Description
If a numeric field such as a quantity or amount needs an upper bound, omitting maximum or an equivalent constraint can allow values outside the permitted business range to pass schema validation.
Potential impact
If the server also omits the upper-bound check, excessively large values may cause calculation errors or processing failures.
Remediation
Define maximum according to the permitted range and enforce the same limit on the server. Check whether a list of allowed values or a referenced schema already supplies the upper bound.
Examples
This OpenAPI 3.0 excerpt adds a maximum of 50 to the existing minimum of 0 for code. The value 50 is the business limit chosen for this example.
Before
json
{
"openapi": "3.0.0",
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"properties": {
"code": {
"type": "integer",
"format": "int32",
"minimum": 0
}
}
}
}
}
}
After
json
{
"openapi": "3.0.0",
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"properties": {
"code": {
"type": "integer",
"format": "int32",
"minimum": 0,
"maximum": 50
}
}
}
}
}
}