Skip to content

[6161] Swagger fix#1405

Merged
strongmindsaln merged 7 commits into
masterfrom
bugfix/kitosudb-6161
May 19, 2026
Merged

[6161] Swagger fix#1405
strongmindsaln merged 7 commits into
masterfrom
bugfix/kitosudb-6161

Conversation

@strongmindsaln

@strongmindsaln strongmindsaln commented May 14, 2026

Copy link
Copy Markdown
Collaborator

KITOS Pull request template

Description

This PR fixes swagger requests

Checklist

The following procedure dictates the steps needed before a Pull request can be merged into master.

  • Implement:
    All requirements are implemented and unit tests are green

  • Merge master into branch / rebase with master:
    Make sure you are testing your changes and how they co-exist with the latest version of master

  • Green on integration:
    All integration tests are green on integration

  • Add a description
    Under "Description" above, explain what was changed in this branch, and WHY it was changed

  • Request review:
    Tag whomever you wish to review your code

  • Review completed:
    Reviewer ticks this box when review comments have been submitted

  • Changes:
    PR owner and reviewer agrees on which changes must be made and the changes are committed.

  • Merge master into branch / rebase with master:
    Make sure you are testing your changes and how they co-exist with the latest version of master

  • Green on integration:
    All integration tests are green on integration

Copilot AI review requested due to automatic review settings May 14, 2026 08:34

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates Swagger/OpenAPI authentication metadata so Swagger UI can send KITOS JWT bearer tokens with API requests.

Changes:

  • Changes the Swagger security definition from API key-style auth to HTTP bearer JWT auth.
  • Adds a global bearer security requirement.
  • Adds a new operation filter that applies bearer security requirements to operations.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
Presentation.Web/Swagger/AddBearerSecurityRequirementOperationFilter.cs Adds an operation filter for bearer security metadata.
Presentation.Web/Infrastructure/Configuration/SwaggerServiceCollectionExtensions.cs Updates Swagger security configuration and registers the new filter.
Comments suppressed due to low confidence (1)

Presentation.Web/Infrastructure/Configuration/SwaggerServiceCollectionExtensions.cs:62

  • This document-level security requirement duplicates the operation filter registered below, which adds the same bearer requirement to every operation. Keeping both creates two sources of truth for authentication metadata and makes legitimate anonymous exceptions harder to model; use either a global requirement with explicit anonymous overrides or a single operation filter that only marks secured actions.
                c.AddSecurityRequirement(document => new OpenApiSecurityRequirement
                {
                    { new OpenApiSecuritySchemeReference("Bearer", document), new List<string>() }

Comment thread Presentation.Web/Swagger/AddBearerSecurityRequirementOperationFilter.cs Outdated
@strongmindsaln strongmindsaln changed the title [6161] I-trust issue [6161] Swagger fix May 14, 2026

@strongmindsnan strongmindsnan left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I tried testing it with these steps, but got a Forbidden response when trying to patch to the DBS endpoint.

  • Create an org that is a company and ISMS supplier
  • Add the local-api-user to that organization
  • Select that organization as supplier in Fælles Kommune
  • Find a system that is used by Fælles Kommune
  • Get a token for local-api-user
  • patch /it-systems//dbs with the token

Comment thread Presentation.Web/Swagger/AddBearerSecurityRequirementOperationFilter.cs Outdated
@strongmindsaln
strongmindsaln merged commit 59ce137 into master May 19, 2026
6 checks passed
@strongmindsaln
strongmindsaln deleted the bugfix/kitosudb-6161 branch May 19, 2026 07:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants