Review HTTPS use for global OpenAPI servers

Check that the default OpenAPI server addresses use HTTPS.

Description

In OpenAPI 3.0, global servers defines the API's default addresses. An HTTP address can lead clients to communicate in plaintext. If servers is omitted or empty, the default is the relative URL /, so check the protocol of the base URL used to resolve it.

Potential impact

If the actual connection uses HTTP, request credentials and response data can be exposed or modified in transit.

Remediation

Configure default server addresses to use HTTPS. Ensure relative URLs resolve against an HTTPS base URL and check path and operation server overrides. Configure HTTPS on the actual servers and gateways too.

Examples

These excerpts change the staging address to HTTPS and add an HTTPS production address.

Before

json
{
  "openapi": "3.0.0",
  "servers": [
    {
      "url": "https://development.gigantic-server.com/v1"
    },
    {
      "url": "http://staging.gigantic-server.com/v1"
    }
  ]
}

After

json
{
  "openapi": "3.0.0",
  "servers": [
    {
      "url": "https://development.gigantic-server.com/v1"
    },
    {
      "url": "https://staging.gigantic-server.com/v1"
    },
    {
      "url": "https://api.gigantic-server.com/v1"
    }
  ]
}

References