FAQ

  • GitHub GitHub Repo stars
  • Discord Discord Server
  • ✨ New! Try the OpenAPI Doctor ✨ The OpenAPI Doctor
    Recommended

    owasp-oauth-no-implicit


    Formats: Severity:

    The OAuth implicit flow returns access tokens through the browser authorization response. Use authorization code with PKCE for user authorization instead.

    This rule reports OAuth security schemes that declare an implicit flow.

    Bad example

    openapi: "3.1.0"
    info:
      title: Chicken Nuggets API
      version: "1.0"
    paths: {}
    components:
      securitySchemes:
        NuggetsAuth:
          type: oauth2
          flows:
            implicit:
              authorizationUrl: https://auth.quobix.com/authorize
              scopes:
                nuggets:read: Read chicken nuggets
    

    Good Example

    openapi: "3.1.0"
    info:
      title: Chicken Nuggets API
      version: "1.0"
    paths: {}
    components:
      securitySchemes:
        NuggetsAuth:
          type: oauth2
          flows:
            authorizationCode:
              authorizationUrl: https://auth.quobix.com/authorize
              tokenUrl: https://auth.quobix.com/token
              scopes:
                nuggets:read: Read chicken nuggets
    

    How do I fix this violation?

    Use authorization code with PKCE for user authorization. OpenAPI documents the flow and endpoints; configure and test PKCE in your client and authorization server too. This rule does not verify PKCE at runtime.

    The clientCredentials flow is still available for machine-to-machine access. Choose the flow that fits the caller.

    Read the OWASP OAuth2 Cheat Sheet for more guidance.