在 Debian 上部署的 Swagger(通常指 Swagger UI / Swagger Editor / 基于 OpenAPI 的服务) 本身不负责业务鉴权,它只是 API 文档和调试工具。所谓“Swagger 怎么鉴权”,一般分三种场景:
如果你用 Nginx 托管 Swagger UI:
sudo apt install nginx apache2-utils
生成密码文件:
htpasswd -c /etc/nginx/swagger.htpasswd admin
Nginx 配置:
location /swagger/ {
auth_basic "Swagger Restricted";
auth_basic_user_file /etc/nginx/swagger.htpasswd;
root /var/www/html;
}
重启:
systemctl restart nginx
nginx-auth-jwtoauth2-proxy这是在 Swagger UI 页面里填 Token,不是保护 Swagger。
OpenAPI 配置:
components:
securitySchemes:
bearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
security:
- bearerAuth: []
Swagger UI 中:
Bearer xxx.yyy.zzzcomponents:
securitySchemes:
apiKey:
type: apiKey
in: header
name: X-API-Key
security:
- apiKey: []
securitySchemes:
basicAuth:
type: http
scheme: basic
securitySchemes:
oauth2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://auth.example.com/oauth/authorize
tokenUrl: https://auth.example.com/oauth/token
scopes:
read: read data
@SecurityScheme(
name = "bearerAuth",
type = SecuritySchemeType.HTTP,
scheme = "bearer",
bearerFormat = "JWT"
)
Swagger 地址:
/swagger-ui.html
❌ 不要在生产环境直接暴露 Swagger
✅ 推荐做法:
Swagger 本身不鉴权,要么用 Nginx 保护 Swagger,要么在 OpenAPI 里配置 API 的鉴权方式。
如果你能告诉我:
我可以给你更精确的 Debian 配置示例。