我也遇到了这个问题,并意识到当fetch 重定向到预签名的 S3 URL 时,您无法阻止它从您的 API 发送授权标头。
最终我可以通过使用 Swagger 的 responseInterceptor 配置参数和一个自定义函数来实现这个工作,该函数检测来自 S3 的错误请求 (400) 响应,然后使用 credentials: 'omit' 重新发出 fetch 请求.
这是我对 Swagger 的自定义响应拦截器:
// swagger-ui-extensions.js
function serializeHeaderValue(value) {
const isMulti = value.includes(', ');
return isMulti ? value.split(', ') : value;
}
function serializeHeaders(headers = {}) {
return Array.from(headers.entries()).reduce((acc, [header, value]) => {
acc[header] = serializeHeaderValue(value);
return acc;
}, {});
}
function myResponseInterceptor(response) {
// NOTE: Additional checks should probably be added whether to re-issue the fetch. This was just an initial starting point.
if (response.ok === false && response.status === 400 && response.headers['server'] === 'AmazonS3') {
// Here is the important part, re-issue fetch but don't allow our Authentication header to flow
response = fetch(response.url, { credentials: 'omit' })
.then(nativeResponse => {
// We can't return the native response because Swagger UI attempts to assign the header property (and potentially other properties
// too) on the response. So return a serialized clone of the native response. FYI, this is the same exact logic from Swagger's fake
// implementation of fetch.
const getBody = nativeResponse.blob || nativeResponse.buffer;
return getBody.call(nativeResponse).then(body => {
return {
ok: nativeResponse.ok,
url: nativeResponse.url,
status: nativeResponse.status,
statusText: nativeResponse.statusText,
headers: serializeHeaders(nativeResponse.headers),
data: body
};
});
});
}
return response;
}
然后我必须在 index.html 中初始化 Swagger UI 时指定我的自定义 myResponseInterceptor
// (other code omitted for brevity...)
// Make sure to include your custom JS in the page
// <script src="./swagger-ui-extensions.js"></script>
// Specifying the custom responseInterceptor here...
configObject.responseInterceptor = myResponseInterceptor;
// Begin Swagger UI call region
const ui = SwaggerUIBundle(configObject);
ui.initOAuth(oauthConfigObject);
// End Swagger UI call region
window.ui = ui;
我使用的是 ASP.NET Core,并使用这些说明为 Swagger UI 提供了我自己的 index.html:
https://github.com/domaindrivendev/Swashbuckle.AspNetCore#customize-indexhtml
毕竟,这出人意料地奏效了,我能够在 Swagger 中看到来自 S3 的重定向响应。