An operation-level security array is empty

An empty operation-level security array removes the inherited authentication requirement.

Description

An operation's security: [] removes the global authentication requirement and declares that the operation needs no authentication. This is valid for a public operation, but using it accidentally on a protected operation makes the specification inconsistent with the intended policy.

Potential impact

Reviewing only the global policy can miss a public-access exception for an individual operation. Clients following the specification may omit credentials for that operation.

Remediation

Remove the operation's empty security field to inherit the global policy. If a different requirement is needed, specify its defined scheme and required scopes at operation level. Keep empty arrays only for intentionally public operations, and check the server's policy too.

Examples

The example replaces an empty array on a read operation with a requirement for the OAuth2 read scope. Replace the example OAuth2 URLs with your provider's URLs.

Before

json
{
  "openapi": "3.0.0",
  "paths": {
    "/": {
      "get": {
        "security": [],
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  },
  "security": [
    {
      "OAuth2": [
        "read"
      ]
    }
  ],
  "info": {
    "title": "Simple API overview",
    "version": "1.0.0"
  },
  "components": {
    "securitySchemes": {
      "OAuth2": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://example.com/oauth/authorize",
            "tokenUrl": "https://example.com/oauth/token",
            "scopes": {
              "read": "Read API versions"
            }
          }
        }
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "OAuth2": [
              "read"
            ]
          }
        ],
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  },
  "security": [
    {
      "OAuth2": [
        "read"
      ]
    }
  ],
  "info": {
    "title": "Simple API overview",
    "version": "1.0.0"
  },
  "components": {
    "securitySchemes": {
      "OAuth2": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://example.com/oauth/authorize",
            "tokenUrl": "https://example.com/oauth/token",
            "scopes": {
              "read": "Read API versions"
            }
          }
        }
      }
    }
  }
}

References