Description
In a composed schema, additionalProperties: false can reject valid data when it blocks fields the API should allow. In particular, an allOf branch does not automatically recognize properties defined in other branches as its own.
Potential impact
Valid requests or responses may fail validation and break client-server integration. Using oneOf or anyOf does not, by itself, require allowing additional properties.
Remediation
Check which fields each branch must accept, then adjust the property definitions or schema composition. Allow additional properties only where extension fields are intentional, and constrain their values where needed.
Examples
This OpenAPI 3.0 excerpt allows additional properties assuming that MyObject must accept extension fields beyond id and name. Without that requirement, the original closed object schema is also valid.
Before
{
"openapi": "3.0.0",
"components": {
"schemas": {
"MyObject": {
"oneOf": [
{
"type": "object",
"properties": {
"id": { "type": "string" },
"name": { "type": "string" }
},
"additionalProperties": false
}
]
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"schemas": {
"MyObject": {
"oneOf": [
{
"type": "object",
"properties": {
"id": { "type": "string" },
"name": { "type": "string" }
},
"additionalProperties": true
}
]
}
}
}
}