Review security on callbacks and referenced Path Items

Shared or callback operations need manual security review before any repair.

Match the finding

These titles and messages come from this local checker. They are not AWS service error quotes.

Cause and scope

This MVP only copies security into directly declared operations under paths. Callback coverage and operations reached through referenced Path Items are outside that guarded repair, so automatic repair is disabled for the document.

What to do

Review the effective security of every affected operation manually. If expanding shared Path Items, retain operation fields, parameters, references, and all explicit security overrides.

  1. List the operations in the reported callback or shared Path Item and every place the shared object is used.
  2. Determine the intended requirements and explicit overrides for each operation, including public access.
  3. Make any approved structural or security edits manually, validate again, and test the affected flows.

Diagnostic path fragment: a shared operation requires manual review

paths:
  /pets:
    get:
      security: []
      responses:
        '200':
          description: Public pet list
  /shared-pets:
    $ref: '#/paths/~1pets'

The second path references the first Path Item. This checker reports referenced Path Item coverage and disables repair, even though the pointer resolves. Review both use sites and retain the explicit public override if it is intended; deleting the reference is not a security fix.

Avoid a misleading fix

Do not remove callbacks or shared Path Items to enable the repair. Do not assume a shared operation has the same effective security at every use site.

Check your complete file locally

Choose one OpenAPI 3.0 JSON or YAML file, diagnose the findings, and review any eligible security-copy preview before downloading. No file upload or account is needed.

Open the free OpenAPI checker →

Related findings

Sources and scope

Scope: this local checker, API Gateway REST APIs, and OpenAPI 3.0. Guidance reviewed 4 October 2026. A passing check does not guarantee import or runtime behavior.