Skip to content

Swagger Parser doesn't have SafeURLResolve option for OAS 3.0 and OAS 2.0. #2030

@MiloszTarka

Description

@MiloszTarka

The following PRs:

  1. Initial commit of safe url resolver #1910
  2. SWG-7516 utilizing safeURLResolver in swagger-parser-v3 #1911

Added a possibility for swagger-parser to provide a Allow & Block list when resolving external refs. Thanks to that, it is possible provide additional security layer when using this tool inside services. This functionality is still missing when resolving 3.0 and 2.0 versions of OAS.

I've the proposal of the code prepared, so I'll put it on the PR when done.

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions