<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 20:16:24 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[NETCONF-990] Explore swagger authentication feature</title>
                <link>https://jira.opendaylight.org/browse/NETCONF-990</link>
                <project id="10142" key="NETCONF">netconf</project>
                    <description>&lt;p&gt;We can explore swagger authentication feature according to &lt;a href=&quot;https://swagger.io/docs/specification/authentication/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://swagger.io/docs/specification/authentication/.&lt;/a&gt; This way we could be able to make our swagger UI to show &lt;b&gt;Authorize&lt;/b&gt; button as seen at &lt;a href=&quot;https://petstore3.swagger.io/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://petstore3.swagger.io/.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We hope that in the future, we can make our swagger UI to be available for browsing without requiring credentials, and credentials will be attached only when user wants to try some requests.&lt;/p&gt;</description>
                <environment></environment>
        <key id="36829">NETCONF-990</key>
            <summary>Explore swagger authentication feature</summary>
                <type id="10103" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10311&amp;avatarType=issuetype">New Feature</type>
                                            <priority id="3" iconUrl="https://jira.opendaylight.org/images/icons/priorities/major.svg">Medium</priority>
                        <status id="5" iconUrl="https://jira.opendaylight.org/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10000">Done</resolution>
                                        <assignee username="ivanhrasko">Ivan Hrasko</assignee>
                                    <reporter username="ivanhrasko">Ivan Hrasko</reporter>
                        <labels>
                            <label>pt</label>
                    </labels>
                <created>Wed, 12 Apr 2023 08:55:58 +0000</created>
                <updated>Thu, 22 Jun 2023 10:55:40 +0000</updated>
                            <resolved>Wed, 19 Apr 2023 12:24:10 +0000</resolved>
                                                    <fixVersion>5.0.5</fixVersion>
                                    <component>restconf-openapi</component>
                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                                                                <comments>
                            <comment id="72117" author="ivanhrasko" created="Tue, 18 Apr 2023 11:53:28 +0000"  >&lt;p&gt;We were able to apply &lt;b&gt;security&lt;/b&gt; tag for every example shown by swagger UI (version OpenAPI2 and version ApenAPI3). It makes &lt;b&gt;Authorize&lt;/b&gt; button visible and offers &lt;b&gt;basicAuth&lt;/b&gt; option. When user authorizes then every request send using swagger UI contains Authorization header with basic auth.&lt;/p&gt;

&lt;p&gt;By default when (default ODL) basic shiro filter is used to secure both swagger UI and restconf interface user does not need to be authorized because session cookie is in place. But in situation when other filters are configured to be used (ODL allows to register additional filters) and basic shiro filter is turned off it allows to provide authorization header in the request as potentially required by that 3rd party filter.&lt;/p&gt;

&lt;p&gt;This is especially useful when 3rd party filter does not provide login page in case of missing credentials (basic shiro filter prompts for credentials by default). In this case using &lt;b&gt;Authorize&lt;/b&gt; button is the only possibility to authorize requests - otherwise they will get 401.&lt;/p&gt;

&lt;p&gt;For now we have implemented &lt;b&gt;basicAuth&lt;/b&gt;. Later we can add others methods as defined in &lt;a href=&quot;https://swagger.io/docs/specification/authentication/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://swagger.io/docs/specification/authentication/&lt;/a&gt; as well.&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10003">
                    <name>Relates</name>
                                                                <inwardlinks description="relates to">
                                        <issuelink>
            <issuekey id="37020">NETCONF-1064</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i044sv:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>