Rswag:授权标头出现在查询参数中

时间:2019-09-29 03:47:56

标签: header rswag

版本:rswag(2.0.5),rspec(3.8.0)

环境:Rails 5.2.3,Ruby 2.4.5

这是我第一次使用它,在授权标头中停留了一天。 这是我所做的:

# in spec/swagger_helper.rb
  config.swagger_docs = {
    'api/v1/swagger.json' => {
      swagger: '2.0',
      info: {
        title: 'API V1',
        version: 'v1'
      },
      paths: {},
      securityDefinitions: {
        JWT: {
          description: 'the jwt for API auth',
          type: :apiKey,
          name: 'Authorization',
          in: :header
        }
      }
    }
  }
# in spec/integration/api/v1/nodes_spec.rb
  path '/api/v1/nodes' do
    get 'Get all servers' do
      tags TAGS_NODE
      produces  'application/json'
      security [JWT: {}]

      parameter name: :searchString, in: :query, type: :string
      parameter name: :searchColumn, in: :query, type: :string
      #parameter name: 'Authorization', :in => :header, :type => :string
      let(:nodes) { create_list(:node_list, 32) }

      response '200', 'Servers found' do
        let(:'Authorization') { "Bearer #{gen_jwt}" }
        let(:searchString) { 'test' }
        let(:searchColumn) { ';Name;' }
        run_test! do |repsonse|
          data = JSON.parse(response.body)
          puts data
        end
      end
    end
  end

预期:“ Bearer ....”设置在“ Authorization”标题中 实际:在测试日志中,我发现:

[INFO] [2019-09-29 01:11:13 UTC] [匿名] [无会话] [无要求] [其他] Started GET“ / api / v1 / nodes?searchString = test&searchColumn =; Name ;&PARAMS&头[HTTP_AUTHORIZATION] =承载+ eyJhbGciOiJIUzI1NiJ9.eyJleHAiOjE1Njk3NjI2NzMsImVtYWlsIjoidGVzdEBpYm0uY29tIiwib3JnYW5pemF0aW9ucyI6WyJ0ZXN0X29yZzEiLCJvcmcyIl0sInJvbGVzIjpbImNjX2NvbnNvbGVfYWRtaW4iLCJyb2xlMiJdLCJpbnZlbnRvc​​nkiOlsidGVzdF9pbnYiXX0.eenTMWUy6kSHO58_kLKoKWmNjvQ9i5TU9ex4Ou-A使用与报头[HTTP_ACCEPT] =应用%2Fjson”为127.0.0.1在2019年9月29日1点11分十三秒0000 [INFO] [2019-09-29 01:11:13 UTC] [匿名] [无会话] [无要求] [其他]由Api :: V1 :: NodesController#index作为HTML处理 ...... [DEBUG] [2019-09-29 01:11:13 UTC] [匿名] [无会话] [无要求] [其他]通过JWT令牌进行验证。... [错误] [2019-09-29 01:11:13 UTC] [匿名] [无会话] [无要求] [其他] 请求中未包含JWT令牌

在日志中标记为粗体的'Authorization'和'Accept'标头出现在查询参数中,这些参数应该是http标头,因此无法从代码标头中检索到JWT令牌。 / p>

我也尝试不使用securityDefinition,而是在标头中指定一个参数,如下所示:参数名称:'Authorization',:in =>:header,:type =>:string。它也不起作用。

不确定我错过了任何配置还是我做错了什么?谢谢!

更新:它似乎与其他宝石冲突有关?我还尝试创建一个新的仅适用于Rails 5 api的应用程序,仅添加rspec和rswag gems,并使用一个简单的测试用例运行,它起作用了! 这是我的Gemfile:

source 'https://rubygems.org'
git_source(:github) { |repo| "https://github.com/#{repo}.git" }

ruby '2.4.5'

gem 'rails', '5.2.3'
gem 'puma', '3.11'
gem 'bootsnap', '1.1.0', require: false

group :development, :test do
  # Call 'byebug' anywhere in the code to stop execution and get a debugger console
  gem 'byebug', platforms: [:mri, :mingw, :x64_mingw]
end

group :development do
  gem 'listen', '>= 3.0.5', '< 3.2'
end

group :test do
  # Test framework
  gem "rspec-rails"
  gem "database_cleaner", '1.6.0'
  gem "simplecov"
  gem "simplecov-rcov"
  gem "factory_bot_rails", '5.1.0'
  gem "ci_reporter_rspec"
  gem "faker"
end

# Windows does not include zoneinfo files, so bundle the tzinfo-data gem
gem 'tzinfo-data', platforms: [:mingw, :mswin, :x64_mingw, :jruby]

gem 'pg', '1.1.4'
gem 'delayed_job_active_record', '4.1.3'
gem 'delayed_job_worker_pool', '0.2.3'

gem 'dalli', '2.7.8'
gem 'ruby-kafka', '0.7.5'

gem 'active_model_serializers', '0.10.10'
gem 'will_paginate', '3.1.7'
gem 'rest-client', '1.8.0'
gem 'symmetric-encryption', '4.3.0', require: false
gem 'unicorn', '5.2.0'
gem 'rubyzip', '1.2.2'
gem 'jwt', '2.2.1'
gem 'rubyXL', '3.3.30'
gem 'apartment', '2.2.1'
gem 'rswag', '2.0.5'

[已解决] 似乎无法使用Rack :: Test :: Methods

在删除帮助程序文件中的“ include Rack :: Test :: Methods”行后,该行起作用了,该文件先前已添加以使用“ get”来测试API。

1 个答案:

答案 0 :(得分:0)

似乎无法使用Rack :: Test :: Methods

在删除帮助程序文件中的“ include Rack :: Test :: Methods”行后,该行起作用了,该文件先前已添加以使用“ get”来测试API。