Description
When an OpenAPI 2.0 operation's security references a Basic authentication definition, it specifies username-and-password authentication for that operation. Basic authentication does not itself encrypt the connection.
Potential impact
Credentials sent without HTTPS can be exposed in transit. An attacker may reuse a stolen password with the account's permissions while it remains valid.
Remediation
Protect the actual operation endpoint with HTTPS and certificate validation. If moving to delegated authorization, configure the OAuth2 authorization code flow with PKCE and make the operation's security reference defined scopes. Enforce the required permissions on the server too.
Examples
These examples move GET / to OAuth2 and align its required scopes with the defined write:api and read:api. Request only the scopes the actual operation needs.
Before
{
"swagger": "2.0",
"paths": {
"/": {
"get": {
"security": [
{
"oAuth2AuthCodeNeg2": []
}
]
}
}
},
"securityDefinitions": {
"oAuth2AuthCodeNeg2": {
"type": "basic"
}
}
}
After
{
"swagger": "2.0",
"paths": {
"/": {
"get": {
"security": [
{
"oAuth2AuthCodeNeg2": [
"write:api",
"read:api"
]
}
]
}
}
},
"securityDefinitions": {
"oAuth2AuthCodeNeg2": {
"type": "oauth2",
"flow": "accessCode",
"authorizationUrl": "https://api.my.company.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}