { scheme => checker } map
  • Open::API::Client attaches credentials to match: security => { scheme => credential } sends apiKey / bearer / basic automatically,
  • CSRF protection on to_app: an always-on Origin/Referer check on state-changing methods (GET/HEAD/OPTIONS/TRACE are exempt), plus an optional server-side single-use token via a check callback. The callback verifies against your own store, its return is stashed as $env->{'openapi.csrf'}, and returning a string rotates the token cookie for you.
  • Open::API::Client handles CSRF transparently with csrf => 1
  • Secure response headers on by default (X-Content-Type-Options, Content-Security-Policy, X-Frame-Options, Referrer-Policy)
  • CORS: the cors => {} option answers preflight OPTIONS and adds Access-Control-* headers to actual responses, with an origin allowlist, credentials, exposed headers and max-age. A wildcard origin with credentials is refused at to_app.
  • max_body_size => N rejects an over-large request body with 413.
  • Opt-in content negotiation (negotiate => 1): 415 for an undeclared request Content-Type, 406 when Accept admits no declared response type.
  • error_format => 'problem' emits RFC 7807 application/problem+json for the errors this layer generates.
  • examples/ - a runnable, login-based petstore showing authentication, CSRF and the transparent client together.

Modules

OpenAPI 3.1 server and client
a spec driven HTTP client using Fetch