Description
The variables map in an OpenAPI 3.0 server object defines substitutions for its URL template. An unused definition can mislead consumers about which parts of the server address they can change.
Potential impact
Consumers may configure an ineffective variable or mismanage addresses for different environments. An unused variable does not itself change server access controls.
Remediation
Compare variable names with the URL template and remove unused definitions. If the variable is needed, add its placeholder to the URL and verify the address produced from the default values.
Examples
These excerpts focus on the server inside a Link object. A complete Link also needs an operationId or operationRef identifying its target operation; that context is omitted here.
Before
{
"openapi": "3.0.0",
"info": {
"title": "Simple API Overview",
"version": "1.0.0"
},
"paths": {
"/": {
"get": {
"summary": "List API versions",
"responses": {
"200": {
"description": "the user being returned",
"content": {
"application/json": {
"schema": {
"type": "object",
"properties": {
"uuid": {
"type": "string",
"format": "uuid"
}
}
}
}
},
"links": {
"address": {
"server": {
"url": "https://development.{server}.com/{base}",
"variables": {
"base": {
"default": "v2"
},
"server": {
"default": "gigant-server"
},
"another": {
"default": "another"
}
}
}
}
}
}
},
"operationId": "listVersionsv2"
}
}
}
}
After
{
"openapi": "3.0.0",
"info": {
"title": "Simple API Overview",
"version": "1.0.0"
},
"paths": {
"/": {
"get": {
"summary": "List API versions",
"responses": {
"200": {
"description": "the user being returned",
"content": {
"application/json": {
"schema": {
"type": "object",
"properties": {
"uuid": {
"type": "string",
"format": "uuid"
}
}
}
}
},
"links": {
"address": {
"server": {
"url": "https://development.{server}.com/{base}",
"variables": {
"base": {
"default": "v2"
},
"server": {
"default": "gigant-server"
}
}
}
}
}
}
},
"operationId": "listVersionsv2"
}
}
}
}
The original another variable is not used in the URL. The revised map keeps only server and base, which correspond to actual placeholders.