Hide Authorization header from being displayed in Swagger3

Viewed 34

I am using JWT Bearer token for authorization. I have added common authorization in SWAGGER UI which is working fine. But API level authorization RequestHeader is still showing in swagger UI. How can I hide it. Please refer to image 1.

Swagger UI Screenshot

Controller Code

@SecurityRequirement(name = "my-notes-api")
@Operation(description = "Update the existing note", 
            summary = "Update Note", 
            tags = "Notes")
@PutMapping(path = "/update-note", 
            consumes = MediaType.APPLICATION_JSON_VALUE, 
            produces = MediaType.APPLICATION_JSON_VALUE) 
public Notes updateNote(@RequestHeader("Authorization") String authToken, 
                        @RequestHeader("note-id") String noteId, 
                        @RequestBody @Valid NotePOJO note) throws BusinessException {
                        
    return notesService.updateNote(jwtUtils.extractUserId(authToken.substring(7)), noteId, note);
    
}

I can not remove @RequestHeader("Authorization") String authToken from controller parameters as I am fetching the userId from this token only.

1 Answers

You can use @Parameter to mark the parameter as hidden.

public Notes updateNote(
        @io.swagger.v3.oas.annotations.Parameter(hidden = true) @RequestHeader("Authorization") String authToken,
        @RequestHeader("note-id") String noteId,
        @RequestBody @Validated NotePOJO note
) throws BusinessException {

See https://springdoc.org/#migrating-from-springfox

Related