個別の操作にOAuth2パスワードフローを使用

操作の認証にOAuth2パスワードフローを使うと、クライアントがユーザーのパスワードを直接送信します。

説明

OpenAPI 2.0の操作がOAuth2のpassword方式を使用する場合、クライアントはユーザーのパスワードを受け取り、トークン取得のために送信します。RFC 9700はこのフローの使用を禁止しています。

想定される影響

パスワードを扱う構成要素が増えて漏えいの危険が高まり、MFAなど複数段階のユーザー操作を必要とする認証も適用しにくくなります。

対処方法

ユーザーが操作する認可では、PKCEを使用するaccessCodeフローに切り替えてください。操作のsecurityが参照する方式とスコープを一致させ、クライアントと認可サーバーも変更してください。

例

次の例では読み取り操作のpetstore_auth参照を維持し、認可コードフローとread:apiスコープを使用します。URLは実際のプロバイダーのものに置き換え、PKCEは実際のクライアントとサーバーに実装してください。

変更前

json
{
  "swagger": "2.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "petstore_auth": [
              "read:api"
            ]
          }
        ]
      }
    }
  },
  "securityDefinitions": {
    "petstore_auth": {
      "type": "oauth2",
      "flow": "password",
      "tokenUrl": "https://api.my.company.com/oauth/token",
      "scopes": {
        "read:api": "read your apis"
      }
    }
  }
}

変更後

json
{
  "swagger": "2.0",
  "paths": {
    "/": {
      "get": {
        "security": [
          {
            "petstore_auth": [
              "read:api"
            ]
          }
        ]
      }
    }
  },
  "securityDefinitions": {
    "petstore_auth": {
      "type": "oauth2",
      "flow": "accessCode",
      "authorizationUrl": "https://api.my.company.com/oauth/authorize",
      "tokenUrl": "https://api.my.company.com/oauth/token",
      "scopes": {
        "write:api": "modify apis in your account",
        "read:api": "read your apis"
      }
    }
  }
}

参考資料