OpenAPI 3 작업별 보안 설정에 정의되지 않은 scope를 사용하는 경우

OpenAPI 3.0의 개별 작업에서 OAuth2 정의에 없는 스코프를 요구합니다.

설명

OpenAPI 3.0의 작업별 security에서 해당 OAuth2 방식의 flows에 없는 스코프를 참조하면, 그 작업에 필요한 권한이 문서의 정의와 맞지 않게 됩니다.

잠재적 영향

API 사용자가 잘못된 스코프로 토큰을 요청하거나 해당 작업의 권한 요구사항을 잘못 구현할 수 있습니다.

해결 방법

작업에서 요구하는 스코프를 해당 components.securitySchemes의 OAuth2 scopes 및 인증 서버 설정과 일치시키십시오. 필요한 권한이 빠졌다면 정의를 추가하십시오. 작업별 요구사항은 전역 security를 대체하므로 기존에 필요한 권한도 유지해야 합니다.

예시

예시는 작업의 불필요한 error:api 참조를 제거합니다. OpenID Connect의 스코프는 OAuth2 흐름의 로컬 정의 대신 제공자의 설정과 대조하십시오.

변경 전

json
{
  "openapi": "3.0.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "oAuth2AuthCode": [
              "read:api",
              "error:api"
            ]
          }
        ]
      }
    }
  },
  "components": {
    "securitySchemes": {
      "oAuth2AuthCode": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://api.example.com/oauth/authorize",
            "tokenUrl": "https://api.example.com/oauth/token",
            "scopes": {
              "read:api": "read your apis"
            }
          }
        }
      }
    }
  }
}

변경 후

json
{
  "openapi": "3.0.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "oAuth2AuthCode": [
              "read:api"
            ]
          }
        ]
      }
    }
  },
  "components": {
    "securitySchemes": {
      "oAuth2AuthCode": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://api.example.com/oauth/authorize",
            "tokenUrl": "https://api.example.com/oauth/token",
            "scopes": {
              "read:api": "read your apis"
            }
          }
        }
      }
    }
  }
}

참조