String pattern is too broad (OpenAPI 3.0)

A string pattern does not adequately restrict the intended format

Description

A pattern intended to restrict a string format may still accept unexpected values if it is too broad. For example, .* does not constrain the string format.

Potential impact

If the server validates input against the same loose requirements, incorrectly formatted values may be stored or cause errors in later processing.

Remediation

Make the pattern reflect the allowed characters, length, and other actual requirements. Use ^ and $ when the whole string must match, and apply the same validation on the server. Whole-string matching is unnecessary when a partial match is intentional.

Examples

This OpenAPI 3.0 excerpt replaces the .* pattern for code with one allowing 15 lowercase ASCII letters or digits. The example also assumes that message is a code in that format, rather than free-form text.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "schemas": {
      "GeneralError": {
        "type": "object",
        "properties": {
          "code": {
            "type": "string",
            "maxLength": 15,
            "pattern": ".*"
          },
          "message": {
            "type": "string",
            "maxLength": 15,
            "pattern": "^[0-9a-z]{15}$"
          }
        }
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "schemas": {
      "GeneralError": {
        "type": "object",
        "properties": {
          "code": {
            "type": "string",
            "maxLength": 15,
            "pattern": "^[0-9a-z]{15}$"
          },
          "message": {
            "type": "string",
            "maxLength": 15,
            "pattern": "^[0-9a-z]{15}$"
          }
        }
      }
    }
  }
}

References