Description
For a numeric schema, minimum sets the lower bound and maximum sets the upper bound. No number can satisfy a minimum greater than maximum. Review string minLength and maxLength, and array minItems and maxItems, for the same contradiction.
Potential impact
- Otherwise legitimate data may fail the range constraints.
- Incorrect bounds in clients and servers can cause integration failures.
Remediation
Ensure each minimum is no greater than its corresponding maximum, using the actual business constraints. If numeric bounds are equal, also check whether exclusiveMinimum or exclusiveMaximum excludes that value.
Examples
These OpenAPI 3.0 numeric-schema excerpts omit info and paths. The first requires code to be an integer at least 3 and at most 1.
Before
{
"openapi": "3.0.0",
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"properties": {
"code": {
"type": "integer",
"minimum": 3,
"maximum": 1
}
}
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"properties": {
"code": {
"type": "integer",
"minimum": 0,
"maximum": 50
}
}
}
}
}
}
The second allows integers from 0 through 50. This range is illustrative and should match the actual contract for code values.