Skip to content

fix(auth): preserve security requirement alternatives - #191

Merged
samzong merged 2 commits into
mainfrom
fix/auth-security-alternatives
Oct 3, 2026
Merged

samzong merged 2 commits into
mainfrom
fix/auth-security-alternatives

Conversation

@samzong

@samzong samzong commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

Summary

Closes #122.

  • Swagger 2 and OpenAPI 3 security requirements are preserved as alternatives (OR) of scheme combinations (AND) instead of being flattened. Scheme definitions (type, scheme, in, param, scopes) come from securityDefinitions / components.securitySchemes; Swagger basic maps to http basic.
  • An empty requirement {} makes the operation public, so it runs without a stored host.
  • Catalog: auth.requirements lists every alternative; auth.scopes stays the sorted union. Workflow entries keep required/scopes only.
  • Runtime: before sending, the resolved request (stored credential plus header and query parameters passed to the command) must satisfy at least one requirement; otherwise not_authenticated (exit 4) with error.detail listing accepted alternatives from spec metadata only. Undefined/unknown schemes, mutual TLS, custom authenticators, and dry-run are not checked. An API key stored for the Authorization header satisfies http/oauth2/openIdConnect schemes.
  • Generated Skills describe requirements and the satisfaction rules.
  • examples/richapi: Users_List accepts bearer or API key; new Audit_Export requires bearer and a tenant key.

Verification

  • make check — passed.
  • go test -race ./pkg/runtime/... ./internal/codegen/... — passed.
  • TestSecurityRequirements_BeforeSend covers OR alternatives (bearer, API key), AND combinations, anonymous alternatives without a host, workflow steps, header/query parameters supplying schemes, and an API key in Authorization; error output never contains credential values.
  • examples/richapi: lathe codegen -cache fixtures, build, __lathe verify --json → ok: true; commands --json → catalog_schema_version 26 with auth.requirements.
  • Against a local HTTP server with an isolated config dir: bearer login → users list sent with Authorization, audit export exit 4 with no request; API key login → users list sent with X-API-Key, audit export exit 4.

Not verified: real OAuth device login end to end (unit-level: it stores a bearer credential); a live service with cookie API keys.

Compatibility

  • runtime.SchemaVersion 19 and runtime.CatalogSchemaVersion 26; regenerate downstream CLIs.
  • After regeneration, a stored credential that satisfies no requirement (API key header name mismatch, API key in query/cookie not passed as a parameter, AND of different credential kinds) fails locally with exit 4 instead of sending a request the server would reject.
  • Operations with an anonymous alternative no longer require a stored host.

Checklist

  • Tests or focused verification cover the changed surface.
  • User-facing behavior changes are documented.
  • Generated output under internal/generated/, .cache/, and ad-hoc skills/<cli-name>/ directories is not committed.
  • Commits are signed off when this is ready to merge.

Keep OpenAPI and Swagger security requirements as OR-of-AND entries
instead of flattening them. Generated specs carry each scheme's type,
scheme, location, parameter, and scopes; the catalog exposes them as
auth.requirements; an empty entry makes the operation public. Before
sending, the runtime checks the resolved request (stored credential
plus header and query parameters) and fails with not_authenticated
when no entry is satisfied.

Closes #122

Signed-off-by: samzong <samzong.lu@gmail.com>
@ghfind-review ghfind-review Bot added the review: top ghfind author score; see https://ghfind.com label Oct 3, 2026
@codspeed

codspeed Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

⚠️ Unknown Walltime execution environment detected

Using the Walltime instrument on standard Hosted Runners will lead to inconsistent data.

For the most accurate results, we recommend using CodSpeed Macro Runners: bare-metal machines fine-tuned for performance measurement consistency.

✅ 21 untouched benchmarks


Comparing fix/auth-security-alternatives (ccb9272) with main (adcb3f1)

Open in CodSpeed

@samzong
samzong marked this pull request as ready for review October 3, 2026 19:01
@samzong
samzong merged commit bad7939 into main Oct 3, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review: top ghfind author score; see https://ghfind.com

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(auth): preserve security alternatives and combinations

1 participant