Review the Basic authentication definition in OpenAPI 2.0

Check where the Basic authentication definition is used and how credentials are protected.

Description

In OpenAPI 2.0, type: basic in securityDefinitions defines a reusable Basic authentication scheme. The definition does not apply to every operation automatically; global or operation-level security must reference it.

Potential impact

Basic authentication sends a Base64-encoded username and password. Encoding is not encryption, so using it without HTTPS can expose credentials, and a stolen password may be reused.

Remediation

Use HTTPS and server certificate validation for connections using Basic authentication. For APIs that need delegated user authorization, consider an alternative such as the OAuth2 authorization code flow with PKCE. Update actual clients, servers and security references together when migrating.

Examples

These examples change the scheme to OAuth2 while keeping its name. Configure the relevant security references and actual authorization server separately.

Before

json
{
  "swagger": "2.0",
  "securityDefinitions": {
    "petstore_auth": {
      "type": "basic",
      "description": "Basic authentication"
    }
  }
}

After

json
{
  "swagger": "2.0",
  "securityDefinitions": {
    "petstore_auth": {
      "type": "oauth2",
      "flow": "accessCode",
      "authorizationUrl": "https://api.my.company.com/oauth/authorize",
      "tokenUrl": "https://api.my.company.com/oauth/token",
      "scopes": {
        "write:api": "modify apis in your account",
        "read:api": "read your apis"
      }
    }
  }
}

References