Description
OpenAPI 2.0 allows at most one in: body parameter per operation. To send multiple values in the body, include them in a single body schema.
Potential impact
Document validation or code generation may fail, and clients may construct an incorrect request body.
Remediation
Combine body values in one object schema. Move values to query parameters or headers only when the actual API accepts them there, and do not combine body parameters with formData.
Examples
These POST examples reduce the body parameters to one and define pageCount as an integer query parameter. The actual API must support this request format.
Before
json
{
"swagger": "2.0",
"info": {
"title": "Simple API Overview",
"version": "1.0.0"
},
"paths": {
"/": {
"post": {
"parameters": [
{
"name": "limit",
"in": "body",
"description": "max records to return",
"required": true,
"schema": {
"type": "integer"
}
},
{
"name": "limit2",
"in": "body",
"description": "max records to return",
"required": true,
"schema": {
"type": "string"
}
}
],
"operationId": "listVersionsv2",
"summary": "List API versions",
"responses": {
"200": {
"description": "200 response"
}
}
}
}
}
}
After
json
{
"swagger": "2.0",
"info": {
"title": "Simple API Overview",
"version": "1.0.0"
},
"paths": {
"/": {
"post": {
"parameters": [
{
"name": "limit",
"in": "body",
"description": "max records to return",
"required": true,
"schema": {
"type": "integer"
}
},
{
"name": "pageCount",
"in": "query",
"description": "records per page",
"required": true,
"type": "integer"
}
],
"operationId": "listVersionsv2",
"summary": "List API versions",
"responses": {
"200": {
"description": "200 response"
}
}
}
}
}
}