Description
Defining an OAuth2 password flow in OpenAPI 2.0 securityDefinitions documents a flow that passes the user's password to the client. Current OAuth security best practices prohibit this flow.
Potential impact
More clients handle the user's password, increasing its exposure. The flow also makes multistep MFA and browser-based login difficult to support.
Remediation
For delegated user access, move to accessCode with PKCE. Update the authorization server and clients together, and align authorizationUrl, tokenUrl, and scopes with the actual configuration.
Examples
The example shows the scheme definition change. Global or operation-level security must reference the scheme to apply it as a documented authentication requirement.
Before
{
"swagger": "2.0",
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "password",
"tokenUrl": "https://api.my.company.com/oauth/token"
}
}
}
After
{
"swagger": "2.0",
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "accessCode",
"authorizationUrl": "https://api.my.company.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}