diff --git a/src/Squidex.Core/Schemas/Schema.cs b/src/Squidex.Core/Schemas/Schema.cs index 8832374d0..b27427091 100644 --- a/src/Squidex.Core/Schemas/Schema.cs +++ b/src/Squidex.Core/Schemas/Schema.cs @@ -289,7 +289,7 @@ namespace Squidex.Core.Schemas } } - private void ValidateUnknownFields(ContentData data, IList errors) + private void ValidateUnknownFields(ContentData data, ICollection errors) { foreach (var fieldData in data) { @@ -300,7 +300,7 @@ namespace Squidex.Core.Schemas } } - private static async Task ValidateLocalizableFieldAsync(ICollection languages, ContentFieldData fieldData, List fieldErrors, Field field) + private static async Task ValidateLocalizableFieldAsync(ICollection languages, ContentFieldData fieldData, ICollection fieldErrors, Field field) { foreach (var valueLanguage in fieldData.Keys) { @@ -322,7 +322,7 @@ namespace Squidex.Core.Schemas } } - private static async Task ValidateNonLocalizableField(ContentFieldData fieldData, List fieldErrors, Field field) + private static async Task ValidateNonLocalizableField(ContentFieldData fieldData, ICollection fieldErrors, Field field) { if (fieldData.Keys.Any(x => x != Language.Invariant.Iso2Code)) { diff --git a/src/Squidex/Config/Constants.cs b/src/Squidex/Config/Constants.cs index 0c994fb2a..dbf547316 100644 --- a/src/Squidex/Config/Constants.cs +++ b/src/Squidex/Config/Constants.cs @@ -10,6 +10,8 @@ namespace Squidex.Config { public class Constants { + public static readonly string SecurityDefinition = "oauth-client-auth"; + public static readonly string ApiPrefix = "/api"; public static readonly string ApiScope = "squidex-api"; diff --git a/src/Squidex/Config/Swagger/SwaggerServices.cs b/src/Squidex/Config/Swagger/SwaggerServices.cs index 5a0c5ee28..75ac816fd 100644 --- a/src/Squidex/Config/Swagger/SwaggerServices.cs +++ b/src/Squidex/Config/Swagger/SwaggerServices.cs @@ -43,9 +43,9 @@ namespace Squidex.Config.Swagger private static SwaggerOwinSettings ConfigureIdentity(this SwaggerOwinSettings settings, MyUrlsOptions urlOptions) { settings.DocumentProcessors.Add( - new SecurityDefinitionAppender("OAuth2", SwaggerHelper.CreateOAuthSchema(urlOptions))); + new SecurityDefinitionAppender(Constants.SecurityDefinition, SwaggerHelper.CreateOAuthSchema(urlOptions))); - settings.OperationProcessors.Add(new OperationSecurityScopeProcessor("roles")); + settings.OperationProcessors.Add(new OperationSecurityScopeProcessor(Constants.SecurityDefinition)); return settings; } diff --git a/src/Squidex/Controllers/ContentApi/Generator/SchemasSwaggerGenerator.cs b/src/Squidex/Controllers/ContentApi/Generator/SchemasSwaggerGenerator.cs index 2f62af27e..010fafcc7 100644 --- a/src/Squidex/Controllers/ContentApi/Generator/SchemasSwaggerGenerator.cs +++ b/src/Squidex/Controllers/ContentApi/Generator/SchemasSwaggerGenerator.cs @@ -145,7 +145,7 @@ namespace Squidex.Controllers.ContentApi.Generator { new SwaggerSecurityRequirement { - { "roles", new List { SquidexRoles.AppOwner, SquidexRoles.AppDeveloper, SquidexRoles.AppEditor } } + { Constants.SecurityDefinition, new List { SquidexRoles.AppOwner, SquidexRoles.AppDeveloper, SquidexRoles.AppEditor } } } }; diff --git a/src/Squidex/Pipeline/Swagger/SwaggerHelper.cs b/src/Squidex/Pipeline/Swagger/SwaggerHelper.cs index a7c1ff130..4c27af4d7 100644 --- a/src/Squidex/Pipeline/Swagger/SwaggerHelper.cs +++ b/src/Squidex/Pipeline/Swagger/SwaggerHelper.cs @@ -13,6 +13,7 @@ using NJsonSchema; using NSwag; using Squidex.Config; using System.Reflection; +using Squidex.Core.Identity; namespace Squidex.Pipeline.Swagger { @@ -46,11 +47,15 @@ namespace Squidex.Pipeline.Swagger new SwaggerSecurityScheme { TokenUrl = tokenUrl, + Name = Constants.SecurityDefinition, Type = SwaggerSecuritySchemeType.OAuth2, Flow = SwaggerOAuth2Flow.Application, Scopes = new Dictionary { - { Constants.ApiScope, "Read and write access to the API" } + { Constants.ApiScope, "Read and write access to the API" }, + { SquidexRoles.AppOwner, "You get this scope / role when you are owner of the app you are accessing." }, + { SquidexRoles.AppEditor, "You get this scope / role when you are owner of the app you are accessing or when the subject is a client." }, + { SquidexRoles.AppDeveloper, "You get this scope / role when you are owner of the app you are accessing." } }, Description = securityDescription };