Undefined OAuth2 scope in global security requirements

Global security requirements in OpenAPI 2.0 reference an undefined OAuth2 scope.

Description

In OpenAPI 2.0, a global security requirement is inconsistent when it references a scope missing from the corresponding OAuth2 scheme in securityDefinitions.

Potential impact

API users may misunderstand the required permissions, and document validation or client generation may fail.

Remediation

Match scope names in global security requirements to the scheme's scopes. Correct typos or remove unnecessary scopes. If a required scope is missing from the definition, add it to match the authorization server's actual permissions.

Examples

The example removes the undefined error:api scope. If that permission is actually required, correct its definition instead of removing the requirement.

Before

yaml
swagger: "2.0"
securityDefinitions:
  oAuth2AuthCode:
    type: oauth2
    flow: accessCode
    authorizationUrl: https://api.example.com/oauth/authorize
    tokenUrl: https://api.example.com/oauth/token
    scopes:
      read:api: read your apis
security:
  - oAuth2AuthCode:
      - read:api
      - error:api

After

yaml
swagger: "2.0"
securityDefinitions:
  oAuth2AuthCode:
    type: oauth2
    flow: accessCode
    authorizationUrl: https://api.example.com/oauth/authorize
    tokenUrl: https://api.example.com/oauth/token
    scopes:
      read:api: read your apis
security:
  - oAuth2AuthCode:
      - read:api

References