An operation uses the OAuth2 password flow

Using the OAuth2 password flow for an operation makes clients submit the user's password directly.

Description

When an OpenAPI 2.0 operation uses an OAuth2 password scheme, the client collects the user's password and submits it to obtain a token. RFC 9700 prohibits this flow.

Potential impact

More components handle the password, increasing its exposure. Authentication requiring several user interactions, such as MFA, is difficult to support with this flow.

Remediation

For interactive user authorization, switch to the accessCode flow with PKCE. Match the scheme and scopes referenced by the operation's security, and update the clients and authorization server as well.

Examples

The example retains the read operation's petstore_auth reference and uses the authorization code flow with the read:api scope. Replace the URLs with your provider's endpoints and implement PKCE in the actual clients and server.

Before

json
{
  "swagger": "2.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "petstore_auth": [
              "read:api"
            ]
          }
        ]
      }
    }
  },
  "securityDefinitions": {
    "petstore_auth": {
      "type": "oauth2",
      "flow": "password",
      "tokenUrl": "https://api.my.company.com/oauth/token",
      "scopes": {
        "read:api": "read your apis"
      }
    }
  }
}

After

json
{
  "swagger": "2.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "petstore_auth": [
              "read:api"
            ]
          }
        ]
      }
    }
  },
  "securityDefinitions": {
    "petstore_auth": {
      "type": "oauth2",
      "flow": "accessCode",
      "authorizationUrl": "https://api.my.company.com/oauth/authorize",
      "tokenUrl": "https://api.my.company.com/oauth/token",
      "scopes": {
        "write:api": "modify apis in your account",
        "read:api": "read your apis"
      }
    }
  }
}

References