Description
HTTP Digest uses challenge-response authentication instead of sending the password directly. However, it does not encrypt the HTTP body, and weak passwords may be guessed from captured authentication values.
Potential impact
Without HTTPS, request and response content may be exposed. Guessing a weak password may also allow account impersonation.
Remediation
Use HTTPS, strong passwords, and a supported secure algorithm. Check Digest support in the server and clients; consider an alternative such as OAuth2 if it cannot meet your delegated-authorization or compatibility needs.
Examples
These excerpts show switching from Digest to OAuth2 as an option. Digest is not inherently an invalid configuration, and switching requires actual server and client support. Protect API traffic with HTTPS whichever method you use.
Before
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "http",
"scheme": "digest"
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://example.com/api/oauth/dialog",
"tokenUrl": "https://example.com/api/oauth/token",
"scopes": {
"read:pets": "read your pets"
}
}
}
}
}
}
}