Description
An OpenAPI 3.0 operation using Basic authentication sends Base64-encoded credentials. The encoded value is not encrypted, so protect the connection with HTTPS. A Basic authentication setting alone does not establish that HTTP is used.
Potential impact
Sending Basic credentials over HTTP lets someone on the communication path read or reuse the password.
Remediation
Configure the actual operation server address and connection to use HTTPS with certificate validation. If migrating to OAuth2 for delegated user authorization, use the authorization code flow with PKCE and update server-side token and permission checks and the clients together. Token-based authentication also needs HTTPS.
Examples
These examples change the operation's connection from HTTP to HTTPS and its authentication requirement from Basic to OAuth2. Configure the actual servers and clients alongside the specification.
Before
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"regularSecurity": {
"type": "http",
"scheme": "basic"
}
}
},
"paths": {
"/": {
"get": {
"servers": [
{
"url": "http://myapi.com/"
}
],
"security": [
{
"regularSecurity": []
}
]
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"OAuth2": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://myapi.com/oauth/authorize",
"tokenUrl": "https://myapi.com/oauth/token",
"scopes": {
"write": "modify objects",
"read": "read objects"
}
}
}
}
}
},
"paths": {
"/": {
"get": {
"servers": [
{
"url": "https://myapi.com/"
}
],
"security": [
{
"OAuth2": [
"write",
"read"
]
}
]
}
}
}
}