Review HTTP Digest authentication (OpenAPI 3.0)

Check transport protection and password strength for Digest authentication

Description

HTTP Digest uses challenge-response authentication instead of sending the password directly. However, it does not encrypt the HTTP body, and weak passwords may be guessed from captured authentication values.

Potential impact

Without HTTPS, request and response content may be exposed. Guessing a weak password may also allow account impersonation.

Remediation

Use HTTPS, strong passwords, and a supported secure algorithm. Check Digest support in the server and clients; consider an alternative such as OAuth2 if it cannot meet your delegated-authorization or compatibility needs.

Examples

These excerpts show switching from Digest to OAuth2 as an option. Digest is not inherently an invalid configuration, and switching requires actual server and client support. Protect API traffic with HTTPS whichever method you use.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "http",
        "scheme": "digest"
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://example.com/api/oauth/dialog",
            "tokenUrl": "https://example.com/api/oauth/token",
            "scopes": {
              "read:pets": "read your pets"
            }
          }
        }
      }
    }
  }
}

References