Description
OpenAPI 3.0 objects have required properties. For example, info requires title and version, while a Response Object requires description. Omitting a required property leaves the specification incomplete and can disrupt documentation or tooling.
Potential impact
- API identity information or request and response descriptions may be missing.
- Specification validation, documentation generation or client generation can fail.
Remediation
Check the required properties for each object type and the OpenAPI version in use, then supply meaningful values. Review nested objects as well as the root openapi, info and paths fields. Validate the complete specification after changes.
Examples
These examples correct a missing info.title. An empty paths object is permitted; this example defines no API operations.
Before
{
"openapi": "3.0.0",
"info": {
"version": "1.0.0",
"contact": {
"name": "contact",
"url": "/",
"email": "user@gmail.com"
}
},
"paths": {}
}
After
{
"openapi": "3.0.0",
"info": {
"title": "Simple API Overview",
"version": "1.0.0",
"contact": {
"name": "contact",
"url": "/",
"email": "user@gmail.com"
}
},
"paths": {}
}
The second example provides both title and version to identify the API. Other objects in a real specification must also contain their required properties.