Description
A length limit alone cannot validate the format of an ID or code. Without the necessary pattern constraint, a schema may accept incorrectly formatted strings. Free-form text does not always need a regular expression.
Potential impact
If the server also omits format validation, malformed values may cause errors in later processing. The documented input requirements may also differ from the implementation.
Remediation
Define a pattern for the permitted format and align it with server validation. If enum or another constraint already enforces that format, duplicating the constraint is unnecessary.
Examples
This OpenAPI 3.0 excerpt adds patterns assuming that both code and message contain 15-character codes made of lowercase ASCII letters and digits. This is not a general rule for free-form messages.
Before
{
"components": {
"schemas": {
"GeneralError": {
"properties": {
"code": {
"type": "string",
"maxLength": 15
},
"message": {
"type": "string",
"maxLength": 15
}
}
}
}
}
}
After
{
"components": {
"schemas": {
"GeneralError": {
"properties": {
"code": {
"type": "string",
"maxLength": 15,
"pattern": "^[0-9a-z]{15}$"
},
"message": {
"type": "string",
"maxLength": 15,
"pattern": "^[0-9a-z]{15}$"
}
}
}
}
}
}