Description
In OpenAPI 2.0, a global security requirement is inconsistent when it references a scope missing from the corresponding OAuth2 scheme in securityDefinitions.
Potential impact
API users may misunderstand the required permissions, and document validation or client generation may fail.
Remediation
Match scope names in global security requirements to the scheme's scopes. Correct typos or remove unnecessary scopes. If a required scope is missing from the definition, add it to match the authorization server's actual permissions.
Examples
The example removes the undefined error:api scope. If that permission is actually required, correct its definition instead of removing the requirement.
Before
yaml
swagger: "2.0"
securityDefinitions:
oAuth2AuthCode:
type: oauth2
flow: accessCode
authorizationUrl: https://api.example.com/oauth/authorize
tokenUrl: https://api.example.com/oauth/token
scopes:
read:api: read your apis
security:
- oAuth2AuthCode:
- read:api
- error:api
After
yaml
swagger: "2.0"
securityDefinitions:
oAuth2AuthCode:
type: oauth2
flow: accessCode
authorizationUrl: https://api.example.com/oauth/authorize
tokenUrl: https://api.example.com/oauth/token
scopes:
read:api: read your apis
security:
- oAuth2AuthCode:
- read:api