Description
OpenAPI 2.0 host contains only the hostname or IP address and an optional port. Define the protocol and path separately in schemes and basePath.
Potential impact
Documentation tools or generated clients may use an incorrect server address.
Remediation
Separate the protocol and path from host, retaining only any needed port. Verify that the combined fields produce the intended API URL.
Examples
These excerpts compare kics.io/test, which contains a path, with the host-and-port format 127.0.0.1:8080. The local address only illustrates the format; replace it with the actual API host.
Before
json
{
"swagger": "2.0",
"host": "kics.io/test"
}
After
json
{
"swagger": "2.0",
"host": "127.0.0.1:8080"
}