有谁知道如何在Swagger SwashBuckle的“可用授权”对话框中隐藏client_id和client_secret?

时间:2019-11-20 00:03:20

标签: asp.net-core swagger swashbuckle

我允许客户通过Swashbuckle访问我的SaaS API。他们需要通过“可用授权”弹出窗口使用OAuth进行身份验证。当他们通过弹出窗口单击“授权”按钮时,需要通过gmail进行身份验证。但是,这显示了我需要向最终用户隐藏的Auth0 client_id和client_secret SwashBuckle使用情况。

有人知道这种隐藏方式吗?

我已经为该问题附加了屏幕截图。

我在AddSwaggerGen中的代码包含以下内容

c.AddSecurityDefinition("oauth2", new OpenApiSecurityScheme
{
    Description = "oauth2",
    Name = "Authorization",
    In = ParameterLocation.Header,
    Type = SecuritySchemeType.OAuth2,
    Flows = new OpenApiOAuthFlows()
    {
        AuthorizationCode = new OpenApiOAuthFlow()
        {
            AuthorizationUrl = new Uri(settings.AuthorityAuthorizeUri),
            TokenUrl = new Uri(settings.AuthorityTokenUri),
        }
    },
    Scheme = "oauth2"
});

c.AddSecurityDefinition("Bearer", new OpenApiSecurityScheme
{
    Description = "Standard Authorization header using the Bearer scheme. Example: \"Bearer {token}\"",
    Name = "Authorization",
    In = ParameterLocation.Header,
    Type = SecuritySchemeType.ApiKey,
    Scheme = "Bearer"
});

c.AddSecurityDefinition("ApiKey", new OpenApiSecurityScheme
{
    Description = "Standard Authorization header using the ApiKey scheme. Example: \"ApiKey {ClientId:ClientSecret}\". Please note the prefix \"ApiKey\" is required!",
    Name = "Authorization",
    In = ParameterLocation.Header,
    Type = SecuritySchemeType.ApiKey,
    Scheme = "ApiKey"
});


c.AddSecurityRequirement(new OpenApiSecurityRequirement()
{
    {
        new OpenApiSecurityScheme
        {
            Reference = new OpenApiReference
            {
                Type = ReferenceType.SecurityScheme,
                Id = "oauth2"
            },
            Scheme = "oauth2",
            Name = "oauth2",
            In = ParameterLocation.Header,

        },
        new List<string>()
    },
    {
        new OpenApiSecurityScheme
        {
            Reference = new OpenApiReference
            {
                Type = ReferenceType.SecurityScheme,
                Id = "Bearer"
            },
            Scheme = "ApiKey",
            Name = "Bearer",
            In = ParameterLocation.Header,

        },
        new List<string>()
    },
    {
        new OpenApiSecurityScheme
        {
            Reference = new OpenApiReference
            {
                Type = ReferenceType.SecurityScheme,
                Id = "ApiKey"
            },
            Scheme = "ApiKey",
            Name = "ApiKey",
            In = ParameterLocation.Header,

        },
        new List<string>()
    }
});

我的UseSwaggerUI中的代码包含

c.OAuthClientId(config["ClientId"]);
c.OAuthClientSecret(config["ClientSecret"]);
c.OAuthAppName("blah");
c.OAuthScopeSeparator(string.Empty);
var param = new Dictionary<string, string>();
param.Add("audience", "blah");
param.Add("scope", "openid profile email");
c.OAuthAdditionalQueryStringParams(param);

enter image description here

0 个答案:

没有答案