Description
In OpenAPI 2.0, type: basic in securityDefinitions defines a reusable Basic authentication scheme. The definition does not apply to every operation automatically; global or operation-level security must reference it.
Potential impact
Basic authentication sends a Base64-encoded username and password. Encoding is not encryption, so using it without HTTPS can expose credentials, and a stolen password may be reused.
Remediation
Use HTTPS and server certificate validation for connections using Basic authentication. For APIs that need delegated user authorization, consider an alternative such as the OAuth2 authorization code flow with PKCE. Update actual clients, servers and security references together when migrating.
Examples
These examples change the scheme to OAuth2 while keeping its name. Configure the relevant security references and actual authorization server separately.
Before
{
"swagger": "2.0",
"securityDefinitions": {
"petstore_auth": {
"type": "basic",
"description": "Basic authentication"
}
}
}
After
{
"swagger": "2.0",
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "accessCode",
"authorizationUrl": "https://api.my.company.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}