TROLIE · API Governance Rules
TROLIE API Rules
Spectral linting rules defining API design standards and conventions for TROLIE.
5 Rules
warn 5
Published by TROLIE
Served by the provider at https://github.com/trolie/spec/blob/39741d03365cb430ab5d7e677312759a7f4a6d14/.spectral.yaml; the copy below was fetched from there.
Rule Categories
owasp:api3:2019
owasp:api4:2019
should
Rules
warn
owasp:api3:2019-define-error-responses-500
OWASP API Security recommends defining schemas for all responses, even errors. The 500 describes what happens when a request fails with an internal server error, so its important to define this not just for documentation, but to empower contract testing to make sure the proper JSON structure is being returned instead of leaking implementation details in backtraces.
$.paths.*[get,put,post,patch,delete].responses
warn
owasp:api3:2019-define-error-responses-500-head
OWASP API Security recommends defining schemas for all responses, even errors. The 500 describes what happens when a request fails with an internal server error, so its important to define this not just for documentation, but to empower contract testing to make sure the proper JSON structure is being returned instead of leaking implementation details in backtraces.
$.paths.*[head].responses
warn
owasp:api3:2019-define-error-responses-401
OWASP API Security recommends defining schemas for all responses, even errors. The 401 describes what happens when a request is unauthorized, so its important to define this not just for documentation, but to empower contract testing to make sure the proper JSON structure is being returned instead of leaking implementation details in backtraces.
$.paths.*[get,put,post,patch,delete].responses
warn
owasp:api4:2019-rate-limit-responses-429
$.paths..responses
warn
should-have-422
$.paths.*[put,post,patch].responses
Spectral Ruleset
Work with this as data
Every ruleset here is available over the APIs.io API and to AI agents over MCP.