Description
An object schema’s required array names properties that must be present, while properties defines their value constraints. A required name missing from the same properties object is not inherently contradictory. Additional properties may be allowed, or another schema such as an allOf member may define it.
Potential impact
If a required field has no definition anywhere, consumers may not know its expected value and type validation may be incomplete. Conversely, forbidding additional properties without allowing a required name can make the object constraints impossible to satisfy.
Remediation
Review composed schemas and additionalProperties, then define the necessary types and constraints in the appropriate place. Preserve genuine presence requirements; do not remove a name from required merely because it is absent from the same properties object.
Examples
These are OpenAPI 3.0 object-schema excerpts; info and paths are omitted. The first still requires name to be present. Because it does not forbid additional properties, the structure is not inherently contradictory.
Before
{
"openapi": "3.0.0",
"components": {
"schemas": {
"Example": {
"type": "object",
"required": [
"name"
],
"properties": {
"age": {
"type": "integer"
}
}
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"schemas": {
"Example": {
"type": "object",
"required": [
"name"
],
"properties": {
"name": {
"type": "string"
},
"age": {
"type": "integer"
}
}
}
}
}
}
The second adds a string type for name. This adds a value constraint to the presence requirement and may reject previously valid values of other types, so it must match the actual contract.