Description
Each authentication name used in OpenAPI 2.0 security must be defined in securityDefinitions. A reference to an undefined name leaves the required authentication mechanism and credentials unspecified.
Potential impact
An invalid reference can fail specification validation or client generation, or mislead developers about authentication requirements.
Remediation
Match each reference to an actual definition and define the required scopes when using OAuth2. Correct the specification to match the server's policy instead of simply deleting the authentication requirement.
Examples
The first example references an undefined petstore_auth scheme. The corrected example defines the scheme and its scopes. Replace the example OAuth2 URLs with those of your authentication provider.
Before
{
"swagger": "2.0",
"paths": {
"/": {
"get": {
"responses": {
"200": {
"description": "ok"
}
}
}
}
},
"security": [
{
"petstore_auth": [
"write:pets",
"read:pets"
]
}
],
"securityDefinitions": {
"api_key": {
"type": "apiKey",
"name": "api_key",
"in": "header"
}
},
"info": {
"title": "Simple API overview",
"version": "1.0.0"
}
}
After
{
"swagger": "2.0",
"paths": {
"/": {
"get": {
"responses": {
"200": {
"description": "ok"
}
}
}
}
},
"security": [
{
"petstore_auth": [
"write:pets",
"read:pets"
]
}
],
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "accessCode",
"authorizationUrl": "https://example.com/oauth/authorize",
"tokenUrl": "https://example.com/oauth/token",
"scopes": {
"write:pets": "modify pets in your account",
"read:pets": "read your pets"
}
}
},
"info": {
"title": "Simple API overview",
"version": "1.0.0"
}
}