説明
OpenAPI 3.0のOAuth2のauthorizationCodeとimplicitフローは、authorizationUrlでログインと同意の画面を指定します。アドレスが誤っていると、利用者が認可の手続きを完了できない可能性があります。
想定される影響
文書を使用するクライアントやテストツールで、ログインや同意の手続きに失敗する可能性があります。信頼できないサーバーを指している場合は、認証情報の漏えいにもつながり得ます。
対処方法
components.securitySchemes内の該当するフローに、信頼できるHTTPSの認可URLを指定します。フラグメントを含めず、プロバイダーのホストとパスを確認してください。認可コードフローはPKCEと併用してください。
例
変更前のURLの#@evil.com/oauth/authorizeはフラグメントです。認可エンドポイントのURLにフラグメントは使用できません。変更後は、正しいサーバーの認可パスを指定しています。
変更前
json
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://api.invalid.company.com#@evil.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}
}
}
}
変更後
json
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://api.my.company.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}
}
}
}