Description
enum restricts a value to an explicit set. It can coexist with constraints such as minLength or maximum, and a value must satisfy every applicable constraint. An enumerated value that violates another constraint is not actually allowed.
Potential impact
A consumer relying only on the enum list may send a rejected value, or the combined schema may leave no allowed value at all.
Remediation
Check that intended enum values satisfy the type and every additional constraint. Retain necessary rules and remove only redundant or incorrect ones. Do not remove a valid constraint merely because it appears beside enum.
Examples
These are OpenAPI 3.0 schema excerpts. All four example strings are at least four characters long, so they do not conflict with minLength: 4.
Before
{
"openapi": "3.0.0",
"components": {
"schemas": {
"Cat": {
"type": "object",
"properties": {
"huntingSkill": {
"type": "string",
"enum": [
"clueless",
"lazy",
"adventurous",
"aggressive"
],
"minLength": 4
}
}
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"schemas": {
"Cat": {
"type": "object",
"properties": {
"huntingSkill": {
"type": "string",
"enum": [
"clueless",
"lazy",
"adventurous",
"aggressive"
]
}
}
}
}
}
}
The after schema omits a length constraint already satisfied by every enum value. Both schemas allow the same set of strings; the before configuration is not invalid.