Global security contains an empty object

An empty requirement object in global security allows an unauthenticated alternative.

Description

An empty requirement object {} in the global security array allows unauthenticated access as an alternative. Other entries do not make authentication mandatory because only one requirement needs to be satisfied. In contrast, security: {} makes the field itself an object and violates the required array format.

Potential impact

If shared authentication was intended, operations using this policy are also documented as allowing anonymous access. Clients and servers may apply different access policies.

Remediation

When authentication is mandatory, remove empty objects from the array and reference only defined authentication schemes. The security value must itself be an array, so security: {} is invalid. Decide whether public access is appropriate based on the service's actual policy.

Examples

The example replaces the empty requirement with the exampleSecurity API key requirement. Enforce the same authentication policy on the server.

Before

json
{
  "openapi": "3.0.0",
  "paths": {
    "/": {
      "get": {
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  },
  "security": [
    {}
  ],
  "info": {
    "title": "Simple API overview",
    "version": "1.0.0"
  },
  "components": {
    "securitySchemes": {
      "exampleSecurity": {
        "type": "apiKey",
        "in": "header",
        "name": "X-API-Key"
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "paths": {
    "/": {
      "get": {
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  },
  "security": [
    {
      "exampleSecurity": []
    }
  ],
  "info": {
    "title": "Simple API overview",
    "version": "1.0.0"
  },
  "components": {
    "securitySchemes": {
      "exampleSecurity": {
        "type": "apiKey",
        "in": "header",
        "name": "X-API-Key"
      }
    }
  }
}

References