Review security on callbacks and referenced Path Items
Shared or callback operations need manual security review before any repair.
Match the finding
These titles and messages come from this local checker. They are not AWS service error quotes.
Callback security needs manual reviewReferenced Path Item needs manual review
Cause and scope
This MVP only copies security into directly declared operations under paths. Callback coverage and operations reached through referenced Path Items are outside that guarded repair, so automatic repair is disabled for the document.
What to do
Review the effective security of every affected operation manually. If expanding shared Path Items, retain operation fields, parameters, references, and all explicit security overrides.
- List the operations in the reported callback or shared Path Item and every place the shared object is used.
- Determine the intended requirements and explicit overrides for each operation, including public access.
- Make any approved structural or security edits manually, validate again, and test the affected flows.
Diagnostic path fragment: a shared operation requires manual review
paths:
/pets:
get:
security: []
responses:
'200':
description: Public pet list
/shared-pets:
$ref: '#/paths/~1pets'The second path references the first Path Item. This checker reports referenced Path Item coverage and disables repair, even though the pointer resolves. Review both use sites and retain the explicit public override if it is intended; deleting the reference is not a security fix.
Avoid a misleading fix
Do not remove callbacks or shared Path Items to enable the repair. Do not assume a shared operation has the same effective security at every use site.
Check your complete file locally
Choose one OpenAPI 3.0 JSON or YAML file, diagnose the findings, and review any eligible security-copy preview before downloading. No file upload or account is needed.
Related findings
Sources and scope
Scope: this local checker, API Gateway REST APIs, and OpenAPI 3.0. Guidance reviewed 4 October 2026. A passing check does not guarantee import or runtime behavior.