Description
An empty requirement object {} in the global security array allows unauthenticated access as an alternative. Other entries do not make authentication mandatory because only one requirement needs to be satisfied. In contrast, security: {} makes the field itself an object and violates the required array format.
Potential impact
If shared authentication was intended, operations using this policy are also documented as allowing anonymous access. Clients and servers may apply different access policies.
Remediation
When authentication is mandatory, remove empty objects from the array and reference only defined authentication schemes. The security value must itself be an array, so security: {} is invalid. Decide whether public access is appropriate based on the service's actual policy.
Examples
The example replaces the empty requirement with the exampleSecurity API key requirement. Enforce the same authentication policy on the server.
Before
{
"openapi": "3.0.0",
"paths": {
"/": {
"get": {
"responses": {
"200": {
"description": "ok"
}
}
}
}
},
"security": [
{}
],
"info": {
"title": "Simple API overview",
"version": "1.0.0"
},
"components": {
"securitySchemes": {
"exampleSecurity": {
"type": "apiKey",
"in": "header",
"name": "X-API-Key"
}
}
}
}
After
{
"openapi": "3.0.0",
"paths": {
"/": {
"get": {
"responses": {
"200": {
"description": "ok"
}
}
}
}
},
"security": [
{
"exampleSecurity": []
}
],
"info": {
"title": "Simple API overview",
"version": "1.0.0"
},
"components": {
"securitySchemes": {
"exampleSecurity": {
"type": "apiKey",
"in": "header",
"name": "X-API-Key"
}
}
}
}