You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WebAPI中AzureAD令牌认证时如何在Swagger隐藏真实ClientId

问题:Swagger页面隐藏AzureAD真实ClientId,显示虚拟值

我已为WebAPI配置AzureAD令牌认证,但Swagger页面显示了真实的ClientId值,我不希望终端用户看到该真实值。代码中可硬编码真实ClientId,但希望Swagger页面的ClientId输入框显示如swaggerClient这类虚拟值,该如何实现?

Swagger页面显示真实ClientId

现有代码:

services.AddSwaggerGen(op =>
{
    var openApi = new OpenApiSecurityScheme
    {
        Flows = new OpenApiOAuthFlows
        {
            AuthorizationCode = new OpenApiOAuthFlow
            {
                AuthorizationUrl = "https://abcde.com",
                Scopes = new Dictionary<string, string>
                {
                    { Scope, "mvc1"}
                },
                TokenUrl = "https://abcde.com/token"
            }
        },
        In = ParameterLocation.Header,
        Name = "Authorization",
        Type = SecuritySchemeType.OAuth2
    };

    op.AddSecurityRequirement(new OpenApiSecurityRequirement
    {
        {
              new OpenApiSecurityScheme
              {
                  Reference = new OpenApiReference
                  {
                      Type = ReferenceType.SecurityScheme,
                      Id = "oauth2"
                  }
              },
             new string[] {}
        }
    });

    options.AddSecurityDefinition("oauth2", openApi);
    options.OperationFilter<SecurityRequirementsOperationFilter>();
});

解决方案

可以通过分离Swagger文档定义和Swagger UI的实际请求配置来实现:

  1. 在AddSwaggerGen的OAuth流配置中,设置虚拟ClientId(比如swaggerClient),让Swagger页面的输入框显示这个值;
  2. 在AddSwaggerUI的配置里,指定真实的ClientId,确保实际向AzureAD发起授权请求时使用正确的ClientId。

修改后的完整配置示例:

// 配置Swagger文档生成
services.AddSwaggerGen(op =>
{
    var openApi = new OpenApiSecurityScheme
    {
        Flows = new OpenApiOAuthFlows
        {
            AuthorizationCode = new OpenApiOAuthFlow
            {
                AuthorizationUrl = new Uri("https://abcde.com"),
                Scopes = new Dictionary<string, string>
                {
                    { Scope, "mvc1"}
                },
                TokenUrl = new Uri("https://abcde.com/token"),
                // 设置虚拟ClientId,用于Swagger页面显示
                ClientId = "swaggerClient"
            }
        },
        In = ParameterLocation.Header,
        Name = "Authorization",
        Type = SecuritySchemeType.OAuth2
    };

    op.AddSecurityRequirement(new OpenApiSecurityRequirement
    {
        {
              new OpenApiSecurityScheme
              {
                  Reference = new OpenApiReference
                  {
                      Type = ReferenceType.SecurityScheme,
                      Id = "oauth2"
                  }
              },
             new string[] {}
        }
    });

    op.AddSecurityDefinition("oauth2", openApi);
    op.OperationFilter<SecurityRequirementsOperationFilter>();
});

// 配置Swagger UI
services.AddSwaggerUI(uiOptions =>
{
    // 其他UI配置...
    
    // 设置OAuth实际请求用的真实ClientId
    uiOptions.OAuthClientId("你的真实ClientId");
    uiOptions.OAuthUsePkce(); // 若AzureAD配置要求PKCE,开启此项
});

原理说明

  • Swagger文档(AddSwaggerGen)里的ClientId负责渲染页面输入框内容,设置虚拟值即可隐藏真实信息;
  • Swagger UI(AddSwaggerUI)里的OAuthClientId是发起授权请求时的实际参数,填写真实值不会影响认证流程。

内容的提问来源于stack exchange,提问作者Abhishek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 01:54:25