mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: improve validation of Security tag in swaggerparser (#15660)
Aims to resolve #15605 There's currently one option valid for the `@Security` tag in swaggerparser - which fails in the CI if we try to put any other value. At least one of our endpoints does not accept `CoderSessionToken` as an option for the authentication and so we need to add new possibilities in order to keep the documentation up-to-date. In this PR , I added `ProvisionerKey` which is the way our provisioner daemon can authenticate to the backend - also modified a bit the code to simplify other options later.
This commit is contained in:
Generated
+1
-1
@@ -3642,7 +3642,7 @@ const docTemplate = `{
|
||||
"get": {
|
||||
"security": [
|
||||
{
|
||||
"CoderSessionToken": []
|
||||
"CoderProvisionerKey": []
|
||||
}
|
||||
],
|
||||
"produces": [
|
||||
|
||||
Generated
+1
-1
@@ -3208,7 +3208,7 @@
|
||||
"get": {
|
||||
"security": [
|
||||
{
|
||||
"CoderSessionToken": []
|
||||
"CoderProvisionerKey": []
|
||||
}
|
||||
],
|
||||
"produces": ["application/json"],
|
||||
|
||||
@@ -300,6 +300,11 @@ func assertPathParametersDefined(t *testing.T, comment SwaggerComment) {
|
||||
}
|
||||
|
||||
func assertSecurityDefined(t *testing.T, comment SwaggerComment) {
|
||||
authorizedSecurityTags := []string{
|
||||
"CoderSessionToken",
|
||||
"CoderProvisionerKey",
|
||||
}
|
||||
|
||||
if comment.router == "/updatecheck" ||
|
||||
comment.router == "/buildinfo" ||
|
||||
comment.router == "/" ||
|
||||
@@ -308,7 +313,7 @@ func assertSecurityDefined(t *testing.T, comment SwaggerComment) {
|
||||
comment.router == "/users/otp/change-password" {
|
||||
return // endpoints do not require authorization
|
||||
}
|
||||
assert.Equal(t, "CoderSessionToken", comment.security, "@Security must be equal CoderSessionToken")
|
||||
assert.Containsf(t, authorizedSecurityTags, comment.security, "@Security must be either of these options: %v", authorizedSecurityTags)
|
||||
}
|
||||
|
||||
func assertAccept(t *testing.T, comment SwaggerComment) {
|
||||
|
||||
Generated
+1
-2
@@ -2032,8 +2032,7 @@ To perform this operation, you must be authenticated. [Learn more](authenticatio
|
||||
```shell
|
||||
# Example request using curl
|
||||
curl -X GET http://coder-server:8080/api/v2/provisionerkeys/{provisionerkey} \
|
||||
-H 'Accept: application/json' \
|
||||
-H 'Coder-Session-Token: API_KEY'
|
||||
-H 'Accept: application/json'
|
||||
```
|
||||
|
||||
`GET /provisionerkeys/{provisionerkey}`
|
||||
|
||||
@@ -202,7 +202,7 @@ func (api *API) deleteProvisionerKey(rw http.ResponseWriter, r *http.Request) {
|
||||
|
||||
// @Summary Fetch provisioner key details
|
||||
// @ID fetch-provisioner-key-details
|
||||
// @Security CoderSessionToken
|
||||
// @Security CoderProvisionerKey
|
||||
// @Produce json
|
||||
// @Tags Enterprise
|
||||
// @Param provisionerkey path string true "Provisioner Key"
|
||||
|
||||
Reference in New Issue
Block a user