Description
TRACE is a diagnostic method that reflects the request received by the server. If a supported operation lacks a documented 200 success response, callers may not understand its normal result.
Potential impact
Clients or tests based on the documentation may misinterpret the diagnostic response.
Remediation
Describe 200 and the response format in the supported TRACE operation’s responses. If the service does not support TRACE, remove that operation from the documentation.
Examples
This OpenAPI 3.0 excerpt adds 200 to an already supported TRACE operation. Changing the document does not enable the method on the server.
Before
json
{
"openapi": "3.0.0",
"paths": {
"/item": {
"trace": {
"operationId": "traceItem",
"responses": {
"default": {
"description": "Error"
}
}
}
}
}
}
After
json
{
"openapi": "3.0.0",
"paths": {
"/item": {
"trace": {
"operationId": "traceItem",
"responses": {
"200": {
"description": "success"
},
"default": {
"description": "Error"
}
}
}
}
}
}