Description
When an OpenAPI 2.0 operation's security references an implicit flow, the client receives an access token directly in the authorization response. This flow is discouraged because of token leakage and injection risks.
Potential impact
A token leaked during redirection can be used to abuse its permissions. A client that accepts an attacker-supplied token may also perform actions under an unintended account.
Remediation
Move to the authorization code flow with PKCE and change the securityDefinitions flow to accessCode. Match the operation's required scopes to their definitions. Update the actual clients and authorization server to complete the change.
Examples
The example retains the petstore_auth reference and switches to the authorization code flow. The GET operation requires only the defined read:api scope. Use your provider's URLs and implement PKCE in the actual clients and server.
Before
{
"swagger": "2.0",
"paths": {
"/": {
"get": {
"security": [
{
"petstore_auth": []
}
]
}
}
},
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "implicit",
"authorizationUrl": "https://api.my.company.com/oauth/authorize",
"scopes": {
"read:api": "read your apis"
}
}
}
}
After
{
"swagger": "2.0",
"paths": {
"/": {
"get": {
"security": [
{
"petstore_auth": [
"read:api"
]
}
]
}
}
},
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "accessCode",
"authorizationUrl": "https://api.my.company.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}