Commit 4e59295
authored
feat(openapi): add allow option to OpenAPIReferenceHandlerPlugin (#1911)
Adds an `allow` option to `OpenAPIReferenceHandlerPlugin` so the docs UI
and OpenAPI spec can be served conditionally, for example only to
authenticated users. When it resolves to `false`, the request falls
through as unmatched, as if the plugin were not installed, so
unauthorized clients cannot tell the docs and spec paths exist.
Resolves #1907
## Design
- `allow: Value<Promisable<boolean>,
[StandardHandlerRoutingInterceptorOptions<T>]>`, defaulting to `true`.
It receives the same options as `spec`, `docsTitle`, and `docsHead`, so
decisions can use the handler context or request headers.
- Evaluated only after a docs/spec path matches, so no check runs on
unrelated requests.
## Testing
- Denied requests return the unmatched result for both paths without
generating the spec, and the predicate receives the routing interceptor
options.
- The predicate is never called for unrelated paths; behavior is
unchanged when the option is omitted.
- Docs gain a "Restricting Access" section on the plugin page.1 parent 416b6bc commit 4e59295
3 files changed
Lines changed: 67 additions & 0 deletions
File tree
- apps/content/docs/plugins
- packages/openapi/src/plugins
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
83 | 83 | | |
84 | 84 | | |
85 | 85 | | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
86 | 101 | | |
87 | 102 | | |
88 | 103 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
119 | 119 | | |
120 | 120 | | |
121 | 121 | | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
122 | 160 | | |
123 | 161 | | |
124 | 162 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
28 | 36 | | |
29 | 37 | | |
30 | 38 | | |
| |||
102 | 110 | | |
103 | 111 | | |
104 | 112 | | |
| 113 | + | |
105 | 114 | | |
106 | 115 | | |
107 | 116 | | |
| |||
113 | 122 | | |
114 | 123 | | |
115 | 124 | | |
| 125 | + | |
116 | 126 | | |
117 | 127 | | |
118 | 128 | | |
| |||
150 | 160 | | |
151 | 161 | | |
152 | 162 | | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
153 | 167 | | |
154 | 168 | | |
155 | 169 | | |
| |||
0 commit comments