SAP-samples/recap2026-cap-level-data-federation
60 issues need attention.
26 errors and 34 warnings in the paths between 31 routes and 11 tables.
- ROUTES
- 31
- TABLES
- 11
- FILES READ
- 22
- RULES RUN
- 7/7
60 findings
GET /odata/v4/admin/FlightConnections can reach FlightConnections without authenticating.
auth-before-dataGET /odata/v4/admin/FlightConnections → FlightConnectionsPOST /odata/v4/admin/FlightConnections can reach FlightConnections without authenticating.
auth-before-dataPOST /odata/v4/admin/FlightConnections → FlightConnectionsPATCH /odata/v4/admin/FlightConnections can reach FlightConnections without authenticating.
auth-before-dataPATCH /odata/v4/admin/FlightConnections → FlightConnectionsDELETE /odata/v4/admin/FlightConnections can reach FlightConnections without authenticating.
auth-before-dataDELETE /odata/v4/admin/FlightConnections → FlightConnectionsGET /odata/v4/admin/Flights can reach Flights without authenticating.
auth-before-dataGET /odata/v4/admin/Flights → FlightsPOST /odata/v4/admin/Flights can reach Flights without authenticating.
auth-before-dataPOST /odata/v4/admin/Flights → FlightsPATCH /odata/v4/admin/Flights can reach Flights without authenticating.
auth-before-dataPATCH /odata/v4/admin/Flights → FlightsDELETE /odata/v4/admin/Flights can reach Flights without authenticating.
auth-before-dataDELETE /odata/v4/admin/Flights → FlightsGET /odata/v4/admin/Airlines can reach Airlines without authenticating.
auth-before-dataGET /odata/v4/admin/Airlines → AirlinesPOST /odata/v4/admin/Airlines can reach Airlines without authenticating.
auth-before-dataPOST /odata/v4/admin/Airlines → AirlinesPATCH /odata/v4/admin/Airlines can reach Airlines without authenticating.
auth-before-dataPATCH /odata/v4/admin/Airlines → AirlinesDELETE /odata/v4/admin/Airlines can reach Airlines without authenticating.
auth-before-dataDELETE /odata/v4/admin/Airlines → AirlinesGET /odata/v4/admin/Airports can reach Airports without authenticating.
auth-before-dataGET /odata/v4/admin/Airports → AirportsPOST /odata/v4/admin/Airports can reach Airports without authenticating.
auth-before-dataPOST /odata/v4/admin/Airports → AirportsPATCH /odata/v4/admin/Airports can reach Airports without authenticating.
auth-before-dataPATCH /odata/v4/admin/Airports → AirportsDELETE /odata/v4/admin/Airports can reach Airports without authenticating.
auth-before-dataDELETE /odata/v4/admin/Airports → AirportsGET /odata/v4/admin/Supplements can reach Supplements without authenticating.
auth-before-dataGET /odata/v4/admin/Supplements → SupplementsPOST /odata/v4/admin/Supplements can reach Supplements without authenticating.
auth-before-dataPOST /odata/v4/admin/Supplements → SupplementsPATCH /odata/v4/admin/Supplements can reach Supplements without authenticating.
auth-before-dataPATCH /odata/v4/admin/Supplements → SupplementsDELETE /odata/v4/admin/Supplements can reach Supplements without authenticating.
auth-before-dataDELETE /odata/v4/admin/Supplements → SupplementsGET /odata/v4/travel/Travels can reach Travels without authenticating.
auth-before-dataGET /odata/v4/travel/Travels → TravelsPOST /odata/v4/travel/Travels can reach Travels without authenticating.
auth-before-dataPOST /odata/v4/travel/Travels → TravelsPATCH /odata/v4/travel/Travels can reach Travels without authenticating.
auth-before-dataPATCH /odata/v4/travel/Travels → TravelsDELETE /odata/v4/travel/Travels can reach Travels without authenticating.
auth-before-dataDELETE /odata/v4/travel/Travels → TravelsGET /odata/v4/travel/TravelAgencies can reach TravelAgencies without authenticating.
auth-before-dataGET /odata/v4/travel/TravelAgencies → TravelAgenciesGET /odata/v4/travel/Passengers can reach Passengers without authenticating.
auth-before-dataGET /odata/v4/travel/Passengers → PassengersGET /odata/v4/admin/FlightConnections has no validator or rate limiter attached.
public-entry-guardedPOST /odata/v4/admin/FlightConnections has no validator or rate limiter attached.
public-entry-guardedPATCH /odata/v4/admin/FlightConnections has no validator or rate limiter attached.
public-entry-guardedDELETE /odata/v4/admin/FlightConnections has no validator or rate limiter attached.
public-entry-guardedGET /odata/v4/admin/Flights has no validator or rate limiter attached.
public-entry-guardedPOST /odata/v4/admin/Flights has no validator or rate limiter attached.
public-entry-guardedPATCH /odata/v4/admin/Flights has no validator or rate limiter attached.
public-entry-guardedDELETE /odata/v4/admin/Flights has no validator or rate limiter attached.
public-entry-guardedGET /odata/v4/admin/Airlines has no validator or rate limiter attached.
public-entry-guardedPOST /odata/v4/admin/Airlines has no validator or rate limiter attached.
public-entry-guardedPATCH /odata/v4/admin/Airlines has no validator or rate limiter attached.
public-entry-guardedDELETE /odata/v4/admin/Airlines has no validator or rate limiter attached.
public-entry-guardedGET /odata/v4/admin/Airports has no validator or rate limiter attached.
public-entry-guardedPOST /odata/v4/admin/Airports has no validator or rate limiter attached.
public-entry-guardedPATCH /odata/v4/admin/Airports has no validator or rate limiter attached.
public-entry-guardedDELETE /odata/v4/admin/Airports has no validator or rate limiter attached.
public-entry-guardedGET /odata/v4/admin/Supplements has no validator or rate limiter attached.
public-entry-guardedPOST /odata/v4/admin/Supplements has no validator or rate limiter attached.
public-entry-guardedPATCH /odata/v4/admin/Supplements has no validator or rate limiter attached.
public-entry-guardedDELETE /odata/v4/admin/Supplements has no validator or rate limiter attached.
public-entry-guardedGET /odata/v4/travel/Travels has no validator or rate limiter attached.
public-entry-guardedPOST /odata/v4/travel/Travels has no validator or rate limiter attached.
public-entry-guardedPATCH /odata/v4/travel/Travels has no validator or rate limiter attached.
public-entry-guardedDELETE /odata/v4/travel/Travels has no validator or rate limiter attached.
public-entry-guardedGET /odata/v4/travel/TravelAgencies has no validator or rate limiter attached.
public-entry-guardedGET /odata/v4/travel/Currencies has no validator or rate limiter attached.
public-entry-guardedGET /odata/v4/travel/Passengers has no validator or rate limiter attached.
public-entry-guardedPOST /odata/v4/travel/deductDiscount has no validator or rate limiter attached.
public-entry-guardedPOST /odata/v4/travel/acceptTravel has no validator or rate limiter attached.
public-entry-guardedPOST /odata/v4/travel/rejectTravel has no validator or rate limiter attached.
public-entry-guardedPOST /odata/v4/travel/reopenTravel has no validator or rate limiter attached.
public-entry-guardedBookings is not connected to anything.
no-orphan-datastoreTravelStatus is not connected to anything.
no-orphan-datastoreSupplementTypes is not connected to anything.
no-orphan-datastore
Part of this repository was not read, so this report is incomplete. Unread: ws/xtravels/srv/travel-service.cds, ws/xtravels/srv/travel-service.cds, ws/xtravels/srv/travel-service.cds.
Free account, no card. The repository opens as an editable graph.
Add this check to the README
[](https://wyro.in/scan/SAP-samples/recap2026-cap-level-data-federation)It updates itself whenever the repository changes and links back to this report.
What this is
Wyro reads the repository’s routes and data models and checks the paths between them: whether a route can reach a table without passing a guard, whether a datastore holding personal data is exposed to a public read, whether an endpoint that issues credentials requires the credentials it issues.
It is rule-based, not a model. The same commit produces the same result every time, and it does not guess at business rules it cannot see. A rule with nothing to look at is reported as not having run — never as a pass.
This check runs on public source through GitHub’s own API and needs no account. A free account adds the editable architecture canvas, private repositories on paid plans, and a CI gate. No card required.