An OpenAPI operation allows HTTP

HTTP in operation-level schemes advertises plaintext communication for that operation.

Description

In OpenAPI 2.0, schemes on an operation such as get overrides the global transport protocols. Including http documents HTTP as an option for that operation even when the global setting is HTTPS.

Potential impact

If a client uses the HTTP address, credentials or response data can be exposed or modified in transit.

Remediation

Remove http from the operation's schemes and use https. Alternatively, remove the override to inherit a global HTTPS setting. Configure HTTPS on the actual endpoint as well.

Examples

These examples change the transport protocol for GET /. The schemes property belongs to the Operation Object, not the Path Item itself.

Before

json
{
  "swagger": "2.0",
  "paths": {
    "/": {
      "get": {
        "schemes": [
          "http"
        ],
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  }
}

After

json
{
  "swagger": "2.0",
  "paths": {
    "/": {
      "get": {
        "schemes": [
          "https"
        ],
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  }
}

References