Description
In OpenAPI 3.0, an operation's servers overrides path-level or global server settings. An HTTP address lets clients select a plaintext connection for that operation even when the global default is HTTPS.
Potential impact
Requests and responses using the HTTP connection can be exposed or modified in transit.
Remediation
Change the operation's server addresses to HTTPS, or remove the override to inherit an HTTPS configuration. Update the connection settings on the actual servers and gateways as well.
Examples
These excerpts change the staging address for GET / to HTTPS and add an HTTPS production address.
Before
json
{
"openapi": "3.0.0",
"paths": {
"/": {
"get": {
"servers": [
{
"url": "https://development.gigantic-server.com/v1"
},
{
"url": "http://staging.gigantic-server.com/v1"
}
]
}
}
}
}
After
json
{
"openapi": "3.0.0",
"paths": {
"/": {
"get": {
"servers": [
{
"url": "https://development.gigantic-server.com/v1"
},
{
"url": "https://staging.gigantic-server.com/v1"
},
{
"url": "https://api.gigantic-server.com/v1"
}
]
}
}
}
}