Description
If a numeric field needs a lower bound, such as a quantity that cannot be negative, omitting minimum or an equivalent constraint can allow values below the permitted range to pass schema validation.
Potential impact
If the server also omits the lower-bound check, invalid values may cause errors in calculations or business processing.
Remediation
Define minimum according to the field’s purpose and align it with server validation. Do not impose a minimum of zero on fields where negative values are valid.
Examples
This OpenAPI 3.0 excerpt uses minimum: 0 to specify that code cannot be negative.
Before
json
{
"openapi": "3.0.0",
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"properties": {
"code": {
"type": "integer",
"format": "int32"
}
}
}
}
}
}
After
json
{
"openapi": "3.0.0",
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"properties": {
"code": {
"type": "integer",
"format": "int32",
"minimum": 0
}
}
}
}
}
}