TRACE success response is undefined (OpenAPI 3.0)

A supported TRACE operation lacks a documented success response

Description

TRACE is a diagnostic method that reflects the request received by the server. If a supported operation lacks a documented 200 success response, callers may not understand its normal result.

Potential impact

Clients or tests based on the documentation may misinterpret the diagnostic response.

Remediation

Describe 200 and the response format in the supported TRACE operation’s responses. If the service does not support TRACE, remove that operation from the documentation.

Examples

This OpenAPI 3.0 excerpt adds 200 to an already supported TRACE operation. Changing the document does not enable the method on the server.

Before

json
{
  "openapi": "3.0.0",
  "paths": {
    "/item": {
      "trace": {
        "operationId": "traceItem",
        "responses": {
          "default": {
            "description": "Error"
          }
        }
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "paths": {
    "/item": {
      "trace": {
        "operationId": "traceItem",
        "responses": {
          "200": {
            "description": "success"
          },
          "default": {
            "description": "Error"
          }
        }
      }
    }
  }
}

References