Description
When global security in OpenAPI 2.0 references a password flow, the API's default authentication scheme requires the client to collect and submit the user's password. The OAuth security guidance in RFC 9700 prohibits this flow.
Potential impact
A compromised client or mishandled credentials can expose the user's password. The flow is also unsuitable for authentication such as MFA that requires multiple user interactions.
Remediation
For interactive user authorization, move to the authorization code flow with PKCE. In OpenAPI 2.0, use flow: accessCode with HTTPS authorization and token URLs. Update the actual clients and authorization server together, then disable the password flow.
Examples
The example keeps the global oauth2 requirement while changing its flow. Use your provider's URLs and configure PKCE in the client and authorization server separately.
Before
{
"securityDefinitions": {
"oauth2": {
"type": "oauth2",
"flow": "password",
"tokenUrl": "https://api.example.com/oauth/token",
"scopes": {}
}
},
"security": [
{
"oauth2": []
}
]
}
After
{
"securityDefinitions": {
"oauth2": {
"type": "oauth2",
"flow": "accessCode",
"authorizationUrl": "https://api.example.com/oauth/authorize",
"tokenUrl": "https://api.example.com/oauth/token",
"scopes": {}
}
},
"security": [
{
"oauth2": []
}
]
}