Swagger 2.0安全方案已定义但未使用问题:端点认证保护配置方法问询
Hey there, let's get that warning sorted out and make sure your API endpoints are properly locked down—no need to stress about competitors sneaking in once we fix this!
Why you're seeing the warning
You've correctly set up your api_key security scheme in securityDefinitions, but Swagger has no clue which endpoints should use it until you explicitly link the scheme to your paths or operations. That's exactly why you're getting the "never used" error message.
Two ways to apply the security scheme
You’ve got two solid options to associate your api_key with your endpoints—pick the one that fits your API’s needs:
1. Apply to ALL endpoints (global security)
Add a top-level security section to your Swagger file. This will enforce the API key requirement for every path in your document automatically:
swagger: "2.0" info: version: 1.0.0 title: Das ERP host: virtserver.swaggerhub.com basePath: /rossja/whatchamacallit/1.0.0 schemes: - https securityDefinitions: api_key: type: apiKey name: api_key in: header description: API Key # Add this global security block to enforce auth everywhere security: - api_key: [] # References your defined api_key scheme paths: /dt/invoicestatuses: get: tags: - invoice summary: Returns a list of invoice statuses produces: - application/json operationId: listInvoiceStatuses responses: 200: description: OK schema: type: object properties: code: type: integer value: type: string
2. Apply to specific endpoints
If only certain paths need the API key check, add the security section directly inside the individual operation (like the get method for /dt/invoicestatuses):
paths: /dt/invoicestatuses: get: tags: - invoice summary: Returns a list of invoice statuses produces: - application/json operationId: listInvoiceStatuses # Add this to lock down just this endpoint security: - api_key: [] responses: 200: description: OK schema: type: object properties: code: type: integer value: type: string
Verifying your setup
Since you mentioned the authentication already works in production, your api_key configuration (name, location in the header) is spot-on. Adding the security reference will just update your Swagger documentation to reflect this requirement, and the warning will vanish immediately.
Now your Swagger docs will clearly show which endpoints require the api_key header, and you can rest easy knowing your data is properly protected as you intended.
内容的提问来源于stack exchange,提问作者jimjoseph_lebonboncroissant

