Description
An empty Schema Object {} defines no constraints on types, fields, or required values. Using it where a defined structure is expected leaves the document without the necessary validation criteria.
Potential impact
Document-based validation may accept unintended structures, or clients may assume the wrong data model.
Remediation
Define the type, properties, items, required, and other constraints the actual data needs. If arbitrary structures are intentional, document that purpose and enforce any necessary limits in the implementation.
Examples
The example defines an object with two fields and makes message required. It does not prohibit additional fields.
Before
json
{
"components": {
"schemas": {
"GeneralError": {}
}
}
}
After
json
{
"components": {
"schemas": {
"GeneralError": {
"type": "object",
"properties": {
"code": {
"type": "integer",
"format": "int32"
},
"message": {
"type": "string"
}
},
"required": [
"message"
]
}
}
}
}