Skip to content

fix(contacts): add fieldValue (preferred) + deprecate field_value in custom-field schemas - #320

Open
MCPVOT wants to merge 1 commit into
GoHighLevel:mainfrom
MCPVOT:fix/stale-field-value-spec
Open

fix(contacts): add fieldValue (preferred) + deprecate field_value in custom-field schemas#320
MCPVOT wants to merge 1 commit into
GoHighLevel:mainfrom
MCPVOT:fix/stale-field-value-spec

fix(contacts): add fieldValue (preferred) + deprecate field_value in …

ce2607c
Select commit
Loading
Failed to load commit list.
Orca Security (US) / Orca Security - Infrastructure as Code succeeded Aug 9, 2026 in 17s

Orca Security Scan Summary

StatusCheckIssues by priority
Passed PassedInfrastructure as Codehigh 0 medium 0 low 4 info 159View in Orca
🛡️ The following IaC misconfigurations have been detected
NAMEFILE
lowResponse on operations that should have a body has undefined schemaapps/contacts.jsonView in code
lowResponse on operations that should have a body has undefined schemaapps/contacts.jsonView in code
lowResponse on operations that should have a body has undefined schemaapps/contacts.jsonView in code
lowResponse on operations that should have a body has undefined schemaapps/contacts.jsonView in code
infoUnknown Propertyapps/contacts.jsonView in code
infoUnknown Propertyapps/contacts.jsonView in code
infoUnknown Propertyapps/contacts.jsonView in code
infoUnknown Propertyapps/contacts.jsonView in code
infoUnknown Propertyapps/contacts.jsonView in code
infoUnknown Propertyapps/contacts.jsonView in code
infoUnknown Propertyapps/contacts.jsonView in code
infoUnknown Propertyapps/contacts.jsonView in code
infoUnknown Propertyapps/contacts.jsonView in code
infoUnknown Propertyapps/contacts.jsonView in code
infoComponents Object Fixed Field Key Improperly Namedapps/contacts.jsonView in code
infoComponents Object Fixed Field Key Improperly Namedapps/contacts.jsonView in code
infoComponents Object Fixed Field Key Improperly Namedapps/contacts.jsonView in code
infoComponents Object Fixed Field Key Improperly Namedapps/contacts.jsonView in code
infoObject Without Required Propertyapps/contacts.jsonView in code
infoObject Without Required Propertyapps/contacts.jsonView in code
infoObject Without Required Propertyapps/contacts.jsonView in code
infoObject Without Required Propertyapps/contacts.jsonView in code
infoObject Without Required Propertyapps/contacts.jsonView in code
infoObject Without Required Propertyapps/contacts.jsonView in code
infoObject Without Required Propertyapps/contacts.jsonView in code
............

Annotations

Check warning on line 4524 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Unknown Property

Details:
OpenAPI v3.0 specifications contain properties not recognized by the standard
schema, indicating potential typos, deprecated fields, or custom extensions.
Unknown properties may cause validation failures or unexpected API behavior.
Review and remove unrecognized fields or properly namespace custom extensions
using 'x-' prefix.
Recommendation:
The field '$ref' is known in the contact object

Check warning on line 3395 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Unknown Property

Details:
OpenAPI v3.0 specifications contain properties not recognized by the standard
schema, indicating potential typos, deprecated fields, or custom extensions.
Unknown properties may cause validation failures or unexpected API behavior.
Review and remove unrecognized fields or properly namespace custom extensions
using 'x-' prefix.
Recommendation:
The field '%!s(int=2)' is known in the responses object

Check warning on line 3395 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Unknown Property

Details:
OpenAPI v3.0 specifications contain properties not recognized by the standard
schema, indicating potential typos, deprecated fields, or custom extensions.
Unknown properties may cause validation failures or unexpected API behavior.
Review and remove unrecognized fields or properly namespace custom extensions
using 'x-' prefix.
Recommendation:
The field '%!s(int=3)' is known in the responses object

Check warning on line 5070 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Unknown Property

Details:
OpenAPI v3.0 specifications contain properties not recognized by the standard
schema, indicating potential typos, deprecated fields, or custom extensions.
Unknown properties may cause validation failures or unexpected API behavior.
Review and remove unrecognized fields or properly namespace custom extensions
using 'x-' prefix.
Recommendation:
The field 'x-tagGroups' is known in the openapi object

Check warning on line 4838 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Unknown Property

Details:
OpenAPI v3.0 specifications contain properties not recognized by the standard
schema, indicating potential typos, deprecated fields, or custom extensions.
Unknown properties may cause validation failures or unexpected API behavior.
Review and remove unrecognized fields or properly namespace custom extensions
using 'x-' prefix.
Recommendation:
The field '$ref' is known in the contact object

Check warning on line 4671 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Unknown Property

Details:
OpenAPI v3.0 specifications contain properties not recognized by the standard
schema, indicating potential typos, deprecated fields, or custom extensions.
Unknown properties may cause validation failures or unexpected API behavior.
Review and remove unrecognized fields or properly namespace custom extensions
using 'x-' prefix.
Recommendation:
The field '$ref' is known in the contact object

Check warning on line 3425 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Unknown Property

Details:
OpenAPI v3.0 specifications contain properties not recognized by the standard
schema, indicating potential typos, deprecated fields, or custom extensions.
Unknown properties may cause validation failures or unexpected API behavior.
Review and remove unrecognized fields or properly namespace custom extensions
using 'x-' prefix.
Recommendation:
The field 'type' is known in the responses object

Check warning on line 3395 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Unknown Property

Details:
OpenAPI v3.0 specifications contain properties not recognized by the standard
schema, indicating potential typos, deprecated fields, or custom extensions.
Unknown properties may cause validation failures or unexpected API behavior.
Review and remove unrecognized fields or properly namespace custom extensions
using 'x-' prefix.
Recommendation:
The field '%!s(int=1)' is known in the responses object

Check warning on line 3794 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Unknown Property

Details:
OpenAPI v3.0 specifications contain properties not recognized by the standard
schema, indicating potential typos, deprecated fields, or custom extensions.
Unknown properties may cause validation failures or unexpected API behavior.
Review and remove unrecognized fields or properly namespace custom extensions
using 'x-' prefix.
Recommendation:
The field '$ref' is known in the contact object

Check warning on line 3395 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Unknown Property

Details:
OpenAPI v3.0 specifications contain properties not recognized by the standard
schema, indicating potential typos, deprecated fields, or custom extensions.
Unknown properties may cause validation failures or unexpected API behavior.
Review and remove unrecognized fields or properly namespace custom extensions
using 'x-' prefix.
Recommendation:
The field '%!s(int=0)' is known in the responses object

Check warning on line 2908 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Components Object Fixed Field Key Improperly Named

Details:
Component object field keys in OpenAPI specifications must follow naming
conventions allowing only alphanumeric characters, periods, hyphens, and
underscores. Non-compliant keys cause parsing errors and break tooling
compatibility. Use keys matching the pattern `^[a-zA-Z0-9\.\-_]+$`.
Recommendation:
components.{{securitySchemes}}.{{Location-Access}} is properly named

Check warning on line 2932 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Components Object Fixed Field Key Improperly Named

Details:
Component object field keys in OpenAPI specifications must follow naming
conventions allowing only alphanumeric characters, periods, hyphens, and
underscores. Non-compliant keys cause parsing errors and break tooling
compatibility. Use keys matching the pattern `^[a-zA-Z0-9\.\-_]+$`.
Recommendation:
components.{{securitySchemes}}.{{Agency-Access-Only}} is properly named

Check warning on line 2924 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Components Object Fixed Field Key Improperly Named

Details:
Component object field keys in OpenAPI specifications must follow naming
conventions allowing only alphanumeric characters, periods, hyphens, and
underscores. Non-compliant keys cause parsing errors and break tooling
compatibility. Use keys matching the pattern `^[a-zA-Z0-9\.\-_]+$`.
Recommendation:
components.{{securitySchemes}}.{{Agency-Access}} is properly named

Check warning on line 2916 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Components Object Fixed Field Key Improperly Named

Details:
Component object field keys in OpenAPI specifications must follow naming
conventions allowing only alphanumeric characters, periods, hyphens, and
underscores. Non-compliant keys cause parsing errors and break tooling
compatibility. Use keys matching the pattern `^[a-zA-Z0-9\.\-_]+$`.
Recommendation:
components.{{securitySchemes}}.{{Location-Access-Only}} is properly named

Check warning on line 3352 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Object Without Required Property

Details:
OpenAPI v3 specification objects lack required fields defined by the standard,
causing schema validation failures and potential client integration issues.
Missing required properties prevent proper API documentation parsing and code
generation. Include all mandatory fields as specified in the OpenAPI 3.0
specification.
Recommendation:
tags has all required fields

Check warning on line 2709 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Object Without Required Property

Details:
OpenAPI v3 specification objects lack required fields defined by the standard,
causing schema validation failures and potential client integration issues.
Missing required properties prevent proper API documentation parsing and code
generation. Include all mandatory fields as specified in the OpenAPI 3.0
specification.
Recommendation:
tags has all required fields

Check warning on line 1842 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Object Without Required Property

Details:
OpenAPI v3 specification objects lack required fields defined by the standard,
causing schema validation failures and potential client integration issues.
Missing required properties prevent proper API documentation parsing and code
generation. Include all mandatory fields as specified in the OpenAPI 3.0
specification.
Recommendation:
tags has all required fields

Check warning on line 2832 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Object Without Required Property

Details:
OpenAPI v3 specification objects lack required fields defined by the standard,
causing schema validation failures and potential client integration issues.
Missing required properties prevent proper API documentation parsing and code
generation. Include all mandatory fields as specified in the OpenAPI 3.0
specification.
Recommendation:
tags has all required fields

Check warning on line 3395 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Object Without Required Property

Details:
OpenAPI v3 specification objects lack required fields defined by the standard,
causing schema validation failures and potential client integration issues.
Missing required properties prevent proper API documentation parsing and code
generation. Include all mandatory fields as specified in the OpenAPI 3.0
specification.
Recommendation:
responses has all required fields

Check warning on line 4595 in apps/contacts.json

See this annotation in the file changed.

@orca-security-usorca-security-us/ Orca Security - Infrastructure as Code

[INFO] Object Without Required Property

Details:
OpenAPI v3 specification objects lack required fields defined by the standard,
causing schema validation failures and potential client integration issues.
Missing required properties prevent proper API documentation parsing and code
generation. Include all mandatory fields as specified in the OpenAPI 3.0
specification.
Recommendation:
tags has all required fields