설명
OpenAPI 2.0의 개별 작업에 지정한 security가 해당 OAuth2 방식의 securityDefinitions에 없는 스코프를 참조하면, 그 작업에 필요한 권한을 잘못 문서화하게 됩니다.
잠재적 영향
클라이언트가 잘못된 스코프로 토큰을 요청하거나 개발자가 작업의 권한 요구사항을 잘못 구현할 수 있습니다.
해결 방법
각 작업의 스코프 이름을 해당 방식의 scopes와 대조하고 오타나 오래된 참조를 수정하십시오. 필요한 권한은 인증 서버 설정에 맞게 정의하십시오. 작업별 security는 전역 설정을 대체하므로 수정할 때 필요한 요구사항이 빠지지 않도록 확인하십시오.
예시
예시는 작업에서 불필요한 error:api를 제거하고 read:api를 유지합니다. error:api가 필요한 권한이라면 먼저 그 정의를 추가하십시오.
변경 전
yaml
swagger: "2.0"
paths:
/:
get:
security:
- oAuth2AuthCode:
- read:api
- error:api
securityDefinitions:
oAuth2AuthCode:
type: oauth2
flow: accessCode
authorizationUrl: https://api.example.com/oauth/authorize
tokenUrl: https://api.example.com/oauth/token
scopes:
read:api: read your apis
변경 후
yaml
swagger: "2.0"
paths:
/:
get:
security:
- oAuth2AuthCode:
- read:api
securityDefinitions:
oAuth2AuthCode:
type: oauth2
flow: accessCode
authorizationUrl: https://api.example.com/oauth/authorize
tokenUrl: https://api.example.com/oauth/token
scopes:
read:api: read your apis