Linting Rules - OpenAPI V3 Security Scheme OAuth2 Password

Number of APIs: 1

This is a Spectral governance rule to enforce that OAuth2 implicit security is applied to the OpenAPI. Here is a JSON version of the rule that can be applied using this API-driven collection API, or at CLI or CI/CD pipeline.

{
  "openapi-v3-security-scheme-oauth2-password": {
    "description": "Requires the usage of OAuth2 password for security scheme.",
    "message": "Must add OAuth2 password implicit for security scheme.",
    "recommended": true,
    "severity": "error",
    "formats": [
      "oas3"
    ],
    "type": "style",
    "given": "$",
    "then": {
      "field": "$.components.securitySchemes.[*].flows.password",
      "function": "truthy"
    }
  }
}

This request can be run as part of this collection, or dragged and dropped to another collection of governance requests organized by folder, demonstrating how API governance linting works, but also providing a rule that can be used as part of your wider API governance strategy.

  1. OpenAPI V3 Security Scheme OAuth2 Password POST {{baseUrl}}/linter?rulesUrl=https://rules.linting.org/rules/openapi-v3-security-scheme-oauth2-password/