Description
In OpenAPI 3.0, an OAuth2 flow's tokenUrl identifies its token endpoint. Flows that require a token endpoint must use a valid URL and connect to the provider's actual token server over HTTPS.
Potential impact
An incorrect endpoint can prevent token issuance needed for authentication. Using HTTP or the wrong destination can expose credentials or tokens.
Remediation
Set the provider's official HTTPS tokenUrl on the applicable OAuth2 flow under components.securitySchemes. Omit URL fragments and check the client's actual destination and server certificate validation.
Examples
These examples change the token URL for the authorization code flow. The HTTP address with a fragment is replaced with the provider's correct HTTPS address.
Before
openapi: 3.0.0
components:
securitySchemes:
petstore_auth:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://api.my.company.com/oauth/authorize
tokenUrl: http://example.com#@evil.com/
scopes:
read:api: read your apis
After
openapi: 3.0.0
components:
securitySchemes:
petstore_auth:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://api.my.company.com/oauth/authorize
tokenUrl: https://api.my.company.com/oauth/token
scopes:
read:api: read your apis