HTTP transport documented in OpenAPI 2.0

Check the documented API transport together with the actual HTTPS configuration.

Description

An http entry in OpenAPI 2.0 schemes documents support for HTTP transport. If credentials or sensitive data are actually sent over HTTP, someone on the communication path may read or alter them.

Operation-level schemes can override the global value. If schemes is omitted, the scheme used to retrieve the document applies. The specification alone does not establish the deployed server’s TLS configuration.

Potential impact

  • Passwords, tokens and personal data sent over HTTP may be disclosed.
  • Altered plaintext requests or responses can cause clients and servers to process incorrect data.

Remediation

Use HTTPS for sensitive communication and align global and operation-level schemes with the transports actually supported. Check TLS on servers and gateways, client certificate validation and rejection of plaintext requests. Redirecting to HTTPS does not protect an initial HTTP request already sent.

Examples

These excerpts compare global transport declarations. Other required document information, including info, is omitted.

Before

json
{
  "swagger": "2.0",
  "schemes": [
    "http"
  ],
  "paths": {
    "/": {
      "get": {
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  }
}

After

json
{
  "swagger": "2.0",
  "schemes": [
    "https"
  ],
  "paths": {
    "/": {
      "get": {
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  }
}

The second document declares HTTPS. Configure the actual server and clients to use HTTPS and check operation-level overrides as well.

References