説明
OpenAPI 2.0の全体のsecurity設定で、対応するOAuth2方式のsecurityDefinitionsにないスコープを参照すると、定義された権限と要求する権限が一致しなくなります。
想定される影響
APIの利用者が必要な権限を誤解したり、文書の検証やクライアント生成に失敗したりする可能性があります。
対処方法
全体のsecurityで参照するスコープ名を、該当の方式のscopesと一致させます。誤記や不要なスコープは修正または削除し、必要なスコープが定義から抜けている場合は、認可サーバーの実際の権限に合わせて追加してください。
例
この例では、未定義のerror:apiを削除しています。実際に必要な権限であれば、要件を削除せずに定義を修正してください。
変更前
yaml
swagger: "2.0"
securityDefinitions:
oAuth2AuthCode:
type: oauth2
flow: accessCode
authorizationUrl: https://api.example.com/oauth/authorize
tokenUrl: https://api.example.com/oauth/token
scopes:
read:api: read your apis
security:
- oAuth2AuthCode:
- read:api
- error:api
変更後
yaml
swagger: "2.0"
securityDefinitions:
oAuth2AuthCode:
type: oauth2
flow: accessCode
authorizationUrl: https://api.example.com/oauth/authorize
tokenUrl: https://api.example.com/oauth/token
scopes:
read:api: read your apis
security:
- oAuth2AuthCode:
- read:api