Description
OpenAPI 2.0 basePath identifies the API’s shared path and must start with / when specified. If omitted, the API is served directly under the host.
Potential impact
Tools may construct incorrect request URLs or fail specification validation.
Remediation
Write the actual shared path with a leading /. Check that combining host, basePath, and each operation’s path produces the actual API address.
Examples
These excerpts use /api as the shared path instead of a path without a leading slash.
Before
json
{
"swagger": "2.0",
"basePath": "api/incorrect"
}
After
json
{
"swagger": "2.0",
"basePath": "/api"
}