An OpenAPI operation server uses HTTP

An HTTP operation server address can send that API call over a plaintext connection.

Description

In OpenAPI 3.0, an operation's servers overrides path-level or global server settings. An HTTP address lets clients select a plaintext connection for that operation even when the global default is HTTPS.

Potential impact

Requests and responses using the HTTP connection can be exposed or modified in transit.

Remediation

Change the operation's server addresses to HTTPS, or remove the override to inherit an HTTPS configuration. Update the connection settings on the actual servers and gateways as well.

Examples

These excerpts change the staging address for GET / to HTTPS and add an HTTPS production address.

Before

json
{
  "openapi": "3.0.0",
  "paths": {
    "/": {
      "get": {
        "servers": [
          {
            "url": "https://development.gigantic-server.com/v1"
          },
          {
            "url": "http://staging.gigantic-server.com/v1"
          }
        ]
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "paths": {
    "/": {
      "get": {
        "servers": [
          {
            "url": "https://development.gigantic-server.com/v1"
          },
          {
            "url": "https://staging.gigantic-server.com/v1"
          },
          {
            "url": "https://api.gigantic-server.com/v1"
          }
        ]
      }
    }
  }
}

References