owasp-oauth-no-implicit
The OAuth implicit flow returns access tokens through the browser authorization response. Use authorization code with PKCE for user authorization instead.
This rule reports OAuth security schemes that declare an implicit flow.
Bad example
openapi: "3.1.0"
info:
title: Chicken Nuggets API
version: "1.0"
paths: {}
components:
securitySchemes:
NuggetsAuth:
type: oauth2
flows:
implicit:
authorizationUrl: https://auth.quobix.com/authorize
scopes:
nuggets:read: Read chicken nuggets
Good Example
openapi: "3.1.0"
info:
title: Chicken Nuggets API
version: "1.0"
paths: {}
components:
securitySchemes:
NuggetsAuth:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://auth.quobix.com/authorize
tokenUrl: https://auth.quobix.com/token
scopes:
nuggets:read: Read chicken nuggets
How do I fix this violation?
Use authorization code with PKCE for user authorization. OpenAPI documents the flow and endpoints; configure and test PKCE in your client and authorization server too. This rule does not verify PKCE at runtime.
The clientCredentials flow is still available for machine-to-machine access. Choose the flow that fits the caller.
Read the OWASP OAuth2 Cheat Sheet for more guidance.
