Description
OpenAPI 2.0 flow: implicit defines an OAuth2 flow that returns an access token directly in the authorization response. The authorization code flow with PKCE is recommended for new implementations because of token leakage and injection risks.
Potential impact
A token exposed during redirection, or an attacker-supplied token accepted by the client, can lead to unintended access or account associations.
Remediation
Move the authorization server and clients to the authorization code flow with PKCE, and update the specification to flow: accessCode. Use the provider's actual HTTPS authorizationUrl and tokenUrl. Editing the specification alone does not change the running flow.
Examples
The example changes the oauth2 definition to the authorization code flow. Configure PKCE in the client and authorization server.
Before
{
"securityDefinitions": {
"oauth2": {
"type": "oauth2",
"flow": "implicit",
"authorizationUrl": "https://api.example.com/oauth/authorize",
"scopes": {}
}
}
}
After
{
"securityDefinitions": {
"oauth2": {
"type": "oauth2",
"flow": "accessCode",
"authorizationUrl": "https://api.example.com/oauth/authorize",
"tokenUrl": "https://api.example.com/oauth/token",
"scopes": {}
}
}
}