FAQ

  • GitHub GitHub Repo stars
  • Discord Discord Server
  • ✨ New! Try the OpenAPI Doctor ✨ The OpenAPI Doctor
    Recommended

    owasp-auth-urls-https


    Formats: Severity:

    Authentication endpoints handle credentials, authorization codes, and tokens. Give them the same transport protection as the rest of your API.

    This rule checks authorizationUrl, tokenUrl, and refreshUrl in OAuth flows, and openIdConnectUrl in OpenID Connect security schemes. An explicit URL scheme must be https.

    Bad example

    openapi: "3.1.0"
    info:
      title: Chicken Nuggets API
      version: "1.0"
    paths: {}
    components:
      securitySchemes:
        NuggetsAuth:
          type: oauth2
          flows:
            clientCredentials:
              tokenUrl: http://auth.quobix.com/token
              scopes: {}
        NuggetsIdentity:
          type: openIdConnect
          openIdConnectUrl: http://auth.quobix.com/.well-known/openid-configuration
    

    Good Example

    openapi: "3.1.0"
    info:
      title: Chicken Nuggets API
      version: "1.0"
    paths: {}
    components:
      securitySchemes:
        NuggetsAuth:
          type: oauth2
          flows:
            clientCredentials:
              tokenUrl: https://auth.quobix.com/token
              scopes: {}
        NuggetsIdentity:
          type: openIdConnect
          openIdConnectUrl: https://auth.quobix.com/.well-known/openid-configuration
    

    How do I fix this violation?

    Use https:// for each authentication endpoint with an explicit scheme. Check authorization, token, refresh, and discovery URLs, including flows you use less often.

    Relative URLs, such as /oauth/token, are accepted. They inherit transport from their deployment location, so make sure that location uses HTTPS. The rule checks declarations; it does not contact the identity provider or test its TLS configuration.