Description
Without properties, an object with a fixed structure does not document its field names and types clearly. Declaring properties alone neither rejects other fields nor makes the listed fields required.
Potential impact
Clients and servers may assume different object structures, or unwanted fields may pass validation.
Remediation
Define expected fields in properties and mandatory fields in required. Use additionalProperties: false only when other fields must be rejected. For maps with dynamic keys, an additionalProperties schema can define the value format.
Examples
The example defines permitted fields, including the required petType, and rejects other fields.
Before
json
{
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"required": [
"petType"
]
}
}
}
}
After
json
{
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"additionalProperties": false,
"properties": {
"code": {
"type": "integer",
"format": "int32"
},
"message": {
"type": "string"
},
"petType": {
"type": "string"
}
},
"required": [
"petType"
]
}
}
}
}