OpenAPI 3 MicroProfile, using @SecurityRequirementSet in @OpenApiDefinition

Viewed 307

I'm working on switching OpenAPI v2 to Open API 3, we'll be using MicroProfile 2.0 with Projects as the plugin that will generate the OAS from the code.

Now, we have different headers that are needed as a kind of authorization. I know I can put them on each resource, that seems just a lot of repetition, so I thought it was a good idea to put in the JaxRSConfiguration file as a @SecurityScheme and add them as security to the @OpenApiDefinition.

@OpenAPIDefinition(
    info = @Info(
            ...
           )
    ),
    security = {
       @SecurityRequirement(name = Header1),
       @SecurityRequirement(name = Header2)
    },
    components = @Components(
             securitySchemes = {
                    @SecurityScheme(  apiKeyName = Header1 ... ) ,
                    @SecurityScheme(  apiKeyName = Header2 ....) 
    }),
    ...
)

This is working, however it generates an OR, while it should be an AND (without the - )

security:
  - Header1: []
  - Header2: []

I thought I could use @SecurityRequirementsSet inside security in the @OpenApiDefinition, but unfortunately this is not allowed. I know I can use it on each call or on top of the class of the different calls but as this is still a sort of repetition, I would prefer to have it as a general authentication security.

Does anybody know how I can achieve this ?

0 Answers
Related