Description
allowEmptyValue allows an empty value to be sent and does not apply to every parameter location. OpenAPI 3.0 permits it only for query parameters and does not recommend its use. OpenAPI 2.0 permits it for query and formData. Whether the parameter itself is required is set separately with required.
Potential impact
- Clients and servers may disagree about empty values.
- Tools may reject or ignore the option at unsupported locations, causing integration errors.
Remediation
Check the specification version and parameter location, and remove unsupported uses of allowEmptyValue. If empty values are needed, review the actual input location, type and serialization together. Do not move a path input to a query solely to use this option.
Examples
These OpenAPI 3.0 excerpts omit info and operation responses. The first incorrectly places allowEmptyValue on an in: path parameter.
Before
{
"openapi": "3.0.0",
"paths": {
"/users/{id}": {
"get": {
"parameters": [
{
"name": "id",
"in": "path",
"required": true,
"allowEmptyValue": true,
"schema": {
"type": "integer"
}
}
]
}
}
}
}
After
{
"openapi": "3.0.0",
"paths": {
"/users": {
"get": {
"parameters": [
{
"name": "id",
"in": "query",
"allowEmptyValue": true,
"schema": {
"type": "integer"
}
}
]
}
}
}
}
The second changes the API contract to a query input on /users. This is appropriate only when that is the intended API; verify empty-value handling and tool support. To retain the original path contract, remove only the unsupported option from the path parameter.