Description
An object schema’s required list means that a property must be present. A default on that property is not inherently prohibited, but declaring it does not by itself fill a missing required value or make validation succeed. Applying the value depends on the client, server or tooling.
Potential impact
A consumer may omit a required value after seeing a default, or clients and servers may apply defaults at different stages. This can cause validation failures or unexpected data handling.
Remediation
Keep presence requirements aligned with the actual contract and document who applies defaults and when. Remove misleading defaults without banning valid ones categorically. Verify server and client behavior when values are absent.
Examples
These OpenAPI 3.0 object-schema excerpts omit info and paths. In the first, id remains required despite its default; combining these keywords is not itself invalid.
Before
{
"openapi": "3.0.0",
"components": {
"schemas": {
"MyObject": {
"type": "object",
"required": [
"id"
],
"properties": {
"id": {
"type": "string",
"default": "4056684e4e1347579362617ad82e5b4e"
}
}
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"schemas": {
"MyObject": {
"type": "object",
"required": [
"id"
],
"properties": {
"id": {
"type": "string"
},
"name": {
"type": "string",
"default": "guest"
}
}
}
}
}
}
The second removes the default from id and sets guest on the optional name property. This is a separate contract choice; the declaration alone does not automatically populate name.