Description
OpenAPI 3.0 OAuth2 flows.implicit defines a flow that includes an access token in the authorization response. Replacing it with the authorization code flow using PKCE is generally recommended because of token leakage and injection risks.
Potential impact
A token exposed during redirection can enable unauthorized access within its permissions. A client that accepts an injected token may also operate under the wrong account.
Remediation
Move the actual clients and authorization server to the authorization code flow with PKCE, and update the definition to authorizationCode. Use HTTPS endpoints. Clients must still protect the tokens they receive with this flow.
Examples
The excerpts switch petstore_auth to the authorization code flow and correct the authorization URL to HTTPS. Use your provider's URLs and implement PKCE in the actual clients and server.
Before
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"implicit": {
"authorizationUrl": "http://example.org/api/oauth/dialog",
"scopes": {
"write:pets": "modify pets in your account",
"read:pets": "read your pets"
}
}
}
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://example.org/api/oauth/dialog",
"tokenUrl": "https://example.com/api/oauth/token",
"scopes": {
"write:pets": "modify pets in your account",
"read:pets": "read your pets"
}
}
}
}
}
}
}