Automatically infer `OpenApiSecuritySchemes` from authentication configuration
Open
area-minimal
area-mvc
enhancement
feature-openapi
Priority:1
- Dominant language
- C#
- Stars
- 38.4k
- Forks
- 10.9k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 276
Description
At the moment, when users enable authentication in their ASP.NET apps, they typically have to manually the describe the `OpenApiSecuritySchemes` in their application and the top level and configure `OpenApiSecurityRequirements` for each route that requires authentication and authorization.
We should infer as much of these definitions as possible so users don't need to configure auth twice, once for their application and another time for OpenAPI.
Provide metadata support for parts of the specification documented in https://swagger.io/docs/specification/authentication/.
Contributor guide
Assessment
This issue has not been assessed yet.