## **Release 5.0.0** ### **New Features** #### **CAPIF Interconnection** Implementation of **CAPIF Interconnection** capability to enable multiple CCFs — either of the same or different trust domains — to seamlessly interact, discover services, and publish APIs with one another. At the same time, CAPIF Interconnection enables API invokers to utilize the service APIs from 3rd party API providers. In order to include this functionality in the release the following developments were performed: - Creation of new Helper API to manage CAPIF interconnection establishment among CCFs. - Publish API funcationalities (Publish, Update/Modify, Unpublish) support interconnection feature. - Security Context API funcationalities (Create context, Get, Delete, Create Access Token) now support interconnection, allowing OAUTH, PSK and PKI security methods. - New way to read configuration yaml files inside microservices, allowing forwarding to local variables. This changes also HELM scripts at configuration map file. - Local scripts improved in order to allow interconnection tests with local deployments. - NGINX image is upgraded to latest version of debian. - All docker images are updated to python 3.13. - New set of tests with robot framework created in order to test interconnection. Check [Interconnection Test Plan](./testing/testplan/helper/interconnection/README.md) - New section at documentation with detailed information of this Feature at [Interconnection section](./interconnection/interconnection.md) #### **CAPIF Open Discover Service** Added implementation of **CAPIF_Open_Discover_Service_API** to support open discovery of published APIs. - New endpoint: `GET /open-api-disc/v1/service-apis`. - Security aligned with token-based flow (JWT token obtained from Register). - Filtering behavior aligned with Discover service logic, including standardized query parameters. - Deployment upgraded: - New Helm chart related with new Open Discover Service. - Scripts updated to include new service. - CI/CD also upgraded to generate new images of this new service. #### **Visibility Control API** Added the complete implementation of the **Visibility Control API** as a Helper service. - API Providers and administrators can create, update, list, and delete visibility rules. - Rules support provider selectors, invoker exceptions, default access behavior, enabled status, and validity periods. - Discover service integration filters published APIs according to the active rules and the API Invoker identity. - More information is available in the [Visibility Control feature documentation](./features/visibility-control/visibility-control.md). ### **Technical Debt Solved** #### **Upgrade packages** For security reasons: - opentelemetry-instrumentation was upgraded to 0.61b0 - opentelemetry-instrumentation-flask was upgraded to 0.61b0 - opentelemetry-instrumentation-redis was upgraded to 0.61b0 - opentelemetry-instrumentation-pymongo was upgraded to 0.61b0 - opentelemetry-exporter-otlp was upgraded to 1.40.0 - opentelemetry-api was upgraded to 1.40.0 - opentelemetry-sdk was upgraded to 1.40.0 - opentelemetry-exporter-jaeger was removed - cryptography was upgraded to 46.0.1 #### **Minor fixes on Rel4** - Fix the check of the Docker version in the run.sh - Simplify check of vendor extensibility attributes in Discover API - Fix way to check if robot image is present to run testing scripts. (remote and local tests) - Local scripts now support environments and multiple deployment of local instances, with 2 dev purpouses environments. - New run_capif_interconnection_environment.sh, created to raise 2 environments locally to test capif interconnection. - Local testing scripts now check is destination hosts are reachable by host. - Log Level reviewed at all microservices. #### **Allow same apiName across different AEFs** Publish Service now enforces uniqueness by aefId/apiName instead of global apiName, allowing different AEFs to publish the same apiName while rejecting duplicates from the same AEF on POST, PUT, and PATCH. #### **OpenCAPIF Helm Charts split to manage deployment order** This improvement introduces a structured deployment order for OpenCAPIF components, simplifying deployments in Kubernetes environments. It helps prevent unnecessary restarts that add extra load to the deployment environment and allows the use of smaller, more maintainable Helm charts. Additionally, this change includes minor improvements such as correctly setting the `appVersion` in the charts, code and script enhancements, improved deployment control, and reduced deployment times. #### **Robot image generation upgraded** Robot image was upgraded to latest version on this release, including following work: - Base Ubuntu version updated to 22.04. Also this base ubuntu image was pushed to ETSI registry. - Dockerfile improved. - Base requirements.txt updated to latest versions. - New robot image version 2.0 uploaded to ETSI registry - All Scripts related with robot update current version to be used from 1.0 to 2.0. ### **Testing** - 2 New tests related with use of same apiName across different AEFs. - 6 new tests related with the new service OpenDiscover. - 12 new tests related with the Visibility Control API. - Duplicate test name capif_api_provider_management-10 changed. - 11 new tests related with the Interconnection feature. #### **Security Issues** - **Critical Authorization Bypass** vulnerability solved. ### **Documentation** - 2 New tests added to [OCF Publish API test plan documentation], related with apiName. - 6 New tests added to [OCF Open Discover API test plan documentation](https://ocf.etsi.org/documentation/latest/testing/testplan/api_open_discover_service/), related with the new service Open Discover - Changed name of capif_api_provider_management-10 to Update Registered Api Provider Without SuppFeat field - Updated expected **ProblemDetails** `detail` and `cause` error messages in test plan documentation for Discover, Events, Invoker Management, Provider Management, and Publish services to align responses with current certificate and ID validation behavior. - New test plan section related with OpenCAPIF Interconnection. - New OpenCAPIF Interconnection section under features section. - New [Open Discover](./open-discover/open-discover.md) section added under Features, with a developer guide on how to call the Open Discover Service API (authentication, query parameters and error responses). - New [Visibility Control](./features/visibility-control/visibility-control.md) section added under Features. - New [Visibility Control API test plan](./testing/testplan/helper/visibility_control/README.md) added, covering visibility rule management and discoverable API filtering. - New [Interconnection Test Plan](./testing/testplan/helper/interconnection/README.md) added, covering basic flow of interconnection feature.