Repository navigation
v0.4.1
Added
@tetsujs/openapi:secured(hook, { anyOf: [a, b] })for a hook that accepts any one of several credentials — a session cookie or a bearer token. The document lists every combination a client may bring, each alternative together with the schemes of the route's other hooks.mutualTLSamong the security scheme types, as OpenAPI 3.1 has it.
Fixed
@tetsujs/openapi: a route guarded by severalsecured()hooks was documented as needing any one of their schemes — onesecurityentry per hook, which OpenAPI reads as alternatives. Every hook runs, so every scheme is required: they are one entry now. Two hooks of one scheme with different scopes kept only the first one's scopes; they require both.
Full Changelog: v0.4.0...v0.4.1