Fixes invalid path patterns resulting in public access being rejected - #157
Conversation
There was a problem hiding this comment.
Agent review
Non-blocking: the change looks correct for the reported Swagger problem, but one edge case and one gap remain.
- Dropped sub-paths:
SecurityConfigno longer adds**to prefixes that don't end in/. This also affects/v3/api-docs, which now matches only that exact path./v3/api-docs.yamland/v3/api-docs?group=...variants are not covered, so they would be rejected for unauthenticated users. The bare/swagger-uipath is now non-public as well.JwtAuthFilterstill usesstartsWithon the same list, so it will skip JWT checks for those paths while the authorization rules still reject them. If the.yamlendpoint is needed, add an explicit/v3/api-docs.yamlentry. - No test: There is no test that the public paths are reachable without a token. One
MockMvctest covering/v3/api-docs,/swagger-ui/index.htmland/s/...would prevent this class of regression.
Generated by Pull Request Review for #157 · copilot · auto · 14.3 AIC · ⌖ 5.9 AIC · ⊞ 7K
Fixes `PublicPaths#PREFIXES` to include `v3/api-docs` and `swagger-ui` Fixes `SecurityConfig#filterChain` to add `*/**` wildcard for leaf paths and `**` wildcard for traversable paths (i.e. terminating in '/') Signed-off-by: Ivan Konstantinov <1674639+vanxa@users.noreply.github.com>
058f394 to
5646307
Compare
Added |
There was a problem hiding this comment.
Agent review
Suggestion: approve. I did not find any high-confidence correctness, security, regression, or missing-test issues in this diff.
Generated by Pull Request Review for #157 · copilot · auto · 15 AIC · ⌖ 5.42 AIC · ⊞ 7K
|
@vanxa thanks! |
Fixes invalid path patterns resulting in public access being rejected
Summary
PublicPaths#PREFIXESto includev3/api-docs/andswagger-ui/SecurityConfig#filterChainto add*/**wildcard for lead items (i.e.swagger-ui) and**wildcard for non-leaf ones (i.e./api/auth/), removing the need to declare duplicate paths with and without a terminating slashLinked issue
Closes #156
How to test
Run the app in local dev environment and observe that swagger UI can now be opened.