Invalid OAuth2 token URL in OpenAPI 2.0

tokenUrl must identify the OAuth2 provider's correct token endpoint.

Description

In an OpenAPI 2.0 OAuth2 security definition, tokenUrl identifies the token endpoint. Use a correctly formed URL for the provider's actual endpoint and send token requests over HTTPS.

Potential impact

An incorrect address can prevent token issuance. Using HTTP or sending requests to the wrong server can expose credentials or tokens.

Remediation

Set tokenUrl in securityDefinitions to the provider's official token endpoint. Use HTTPS without a URL fragment, the part following #. Check that the client connects to the intended server and validates its certificate.

Examples

The before URL uses HTTP and contains a fragment, which is not allowed in a token endpoint URL. The after example uses the provider's HTTPS token address.

Before

yaml
swagger: "2.0"
securityDefinitions:
  petstore_auth:
    type: oauth2
    flow: accessCode
    authorizationUrl: https://api.my.company.com/oauth/authorize
    tokenUrl: http://example.com#@evil.com/
    scopes:
      write:pets: modify pets
      read:pets: read pets

After

yaml
swagger: "2.0"
securityDefinitions:
  petstore_auth:
    type: oauth2
    flow: accessCode
    authorizationUrl: https://api.my.company.com/oauth/authorize
    tokenUrl: https://api.my.company.com/oauth/token
    scopes:
      write:pets: modify pets
      read:pets: read pets

References