Review protection for OpenAPI HTTP Basic authentication

Protect credentials and connections that use HTTP Basic authentication.

Description

In OpenAPI 3.0, type: http with scheme: basic defines username-and-password Basic authentication. The http category does not exclude HTTPS. Connections that actually use this authentication need transport protection.

Potential impact

Without HTTPS, the Base64-encoded credentials can be exposed. A stolen password that remains valid may allow misuse of the account's permissions.

Remediation

Use HTTPS and server certificate validation and prevent password exposure. If delegated user authorization or limited token lifetimes are needed, consider an alternative such as the OAuth2 authorization code flow with PKCE. Update actual authentication handling and security references together when migrating.

Examples

These excerpts change only the authentication definition to OAuth2. Configure the required scopes, security requirements and actual clients and servers separately.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "http",
        "scheme": "basic"
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://example.com/api/oauth/dialog",
            "tokenUrl": "https://example.com/api/oauth/token",
            "scopes": {
              "read:pets": "read your pets"
            }
          }
        }
      }
    }
  }
}

References