An operation uses the OAuth2 implicit flow

The client receives an access token directly in the authorization response when an operation uses the OAuth2 implicit flow.

Description

When an OpenAPI 2.0 operation's security references an implicit flow, the client receives an access token directly in the authorization response. This flow is discouraged because of token leakage and injection risks.

Potential impact

A token leaked during redirection can be used to abuse its permissions. A client that accepts an attacker-supplied token may also perform actions under an unintended account.

Remediation

Move to the authorization code flow with PKCE and change the securityDefinitions flow to accessCode. Match the operation's required scopes to their definitions. Update the actual clients and authorization server to complete the change.

Examples

The example retains the petstore_auth reference and switches to the authorization code flow. The GET operation requires only the defined read:api scope. Use your provider's URLs and implement PKCE in the actual clients and server.

Before

json
{
  "swagger": "2.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "petstore_auth": []
          }
        ]
      }
    }
  },
  "securityDefinitions": {
    "petstore_auth": {
      "type": "oauth2",
      "flow": "implicit",
      "authorizationUrl": "https://api.my.company.com/oauth/authorize",
      "scopes": {
        "read:api": "read your apis"
      }
    }
  }
}

After

json
{
  "swagger": "2.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "petstore_auth": [
              "read:api"
            ]
          }
        ]
      }
    }
  },
  "securityDefinitions": {
    "petstore_auth": {
      "type": "oauth2",
      "flow": "accessCode",
      "authorizationUrl": "https://api.my.company.com/oauth/authorize",
      "tokenUrl": "https://api.my.company.com/oauth/token",
      "scopes": {
        "write:api": "modify apis in your account",
        "read:api": "read your apis"
      }
    }
  }
}

References