Global OpenAPI schemes include HTTP

HTTP in global schemes advertises unencrypted API communication.

Description

In OpenAPI 2.0, http in the global schemes includes plaintext HTTP among the API's default transport protocols. Clients following the document may use that protocol.

Potential impact

Requests and responses sent over HTTP can be exposed or modified in transit.

Remediation

Remove http from global schemes and use https. Check operation overrides and configure HTTPS on the actual servers and gateways. Editing the specification alone does not disable HTTP access on the server.

Examples

These excerpts change the default transport protocol from HTTP to HTTPS.

Before

json
{
  "swagger": "2.0",
  "schemes": ["http"]
}

After

json
{
  "swagger": "2.0",
  "schemes": ["https"]
}

References