Description
The OAuth2 accessCode and implicit flows in OpenAPI 2.0 use authorizationUrl to direct users to login and consent. It must identify the correct authorization endpoint of a trusted authorization server.
Potential impact
An incorrect address can prevent login and consent. If it points to an unintended server, users may also enter credentials on that server.
Remediation
Set authorizationUrl to the HTTPS authorization endpoint supplied by the identity provider. Check the host and path and remove any URL fragment (the part after #). Use accessCode with PKCE for new integrations.
Examples
The example shows the URL correction. Set the authorization code flow's tokenUrl to match the same provider's configuration.
Before
swagger: "2.0"
securityDefinitions:
petstore_auth:
type: oauth2
flow: accessCode
authorizationUrl: https://api.invalid.comp@#any.com/oauth/authorize
tokenUrl: https://api.my.company.com/oauth/token
scopes:
read:pets: read pets
After
swagger: "2.0"
securityDefinitions:
petstore_auth:
type: oauth2
flow: accessCode
authorizationUrl: https://api.my.company.com/oauth/authorize
tokenUrl: https://api.my.company.com/oauth/token
scopes:
read:pets: read pets