Description
In an OpenAPI 2.0 OAuth2 security definition, tokenUrl identifies the token endpoint. Use a correctly formed URL for the provider's actual endpoint and send token requests over HTTPS.
Potential impact
An incorrect address can prevent token issuance. Using HTTP or sending requests to the wrong server can expose credentials or tokens.
Remediation
Set tokenUrl in securityDefinitions to the provider's official token endpoint. Use HTTPS without a URL fragment, the part following #. Check that the client connects to the intended server and validates its certificate.
Examples
The before URL uses HTTP and contains a fragment, which is not allowed in a token endpoint URL. The after example uses the provider's HTTPS token address.
Before
swagger: "2.0"
securityDefinitions:
petstore_auth:
type: oauth2
flow: accessCode
authorizationUrl: https://api.my.company.com/oauth/authorize
tokenUrl: http://example.com#@evil.com/
scopes:
write:pets: modify pets
read:pets: read pets
After
swagger: "2.0"
securityDefinitions:
petstore_auth:
type: oauth2
flow: accessCode
authorizationUrl: https://api.my.company.com/oauth/authorize
tokenUrl: https://api.my.company.com/oauth/token
scopes:
write:pets: modify pets
read:pets: read pets