설명
OpenAPI 2.0의 securityDefinitions에 OAuth2 password 흐름을 정의하면 사용자 비밀번호를 클라이언트에 전달하는 방식을 문서화하게 됩니다. 현재 OAuth 보안 모범 사례는 이 흐름의 사용을 금지합니다.
잠재적 영향
사용자 비밀번호를 취급하는 클라이언트가 늘어나 노출 위험이 커집니다. 여러 단계가 필요한 MFA나 브라우저를 통한 로그인을 지원하기도 어렵습니다.
해결 방법
사용자 권한 위임에는 accessCode 흐름과 PKCE로 전환하십시오. 인증 서버와 클라이언트를 함께 변경하고 authorizationUrl, tokenUrl, scopes를 실제 설정과 맞추십시오.
예시
예시는 보안 방식 정의의 변경을 보여 줍니다. 정의한 방식은 전역 또는 작업별 security에서 참조해야 문서의 인증 요구사항으로 적용됩니다.
변경 전
json
{
"swagger": "2.0",
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "password",
"tokenUrl": "https://api.my.company.com/oauth/token"
}
}
}
변경 후
json
{
"swagger": "2.0",
"securityDefinitions": {
"petstore_auth": {
"type": "oauth2",
"flow": "accessCode",
"authorizationUrl": "https://api.my.company.com/oauth/authorize",
"tokenUrl": "https://api.my.company.com/oauth/token",
"scopes": {
"write:api": "modify apis in your account",
"read:api": "read your apis"
}
}
}
}