Operation mixes body and formData parameters (OpenAPI 2.0)

One API operation uses both body and form parameters

Description

An OpenAPI 2.0 operation cannot combine in: body with in: formData. Both describe the request body, so choose one representation.

Potential impact

Specification validation may fail, or clients may construct a body format that differs from what the server expects.

Remediation

Use one body parameter or a set of formData parameters according to the actual request format. For form submissions, specify an appropriate consumes value and each parameter’s type.

Examples

These POST examples replace the mixture of body and form parameters with form parameters. They specify the form encoding and integer types; configure the actual API to accept this format.

Before

json
{
  "swagger": "2.0",
  "info": {
    "title": "Simple API Overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "post": {
        "operationId": "listVersionsv2",
        "summary": "List API versions",
        "responses": {
          "200": {
            "description": "200 response"
          }
        },
        "parameters": [
          {
            "name": "limit2",
            "in": "body",
            "description": "max records to return",
            "required": true,
            "schema": {
              "type": "object"
            }
          },
          {
            "name": "minlimit",
            "in": "formData",
            "description": "min records to return",
            "required": true,
            "type": "integer"
          }
        ],
        "consumes": [
          "application/x-www-form-urlencoded"
        ]
      }
    }
  },
  "parameters": {
    "limitParam": {
      "name": "limit",
      "in": "formData",
      "description": "max records to return",
      "required": true,
      "type": "integer"
    }
  }
}

After

json
{
  "swagger": "2.0",
  "info": {
    "title": "Simple API Overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "post": {
        "operationId": "listVersionsv2",
        "summary": "List API versions",
        "responses": {
          "200": {
            "description": "200 response"
          }
        },
        "parameters": [
          {
            "name": "limit2",
            "in": "formData",
            "description": "max records to return",
            "required": true,
            "type": "integer"
          },
          {
            "name": "minlimit",
            "in": "formData",
            "description": "min records to return",
            "required": true,
            "type": "integer"
          }
        ],
        "consumes": [
          "application/x-www-form-urlencoded"
        ]
      }
    }
  },
  "parameters": {
    "limitParam": {
      "name": "limit",
      "in": "formData",
      "description": "max records to return",
      "required": true,
      "type": "integer"
    }
  }
}

References