Description
In OpenAPI 3.0, type: http with scheme: basic defines username-and-password Basic authentication. The http category does not exclude HTTPS. Connections that actually use this authentication need transport protection.
Potential impact
Without HTTPS, the Base64-encoded credentials can be exposed. A stolen password that remains valid may allow misuse of the account's permissions.
Remediation
Use HTTPS and server certificate validation and prevent password exposure. If delegated user authorization or limited token lifetimes are needed, consider an alternative such as the OAuth2 authorization code flow with PKCE. Update actual authentication handling and security references together when migrating.
Examples
These excerpts change only the authentication definition to OAuth2. Configure the required scopes, security requirements and actual clients and servers separately.
Before
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "http",
"scheme": "basic"
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://example.com/api/oauth/dialog",
"tokenUrl": "https://example.com/api/oauth/token",
"scopes": {
"read:pets": "read your pets"
}
}
}
}
}
}
}