Skip to content

Incorrect default value for OpenApiSecurityScheme.In when using "http" type with "bearer" scheme #1843

Description

Describe the bug
When defining an OpenApiSecurityScheme of type http with the scheme bearer, the default value for In is set to Query instead of Header. According to the OpenAPI Specification, header should be the implied default when the type is http and the scheme is bearer.

OpenApi File To Reproduce

openapi: 3.0.0
info:
  title: Minimal API
  version: 1.0.0
paths:
  /example:
    get:
      summary: Example endpoint
      security:
        - Bearer: []
      responses:
        '200':
          description: Successful response
components:
  securitySchemes:
    Bearer:
      type: http
      scheme: bearer

Expected behavior
The default value for OpenApiSecurityScheme.In should be Header when the type is http and the scheme is bearer, aligning with the OpenAPI Specification’s default behavior.

Additional context
This issue causes incorrect behavior when generating clients or code based on the OpenAPI definition, as the security token is expected to be sent as a query parameter instead of the Authorization header.

Activity

  1. darrelmiller commented on Oct 2, 2024

    @darrelmiller
    Member

    I am assuming you mean the In property rather than Location as there is no Location property.

    However, the In property is only applicable to type equal to apiKey. It has no impact on type equal to http. When using the type http, the credentials are always sent in the Authorization header. This is stated explicitly in the description of the scheme field here https://spec.openapis.org/oas/v3.1.0.html#fixed-fields-22

  2. changed the title [-]Incorrect default value for OpenApiSecurityScheme.Location when using "http" type with "bearer" scheme[/-] [+]Incorrect default value for OpenApiSecurityScheme.In when using "http" type with "bearer" scheme[/+] on Oct 2, 2024
  3. baywet commented on Jul 14, 2026

    @baywet
    Member

    Hi Konstantin S. (@HavenDV)

    Thank you for using the SDK and for reaching out.

    I put together #2952

    Let me know if you have any additional comments or questions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions