Skip to content

Fixes invalid path patterns resulting in public access being rejected - #157

Merged
DenizAltunkapan merged 1 commit into
Vault-Web:mainfrom
vanxa:156/fix-filepath-filter-patterns
Oct 1, 2026
Merged

DenizAltunkapan merged 1 commit into
Vault-Web:mainfrom
vanxa:156/fix-filepath-filter-patterns

Conversation

@vanxa

@vanxa vanxa commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Fixes invalid path patterns resulting in public access being rejected

Summary

  1. Fixes PublicPaths#PREFIXES to include v3/api-docs/ and swagger-ui/
  2. Fixes SecurityConfig#filterChain to add */** wildcard for lead items (i.e. swagger-ui) and ** wildcard for non-leaf ones (i.e. /api/auth/), removing the need to declare duplicate paths with and without a terminating slash

Linked issue

Closes #156

How to test

Run the app in local dev environment and observe that swagger UI can now be opened.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agent review

Non-blocking: the change looks correct for the reported Swagger problem, but one edge case and one gap remain.

  • Dropped sub-paths: SecurityConfig no longer adds ** to prefixes that don't end in /. This also affects /v3/api-docs, which now matches only that exact path. /v3/api-docs.yaml and /v3/api-docs?group=... variants are not covered, so they would be rejected for unauthenticated users. The bare /swagger-ui path is now non-public as well. JwtAuthFilter still uses startsWith on the same list, so it will skip JWT checks for those paths while the authorization rules still reject them. If the .yaml endpoint is needed, add an explicit /v3/api-docs.yaml entry.
  • No test: There is no test that the public paths are reachable without a token. One MockMvc test covering /v3/api-docs, /swagger-ui/index.html and /s/... would prevent this class of regression.

Generated by Pull Request Review for #157 · copilot · auto · 14.3 AIC · ⌖ 5.9 AIC · ⊞ 7K

Fixes `PublicPaths#PREFIXES` to include `v3/api-docs` and `swagger-ui`
Fixes `SecurityConfig#filterChain` to add `*/**` wildcard for leaf paths
and `**` wildcard for traversable paths (i.e. terminating in '/')

Signed-off-by: Ivan Konstantinov <1674639+vanxa@users.noreply.github.com>
@vanxa
vanxa force-pushed the 156/fix-filepath-filter-patterns branch from 058f394 to 5646307 Compare October 1, 2026 20:46
@vanxa

vanxa commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Agent review

Non-blocking: the change looks correct for the reported Swagger problem, but one edge case and one gap remain.

* **Dropped sub-paths:** `SecurityConfig` no longer adds `**` to prefixes that don't end in `/`. This also affects `/v3/api-docs`, which now matches only that exact path. `/v3/api-docs.yaml` and `/v3/api-docs?group=...` variants are not covered, so they would be rejected for unauthenticated users. The bare `/swagger-ui` path is now non-public as well. `JwtAuthFilter` still uses `startsWith` on the same list, so it will skip JWT checks for those paths while the authorization rules still reject them. If the `.yaml` endpoint is needed, add an explicit `/v3/api-docs.yaml` entry.

* **No test:** There is no test that the public paths are reachable without a token. One `MockMvc` test covering `/v3/api-docs`, `/swagger-ui/index.html` and `/s/...` would prevent this class of regression.

Generated by Pull Request Review for #157 · copilot · auto · 14.3 AIC · ⌖ 5.9 AIC · ⊞ 7K

Added */** for leaf paths (those that don't terminate with '/' i.e. 'swagger-ui) and ** for traversable paths (i.e. terminated in / like v3/api-docs/)

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agent review

Suggestion: approve. I did not find any high-confidence correctness, security, regression, or missing-test issues in this diff.

Generated by Pull Request Review for #157 · copilot · auto · 15 AIC · ⌖ 5.42 AIC · ⊞ 7K

@DenizAltunkapan

Copy link
Copy Markdown
Member

@vanxa thanks!

@DenizAltunkapan
DenizAltunkapan merged commit 28bd305 into Vault-Web:main Oct 1, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Unauthorized exception when accessing Swagger UI in local development environment

2 participants