Azure / Azure/data-api-builder

[Bug]: Incorrect OpenAPI Specifiaction causes error in Swagger

Open
#2,486 1 comment 2 reactions 2 assignees Claimed by @JerryNixon View on GitHub
2.2 bug open-api security
Dominant language
C#
Stars
1.5k
Forks
370
Avg merge
3d 17h
Merged PRs (30d)
8

Description

### What happened?

I am running DAB in development mode in Azure Redhat Openshift with AzureAD as AuthenticationProvider and "authenticated:*" on all Entities.

When testing the Rest API using Swagger DAB is adding a "Authorization" of type Header parameter on all endpoints.
![Image](https://github.com/user-attachments/assets/c9c70644-4e36-49e7-8797-5e03807d8368)

However, when using the [Try It Out] feature the Authorization parameter is not added to the request header. This seem to be because parameters of name "Authorization" and type Header should be ignored according to the OpenAPI specification. The incorrect behaviour and how to handle it in swagger is documented here:

https://github.com/swagger-api/swagger-ui/issues/5643#issuecomment-538412105

### Version

1.1.7

### What database are you using?

Azure SQL

### What hosting model are you using?

Custom Docker host

### Which API approach are you accessing DAB through?

REST

### Relevant log output

```Text

```

### Code of Conduct

- [x] I agree to follow this project's Code of Conduct

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.