Repository navigation
Conversation
…-org#3013) When a route handler opts out of authentication via opt={"exclude_from_auth": True}, the generated OpenAPI operation now sets security=[] to override root-level security declarations. This correctly marks the endpoint as unsecured in Swagger/Scalar/Redoc. Previously, AbstractSecurityConfig set security at the root OpenAPI level, which applied to all paths including excluded ones. Per the OpenAPI 3.1 spec, an empty security array on an operation overrides the root-level declaration.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #4755 +/- ##
==========================================
+ Coverage 67.40% 67.41% +0.01%
==========================================
Files 292 292
Lines 15013 15018 +5
Branches 1686 1688 +2
==========================================
+ Hits 10119 10124 +5
Misses 4758 4758
Partials 136 136 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
| ) | ||
|
|
||
| security: list[SecurityRequirement] | None | ||
| if route_handler.opt.get("exclude_from_auth"): |
There was a problem hiding this comment.
The opt key is not static. It can be configured dynamically. This needs to be taken into account here
The exclude_opt_key for security middleware is configurable, not a static string. Updated OpenAPI path generation to extract all exclude_opt_keys from the middleware stack and check route handlers against any of them. Changes: - Pass middleware list to OpenAPIContext - Extract exclude_opt_keys from security configs in middleware - Check handler opt against all discovered keys, not just "exclude_from_auth" Added test for custom exclude_opt_key to verify dynamic configuration works. Addresses review feedback on PR litestar-org#4755.
| """ | ||
| exclude_keys: set[str] = set() | ||
|
|
||
| for mw in middleware: |
There was a problem hiding this comment.
this will break for subclassed middlewares / ones that use custom factories instead of DefineMiddleware
|
Closing as per our AI policy |
|
Sorry for the noise. If you'd like to automatically block and ban AI PRs before they reach your review queue, here's a GitHub Action that catches all the common patterns: https://github.com/kimjune01/sweep/blob/master/action.yml |
|
@kimjune01 are you suggesting to use AI to detect AI PRs? :) |
|
@sobolevn AI is optional. Most of the work is happening as a shell script. give it a skim! |
Fixes #3013.
Routes excluded from auth via
exclude_from_authstill had root-levelsecurity applied in the OpenAPI spec. Per OpenAPI 3.1, setting
security: []on an operation overrides the root-level requirement.
Check
route_handler.opt.get("exclude_from_auth")in path item generationand set
security=[]on the operation when true.📚 Documentation preview 📚: https://litestar-org.github.io/litestar-docs-preview/4755