Description
An array schema's maxItems defines the maximum number of items. When the service has a practical size limit, document it and enforce the same limit in the implementation.
Potential impact
Processing large arrays without limits can increase server resource usage or make responses difficult for clients to handle.
Remediation
Set an appropriate maxItems for arrays that need a limit and enforce it on the server. Paginate response arrays where needed. Avoid adding an arbitrary limit to every array.
Examples
The example limits the array to 5 items. Choose a value that matches the actual requirements.
Before
json
{
"components": {
"schemas": {
"GeneralError": {
"properties": {
"message": {
"type": "array",
"items": {
"type": "string"
}
}
}
}
}
}
}
After
json
{
"components": {
"schemas": {
"GeneralError": {
"properties": {
"message": {
"type": "array",
"maxItems": 5,
"items": {
"type": "string"
}
}
}
}
}
}
}