Skip to content

fix(openapi): set security=[] for routes excluded from auth - #4755

Closed
kimjune01 wants to merge 2 commits into
litestar-org:mainfrom
kimjune01:fix/3013-security-exclude-openapi
Closed

kimjune01 wants to merge 2 commits into
litestar-org:mainfrom
kimjune01:fix/3013-security-exclude-openapi

Conversation

@kimjune01

@kimjune01 kimjune01 commented May 9, 2026 •

Copy link
Copy Markdown

Fixes #3013.

Routes excluded from auth via exclude_from_auth still had root-level
security applied in the OpenAPI spec. Per OpenAPI 3.1, setting security: []
on an operation overrides the root-level requirement.

Check route_handler.opt.get("exclude_from_auth") in path item generation
and set security=[] on the operation when true.


📚 Documentation preview 📚: https://litestar-org.github.io/litestar-docs-preview/4755

…-org#3013)

When a route handler opts out of authentication via
opt={"exclude_from_auth": True}, the generated OpenAPI operation now
sets security=[] to override root-level security declarations. This
correctly marks the endpoint as unsecured in Swagger/Scalar/Redoc.

Previously, AbstractSecurityConfig set security at the root OpenAPI
level, which applied to all paths including excluded ones. Per the
OpenAPI 3.1 spec, an empty security array on an operation overrides
the root-level declaration.
@kimjune01
kimjune01 requested review from a team as code owners May 9, 2026 10:20
@github-actions github-actions Bot added area/openapi This PR involves changes to the OpenAPI schema area/private-api This PR involves changes to the privatized API size: small type/bug pr/external Triage Required 🏥 This requires triage labels May 9, 2026
@codecov

codecov Bot commented May 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 67.41%. Comparing base (c12124b) to head (c05527a).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #4755      +/-   ##
==========================================
+ Coverage   67.40%   67.41%   +0.01%     
==========================================
  Files         292      292              
  Lines       15013    15018       +5     
  Branches     1686     1688       +2     
==========================================
+ Hits        10119    10124       +5     
  Misses       4758     4758              
  Partials      136      136              

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Comment thread litestar/_openapi/path_item.py Outdated
)

security: list[SecurityRequirement] | None
if route_handler.opt.get("exclude_from_auth"):

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The opt key is not static. It can be configured dynamically. This needs to be taken into account here

The exclude_opt_key for security middleware is configurable, not a static
string. Updated OpenAPI path generation to extract all exclude_opt_keys from
the middleware stack and check route handlers against any of them.

Changes:
- Pass middleware list to OpenAPIContext
- Extract exclude_opt_keys from security configs in middleware
- Check handler opt against all discovered keys, not just "exclude_from_auth"

Added test for custom exclude_opt_key to verify dynamic configuration works.

Addresses review feedback on PR litestar-org#4755.
"""
exclude_keys: set[str] = set()

for mw in middleware:

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this will break for subclassed middlewares / ones that use custom factories instead of DefineMiddleware

@provinzkraut

Copy link
Copy Markdown
Member

Closing as per our AI policy

@kimjune01

kimjune01 commented May 12, 2026 •

Copy link
Copy Markdown
Author

Sorry for the noise. If you'd like to automatically block and ban AI PRs before they reach your review queue, here's a GitHub Action that catches all the common patterns: https://github.com/kimjune01/sweep/blob/master/action.yml

@sobolevn

Copy link
Copy Markdown
Member

@kimjune01 are you suggesting to use AI to detect AI PRs? :)

@kimjune01

Copy link
Copy Markdown
Author

@sobolevn AI is optional. Most of the work is happening as a shell script. give it a skim!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/openapi This PR involves changes to the OpenAPI schema area/private-api This PR involves changes to the privatized API pr/external size: small Triage Required 🏥 This requires triage type/bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: AbstractSecurityConfig sets security for all paths, even those excluded

3 participants