説明
OpenAPI 2.0の操作がOAuth2のpassword方式を使用する場合、クライアントはユーザーのパスワードを受け取り、トークン取得のために送信します。RFC 9700はこのフローの使用を禁止しています。
想定される影響
パスワードを扱う構成要素が増えて漏えいの危険が高まり、MFAなど複数段階のユーザー操作を必要とする認証も適用しにくくなります。
対処方法
ユーザーが操作する認可では、PKCEを使用するaccessCodeフローに切り替えてください。操作のsecurityが参照する方式とスコープを一致させ、クライアントと認可サーバーも変更してください。
例
次の例では読み取り操作のpetstore_auth参照を維持し、認可コードフローとread:apiスコープを使用します。URLは実際のプロバイダーのものに置き換え、PKCEは実際のクライアントとサーバーに実装してください。
変更前
json
{
"swagger": "2.0",
"paths": {
"/": {
"get": {
"security": [
{
"petstore_auth": [
"read:api"
]
}
]
}
}
},
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "password",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"read:api": "read your apis"
}
}
}
}
変更後
json
{
"swagger": "2.0",
"paths": {
"/": {
"get": {
"security": [
{
"petstore_auth": [
"read:api"
]
}
]
}
}
},
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "accessCode",
"authorizationUrl": "https://api.my.company.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}