Description
OpenAPI 3.0 OAuth2 flows.password defines a flow in which the client collects the user's password to request a token. RFC 9700 prohibits this flow because it exposes the user's credentials to the client.
Potential impact
A compromised client can expose the original password as well as access tokens. The flow is also unsuitable for multi-step or phishing-resistant authentication.
Remediation
For interactive user authorization, use authorizationCode with PKCE. Set HTTPS authorization and token URLs, update the actual clients and authorization server, then disable the password flow.
Examples
These excerpts change the flow definition for petstore_auth. Replace the URLs with your provider's endpoints. Check PKCE and the security requirements that apply this scheme in the actual configuration too.
Before
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"password": {
"tokenUrl": "https://example.com/api/oauth/token",
"scopes": {
"write:pets": "modify pets in your account",
"read:pets": "read your pets"
}
}
}
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://example.org/api/oauth/dialog",
"tokenUrl": "https://example.com/api/oauth/token",
"scopes": {
"write:pets": "modify pets in your account",
"read:pets": "read your pets"
}
}
}
}
}
}
}