Additional properties are too restrictive (OpenAPI 3.0)

An additional-property restriction rejects fields that the API should allow

Description

In a composed schema, additionalProperties: false can reject valid data when it blocks fields the API should allow. In particular, an allOf branch does not automatically recognize properties defined in other branches as its own.

Potential impact

Valid requests or responses may fail validation and break client-server integration. Using oneOf or anyOf does not, by itself, require allowing additional properties.

Remediation

Check which fields each branch must accept, then adjust the property definitions or schema composition. Allow additional properties only where extension fields are intentional, and constrain their values where needed.

Examples

This OpenAPI 3.0 excerpt allows additional properties assuming that MyObject must accept extension fields beyond id and name. Without that requirement, the original closed object schema is also valid.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "schemas": {
      "MyObject": {
        "oneOf": [
          {
            "type": "object",
            "properties": {
              "id": { "type": "string" },
              "name": { "type": "string" }
            },
            "additionalProperties": false
          }
        ]
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "schemas": {
      "MyObject": {
        "oneOf": [
          {
            "type": "object",
            "properties": {
              "id": { "type": "string" },
              "name": { "type": "string" }
            },
            "additionalProperties": true
          }
        ]
      }
    }
  }
}

References