Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Support for Oauth2 Auth Code Flow with PKCE In Swagger UI #488

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 0 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -60,8 +60,6 @@ histograms/
doc/_build/

# Specifics
flask_restx/static
node_modules

# pyenv
.python-version
Expand Down
2 changes: 1 addition & 1 deletion flask_restx/__about__.py
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# -*- coding: utf-8 -*-
__version__ = "1.0.4.dev"
__version__ = "1.0.3"
__description__ = (
"Fully featured framework for fast, easy and documented API development with Flask"
)
26 changes: 26 additions & 0 deletions flask_restx/static/droid-sans.css
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
/* droid-sans-400normal - latin */
@font-face {
font-family: 'Droid Sans';
font-style: normal;
font-display: swap;
font-weight: 400;
src:
local('Droid Sans Regular '),
local('Droid Sans-Regular'),
url('./files/droid-sans-latin-400.woff2') format('woff2'), /* Super Modern Browsers */
url('./files/droid-sans-latin-400.woff') format('woff'); /* Modern Browsers */
}

/* droid-sans-700normal - latin */
@font-face {
font-family: 'Droid Sans';
font-style: normal;
font-display: swap;
font-weight: 700;
src:
local('Droid Sans Bold '),
local('Droid Sans-Bold'),
url('./files/droid-sans-latin-700.woff2') format('woff2'), /* Super Modern Browsers */
url('./files/droid-sans-latin-700.woff') format('woff'); /* Modern Browsers */
}

Binary file added flask_restx/static/favicon-16x16.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added flask_restx/static/favicon-32x32.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Empty file.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
75 changes: 75 additions & 0 deletions flask_restx/static/oauth2-redirect.html
Original file line number Diff line number Diff line change
@@ -0,0 +1,75 @@
<!doctype html>
<html lang="en-US">
<head>
<title>Swagger UI: OAuth2 Redirect</title>
</head>
<body>
<script>
'use strict';
function run () {
var oauth2 = window.opener.swaggerUIRedirectOauth2;
var sentState = oauth2.state;
var redirectUrl = oauth2.redirectUrl;
var isValid, qp, arr;

if (/code|token|error/.test(window.location.hash)) {
qp = window.location.hash.substring(1);
} else {
qp = location.search.substring(1);
}

arr = qp.split("&");
arr.forEach(function (v,i,_arr) { _arr[i] = '"' + v.replace('=', '":"') + '"';});
qp = qp ? JSON.parse('{' + arr.join() + '}',
function (key, value) {
return key === "" ? value : decodeURIComponent(value);
}
) : {};

isValid = qp.state === sentState;

if ((
oauth2.auth.schema.get("flow") === "accessCode" ||
oauth2.auth.schema.get("flow") === "authorizationCode" ||
oauth2.auth.schema.get("flow") === "authorization_code"
) && !oauth2.auth.code) {
if (!isValid) {
oauth2.errCb({
authId: oauth2.auth.name,
source: "auth",
level: "warning",
message: "Authorization may be unsafe, passed state was changed in server Passed state wasn't returned from auth server"
});
}

if (qp.code) {
delete oauth2.state;
oauth2.auth.code = qp.code;
oauth2.callback({auth: oauth2.auth, redirectUrl: redirectUrl});
} else {
let oauthErrorMsg;
if (qp.error) {
oauthErrorMsg = "["+qp.error+"]: " +
(qp.error_description ? qp.error_description+ ". " : "no accessCode received from the server. ") +
(qp.error_uri ? "More info: "+qp.error_uri : "");
}

oauth2.errCb({
authId: oauth2.auth.name,
source: "auth",
level: "error",
message: oauthErrorMsg || "[Authorization failed]: no accessCode received from the server"
});
}
} else {
oauth2.callback({auth: oauth2.auth, token: qp, isValid: isValid, redirectUrl: redirectUrl});
}
window.close();
}

window.addEventListener('DOMContentLoaded', function () {
run();
});
</script>
</body>
</html>
3 changes: 3 additions & 0 deletions flask_restx/static/swagger-ui-bundle.js

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions flask_restx/static/swagger-ui-bundle.js.map

Large diffs are not rendered by default.

3 changes: 3 additions & 0 deletions flask_restx/static/swagger-ui-es-bundle-core.js

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions flask_restx/static/swagger-ui-es-bundle-core.js.map

Large diffs are not rendered by default.

3 changes: 3 additions & 0 deletions flask_restx/static/swagger-ui-es-bundle.js

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions flask_restx/static/swagger-ui-es-bundle.js.map

Large diffs are not rendered by default.

3 changes: 3 additions & 0 deletions flask_restx/static/swagger-ui-standalone-preset.js

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions flask_restx/static/swagger-ui-standalone-preset.js.map

Large diffs are not rendered by default.

4 changes: 4 additions & 0 deletions flask_restx/static/swagger-ui.css

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions flask_restx/static/swagger-ui.css.map

Large diffs are not rendered by default.

3 changes: 3 additions & 0 deletions flask_restx/static/swagger-ui.js

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions flask_restx/static/swagger-ui.js.map

Large diffs are not rendered by default.

4 changes: 3 additions & 1 deletion flask_restx/templates/swagger-ui.html
Original file line number Diff line number Diff line change
Expand Up @@ -75,7 +75,9 @@
ui.initOAuth({
clientId: "{{ config.SWAGGER_UI_OAUTH_CLIENT_ID }}",
realm: "{{ config.SWAGGER_UI_OAUTH_REALM }}",
appName: "{{ config.SWAGGER_UI_OAUTH_APP_NAME }}"
appName: "{{ config.SWAGGER_UI_OAUTH_APP_NAME }}",
usePkceWithAuthorizationCodeGrant: true

})
{%- endif %}
}
Expand Down