Repository navigation
Conversation
Nine jwt-auth examples used keys the plugin's schema has never had (`required`, `scopes`, `header`, `scheme`, `secret`, `public_key`), so copying one failed compilation with E1023. Seven more set only `issuer`: jwt-auth verifies every token against `public_key_jwk`, so without it they rejected all requests. The jwt-auth guide said signature validation was not implemented, told readers to set `skip_signature_validation: true` in production (the compiled plugin ignores it) and listed HS256 as supported (rejected). It now shows `public_key_jwk`, the algorithms each key type verifies, the alg/use binding, and points to oidc-auth for JWKS. The extensions reference shows a real jwt-auth config. Examples whose point is an authenticated operation use oidc-auth (`issuer_url`, `audience`, `required_scopes` for the scope examples, `allow_query_token` on the WebSocket route), and operation-level ones carry the `security` requirement E1057 asks for; the complete example declares `bearerAuth`. The secrets guide's file-based examples use oauth2-auth's `client_secret` and s3's `secret_access_key`. An oidc-auth example with `issuer`/`required` and two oauth2-auth examples missing required keys are fixed too. Every auth and s3 config in the docs now validates against its schema; the two remaining keyless jwt-auth mentions are name-only chain illustrations. Signed-off-by: Nicolas Dreno <nicolas.dreno@barbacane.dev>
|
Important Review skippedAuto reviews are limited based on label configuration. 🏷️ Required labels (at least one) (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: barbacane-dev/barbacane/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
PR Reviewer Guide 🔍Here are some key observations to aid the review process:
|
Summary
Copying an auth example from the docs mostly didn't work:
jwt-authexamples used keys the schema has never had (required,scopes,header,scheme,secret,public_key), so they fail compilation with E1023.issuer.jwt-authverifies every token againstpublic_key_jwk, so without one they reject every request with a 401.jwt-authguide itself said signature validation "is not yet implemented" and told readers to setskip_signature_validation: true"in production". The compiled plugin ignores that flag. The guide also listed HS256, which is rejected.oidc-authconfig withissuer/requiredinstead ofissuer_url, and twooauth2-authconfigs missing required keys.Changes
The
jwt-authguide and the extensions reference show a workingjwt-authconfig withpublic_key_jwk. They cover which algorithms each key type verifies, thealg/usebinding, thatskip_signature_validationis test-only, thatjwks_url/public_key_pemare accepted but unused, and a pointer tooidc-authfor JWKS.Examples whose point is "this operation needs auth" now use
oidc-auth, which is what most deployments run:issuer_urlandaudience;required_scopeswhere the example meant scopes (scopes: ["admin:read"]becomesrequired_scopes: "admin:read");allow_query_tokenon the WebSocket route, since browsers can't set headers there.This covers spec-configuration (operation, complete and AsyncAPI examples), extensions, dispatchers (WebSocket and S3), the middlewares index, authorization (
cel, OPA) and the AI gateway guide.Operation-level examples get a
securityrequirement, as E1057 demands. The complete example declaresbearerAuthundercomponents.securitySchemes, and the guide now has one sentence explaining E1057.Secrets guide: the
file://examples use real secret fields:oauth2-auth'sclient_secretands3'ssecret_access_key.jwt-authhas no secret field, and its key is a JSON object, not a string a secret reference can hold.Testing
I parsed every YAML block in
docs/and checked each auth ands3config against its plugin'sconfig-schema.json: required keys, unknown keys under closed objects, and value types. Ajwt-authconfig withoutpublic_key_jwkalso counts as a failure.jwt-authmentions in middleware-order illustrations, whose neighbors have no config either.oidc-authwritescontext:auth.subandx-auth-claimslikejwt-authdoes, so the rate-limit partition and OPA claims examples still hold.Docs only, no code change.