FixVibe

// 探索 / 聚焦

Exposed API Documentation

Public Swagger and OpenAPI docs are an API map for you and for the attacker.

What it is

API documentation is meant to be read. The question is by whom. OpenAPI / Swagger specs are extraordinarily useful in development — they generate clients, drive contract testing, and document the API for new team members — but those same properties make them a recon goldmine when shipped to production. The full structure of every endpoint, every parameter name and type, every authentication scheme, every error response shape, served as a single JSON document at a predictable URL. Frameworks like FastAPI, NestJS, Express with swagger-jsdoc, and Spring Boot Actuator publish these by default; many teams never explicitly turned them off when shipping to prod.

How it happens

Several API frameworks make it one line to publish interactive docs and a machine-readable spec, and FastAPI does it by default. NestJS with its Swagger module, Express with swagger-ui-express, and Spring Boot with springdoc work the same way once added. That is great in development and risky when it stays on in production. The spec lists every route, the HTTP methods it accepts, every parameter with its type, the authentication scheme, and sometimes example payloads and responses. The attacker doesn't have to fuzz; they have the contract.

What an attacker gets

Reduces the attacker's effort dramatically. Instead of fuzzing for endpoints (slow, noisy, partial coverage), they have the complete list with parameter names and types. This makes targeted attacks against authorization gaps (IDOR, mass assignment), input validation flaws (SQL/NoSQL injection), and rate-limit bypasses much more efficient. For B2B SaaS, exposed docs also leak product surface — knowing which admin endpoints exist may inform competitive intelligence as much as attack planning.

// what fixvibe reports

What FixVibe reports

Runs on every URL scan: paste your app's URL, nothing to install. The free preview shows your top findings; Hobby and above unlock the full report. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Gate API documentation behind authentication, or remove it from production entirely. The cleanest pattern: serve docs only in development environments via env-driven config. FastAPI: `app = FastAPI(docs_url=None, redoc_url=None, openapi_url=None)` in production. NestJS: only call `SwaggerModule.setup` when `process.env.NODE_ENV !== 'production'`. Spring Boot: exclude springfox/springdoc dependencies from prod builds, or set `springdoc.api-docs.enabled=false`. If documentation is needed for partners or developers, host it on a separate authenticated subdomain that doesn't expose the live API. As a defense-in-depth layer, configure your edge (CDN, WAF) to block requests to the standard documentation paths in production.

// 在你自己的應用上跑一遍

放心继續發布,FixVibe 持續幫你看守風险。

Paste your app's URL for a free preview. Nothing to install.

探索
133
本類别中触發的测試
模塊
16
專属 探索 检查
every URL scan
230+
passive checks on each scan
Scan your URL free →

// 最新检查 · 实用修複 · 安心發布

Exposed API Documentation: what it is and how to fix it · FixVibe