我允许客户通过Swashbuckle访问我的SaaS API。他们需要通过“可用授权”弹出窗口使用OAuth进行身份验证。当他们通过弹出窗口单击“授权”按钮时,需要通过gmail进行身份验证。但是,这显示了我需要向最终用户隐藏的Auth0 client_id和client_secret SwashBuckle使用情况。
有人知道这种隐藏方式吗?
我已经为该问题附加了屏幕截图。
我在AddSwaggerGen中的代码包含以下内容
c.AddSecurityDefinition("oauth2", new OpenApiSecurityScheme
{
Description = "oauth2",
Name = "Authorization",
In = ParameterLocation.Header,
Type = SecuritySchemeType.OAuth2,
Flows = new OpenApiOAuthFlows()
{
AuthorizationCode = new OpenApiOAuthFlow()
{
AuthorizationUrl = new Uri(settings.AuthorityAuthorizeUri),
TokenUrl = new Uri(settings.AuthorityTokenUri),
}
},
Scheme = "oauth2"
});
c.AddSecurityDefinition("Bearer", new OpenApiSecurityScheme
{
Description = "Standard Authorization header using the Bearer scheme. Example: \"Bearer {token}\"",
Name = "Authorization",
In = ParameterLocation.Header,
Type = SecuritySchemeType.ApiKey,
Scheme = "Bearer"
});
c.AddSecurityDefinition("ApiKey", new OpenApiSecurityScheme
{
Description = "Standard Authorization header using the ApiKey scheme. Example: \"ApiKey {ClientId:ClientSecret}\". Please note the prefix \"ApiKey\" is required!",
Name = "Authorization",
In = ParameterLocation.Header,
Type = SecuritySchemeType.ApiKey,
Scheme = "ApiKey"
});
c.AddSecurityRequirement(new OpenApiSecurityRequirement()
{
{
new OpenApiSecurityScheme
{
Reference = new OpenApiReference
{
Type = ReferenceType.SecurityScheme,
Id = "oauth2"
},
Scheme = "oauth2",
Name = "oauth2",
In = ParameterLocation.Header,
},
new List<string>()
},
{
new OpenApiSecurityScheme
{
Reference = new OpenApiReference
{
Type = ReferenceType.SecurityScheme,
Id = "Bearer"
},
Scheme = "ApiKey",
Name = "Bearer",
In = ParameterLocation.Header,
},
new List<string>()
},
{
new OpenApiSecurityScheme
{
Reference = new OpenApiReference
{
Type = ReferenceType.SecurityScheme,
Id = "ApiKey"
},
Scheme = "ApiKey",
Name = "ApiKey",
In = ParameterLocation.Header,
},
new List<string>()
}
});
我的UseSwaggerUI中的代码包含
c.OAuthClientId(config["ClientId"]);
c.OAuthClientSecret(config["ClientSecret"]);
c.OAuthAppName("blah");
c.OAuthScopeSeparator(string.Empty);
var param = new Dictionary<string, string>();
param.Add("audience", "blah");
param.Add("scope", "openid profile email");
c.OAuthAdditionalQueryStringParams(param);