説明
OpenAPI 2.0の操作に指定したsecurityが、対応するOAuth2方式のsecurityDefinitionsにないスコープを参照すると、その操作に必要な権限を誤って記述することになります。
想定される影響
クライアントが誤ったスコープでトークンを要求したり、開発者が操作に必要な権限を誤って実装したりする可能性があります。
対処方法
各操作のスコープ名を該当の方式のscopesと照合し、誤記や古い参照を修正します。必要な権限は認可サーバーの設定に合わせて定義してください。操作のsecurityは全体の設定を置き換えるため、修正時に必要な要件が欠けないようにします。
例
この例では、操作から不要なerror:apiを削除し、read:apiを維持しています。error:apiが必要であれば、先にその定義を追加してください。
変更前
yaml
swagger: "2.0"
paths:
/:
get:
security:
- oAuth2AuthCode:
- read:api
- error:api
securityDefinitions:
oAuth2AuthCode:
type: oauth2
flow: accessCode
authorizationUrl: https://api.example.com/oauth/authorize
tokenUrl: https://api.example.com/oauth/token
scopes:
read:api: read your apis
変更後
yaml
swagger: "2.0"
paths:
/:
get:
security:
- oAuth2AuthCode:
- read:api
securityDefinitions:
oAuth2AuthCode:
type: oauth2
flow: accessCode
authorizationUrl: https://api.example.com/oauth/authorize
tokenUrl: https://api.example.com/oauth/token
scopes:
read:api: read your apis