OpenAPITools / OpenAPITools/openapi-generator

[BUG][java-micronaut-server] Illegal codegeneration for security schemes

Open
#15,428 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Issue: Bug
Dominant language
Java
Stars
26.8k
Forks
7.7k
PR merge metrics
PR metrics pending

Description

Bug Report Checklist
  • Have you provided a full/minimal spec to reproduce the issue?
  • Have you validated the input using an OpenAPI validator (example)?
  • Have you tested with the latest master to confirm the issue still exists?
  • Have you searched for related issues/PRs?
  • What's the actual output vs expected output?
  • [Optional] Sponsorship to speed up the bug fix or feature request (example)
Description

I try to create RBAC authentication based on micronaut controller.
The micronaut controller was generated from openapi spec. The generator ignores the scope of the securitySchemes. I expected the security scopes in @Secured annotation. The generated file contains: @Secured({SecurityRule.IS_AUTHENTICATED}), but expected annotations like: @Secured({"write", "read"})

openapi-generator version
OpenAPI declaration file content or url

Here is a link: https://github.com/rost5000/micronaut-server-openapi/blob/master/src/main/resources/openapi.yaml

Generation Details
  • gradle openapi generator plugin
  • java-micronaut-server
Steps to reproduce
  1. clone the project: https://github.com/rost5000/micronaut-server-openapi.git
  2. assemble the project: ./gradlew clean build
  3. The generated code is in build/generate-resources/main/src/main/java/com/example/api/AbstractDefaultController.java
Related issues/PRs
Suggest a fix

I suggest that openapi generator load scopes information from /security or /components/securitySchemes I expect to see in generated controllers the scopes of the security, like @Secured("write", "admin")

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked openapi.yaml and reproduce the generated output using ./gradlew clean build in the example project. Inspect the java-micronaut-server generation path related to AbstractDefaultController.java and the security/scope data from the OpenAPI declaration. Done means generated @Secured annotations include the declared scopes such as write and read instead of only IS_AUTHENTICATED.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, openapi
Domain
api, authorization, backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.