Global authentication uses the OAuth2 password flow

The OAuth2 password flow makes the client handle the user's password directly.

Description

When global security in OpenAPI 2.0 references a password flow, the API's default authentication scheme requires the client to collect and submit the user's password. The OAuth security guidance in RFC 9700 prohibits this flow.

Potential impact

A compromised client or mishandled credentials can expose the user's password. The flow is also unsuitable for authentication such as MFA that requires multiple user interactions.

Remediation

For interactive user authorization, move to the authorization code flow with PKCE. In OpenAPI 2.0, use flow: accessCode with HTTPS authorization and token URLs. Update the actual clients and authorization server together, then disable the password flow.

Examples

The example keeps the global oauth2 requirement while changing its flow. Use your provider's URLs and configure PKCE in the client and authorization server separately.

Before

json
{
  "securityDefinitions": {
    "oauth2": {
      "type": "oauth2",
      "flow": "password",
      "tokenUrl": "https://api.example.com/oauth/token",
      "scopes": {}
    }
  },
  "security": [
    {
      "oauth2": []
    }
  ]
}

After

json
{
  "securityDefinitions": {
    "oauth2": {
      "type": "oauth2",
      "flow": "accessCode",
      "authorizationUrl": "https://api.example.com/oauth/authorize",
      "tokenUrl": "https://api.example.com/oauth/token",
      "scopes": {}
    }
  },
  "security": [
    {
      "oauth2": []
    }
  ]
}

References