Review Basic authentication for an OpenAPI 2.0 operation

Check transport protection and credential reuse risks for operation-level Basic authentication.

Description

When an OpenAPI 2.0 operation's security references a Basic authentication definition, it specifies username-and-password authentication for that operation. Basic authentication does not itself encrypt the connection.

Potential impact

Credentials sent without HTTPS can be exposed in transit. An attacker may reuse a stolen password with the account's permissions while it remains valid.

Remediation

Protect the actual operation endpoint with HTTPS and certificate validation. If moving to delegated authorization, configure the OAuth2 authorization code flow with PKCE and make the operation's security reference defined scopes. Enforce the required permissions on the server too.

Examples

These examples move GET / to OAuth2 and align its required scopes with the defined write:api and read:api. Request only the scopes the actual operation needs.

Before

json
{
  "swagger": "2.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "oAuth2AuthCodeNeg2": []
          }
        ]
      }
    }
  },
  "securityDefinitions": {
    "oAuth2AuthCodeNeg2": {
      "type": "basic"
    }
  }
}

After

json
{
  "swagger": "2.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "oAuth2AuthCodeNeg2": [
              "write:api",
              "read:api"
            ]
          }
        ]
      }
    }
  },
  "securityDefinitions": {
    "oAuth2AuthCodeNeg2": {
      "type": "oauth2",
      "flow": "accessCode",
      "authorizationUrl": "https://api.my.company.com/oauth/authorize",
      "tokenUrl": "https://api.my.company.com/oauth/token",
      "scopes": {
        "write:api": "modify apis in your account",
        "read:api": "read your apis"
      }
    }
  }
}

References