Server variable is not used in the URL

Keep server variable definitions aligned with the URL template.

Description

The variables map in an OpenAPI 3.0 server object defines substitutions for its URL template. An unused definition can mislead consumers about which parts of the server address they can change.

Potential impact

Consumers may configure an ineffective variable or mismanage addresses for different environments. An unused variable does not itself change server access controls.

Remediation

Compare variable names with the URL template and remove unused definitions. If the variable is needed, add its placeholder to the URL and verify the address produced from the default values.

Examples

These excerpts focus on the server inside a Link object. A complete Link also needs an operationId or operationRef identifying its target operation; that context is omitted here.

Before

json
{
  "openapi": "3.0.0",
  "info": {
    "title": "Simple API Overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "get": {
        "summary": "List API versions",
        "responses": {
          "200": {
            "description": "the user being returned",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "uuid": {
                      "type": "string",
                      "format": "uuid"
                    }
                  }
                }
              }
            },
            "links": {
              "address": {
                "server": {
                  "url": "https://development.{server}.com/{base}",
                  "variables": {
                    "base": {
                      "default": "v2"
                    },
                    "server": {
                      "default": "gigant-server"
                    },
                    "another": {
                      "default": "another"
                    }
                  }
                }
              }
            }
          }
        },
        "operationId": "listVersionsv2"
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "info": {
    "title": "Simple API Overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "get": {
        "summary": "List API versions",
        "responses": {
          "200": {
            "description": "the user being returned",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "uuid": {
                      "type": "string",
                      "format": "uuid"
                    }
                  }
                }
              }
            },
            "links": {
              "address": {
                "server": {
                  "url": "https://development.{server}.com/{base}",
                  "variables": {
                    "base": {
                      "default": "v2"
                    },
                    "server": {
                      "default": "gigant-server"
                    }
                  }
                }
              }
            }
          }
        },
        "operationId": "listVersionsv2"
      }
    }
  }
}

The original another variable is not used in the URL. The revised map keeps only server and base, which correspond to actual placeholders.

References