OAuth2 password flow in security definitions

The OAuth2 password flow gives the client the user's password and must not be used.

Description

Defining an OAuth2 password flow in OpenAPI 2.0 securityDefinitions documents a flow that passes the user's password to the client. Current OAuth security best practices prohibit this flow.

Potential impact

More clients handle the user's password, increasing its exposure. The flow also makes multistep MFA and browser-based login difficult to support.

Remediation

For delegated user access, move to accessCode with PKCE. Update the authorization server and clients together, and align authorizationUrl, tokenUrl, and scopes with the actual configuration.

Examples

The example shows the scheme definition change. Global or operation-level security must reference the scheme to apply it as a documented authentication requirement.

Before

json
{
  "swagger": "2.0",
  "securityDefinitions": {
    "petstore_auth": {
      "type": "oauth2",
      "flow": "password",
      "tokenUrl": "https://api.my.company.com/oauth/token"
    }
  }
}

After

json
{
  "swagger": "2.0",
  "securityDefinitions": {
    "petstore_auth": {
      "type": "oauth2",
      "flow": "accessCode",
      "authorizationUrl": "https://api.my.company.com/oauth/authorize",
      "tokenUrl": "https://api.my.company.com/oauth/token",
      "scopes": {
        "write:api": "modify apis in your account",
        "read:api": "read your apis"
      }
    }
  }
}

References