Description
The OAuth2 authorizationCode and implicit flows in OpenAPI 3.0 use authorizationUrl for login and consent. An incorrect address can prevent users from completing authorization.
Potential impact
Login or consent may fail in clients and test tools that use the document. An address pointing to an untrusted server can also put credentials at risk.
Remediation
Specify a trusted HTTPS authorization URL for the relevant flow under components.securitySchemes. Omit URL fragments and verify the provider's host and path. Use the authorization code flow with PKCE.
Examples
In the before example, #@evil.com/oauth/authorize is a fragment. Authorization endpoint URLs cannot contain fragments. The after example identifies the authorization path on the correct server.
Before
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://api.invalid.company.com#@evil.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://api.my.company.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}
}
}
}