diff --git a/dotCMS/src/main/java/com/dotcms/auth/providers/saml/v1/DotSamlResource.java b/dotCMS/src/main/java/com/dotcms/auth/providers/saml/v1/DotSamlResource.java index 7caa1a17f90b..d8f28d8f660c 100755 --- a/dotCMS/src/main/java/com/dotcms/auth/providers/saml/v1/DotSamlResource.java +++ b/dotCMS/src/main/java/com/dotcms/auth/providers/saml/v1/DotSamlResource.java @@ -30,6 +30,7 @@ import io.swagger.v3.oas.annotations.parameters.RequestBody; import io.swagger.v3.oas.annotations.responses.ApiResponse; import io.swagger.v3.oas.annotations.responses.ApiResponses; +import io.swagger.v3.oas.annotations.security.SecurityRequirement; import io.swagger.v3.oas.annotations.tags.Tag; import org.glassfish.jersey.server.JSONP; @@ -112,7 +113,8 @@ protected DotSamlResource(final SamlConfigurationService samlConfigura */ @Operation( summary = "Initiate SAML login", - description = "Initiates a SAML authentication request by redirecting the user to the Identity Provider (IDP) login screen. Requires IDP metadata to determine the SSO login endpoint." + description = "Initiates a SAML authentication request by redirecting the user to the Identity Provider (IDP) login screen. Requires IDP metadata to determine the SSO login endpoint.", + security = {} ) @ApiResponses(value = { @ApiResponse(responseCode = "200", @@ -180,8 +182,9 @@ public Response doLogin(@Parameter(description = "Identity Provider configuratio @Operation( summary = "Process SAML login callback", description = "Handles the callback from the Identity Provider after successful authentication. Extracts user information from the SAML assertion and creates/logs in the user to dotCMS.", + security = {}, requestBody = @RequestBody(description = "SAML assertion data from Identity Provider", required = true, - content = {@Content(mediaType = "application/xml"), + content = {@Content(mediaType = "application/xml"), @Content(mediaType = "application/x-www-form-urlencoded")}) ) @ApiResponses(value = { @@ -377,7 +380,8 @@ private boolean isBackEndLogin(final String loginPath) { */ @Operation( summary = "Get SAML metadata", - description = "Renders the XML metadata for the SAML Service Provider configuration. This endpoint is only accessible by administrators and provides the metadata required for IDP configuration." + description = "Renders the XML metadata for the SAML Service Provider configuration. This endpoint is only accessible by administrators and provides the metadata required for IDP configuration.", + security = {} ) @ApiResponses(value = { @ApiResponse(responseCode = "200", @@ -439,7 +443,8 @@ public void metadata( @Parameter(description = "Identity Provider configuration @Operation( summary = "Process SAML logout (POST)", - description = "Processes a SAML logout request via POST method. Handles logout callbacks from the Identity Provider and redirects to the configured logout endpoint." + description = "Processes a SAML logout request via POST method. Handles logout callbacks from the Identity Provider and redirects to the configured logout endpoint.", + security = {} ) @ApiResponses(value = { @ApiResponse(responseCode = "200", @@ -494,7 +499,8 @@ public void logoutPost(@Parameter(description = "Identity Provider configuration @Operation( summary = "Process SAML logout (GET)", - description = "Processes a SAML logout request via GET method. Initiates logout flow and redirects to the configured logout endpoint or builds a logout URL based on the request." + description = "Processes a SAML logout request via GET method. Initiates logout flow and redirects to the configured logout endpoint or builds a logout URL based on the request.", + security = {} ) @ApiResponses(value = { @ApiResponse(responseCode = "200", diff --git a/dotCMS/src/main/java/com/dotcms/rest/api/v1/authentication/AuthenticationResource.java b/dotCMS/src/main/java/com/dotcms/rest/api/v1/authentication/AuthenticationResource.java index 02795a453189..4e37f8142f17 100644 --- a/dotCMS/src/main/java/com/dotcms/rest/api/v1/authentication/AuthenticationResource.java +++ b/dotCMS/src/main/java/com/dotcms/rest/api/v1/authentication/AuthenticationResource.java @@ -39,6 +39,7 @@ import io.swagger.v3.oas.annotations.responses.ApiResponse; import io.swagger.v3.oas.annotations.responses.ApiResponses; import io.swagger.v3.oas.annotations.ExternalDocumentation; +import io.swagger.v3.oas.annotations.security.SecurityRequirement; import java.io.Serializable; import java.util.Date; import java.util.List; @@ -118,6 +119,7 @@ protected AuthenticationResource(final LoginServiceAPI loginService, "If the user is found and authenticated, a session is created.\n\n" + "Otherwise the system will return an 'authentication failed' message.\n\n", tags = {"Authentication"}, + security = {}, responses = { @ApiResponse(responseCode = "200", description = "User authentication successful", content = @Content(mediaType = "application/json", @@ -224,6 +226,7 @@ public final Response authentication( description = "Provides information about any users that are currently in a session.\n\n" + "This retrieved data will be formatted into a JSON response body.\n\n", tags = {"Authentication"}, + security = {}, responses = { @ApiResponse(responseCode = "200", description = "User data successfully collected", content = @Content( diff --git a/dotCMS/src/main/java/com/dotcms/rest/api/v1/authentication/ForgotPasswordResource.java b/dotCMS/src/main/java/com/dotcms/rest/api/v1/authentication/ForgotPasswordResource.java index 40f52278603e..e5fe94a6f7f5 100644 --- a/dotCMS/src/main/java/com/dotcms/rest/api/v1/authentication/ForgotPasswordResource.java +++ b/dotCMS/src/main/java/com/dotcms/rest/api/v1/authentication/ForgotPasswordResource.java @@ -39,6 +39,7 @@ import io.swagger.v3.oas.annotations.parameters.RequestBody; import io.swagger.v3.oas.annotations.responses.ApiResponse; import io.swagger.v3.oas.annotations.responses.ApiResponses; +import io.swagger.v3.oas.annotations.security.SecurityRequirement; import io.swagger.v3.oas.annotations.tags.Tag; import javax.ws.rs.Consumes; @@ -81,7 +82,8 @@ public ForgotPasswordResource(final UserLocalManager userLocalManager, @Operation( summary = "Send password reset email", - description = "Sends a password reset email to the specified user. Returns the email address where the reset link was sent." + description = "Sends a password reset email to the specified user. Returns the email address where the reset link was sent.", + security = {} ) @ApiResponses(value = { @ApiResponse(responseCode = "200", diff --git a/dotCMS/src/main/java/com/dotcms/rest/api/v1/health/HealthResource.java b/dotCMS/src/main/java/com/dotcms/rest/api/v1/health/HealthResource.java index 06a969f28358..abc2844f373f 100644 --- a/dotCMS/src/main/java/com/dotcms/rest/api/v1/health/HealthResource.java +++ b/dotCMS/src/main/java/com/dotcms/rest/api/v1/health/HealthResource.java @@ -19,6 +19,7 @@ import io.swagger.v3.oas.annotations.media.Content; import io.swagger.v3.oas.annotations.media.Schema; import io.swagger.v3.oas.annotations.responses.ApiResponse; +import io.swagger.v3.oas.annotations.security.SecurityRequirement; import io.swagger.v3.oas.annotations.tags.Tag; import javax.enterprise.context.RequestScoped; @@ -102,6 +103,7 @@ private boolean isAccessAllowed(HttpServletRequest request, HttpServletResponse description = "Returns comprehensive health status including all registered health checks. " + "Authentication requirements are controlled by the health.detailed.authentication.required configuration property.", tags = {"Health"}, + security = {}, responses = { @ApiResponse( responseCode = "200", @@ -155,6 +157,7 @@ public Response getOverallHealth( "This endpoint provides detailed JSON information about critical system components " + "required for the application to be considered alive.", tags = {"Health"}, + security = {}, responses = { @ApiResponse( responseCode = "200", @@ -206,6 +209,7 @@ public Response getLivenessHealth( "This endpoint provides detailed JSON information about system components " + "required for the application to be considered ready to serve requests.", tags = {"Health"}, + security = {}, responses = { @ApiResponse( responseCode = "200", @@ -255,6 +259,7 @@ public Response getReadinessHealth( description = "Returns the result of a specific health check identified by name. " + "Useful for monitoring individual components or debugging specific health issues.", tags = {"Health"}, + security = {}, responses = { @ApiResponse( responseCode = "200", @@ -317,6 +322,7 @@ public Response getHealthCheck( description = "Returns a list of all registered health check names. " + "Useful for discovering available health checks and building monitoring interfaces.", tags = {"Health"}, + security = {}, responses = { @ApiResponse( responseCode = "200", @@ -369,6 +375,7 @@ public Response getHealthCheckNames( description = "Returns a simple boolean summary of system health status with alive and ready flags. " + "Provides a quick overview of system health without detailed check information.", tags = {"Health"}, + security = {}, responses = { @ApiResponse( responseCode = "200", @@ -425,6 +432,7 @@ public Response getSystemStatus( "bypassing any caching mechanisms. Useful for getting up-to-date health status " + "after configuration changes or system maintenance.", tags = {"Health"}, + security = {}, responses = { @ApiResponse( responseCode = "200", @@ -480,6 +488,7 @@ public Response refreshHealthChecks( "bypassing any caching mechanisms. Useful for testing individual components " + "or getting up-to-date status after targeted maintenance.", tags = {"Health"}, + security = {}, responses = { @ApiResponse( responseCode = "200", diff --git a/dotCMS/src/main/java/com/dotcms/rest/config/DotRestApplication.java b/dotCMS/src/main/java/com/dotcms/rest/config/DotRestApplication.java index 4553cf063d8a..11117eb3ade7 100644 --- a/dotCMS/src/main/java/com/dotcms/rest/config/DotRestApplication.java +++ b/dotCMS/src/main/java/com/dotcms/rest/config/DotRestApplication.java @@ -8,7 +8,12 @@ import com.fasterxml.jackson.jaxrs.json.JacksonJaxbJsonProvider; import io.swagger.v3.oas.annotations.ExternalDocumentation; import io.swagger.v3.oas.annotations.OpenAPIDefinition; +import io.swagger.v3.oas.annotations.enums.SecuritySchemeIn; +import io.swagger.v3.oas.annotations.enums.SecuritySchemeType; import io.swagger.v3.oas.annotations.info.Info; +import io.swagger.v3.oas.annotations.security.SecurityRequirement; +import io.swagger.v3.oas.annotations.security.SecurityScheme; +import io.swagger.v3.oas.annotations.security.SecuritySchemes; import io.swagger.v3.oas.annotations.servers.Server; import io.swagger.v3.oas.annotations.tags.Tag; import io.vavr.Lazy; @@ -33,6 +38,28 @@ */ @ApplicationPath("/api") +@SecuritySchemes({ + @SecurityScheme( + name = "ApiToken", + type = SecuritySchemeType.HTTP, + scheme = "bearer", + bearerFormat = "JWT", + description = "JWT API token. Obtain via POST /api/v1/apitoken or POST /api/v1/authentication" + ), + @SecurityScheme( + name = "BasicAuth", + type = SecuritySchemeType.HTTP, + scheme = "basic", + description = "HTTP Basic authentication with dotCMS username and password" + ), + @SecurityScheme( + name = "DotAuth", + type = SecuritySchemeType.APIKEY, + in = SecuritySchemeIn.HEADER, + paramName = "DOTAUTH", + description = "Base64-encoded username:password in the DOTAUTH header" + ) +}) @OpenAPIDefinition( info = @Info( title = "dotCMS REST API", @@ -40,6 +67,10 @@ servers = @Server( description = "dotCMS Server", url = "/"), + security = { + @SecurityRequirement(name = "ApiToken"), + @SecurityRequirement(name = "BasicAuth") + }, tags = { @Tag(name = "Accessibility Agent", description = "Streaming a11y-fix agent proxy"), @Tag(name = "Accessibility Checker", description = "Web accessibility checking and compliance"),