Description
An empty requirement object {} in an operation's security array allows unauthenticated access. In contrast, security: {} makes the field itself an object and violates the required array format. Operation-level settings override global authentication requirements.
Potential impact
An unintended empty requirement documents a protected operation as allowing anonymous access. Using an object instead of an array can fail specification validation or processing by related tools.
Remediation
Use an array for security and remove empty requirement objects from operations that require authentication. Specify defined schemes and the necessary scopes, or omit the operation's security field to inherit the global policy.
Examples
The first example uses the invalid security: {} format. The corrected example uses an array requiring the OAuth2 read scope. Replace the example OAuth2 URLs with your provider's URLs.
Before
{
"openapi": "3.0.0",
"paths": {
"/": {
"get": {
"security": {},
"responses": {
"200": {
"description": "ok"
}
}
}
}
},
"security": [
{
"OAuth2": [
"read"
]
}
],
"info": {
"title": "Simple API overview",
"version": "1.0.0"
},
"components": {
"securitySchemes": {
"OAuth2": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://example.com/oauth/authorize",
"tokenUrl": "https://example.com/oauth/token",
"scopes": {
"read": "Read API versions"
}
}
}
}
}
}
}
After
{
"openapi": "3.0.0",
"paths": {
"/": {
"get": {
"security": [
{
"OAuth2": [
"read"
]
}
],
"responses": {
"200": {
"description": "ok"
}
}
}
}
},
"security": [
{
"OAuth2": [
"read"
]
}
],
"info": {
"title": "Simple API overview",
"version": "1.0.0"
},
"components": {
"securitySchemes": {
"OAuth2": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://example.com/oauth/authorize",
"tokenUrl": "https://example.com/oauth/token",
"scopes": {
"read": "Read API versions"
}
}
}
}
}
}
}