Review transport protection for Basic authentication on an OpenAPI 3.0 operation

Check that an operation using Basic authentication actually connects over HTTPS.

Description

An OpenAPI 3.0 operation using Basic authentication sends Base64-encoded credentials. The encoded value is not encrypted, so protect the connection with HTTPS. A Basic authentication setting alone does not establish that HTTP is used.

Potential impact

Sending Basic credentials over HTTP lets someone on the communication path read or reuse the password.

Remediation

Configure the actual operation server address and connection to use HTTPS with certificate validation. If migrating to OAuth2 for delegated user authorization, use the authorization code flow with PKCE and update server-side token and permission checks and the clients together. Token-based authentication also needs HTTPS.

Examples

These examples change the operation's connection from HTTP to HTTPS and its authentication requirement from Basic to OAuth2. Configure the actual servers and clients alongside the specification.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "regularSecurity": {
        "type": "http",
        "scheme": "basic"
      }
    }
  },
  "paths": {
    "/": {
      "get": {
        "servers": [
          {
            "url": "http://myapi.com/"
          }
        ],
        "security": [
          {
            "regularSecurity": []
          }
        ]
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "OAuth2": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://myapi.com/oauth/authorize",
            "tokenUrl": "https://myapi.com/oauth/token",
            "scopes": {
              "write": "modify objects",
              "read": "read objects"
            }
          }
        }
      }
    }
  },
  "paths": {
    "/": {
      "get": {
        "servers": [
          {
            "url": "https://myapi.com/"
          }
        ],
        "security": [
          {
            "OAuth2": [
              "write",
              "read"
            ]
          }
        ]
      }
    }
  }
}

References