-
Notifications
You must be signed in to change notification settings - Fork 101
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Broken security definition reference from security requirement for OAuth2 #219
Comments
Kieun
added a commit
to Kieun/restdocs-api-spec
that referenced
this issue
Jan 4, 2023
ozscheyge
pushed a commit
that referenced
this issue
Jan 4, 2023
wodrobina
pushed a commit
that referenced
this issue
Mar 4, 2024
* Update version number in README * fix: better management of numbers in OpenApi3Generator (#202) Co-authored-by: Jordan GAZEAU <[email protected]> * Add project status notice (#209) * Add project status notice * Add link to maintenance issue * Upgrade gradlew to 7.4.2 (#214) * Fix extracting standard scope claim in OAuth2 JWT (#218) fixes #217 This fixes does not break current implementation of treating scope claim as List<String> * Fix broken security definition reference from security requirement for OAuth2 (#220) Fixes #219 * Make classes in restdocs-api-spec modules visible (#223) Fixes #222 * Polish README.md (#227) (cherry picked from commit 213f9e4) * docs: update FieldDescriptors example (#232) * docs: update FieldDescriptors example * docs: add new symbol for java (cherry picked from commit 26cd0dd) * feat: add support for contact object (#208) * feat: add support for contact object Closes #88 * docs: add documentation on how to define contacts (cherry picked from commit 2842c43) * Tabs to spaces (cherry picked from commit 2f5d1e2) * Drop usage of TravisCI (#236) GH-235 (cherry picked from commit 0b5d511) * Add GitHub Actions and Sonar support (#237) GH-235 (cherry picked from commit ac1600f) * Increase MaxMetaspaceSize (cherry picked from commit 1688a77) * ci: fix publish script name (cherry picked from commit 47f2173) * ci: ignore samples for code coverage report (#239) (cherry picked from commit 4893605) * docs: update readme [skip ci] (#238) GH-235 (cherry picked from commit de0c1ab) * feat: apply field optional (#244) * feat: apply field optional * fix lint (cherry picked from commit 4c735ca) * Feat : apply optional is nullable (#245) * feat: apply optional is nullable * chore: refactoring * chore: remove needless * fix deprecated * fix for test (cherry picked from commit 2900374) * Feat : Schema reuse through subschema (#246) * feat : Input a name for the subschema * feat : Input a name for the subschema * feat : Make sub schema * fix: lint * fix: requested & Suggested (cherry picked from commit 437d7da) * Fix to get regexp properly from the pattern constraint (#247) (cherry picked from commit c631886) * Keep supporting 0.16.x train to support Spring Boot 2.7.x and cherry-pick the latest features and fixes. --------- Co-authored-by: Oliver Zscheyge <[email protected]> Co-authored-by: Jojo <[email protected]> Co-authored-by: Jordan GAZEAU <[email protected]> Co-authored-by: Jan Mewes <[email protected]> Co-authored-by: Oliver <[email protected]> Co-authored-by: Johnny Lim <[email protected]> Co-authored-by: Taeyang Jin (Heli) <[email protected]> Co-authored-by: Marcos Paulo Belasco de Almeida <[email protected]> Co-authored-by: Jan Mewes <[email protected]> Co-authored-by: Xeroman.K <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
When generating open api v2 or open api v3 spec with OAuth2 protected APIs, the generated spec does not correctly refer the security definition from the security requirement in the each path definition.
This leads that swagger UI does not properly set the given OAuth2 credential when calling OAuth2 protected APIs.
While digging the issue, I've found that security definition reference is broken from the security requirement.
In current implementation in case of OAuth2 protected APIs, the security definition name is hard-coded with
oauth2
.So, when trying to refer such definition for the swagger UI to populate given credential when calling OAuth2 protected APIs, we should use
oauth2
.But, when creating OAS2 and OAS3 documentation, current implementation composes the such reference name with
oauth2
and following postfix_$flow
which stands for one of OAuth flow (implicit
,clientCredentials
,access_code
and etc.) and adds composed name in the security requirement field.For example., if OAuth2 security definition supports OAuth2
clientCredentials
andimplicit
flows, then the reference names are created:oauth2_clientCredentials
andoauth_implicit
which do not refer anything to the security definition.To fix this problem
The text was updated successfully, but these errors were encountered: