owasp-oauth-no-password
The OAuth password flow asks an application to handle a user’s password. That puts credentials in more places than they need to be, and does not fit modern authentication such as multi-factor authentication.
This rule reports OAuth security schemes that declare a password flow.
Bad example
openapi: "3.1.0"
info:
title: Chicken Nuggets API
version: "1.0"
paths: {}
components:
securitySchemes:
NuggetsAuth:
type: oauth2
flows:
password:
tokenUrl: https://auth.quobix.com/token
scopes:
nuggets:read: Read chicken nuggets
Good Example
openapi: "3.1.0"
info:
title: Chicken Nuggets API
version: "1.0"
paths: {}
components:
securitySchemes:
NuggetsAuth:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://auth.quobix.com/authorize
tokenUrl: https://auth.quobix.com/token
scopes:
nuggets:read: Read chicken nuggets
How do I fix this violation?
Use authorization code with PKCE for user authorization. OpenAPI documents the flow and endpoints; configure and test PKCE in your client and authorization server too. This rule does not verify PKCE at runtime.
The clientCredentials flow is still available for machine-to-machine access. Choose the flow that fits the caller.
Read the OWASP OAuth2 Cheat Sheet for more guidance.
