Object-typed query parameters with explode=true (the default) were
passed as raw Python dicts to httpx, which called str() on them —
producing Python repr syntax (single quotes, capitalized booleans)
instead of proper query parameter serialization.
Per the OpenAPI specification, style=form with explode=true on objects
expands each property as a separate query parameter (e.g.
?myAttribute=true). This change handles dict values in both the
explode=true and explode=false branches of _serialize_query_params,
using the existing _query_scalar_to_str helper for correct boolean
formatting.
Fixes#2857
* fix: URL-encode path params in OpenAPI provider to prevent SSRF/path traversal
Co-authored-by: Claude <noreply@anthropic.com>
* Exempt too-long from core-category requirement in triage
* fix: also encode dots in path params to prevent bare .. traversal
* fix: only encode .. (not all dots) to preserve valid dotted values
* fix: encode all dots in path params to prevent single-dot normalization
* fix: check decoded path stays within prefix in double-encoding test
---------
Co-authored-by: Claude <noreply@anthropic.com>