작업별 보안 설정에 정의되지 않은 OAuth Scope 사용

OpenAPI 2.0의 작업별 보안 설정에서 정의되지 않은 OAuth2 스코프를 참조합니다.

설명

OpenAPI 2.0의 개별 작업에 지정한 security가 해당 OAuth2 방식의 securityDefinitions에 없는 스코프를 참조하면, 그 작업에 필요한 권한을 잘못 문서화하게 됩니다.

잠재적 영향

클라이언트가 잘못된 스코프로 토큰을 요청하거나 개발자가 작업의 권한 요구사항을 잘못 구현할 수 있습니다.

해결 방법

각 작업의 스코프 이름을 해당 방식의 scopes와 대조하고 오타나 오래된 참조를 수정하십시오. 필요한 권한은 인증 서버 설정에 맞게 정의하십시오. 작업별 security는 전역 설정을 대체하므로 수정할 때 필요한 요구사항이 빠지지 않도록 확인하십시오.

예시

예시는 작업에서 불필요한 error:api를 제거하고 read:api를 유지합니다. error:api가 필요한 권한이라면 먼저 그 정의를 추가하십시오.

변경 전

yaml
swagger: "2.0"
paths:
  /:
    get:
      security:
        - oAuth2AuthCode:
            - read:api
            - error:api
securityDefinitions:
  oAuth2AuthCode:
    type: oauth2
    flow: accessCode
    authorizationUrl: https://api.example.com/oauth/authorize
    tokenUrl: https://api.example.com/oauth/token
    scopes:
      read:api: read your apis

변경 후

yaml
swagger: "2.0"
paths:
  /:
    get:
      security:
        - oAuth2AuthCode:
            - read:api
securityDefinitions:
  oAuth2AuthCode:
    type: oauth2
    flow: accessCode
    authorizationUrl: https://api.example.com/oauth/authorize
    tokenUrl: https://api.example.com/oauth/token
    scopes:
      read:api: read your apis

참조