Private/Document/ConvertTo-OpenApiSecurityScheme.ps1

function ConvertTo-OpenApiSecurityScheme {
    <#
    .SYNOPSIS
        Normalises a resolved raw security scheme into the SecurityScheme object, with OA030 for unsupported kinds.
    .DESCRIPTION
        Returns { Name, Type, In, ParameterName, Scheme, BearerFormat, Flows, OpenIdConnectUrl, Description }.
        Flows maps flow names to { TokenUrl, AuthorizationUrl, RefreshUrl, Scopes }. OA030 (Warning) is
        written for openIdConnect, mutualTLS, unknown types, http schemes other than basic/bearer and
        oauth2 schemes without a clientCredentials flow (the runtime only fetches client-credentials tokens).
    #>

    [CmdletBinding()]
    [OutputType([pscustomobject])]
    param(
        [Parameter(Mandatory)]
        [pscustomobject]$Context,

        [Parameter(Mandatory)]
        [string]$Name,

        [Parameter(Mandatory)]
        [System.Collections.IDictionary]$Node,

        [Parameter(Mandatory)]
        [AllowEmptyString()]
        [string]$Pointer
    )

    $type = [string]$Node['type']
    $scheme = $null
    if ($null -ne $Node['scheme']) {
        $scheme = ([string]$Node['scheme']).ToLowerInvariant()
    }
    $flows = $null
    if ($Node['flows'] -is [System.Collections.IDictionary]) {
        $flows = [System.Collections.Specialized.OrderedDictionary]::new([System.StringComparer]::Ordinal)
        foreach ($flowName in @($Node['flows'].Keys)) {
            $flow = $Node['flows'][$flowName]
            if ($flow -isnot [System.Collections.IDictionary]) {
                continue
            }
            $scopes = [System.Collections.Specialized.OrderedDictionary]::new([System.StringComparer]::Ordinal)
            if ($flow['scopes'] -is [System.Collections.IDictionary]) {
                foreach ($scope in @($flow['scopes'].Keys)) {
                    $scopes[$scope] = $flow['scopes'][$scope]
                }
            }
            $flows[$flowName] = [pscustomobject]@{
                TokenUrl         = $flow['tokenUrl']
                AuthorizationUrl = $flow['authorizationUrl']
                RefreshUrl       = $flow['refreshUrl']
                Scopes           = $scopes
            }
        }
    }

    $reason = $null
    switch ($type) {
        'apiKey' {
        }
        'http' {
            if ($scheme -ne 'basic' -and $scheme -ne 'bearer') {
                $reason = "http scheme '$scheme' is not supported (only basic and bearer)"
            }
        }
        'oauth2' {
            if ($null -eq $flows -or -not $flows.Contains('clientCredentials')) {
                $reason = 'only the oauth2 clientCredentials flow is supported'
            }
        }
        'openIdConnect' {
            $reason = 'openIdConnect is not supported'
        }
        default {
            $reason = "security scheme type '$type' is not supported"
        }
    }
    if ($null -ne $reason) {
        Add-OpenApiFinding -Context $Context -Severity Warning -Code 'OA030' -Pointer $Pointer -Operation $null -Message "Security scheme '$Name': $reason; supply credentials with -Header or call Invoke-OpenApiRequest directly."
    }

    [pscustomobject]@{
        PSTypeName       = 'Tcs.OpenApi.SecurityScheme'
        Name             = $Name
        Type             = $type
        In               = $Node['in']
        ParameterName    = $Node['name']
        Scheme           = $scheme
        BearerFormat     = $Node['bearerFormat']
        Flows            = $flows
        OpenIdConnectUrl = $Node['openIdConnectUrl']
        Description      = $Node['description']
    }
}