Journal

· guides

A document hash cannot localize a contract change

A changed OpenAPI document hash forced a manual contract audit because it could not identify the path or schema that moved.

An OpenAPI document passes through one hash before splitting into unresolved maps and individual path and schema records.

A document hash can detect a moved contract, but it cannot name the change. Our Muniment Mobile review turned that limit into an afternoon of manual work.

Stable counts did not narrow the change

Each planning pass fetches and hashes an OpenAPI document owned by another team. A changed hash stops other shipping work until we read the contract change.

This time, the document grew while every inventory count held:

Measure Earlier document Fetched document
Raw bytes 422,506 425,095
Paths 91 91
Operations 123 123
Schemas 207 207

Stable totals only ruled out changes to those totals. They could not identify a changed route, operation, field, or bound.

Separate hashes for the path map and schema map had also moved. Both large maps remained candidates.

We had saved no earlier document, only its hashes. A text diff was impossible.

The manual reading found an uncovered defect

Our roadmap held 46 facts about this API. Each fact names a bound, field, or absent route that client code transcribes.

We checked all 46 facts against the fetched document and the client. Every recorded fact held.

Their coverage still had a hole. One upload operation declares a required header parameter whose string length runs from 1 to 255 characters.

The client sends two headers, but it never sends that required parameter. Every request to the operation would fail server validation.

Response-focused fixtures could not catch a missing request header. A request test can assert it.

Hash the objects that can move

Store one hash for each schema and each path. The next contract change then identifies the objects that moved.

That inventory turns two enormous candidates into a short review list. It preserves the detection value of the document hash while adding useful location.

The record cannot recover its missing past

Nobody can call the required parameter new. No earlier copy of the document survives, and a hash cannot reconstruct one.

This work measured no latency change and no bundle change. It changed contract review, not runtime behavior or shipped code size.

A per-object hash still covers only the published contract. A published route that behaves incorrectly needs a real request.

Visitors cannot exercise Muniment Mobile through a public install or authentication surface yet.

This evidence comes from our Muniment Mobile note pinned to commit b06885afa2ffe3e687cc4d56e6ec3b08d6cdad42.

Keep the document for a text diff. Keep per-path and per-schema hashes for the first useful pointer.

Continue reading

All publications

Join the waitlist

Get desktop release updates.

We will email you about desktop releases and new features. muniment is a desktop workspace for your models, tools, and files.