Description
An operation's security: [] removes the global authentication requirement and declares that the operation needs no authentication. This is valid for a public operation, but using it accidentally on a protected operation makes the specification inconsistent with the intended policy.
Potential impact
Reviewing only the global policy can miss a public-access exception for an individual operation. Clients following the specification may omit credentials for that operation.
Remediation
Remove the operation's empty security field to inherit the global policy. If a different requirement is needed, specify its defined scheme and required scopes at operation level. Keep empty arrays only for intentionally public operations, and check the server's policy too.
Examples
The example replaces an empty array on a read operation with a requirement for the OAuth2 read scope. Replace the example OAuth2 URLs with your provider's URLs.
Before
{
"openapi": "3.0.0",
"paths": {
"/": {
"get": {
"security": [],
"responses": {
"200": {
"description": "ok"
}
}
}
}
},
"security": [
{
"OAuth2": [
"read"
]
}
],
"info": {
"title": "Simple API overview",
"version": "1.0.0"
},
"components": {
"securitySchemes": {
"OAuth2": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://example.com/oauth/authorize",
"tokenUrl": "https://example.com/oauth/token",
"scopes": {
"read": "Read API versions"
}
}
}
}
}
}
}
After
{
"openapi": "3.0.0",
"paths": {
"/": {
"get": {
"security": [
{
"OAuth2": [
"read"
]
}
],
"responses": {
"200": {
"description": "ok"
}
}
}
}
},
"security": [
{
"OAuth2": [
"read"
]
}
],
"info": {
"title": "Simple API overview",
"version": "1.0.0"
},
"components": {
"securitySchemes": {
"OAuth2": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://example.com/oauth/authorize",
"tokenUrl": "https://example.com/oauth/token",
"scopes": {
"read": "Read API versions"
}
}
}
}
}
}
}