Multiple body parameters in one operation (OpenAPI 2.0)

An API operation defines more than one in: body parameter

Description

OpenAPI 2.0 allows at most one in: body parameter per operation. To send multiple values in the body, include them in a single body schema.

Potential impact

Document validation or code generation may fail, and clients may construct an incorrect request body.

Remediation

Combine body values in one object schema. Move values to query parameters or headers only when the actual API accepts them there, and do not combine body parameters with formData.

Examples

These POST examples reduce the body parameters to one and define pageCount as an integer query parameter. The actual API must support this request format.

Before

json
{
  "swagger": "2.0",
  "info": {
    "title": "Simple API Overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "post": {
        "parameters": [
          {
            "name": "limit",
            "in": "body",
            "description": "max records to return",
            "required": true,
            "schema": {
              "type": "integer"
            }
          },
          {
            "name": "limit2",
            "in": "body",
            "description": "max records to return",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "operationId": "listVersionsv2",
        "summary": "List API versions",
        "responses": {
          "200": {
            "description": "200 response"
          }
        }
      }
    }
  }
}

After

json
{
  "swagger": "2.0",
  "info": {
    "title": "Simple API Overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "post": {
        "parameters": [
          {
            "name": "limit",
            "in": "body",
            "description": "max records to return",
            "required": true,
            "schema": {
              "type": "integer"
            }
          },
          {
            "name": "pageCount",
            "in": "query",
            "description": "records per page",
            "required": true,
            "type": "integer"
          }
        ],
        "operationId": "listVersionsv2",
        "summary": "List API versions",
        "responses": {
          "200": {
            "description": "200 response"
          }
        }
      }
    }
  }
}

References