Description
When a string needs a length limit, omitting maxLength or an equivalent constraint can allow excessively long values under the schema.
Potential impact
If the server also accepts unbounded input, large values may increase memory and storage use or cause processing errors.
Remediation
Define maxLength according to business requirements and align it with the server limit. Check whether an existing constraint, such as a list of permitted values, already bounds the length.
Examples
This OpenAPI 3.0 excerpt limits code to 15 characters and message to 255. Choose actual limits according to each field’s purpose.
Before
json
{
"openapi": "3.0.0",
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"properties": {
"code": {
"type": "string"
},
"message": {
"type": "string"
}
}
}
}
}
}
After
json
{
"openapi": "3.0.0",
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"properties": {
"code": {
"type": "string",
"maxLength": 15
},
"message": {
"type": "string",
"maxLength": 255
}
}
}
}
}
}