Description
An http entry in OpenAPI 2.0 schemes documents support for HTTP transport. If credentials or sensitive data are actually sent over HTTP, someone on the communication path may read or alter them.
Operation-level schemes can override the global value. If schemes is omitted, the scheme used to retrieve the document applies. The specification alone does not establish the deployed server’s TLS configuration.
Potential impact
- Passwords, tokens and personal data sent over HTTP may be disclosed.
- Altered plaintext requests or responses can cause clients and servers to process incorrect data.
Remediation
Use HTTPS for sensitive communication and align global and operation-level schemes with the transports actually supported. Check TLS on servers and gateways, client certificate validation and rejection of plaintext requests. Redirecting to HTTPS does not protect an initial HTTP request already sent.
Examples
These excerpts compare global transport declarations. Other required document information, including info, is omitted.
Before
{
"swagger": "2.0",
"schemes": [
"http"
],
"paths": {
"/": {
"get": {
"responses": {
"200": {
"description": "ok"
}
}
}
}
}
}
After
{
"swagger": "2.0",
"schemes": [
"https"
],
"paths": {
"/": {
"get": {
"responses": {
"200": {
"description": "ok"
}
}
}
}
}
}
The second document declares HTTPS. Configure the actual server and clients to use HTTPS and check operation-level overrides as well.