OpenAPITools / OpenAPITools/openapi-generator
[BUG][ALL] HTTP Auth scheme names are (incorrectly) case-sensitive
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 26.8k
- Forks
- 7.7k
- PR merge metrics
- PR metrics pending
Description
Description
The API generator does not generate authorization/authentication code when the user inserts a security scheme like so:
components:
securitySchemes:
bearerToken:
type: http
scheme: Bearer
Note that "Bearer" is title-cased. It works if the scheme is instead lowercase "bearer".
Even though the spec is not clear on the subject, according to the spec author HTTP auth schemes should be case-insensitive. Even if the schemes were case-sensitive, the IANA registry's canonical cases for the two most common schemes are "Bearer" and "Basic".
openapi-generator version
4.3.0
OpenAPI declaration file content or url
See yaml snippet in description above
Command line used for generation
openapi-generator generate -i $OAS3_YAML_FILE -g scala-akka -o /tmp/apiclient-test
I have also tested this with ruby and bash generators
Suggest a fix
I've opened a PR in swagger-api/swagger-js#1531; I don't know where the relevant code is in this project, though.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the YAML securitySchemes snippet and run the documented openapi-generator command for the scala-akka generator. Reproduce the difference between title-cased and lowercase Bearer values, then check the ruby and bash generators mentioned in the report; done means HTTP auth code is generated consistently for case-insensitive scheme names.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- openapi
- Domain
- api, authentication, tooling
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100