FAQ

  • GitHub GitHub Repo stars
  • Discord Discord Server
  • ✨ New! Try the OpenAPI Doctor ✨ The OpenAPI Doctor
    Recommended

    owasp-oauth-no-password


    Formats: Severity:

    The OAuth password flow asks an application to handle a user’s password. That puts credentials in more places than they need to be, and does not fit modern authentication such as multi-factor authentication.

    This rule reports OAuth security schemes that declare a password flow.

    Bad example

    openapi: "3.1.0"
    info:
      title: Chicken Nuggets API
      version: "1.0"
    paths: {}
    components:
      securitySchemes:
        NuggetsAuth:
          type: oauth2
          flows:
            password:
              tokenUrl: https://auth.quobix.com/token
              scopes:
                nuggets:read: Read chicken nuggets
    

    Good Example

    openapi: "3.1.0"
    info:
      title: Chicken Nuggets API
      version: "1.0"
    paths: {}
    components:
      securitySchemes:
        NuggetsAuth:
          type: oauth2
          flows:
            authorizationCode:
              authorizationUrl: https://auth.quobix.com/authorize
              tokenUrl: https://auth.quobix.com/token
              scopes:
                nuggets:read: Read chicken nuggets
    

    How do I fix this violation?

    Use authorization code with PKCE for user authorization. OpenAPI documents the flow and endpoints; configure and test PKCE in your client and authorization server too. This rule does not verify PKCE at runtime.

    The clientCredentials flow is still available for machine-to-machine access. Choose the flow that fits the caller.

    Read the OWASP OAuth2 Cheat Sheet for more guidance.