설명
OpenAPI 3.0의 작업별 security에서 해당 OAuth2 방식의 flows에 없는 스코프를 참조하면, 그 작업에 필요한 권한이 문서의 정의와 맞지 않게 됩니다.
잠재적 영향
API 사용자가 잘못된 스코프로 토큰을 요청하거나 해당 작업의 권한 요구사항을 잘못 구현할 수 있습니다.
해결 방법
작업에서 요구하는 스코프를 해당 components.securitySchemes의 OAuth2 scopes 및 인증 서버 설정과 일치시키십시오. 필요한 권한이 빠졌다면 정의를 추가하십시오. 작업별 요구사항은 전역 security를 대체하므로 기존에 필요한 권한도 유지해야 합니다.
예시
예시는 작업의 불필요한 error:api 참조를 제거합니다. OpenID Connect의 스코프는 OAuth2 흐름의 로컬 정의 대신 제공자의 설정과 대조하십시오.
변경 전
json
{
"openapi": "3.0.0",
"paths": {
"/": {
"get": {
"security": [
{
"oAuth2AuthCode": [
"read:api",
"error:api"
]
}
]
}
}
},
"components": {
"securitySchemes": {
"oAuth2AuthCode": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://api.example.com/oauth/authorize",
"tokenUrl": "https://api.example.com/oauth/token",
"scopes": {
"read:api": "read your apis"
}
}
}
}
}
}
}
변경 후
json
{
"openapi": "3.0.0",
"paths": {
"/": {
"get": {
"security": [
{
"oAuth2AuthCode": [
"read:api"
]
}
]
}
}
},
"components": {
"securitySchemes": {
"oAuth2AuthCode": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://api.example.com/oauth/authorize",
"tokenUrl": "https://api.example.com/oauth/token",
"scopes": {
"read:api": "read your apis"
}
}
}
}
}
}
}