I want to make 2 different documentations. One is for public with few api methods and no authz. Another one is for private usage with all api methods and only for authorized users.
I want to make 2 different documentations. One is for public with few api methods and no authz. Another one is for private usage with all api methods and only for authorized users.
2 choices:
If you use the build-in Swagger and the user visiting the UI is somehow auth'ed, you can use the setting 'SERVE_PUBLIC': False. It will filter the schema based on the permissions the requesting user has access to. Spectacular will attempt to use the (first) credentials provided by the Authorize button and fetch the schema with that. If your auth method differs from DRF's setting AUTHENTICATION_CLASSES, you might also need to set spectacular's SERVE_AUTHENTICATION accordingly.
Or actually create 2(+2) endpoints that serve distinct schemas and potentially customize them
# public part
path('api/schema/swagger-ui-public/', SpectacularSwaggerView.as_view(
custom_settings={
'SERVE_URLCONF': [...] # urlpatterns with the public endpoint list
},
url_name='schema-public')
),
path('api/schema-public/', SpectacularAPIView.as_view(), name='schema-public'),
# private part
path('api/schema-private/', SpectacularAPIView.as_view(
# settings deviating from global spectacular settings go here.
custom_settings={
'TITLE': 'Private API',
'SERVE_URLCONF': [...] # urlpatterns with the private endpoint list
...
},
# not required but might want to also protect if it is sensitive
authentication_classes=[...],
permission_classes=[...],
), name='schema-private'
),
path('api/schema/swagger-ui-private/', SpectacularSwaggerView.as_view(url_name='schema-private')),