Description
In OpenAPI 2.0, produces lists response body media types. A GET operation that returns a body without a global or operation-level definition leaves clients uncertain about the expected format.
Potential impact
Clients may choose the wrong parser or response format and fail to process the data.
Remediation
Specify the actual response media types in global or operation-level produces. The operation's definition overrides the global value. Check that the response body and Content-Type header match the document.
Examples
The example adds produces: [application/json] to an operation that returns JSON.
Before
yaml
swagger: "2.0"
paths:
/users:
get:
responses:
"200":
description: ok
After
yaml
swagger: "2.0"
paths:
/users:
get:
produces:
- application/json
responses:
"200":
description: ok