owasp-auth-urls-https
Authentication endpoints handle credentials, authorization codes, and tokens. Give them the same transport protection as the rest of your API.
This rule checks authorizationUrl, tokenUrl, and refreshUrl in OAuth flows, and openIdConnectUrl in OpenID Connect security schemes. An explicit URL scheme must be https.
Bad example
openapi: "3.1.0"
info:
title: Chicken Nuggets API
version: "1.0"
paths: {}
components:
securitySchemes:
NuggetsAuth:
type: oauth2
flows:
clientCredentials:
tokenUrl: http://auth.quobix.com/token
scopes: {}
NuggetsIdentity:
type: openIdConnect
openIdConnectUrl: http://auth.quobix.com/.well-known/openid-configuration
Good Example
openapi: "3.1.0"
info:
title: Chicken Nuggets API
version: "1.0"
paths: {}
components:
securitySchemes:
NuggetsAuth:
type: oauth2
flows:
clientCredentials:
tokenUrl: https://auth.quobix.com/token
scopes: {}
NuggetsIdentity:
type: openIdConnect
openIdConnectUrl: https://auth.quobix.com/.well-known/openid-configuration
How do I fix this violation?
Use https:// for each authentication endpoint with an explicit scheme. Check authorization, token, refresh, and discovery URLs, including flows you use less often.
Relative URLs, such as /oauth/token, are accepted. They inherit transport from their deployment location, so make sure that location uses HTTPS. The rule checks declarations; it does not contact the identity provider or test its TLS configuration.
