{
  "packVersion": 1,
  "checkedOn": "2026-10-06",
  "target": "Browser-local OpenAPI Repair: selected OpenAPI 3.0 / AWS API Gateway REST checks",
  "method": "Synthetic inputs replayed twice through the existing worker handler in a local test harness including its pinned structural validator. Semantic invariants asserted separately. No AWS import, deployment, authorizer, IAM or runtime test was performed.",
  "engineFingerprintSha256": "c0d62ec2b7cbc649954f2746c7dca80de49390ffb8dd331c6c9388f7546cdf11",
  "cases": [
    {
      "id": "inheritance-overrides",
      "title": "Copy inheritance and preserve explicit overrides",
      "format": "json",
      "inputFile": "cases/inheritance-overrides.input.json",
      "expectedFile": "cases/inheritance-overrides.expected.json",
      "outputFile": "cases/inheritance-overrides.preview.json",
      "inputSha256": "e2ec16861a860732b14261c8c7d033c5fc0a47496e1b942e7718d5de9e5a2931",
      "expectedSha256": "c2b7cba64ff37eb388e67545ca9d556e962c23798c353fa88b62a87969753185",
      "outputSha256": "d5eaaf2dbeea6f2da9e4b10ef043216134aa5d69a1db2366ac1228122e5961e5",
      "previewAvailable": true,
      "invariant": "Exactly one GET security copy; root, POST [], PUT [{}], and extension values remain unchanged."
    },
    {
      "id": "yaml-optional-root",
      "title": "Preserve optional root-security alternatives in YAML",
      "format": "yaml",
      "inputFile": "cases/yaml-optional-root.input.yaml",
      "expectedFile": "cases/yaml-optional-root.expected.json",
      "outputFile": "cases/yaml-optional-root.preview.yaml",
      "inputSha256": "0aad6841ec6c6a4f34b094c0e233786353299d07abc10fa6f774764bfe19653a",
      "expectedSha256": "6af4d614cf736c24eac5d88680d07b5dc12c7b1960bd7ab647980da7a0dff06d",
      "outputSha256": "594fe6d0e47dcf64b01f8e5c1278b7117821a277ff179451a5f2cc6e628010f0",
      "previewAvailable": true,
      "invariant": "Exactly one GET copy preserves the anonymous alternative in root and operation."
    },
    {
      "id": "aws-any-method",
      "title": "Handle the AWS ANY operation explicitly",
      "format": "json",
      "inputFile": "cases/aws-any-method.input.json",
      "expectedFile": "cases/aws-any-method.expected.json",
      "outputFile": "cases/aws-any-method.preview.json",
      "inputSha256": "0fb4d43e112baa49c0ae3a9f3ff3ae72e970980eadf91649f25b6aa0d48c7587",
      "expectedSha256": "1271838b2b8ff52195c8fe331f8e6db15499617c802e811f7182e6f33165a561",
      "outputSha256": "4836c60223f2fb6d602c5cc96be00d319ae762304723b5a494ea262e150d258b",
      "previewAvailable": true,
      "invariant": "Exactly one security copy into x-amazon-apigateway-any-method; no invented HTTP operations."
    },
    {
      "id": "nullable-manual",
      "title": "Leave nullable contract changes for manual review",
      "format": "json",
      "inputFile": "cases/nullable-manual.input.json",
      "expectedFile": "cases/nullable-manual.expected.json",
      "outputFile": null,
      "inputSha256": "d8de6c18da95acccf7907d53c1e153836eb4d14ad9271d97d3b4b06898650052",
      "expectedSha256": "eb7eada35fa16b2bd0e4e69f670efa662dcfd545655ff4fa6c358713e4ad1040",
      "outputSha256": null,
      "previewAvailable": false,
      "invariant": "Report unsupported nullable; do not delete or rewrite the schema keyword."
    },
    {
      "id": "external-reference",
      "title": "Report an external reference without fetching it",
      "format": "json",
      "inputFile": "cases/external-reference.input.json",
      "expectedFile": "cases/external-reference.expected.json",
      "outputFile": null,
      "inputSha256": "b8be726a4d4caa01cc5d0da64746282891cab8c5a6b6d70cb0afd005463f69b8",
      "expectedSha256": "d5e72ec979b2609cf7516cf89c1de48606bafc8bdb7762fd1543821f12a6b856",
      "outputSha256": null,
      "previewAvailable": false,
      "invariant": "Report blocked reference; no fixture-time fetch calls; do not invent the target schema."
    },
    {
      "id": "unsupported-3-1",
      "title": "Reject automatic OpenAPI 3.1 conversion",
      "format": "json",
      "inputFile": "cases/unsupported-3-1.input.json",
      "expectedFile": "cases/unsupported-3-1.expected.json",
      "outputFile": null,
      "inputSha256": "f53846f0e8c9705b023e28905733f0ca5923746163d416f201d066109a6cddb6",
      "expectedSha256": "4e7fd438fd06fd9f49993a4cef91902095a1fa9a8ae1731027168b290d354561",
      "outputSha256": null,
      "previewAvailable": false,
      "invariant": "Report unsupported version; no downgrade or preview candidate."
    },
    {
      "id": "malformed-json",
      "title": "Stop safely on malformed JSON",
      "format": "json",
      "inputFile": "cases/malformed-json.input.json",
      "expectedFile": "cases/malformed-json.expected.json",
      "outputFile": null,
      "inputSha256": "f41585a07e185be4ac4e549c8f42f445f27cb828aa0d884052c4003d9addaa76",
      "expectedSha256": "578404a3f6e862393dd93cf28721d4638c89e7ad2673972dd8d18fefa5c1cbd4",
      "outputSha256": null,
      "previewAvailable": false,
      "invariant": "Report invalid JSON; no preview candidate."
    },
    {
      "id": "invalid-operation",
      "title": "Apply the pinned structure check before repair",
      "format": "json",
      "inputFile": "cases/invalid-operation.input.json",
      "expectedFile": "cases/invalid-operation.expected.json",
      "outputFile": null,
      "inputSha256": "708831ee9058f3ab423d4bbf01987f8789fdb79429612888a30bf0c875731509",
      "expectedSha256": "9e2fe2c7e3361665661b7e0b78ba8f8d9a6b805375a51d09a8f985a050974169",
      "outputSha256": null,
      "previewAvailable": false,
      "invariant": "Missing responses fails structural validation even with root security; repair stays disabled."
    },
    {
      "id": "no-root-security",
      "title": "Do not invent an absent security policy",
      "format": "json",
      "inputFile": "cases/no-root-security.input.json",
      "expectedFile": "cases/no-root-security.expected.json",
      "outputFile": null,
      "inputSha256": "4d8d96e131d8db64ad895d6c9081671d4abac27898cf2f33373bca0fb00ba570",
      "expectedSha256": "f51f7bb0744f06148d38b4ef066e108828194aea05d5e22c3560a89d78576ae3",
      "outputSha256": null,
      "previewAvailable": false,
      "invariant": "No inherited-security repair is offered when the root has no security field."
    }
  ]
}
