如何在Swagger中隐藏curl区域的登录凭证或curl区域本身?
解决登录接口curl区域隐藏凭证或隐藏区域的方案
一、隐藏请求体中的密码字段
1. 字段级注解(最简单实现)
直接在登录请求DTO的password字段上添加对应注解:
- SpringDoc环境:
@Schema(accessMode = Schema.AccessMode.WRITE_ONLY) - Springfox Swagger2环境:
@ApiModelProperty(hidden = true)
添加后Swagger会自动在示例和curl代码中隐藏密码字段,或替换为占位符。
2. 自定义请求示例(SpringDoc)
如果注解不够灵活,可通过OperationCustomizer精准修改登录接口的请求示例,将密码替换为隐藏内容:
@Bean public OperationCustomizer hidePasswordInLoginExample() { return (operation, handlerMethod) -> { // 匹配登录接口(可根据operationId或接口路径判断) if ("login".equals(operation.getOperationId())) { RequestBody requestBody = operation.getRequestBody(); if (requestBody != null && requestBody.getContent().containsKey("application/json")) { MediaType jsonMediaType = requestBody.getContent().get("application/json"); // 修改默认示例的密码 Example defaultExample = jsonMediaType.getExamples().get("default"); if (defaultExample != null && defaultExample.getValue() instanceof Map) { ((Map<String, Object>) defaultExample.getValue()).put("password", "***"); } // 修改Schema的示例值 Schema schema = jsonMediaType.getSchema(); if (schema.getProperties() != null) { schema.getProperties().get("password").setExample("***"); } } } return operation; }; }
3. DocumentFilter修正写法(Springfox)
如果之前用DocumentFilter未生效,试试这个精准拦截并修改请求体的写法:
@Component public class LoginPasswordHideFilter implements DocumentFilter { @Override public void apply(DocumentContext context) { JsonNode paths = context.read("$.paths"); Iterator<String> pathIter = paths.fieldNames(); while (pathIter.hasNext()) { String path = pathIter.next(); JsonNode pathNode = paths.get(path); // 定位POST类型的登录接口 if (pathNode.has("post")) { JsonNode postNode = pathNode.get("post"); if ("login".equals(postNode.get("operationId").asText())) { JsonNode requestBody = postNode.get("requestBody"); if (requestBody != null && requestBody.has("content")) { JsonNode jsonContent = requestBody.get("content").get("application/json"); // 修改示例中的密码 if (jsonContent.has("examples")) { ObjectNode exampleValue = (ObjectNode) jsonContent.get("examples").get("default").get("value"); exampleValue.put("password", "***"); } // 修改Schema示例 if (jsonContent.has("schema")) { ObjectNode props = (ObjectNode) jsonContent.get("schema").get("properties"); props.get("password").put("example", "***"); } } } } } } }
二、完全隐藏curl区域
1. 自定义CSS隐藏(SpringDoc)
在src/main/resources/static/swagger-ui.css中添加样式,可选择隐藏所有或仅登录接口的curl区域:
/* 隐藏所有接口的curl代码块 */ div.response-col_description > div:nth-child(2) > div:nth-child(2) { display: none !important; } /* 仅隐藏登录接口的curl区域(需匹配operation-id) */ .operation-id-login + div > div.response-col_description > div:nth-child(2) > div:nth-child(2) { display: none !important; }
然后在SpringDoc配置中引入自定义CSS:
@Configuration public class SpringDocConfig { @Bean public SwaggerUiConfigParameters swaggerUiConfigParams() { SwaggerUiConfigParameters params = new SwaggerUiConfigParameters(); params.setCssUrl("/swagger-ui.css"); return params; } }
2. JS脚本隐藏(Springfox)
创建src/main/resources/static/swagger-custom.js:
$(document).ready(function() { // 隐藏所有curl区域 $('.curl').hide(); // 仅隐藏登录接口的curl区域,取消注释即可 // $('div.operation:contains("login")').find('.curl').hide(); });
然后在Swagger配置中引入脚本:
@Configuration @EnableSwagger2 public class SwaggerConfig { @Bean public UiConfiguration uiConfig() { return UiConfigurationBuilder.builder() .customScriptUrl("/swagger-custom.js") .build(); } }
内容的提问来源于stack exchange,提问作者Victor Afolabi
相关产品推荐
相关产品推荐

