Quick update on the API v2 beta testing. I’ve now run a smoke test across all 17 public resource families, including Universes and Story Arcs. The collection endpoints are returning the expected pagination structure, and I also confirmed working detail responses, second-page pagination, text filtering, structured 400 and 404 responses, and ETag revalidation returning 304. Basic authentication works, and Story Arcs returned 200 through the authenticated bucket after the anonymous limit had been reached. The response times I saw were generally between about 200 ms and 2.1 seconds, so nothing stood out as an immediate performance blocker.
I did find one deployment issue with token authentication. I confirmed Swagger was sending a correctly formatted Authorization: Token <value> header, but the request still landed in the anonymous throttle bucket and returned 429. Since an invalid token reaching Django should return 401, this looks like the authorization header may not be reaching the WSGI application. If beta is running Apache/mod_wsgi, could you check whether WSGIPassAuthorization On is enabled for the relevant virtual host? If it’s behind something else, the equivalent check would be whether the proxy forwards the Authorization header unchanged.
I also found one API behavior issue while testing malformed filters. An invalid value such as variant_of=not-a-boolean is currently ignored and returns the entire unfiltered Issue collection. I’ve prepared a small local fix that adds strict validation across all four public Boolean filters: Brand generic, Creator death_date__isnull, Indicia Publisher is_surrogate, and Issue variant_of. The full API v2 suite is green with 328 tests. I haven’t pushed that branch yet, but I can open it as a separate focused PR.
Once the beta authorization-header configuration is sorted out, I’ll rerun the token-only Story Arc and Award recipient requests, confirm invalid tokens return 401, and verify the authenticated rate-limit bucket. At that point the beta acceptance pass should be complete. Does that sound like the right next step on your end?
Thanks,
Adam