Description
When both an operation and the top-level document omit security, the specification declares no authentication requirement for that operation. This can be appropriate for an intentionally public operation, but a protected operation needs an explicit requirement.
Potential impact
Developers or client generators using the specification may implement calls without credentials. Whether the server actually enforces authentication must be checked separately.
Remediation
Define the actual authentication scheme and reference it in global or operation-level security. Distinguish public operations from protected ones and align the specification with the server's policy.
Examples
The example defines an API key scheme named exampleSecurity and applies it to the operation through global security.
Before
{
"openapi": "3.0.0",
"info": {
"title": "Simple API overview",
"version": "1.0.0"
},
"paths": {
"/": {
"get": {
"responses": {
"200": {
"description": "ok"
}
}
}
}
},
"components": {
"securitySchemes": {
"exampleSecurity": {
"type": "apiKey",
"in": "header",
"name": "X-API-Key"
}
}
}
}
After
{
"openapi": "3.0.0",
"info": {
"title": "Simple API overview",
"version": "1.0.0"
},
"paths": {
"/": {
"get": {
"responses": {
"200": {
"description": "ok"
}
}
}
}
},
"security": [
{
"exampleSecurity": []
}
],
"components": {
"securitySchemes": {
"exampleSecurity": {
"type": "apiKey",
"in": "header",
"name": "X-API-Key"
}
}
}
}