[6161] Swagger fix#1405
Merged
Merged
Conversation
This reverts commit f638db9.
There was a problem hiding this comment.
Pull request overview
This PR updates Swagger/OpenAPI authentication metadata so Swagger UI can send KITOS JWT bearer tokens with API requests.
Changes:
- Changes the Swagger security definition from API key-style auth to HTTP bearer JWT auth.
- Adds a global bearer security requirement.
- Adds a new operation filter that applies bearer security requirements to operations.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
Presentation.Web/Swagger/AddBearerSecurityRequirementOperationFilter.cs |
Adds an operation filter for bearer security metadata. |
Presentation.Web/Infrastructure/Configuration/SwaggerServiceCollectionExtensions.cs |
Updates Swagger security configuration and registers the new filter. |
Comments suppressed due to low confidence (1)
Presentation.Web/Infrastructure/Configuration/SwaggerServiceCollectionExtensions.cs:62
- This document-level security requirement duplicates the operation filter registered below, which adds the same bearer requirement to every operation. Keeping both creates two sources of truth for authentication metadata and makes legitimate anonymous exceptions harder to model; use either a global requirement with explicit anonymous overrides or a single operation filter that only marks secured actions.
c.AddSecurityRequirement(document => new OpenApiSecurityRequirement
{
{ new OpenApiSecuritySchemeReference("Bearer", document), new List<string>() }
strongmindsnan
left a comment
There was a problem hiding this comment.
I tried testing it with these steps, but got a Forbidden response when trying to patch to the DBS endpoint.
- Create an org that is a company and ISMS supplier
- Add the local-api-user to that organization
- Select that organization as supplier in Fælles Kommune
- Find a system that is used by Fælles Kommune
- Get a token for local-api-user
- patch /it-systems//dbs with the token
strongmindsnan
approved these changes
May 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
KITOS Pull request template
Description
This PR fixes swagger requests
Checklist
The following procedure dictates the steps needed before a Pull request can be merged into master.
Implement:
All requirements are implemented and unit tests are green
Merge master into branch / rebase with master:
Make sure you are testing your changes and how they co-exist with the latest version of master
Green on integration:
All integration tests are green on integration
Add a description
Under "Description" above, explain what was changed in this branch, and WHY it was changed
Request review:
Tag whomever you wish to review your code
Review completed:
Reviewer ticks this box when review comments have been submitted
Changes:
PR owner and reviewer agrees on which changes must be made and the changes are committed.
Merge master into branch / rebase with master:
Make sure you are testing your changes and how they co-exist with the latest version of master
Green on integration:
All integration tests are green on integration