You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python 检查多层嵌套字典键存在及包含指定值的方法

OpenAPI接口安全配置校验方案

需求说明

  • 遍历字典对象r_dict中r_dict['paths']下的所有接口端点(例如/pet/{petId}/uploadImage),逐一对每个端点做两项校验:
    1. 端点对应的请求配置中是否存在security键
    2. security对应的取值中是否包含read或write关键词
  • 初始化结果存储字典:result = {}
  • 标记规则:
    • 同时满足上述两个校验条件的端点,标记为安全:result[end_point_name] = 'secure'
    • 不满足任意一个校验条件的端点,标记为不安全:result[end_point_name] = 'unsecure'

待处理示例数据

r_dict = {"paths": {
"/pet/{petId}/uploadImage": {
"post": {
"tags": [
"pet"
],
"summary": "uploads an image",
"description": "",
"operationId": "uploadFile",
"consumes": [
"multipart/form-data"
],
"produces": [
"application/json"
],
"parameters": [
{
"name": "petId",
"in": "path",
"description": "ID of pet to update",
"required": true,
"type": "integer",
"format": "int64"
},
{
"name": "additionalMetadata",
"in": "formData",
"description": "Additional data to pass to server",
"required": false,
"type": "string"
},
{
"name": "file",
"in": "formData",
"description": "file to upload",
"required": false,
"type": "file"
}
],
"responses": {
"200": {
"description": "successful operation",
"schema": {
"$ref": "#/definitions/ApiResponse"
}
}
},
"security": [
{
"petstore_auth": [
"write:pets",
"read:pets"
]
}
]
}
},
"/pet": {
"post": {
"tags": [
"pet"
],
"summary": "Add a new pet to the store",
"description": "",
"operationId": "addPet",
"consumes": [
"application/json",
"application/xml"
],
"produces": [
"application/json",
"application/xml"
],
"parameters": [
{
"in": "body",
"name": "body",
"description": "Pet object that needs to be added to the store",
"required": true,
"schema": {
"$ref": "#/definitions/Pet"
}
}
],
"responses": {
"405": {
"description": "Invalid input"
}
},
"security": [
{
"petstore_auth": [
"write:pets",
"read:pets"
]
}
]
},
"put": {
"tags": [
"pet"
],
"summary": "Update an existing pet",
"description": "",
"operationId": "updatePet",
"consumes": [
"application/json",
"application/xml"
],
"produces": [
"application/json",
"application/xml"
],
"parameters": [
{
"in": "body",
"name": "body",
"description": "Pet object that needs to be added to the store",
"required": true,
"schema": {
"$ref": "#/definitions/Pet"
}
}
],
"responses": {
"400": {
"description": "Invalid ID supplied"
},
"404": {
"description": "Pet not found"
},
"405": {
"description": "Validation exception"
}
},
"security": [
{
"petstore_auth": [
"write:pets",
"read:pets"
]
}
]
}
},
"/pet/findByStatus": {
"get": {
"tags": [
"pet"
],
"summary": "Finds Pets by status",
"description": "Multiple status values can be provided with comma separated strings",
"operationId": "findPetsByStatus",
"produces": [
"application/json",
"application/xml"
],
"parameters": [
{
"name": "status",
"in": "query",
"description": "Status values that need to be considered for filter",
"required": true,
"type": "array",
"items": {
"type": "string",
"enum": [
"available",
"pending",
"sold"
],
"default": "available"
},
"collectionFormat": "multi"
}
],
"responses": {
"200": {
"description": "successful operation",
"schema": {
"type": "array",
"items": {
"$ref": "#/definitions/Pet"
}
}
},
"400": {
"description": "Invalid status value"
}
},
"security": [
{
"petstore_auth": [
"write:pets",
"read:pets"
]
}
]
}
} }

实现代码

result = {}

# 遍历paths下所有接口端点
for endpoint, method_configs in r_dict["paths"].items():
    endpoint_safe = True
    # 遍历当前端点下所有HTTP请求方法的配置
    for conf in method_configs.values():
        # 校验1:配置中是否存在security键
        if "security" not in conf:
            endpoint_safe = False
            break
        # 校验2:security取值中是否包含read或write关键词
        # 转为字符串做关键词匹配,兼容列表嵌套结构
        security_str = str(conf["security"])
        if "read" not in security_str and "write" not in security_str:
            endpoint_safe = False
            break
    # 写入校验结果
    result[endpoint] = "secure" if endpoint_safe else "unsecure"

示例数据运行结果

针对提供的示例数据执行上述代码后,得到的结果字典如下:

{
    "/pet/{petId}/uploadImage": "secure",
    "/pet": "secure",
    "/pet/findByStatus": "secure"
}

说明:如果需要将「请求路径+HTTP方法」作为独立端点校验,只需要调整遍历逻辑,将方法名和路径拼接作为result的键即可,校验规则不变。

内容的提问来源于stack exchange,提问作者Rikky Bhai

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.27 16:57:16