Description
When an OpenAPI 2.0 operation uses an OAuth2 password scheme, the client collects the user's password and submits it to obtain a token. RFC 9700 prohibits this flow.
Potential impact
More components handle the password, increasing its exposure. Authentication requiring several user interactions, such as MFA, is difficult to support with this flow.
Remediation
For interactive user authorization, switch to the accessCode flow with PKCE. Match the scheme and scopes referenced by the operation's security, and update the clients and authorization server as well.
Examples
The example retains the read operation's petstore_auth reference and uses the authorization code flow with the read:api scope. Replace the URLs with your provider's endpoints and implement PKCE in the actual clients and server.
Before
{
"swagger": "2.0",
"paths": {
"/": {
"get": {
"security": [
{
"petstore_auth": [
"read:api"
]
}
]
}
}
},
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "password",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"read:api": "read your apis"
}
}
}
}
After
{
"swagger": "2.0",
"paths": {
"/": {
"get": {
"security": [
{
"petstore_auth": [
"read:api"
]
}
]
}
}
},
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "accessCode",
"authorizationUrl": "https://api.my.company.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}