Invalid OAuth2 authorization URL in OpenAPI 3.0

Check that the OAuth2 authorization URL in OpenAPI 3.0 identifies the correct authorization server endpoint.

Description

The OAuth2 authorizationCode and implicit flows in OpenAPI 3.0 use authorizationUrl for login and consent. An incorrect address can prevent users from completing authorization.

Potential impact

Login or consent may fail in clients and test tools that use the document. An address pointing to an untrusted server can also put credentials at risk.

Remediation

Specify a trusted HTTPS authorization URL for the relevant flow under components.securitySchemes. Omit URL fragments and verify the provider's host and path. Use the authorization code flow with PKCE.

Examples

In the before example, #@evil.com/oauth/authorize is a fragment. Authorization endpoint URLs cannot contain fragments. The after example identifies the authorization path on the correct server.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://api.invalid.company.com#@evil.com/oauth/authorize",
            "tokenUrl": "https://api.my.company.com/oauth/token",
            "scopes": {
              "write:api": "modify apis in your account",
              "read:api": "read your apis"
            }
          }
        }
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://api.my.company.com/oauth/authorize",
            "tokenUrl": "https://api.my.company.com/oauth/token",
            "scopes": {
              "write:api": "modify apis in your account",
              "read:api": "read your apis"
            }
          }
        }
      }
    }
  }
}

References