Skip to content

DRAFT: [jaxrs-spec][quarkus] Emit @Authenticated for OAuth2 security schemes with empty scopes array#23680

Draft
Ignacio-Vidal wants to merge 5 commits intoOpenAPITools:masterfrom
Ignacio-Vidal:quarkus-authentication
Draft

DRAFT: [jaxrs-spec][quarkus] Emit @Authenticated for OAuth2 security schemes with empty scopes array#23680
Ignacio-Vidal wants to merge 5 commits intoOpenAPITools:masterfrom
Ignacio-Vidal:quarkus-authentication

Conversation

@Ignacio-Vidal
Copy link
Copy Markdown
Contributor

@Ignacio-Vidal Ignacio-Vidal commented May 3, 2026

PR checklist

  • Read the contribution guidelines.
  • Pull Request title clearly describes the work in the pull request and Pull Request description provides details about how to validate the work. Missing information here may result in delayed response from the community.
  • Run the following to build the project and update samples:
    ./mvnw clean package || exit
    ./bin/generate-samples.sh ./bin/configs/*.yaml || exit
    ./bin/utils/export_docs_generators.sh || exit
    
    (For Windows users, please run the script in WSL)
    Commit all changed files.
    This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
    These must match the expectations made by your contribution.
    You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example ./bin/generate-samples.sh bin/configs/java*.
    IMPORTANT: Do NOT purge/delete any folders/files (e.g. tests) when regenerating the samples as manually written tests may be removed.
  • File the PR against the correct branch: master (upcoming 7.x.0 minor release - breaking changes with fallbacks), 8.0.x (breaking changes without fallbacks)
  • If your PR solves a reported issue, reference it using GitHub's linking syntax (e.g., having "fixes #123" present in the PR description)
  • If your PR is targeting a particular programming language, @mention the technical committee members, so they are more likely to review the pull request.

Summary by cubic

Emit @io.quarkus.security.Authenticated on Quarkus JAX-RS endpoints when authentication is required without scopes, so generated APIs enforce auth but not role scopes. Applies to OAuth2/OpenID with empty scopes, basic, bearer, and apiKey; skipped when all alternatives have scopes and deduped across multiple flows and OR lists.

  • New Features
    • Set x-quarkus-authenticated in JavaJAXRSSpecServerCodegen (Quarkus only) and render @io.quarkus.security.Authenticated in apiInterface.mustache and apiMethod.mustache for matching operations.
    • Parameterized tests cover interface/impl, scoped vs unscoped, multi-flow, OR, and additional schemes; assert a single annotation per operation. New fixtures: quarkus-http-basic.yaml, quarkus-http-bearer.yaml, quarkus-api-key.yaml (plus existing OAuth2/OpenID cases).

Written for commit 7479247. Summary will update on new commits.

@Ignacio-Vidal Ignacio-Vidal changed the title DRAFT: [jaxrs-spec][quarkus] Emit @Authenticated for OAuth2 security schemes without scopes DRAFT: [jaxrs-spec][quarkus] Emit @Authenticated for OAuth2 security schemes with empty scopes array May 4, 2026
@Ignacio-Vidal Ignacio-Vidal force-pushed the quarkus-authentication branch from 622ad79 to 7ad9761 Compare May 4, 2026 09:51
# Conflicts:
#	modules/openapi-generator/src/main/java/org/openapitools/codegen/languages/JavaJAXRSSpecServerCodegen.java
#	modules/openapi-generator/src/main/resources/JavaJaxRS/spec/libraries/quarkus/apiInterface.mustache
#	modules/openapi-generator/src/test/java/org/openapitools/codegen/java/jaxrs/JavaJAXRSSpecServerCodegenTest.java
@Ignacio-Vidal Ignacio-Vidal force-pushed the quarkus-authentication branch from 2eb7ff4 to 471d62a Compare May 4, 2026 22:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant