package com.codebyte.api.config;

import io.swagger.v3.oas.annotations.OpenAPIDefinition;
import io.swagger.v3.oas.annotations.enums.SecuritySchemeType;
import io.swagger.v3.oas.annotations.info.Info;
import io.swagger.v3.oas.annotations.info.License;
import io.swagger.v3.oas.annotations.security.SecurityScheme;
import org.springframework.context.annotation.Configuration;

/**
 * OpenAPI metadata and the bearer-JWT security scheme. Protected controllers opt in with
 * {@code @SecurityRequirement("bearerAuth")}; the public /auth endpoints do not, so the generated
 * spec reflects reality.
 */
@Configuration
@OpenAPIDefinition(
        info =
                @Info(
                        title = "demo API",
                        version = "v1",
                        description =
                                "Item CRUD and authentication (registration, activation, JWT login"
                                        + " with lockout, refresh rotation, password reset).",
                        license = @License(name = "Apache-2.0")))
@SecurityScheme(
        name = "bearerAuth",
        type = SecuritySchemeType.HTTP,
        scheme = "bearer",
        bearerFormat = "JWT")
public class OpenApiConfig {}
