Invalid OAuth2 authorization URL in OpenAPI 2.0

An incorrect OAuth2 authorization URL in OpenAPI 2.0 can prevent login and consent.

Description

The OAuth2 accessCode and implicit flows in OpenAPI 2.0 use authorizationUrl to direct users to login and consent. It must identify the correct authorization endpoint of a trusted authorization server.

Potential impact

An incorrect address can prevent login and consent. If it points to an unintended server, users may also enter credentials on that server.

Remediation

Set authorizationUrl to the HTTPS authorization endpoint supplied by the identity provider. Check the host and path and remove any URL fragment (the part after #). Use accessCode with PKCE for new integrations.

Examples

The example shows the URL correction. Set the authorization code flow's tokenUrl to match the same provider's configuration.

Before

yaml
swagger: "2.0"
securityDefinitions:
  petstore_auth:
    type: oauth2
    flow: accessCode
    authorizationUrl: https://api.invalid.comp@#any.com/oauth/authorize
    tokenUrl: https://api.my.company.com/oauth/token
    scopes:
      read:pets: read pets

After

yaml
swagger: "2.0"
securityDefinitions:
  petstore_auth:
    type: oauth2
    flow: accessCode
    authorizationUrl: https://api.my.company.com/oauth/authorize
    tokenUrl: https://api.my.company.com/oauth/token
    scopes:
      read:pets: read pets

References