Repository navigation
Conversation
…OpenAPI spec Fixes #34996 The OpenAPI spec at /api/openapi.json declared security: [] globally with no securitySchemes defined, making all 689 endpoints appear unauthenticated to scanners and API consumers even though the server enforces auth on the vast majority of them. Changes: - DotRestApplication: add @SecuritySchemes (ApiToken/Bearer JWT, BasicAuth, DotAuth header) and set global security default in @OpenAPIDefinition - HealthResource: mark all 8 health/liveness/readiness endpoints as public (security = {}) — required for k8s probes and monitoring - AuthenticationResource: mark login and logInUser as public - ForgotPasswordResource: mark forgot password as public - DotSamlResource: mark all 5 SAML SSO flow endpoints as public (login, callback, metadata, logout POST/GET) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
Claude finished @fabrizzio-dotCMS's task in 1m 27s —— View job Code Review
New Issues
Notes (non-blocking)
The annotation approach itself is correct: --- · |
Security assessment
Why this priority: PR that corrects OpenAPI securitySchemes; documentation accuracy only, no runtime auth change. Labels: already correct, no change. Automated triage by the dotCMS Security team (Claude), 2026-10-06. To override, change the project's Priority field or the CVSS label. The next refresh keeps a manual change. |
fabrizzio-dotCMS
left a comment
There was a problem hiding this comment.
The goal is right, but the PR doesn't produce the spec it describes yet.
1. @Operation(security = {}) is a no-op in swagger-core 2.2.34. SecurityParser.getSecurityRequirements returns Optional.empty() for a zero-length array, so nothing is set on the operation and it inherits the new global ApiToken/BasicAuth requirement. Login, forgot-password and SAML would be documented as authenticated. Method-level @SecurityRequirement goes through the same parser, so there's no annotation-only way to override the global value with an empty list. Suggest a ReaderListener#afterScan that does operation.setSecurity(new ArrayList<>()) on operations flagged public (e.g. an x-public extension).
2. Nine of the 16 "public" endpoints are not public.
- All 8
HealthResourceendpoints callisAccessAllowed, which requires the CMS Admin role unlesshealth.detailed.authentication.required=false(defaulttrue). K8s probes use/dotmgt/livezand/dotmgt/readyz(web.xml), not/api/v1/health. DotSamlResource#metadatarequires an admin backend user (its own description says so).
The 7 that are really public: authentication, logInUser, forgot password, SAML login (GET + callback POST), SAML logout (GET + POST).
3. DotAuth is declared but not in the global requirement, so the spec says no endpoint accepts DOTAUTH while WebResource accepts it everywhere. Add it or drop the scheme.
4. openapi.yaml not regenerated. CI compares it against the build output. Please regenerate (./mvnw compile -pl :dotcms-core --am -DskipTests), commit it, and check that only those 7 operations end up with security: [].
Nit: unused SecurityRequirement import in HealthResource, AuthenticationResource, ForgotPasswordResource and DotSamlResource.
Summary
Fixes #34996
The OpenAPI spec at
/api/openapi.jsondeclaredsecurity: []globally with nosecuritySchemesdefined, documenting all 689 endpoints as unauthenticated even though the server enforces auth on the vast majority of them.@SecuritySchemestoDotRestApplication— three schemes matching the actual auth waterfall inWebResource.java: ApiToken (JWT Bearer), BasicAuth (HTTP Basic), DotAuth (DOTAUTH header)securitydefault in@OpenAPIDefinition— all endpoints now require auth in the spec unless explicitly overriddensecurity = {}override: health/liveness/readiness checks (required for k8s probes), login, forgot password, and all SAML SSO flow endpointsFiles Changed
DotRestApplication.java@SecuritySchemes+ globalsecurityto@OpenAPIDefinitionHealthResource.javasecurity = {}on all 8 health endpointsAuthenticationResource.javasecurity = {}on login + logInUserForgotPasswordResource.javasecurity = {}on forgot passwordDotSamlResource.javasecurity = {}on all 5 SAML SSO endpointsTest Plan
curl https://<instance>/api/openapi.json | jq '.components.securitySchemes'— should return ApiToken, BasicAuth, DotAuth schemescurl https://<instance>/api/openapi.json | jq '.security'— should return[{"ApiToken":[]},{"BasicAuth":[]}]"security": []in the generated spec"security": []/api/openapi.jsonis served without errors🤖 Generated with Claude Code