Apply Open Worldwide Application Security Project (OWASP) API rules to your OpenAPI specification using vacuum. Learn more about OWASP.
The original rules were written by Ricardo Graça, based on work by Phil Sturgeon. vacuum’s native rules continue to grow with the API security guidance.
vacuum supports OWASP API rules out of the box!
Turn up the heat
Use hard mode to enable every built-in OpenAPI rule, including the OWASP rules:
For more control, create a file such as owasp-rules.yaml that extends vacuum:owasp:
extends: [[vacuum:oas, recommended], [vacuum:owasp, all]]
This combines the Recommended Rules with the OWASP Rules.
What gets checked?
The rules cover authentication declarations, transport, request limits, and error responses. For OpenAPI 3.0, 3.1, and 3.2, that includes:
- Rejecting OAuth password and implicit flows.
- Checking authentication endpoint URLs and server declarations for insecure transport, including server overrides and variables.
- Warning about unrestricted request objects and unbounded request maps.
- Requiring authenticated write operations, without anonymous alternatives.
- Checking that declared JWTs document RFC8725, as a warning about documentation.
These are checks of your API description. They do not prove that the running API enforces authorization, rate limits, SSRF protection, or business-flow controls. Test those behaviors too. See the OWASP API Security Top 10 for the wider picture.
Changes for existing users
Strict write-security findings now have error severity, previously info. A requirement such as security: [{auth: []}, {}] allows anonymous access and can now fail a build. Require authentication, or configure a deliberate exception below.
Inline ignores now cover the entire subtree beneath their location, for every ruleset. See Ignoring Violations for scope and examples.
Make a deliberate exception
Use the existing custom ruleset configuration to change a rule’s severity:
extends: [[vacuum:oas, recommended], [vacuum:owasp, all]]
rules:
owasp-protection-global-unsafe-strict: warn
For a specific operation or security scheme, put x-lint-ignore on that object. The directive applies to its descendants too, including nested OAuth flows and endpoint URLs. Document why the exception is needed.
Get ready to be told about all the things you are doing wrong!
What you see may hurt, but it’s for the good of the API.
