An OpenAPI 3.0 scheme uses the OAuth2 implicit flow

The OAuth2 implicit flow returns an access token in the authorization response, increasing leakage risks.

Description

OpenAPI 3.0 OAuth2 flows.implicit defines a flow that includes an access token in the authorization response. Replacing it with the authorization code flow using PKCE is generally recommended because of token leakage and injection risks.

Potential impact

A token exposed during redirection can enable unauthorized access within its permissions. A client that accepts an injected token may also operate under the wrong account.

Remediation

Move the actual clients and authorization server to the authorization code flow with PKCE, and update the definition to authorizationCode. Use HTTPS endpoints. Clients must still protect the tokens they receive with this flow.

Examples

The excerpts switch petstore_auth to the authorization code flow and correct the authorization URL to HTTPS. Use your provider's URLs and implement PKCE in the actual clients and server.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "oauth2",
        "flows": {
          "implicit": {
            "authorizationUrl": "http://example.org/api/oauth/dialog",
            "scopes": {
              "write:pets": "modify pets in your account",
              "read:pets": "read your pets"
            }
          }
        }
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://example.org/api/oauth/dialog",
            "tokenUrl": "https://example.com/api/oauth/token",
            "scopes": {
              "write:pets": "modify pets in your account",
              "read:pets": "read your pets"
            }
          }
        }
      }
    }
  }
}

References