QID 570070
QID 570070: Operation is missing a `401` error response
OWASP API Security recommends defining schemas for all responses. 401 response code should have definition on all endpoints. Analysis of swagger file resulted in an observation that one or more of your operations do not have schemas for 401 response code.
When user submits a request that results in 401 they do not have clarity from the API. The lack of schema definition for error code results in a warning.
Solution
Ensure the responses of all operations to include 401 response error codes.
Example:
get:
summary: Get User Info by User ID
tags: []
responses:
'200':
...
'400':
...
'429':
...
'401':
description: Not Authenticated
headers:
Vendor References
CVEs related to QID 570070
Software Advisories
| Advisory ID | Software | Component | Link |
|---|