Description
A PATCH operation applies a partial modification to a resource. Without a documented success response, callers may not know whether the update completed or how to handle returned data.
Potential impact
Clients or tests may misinterpret the update result and display a state that differs from the server’s state.
Remediation
Define success codes matching the actual update outcome. For example, use 200 when returning a result body or 204 when the update completes without a body. Describe each outcome and any necessary data schema.
Examples
This OpenAPI 3.0 excerpt adds 204 for a completed update that returns no body.
Before
json
{
"openapi": "3.0.0",
"paths": {
"/item": {
"patch": {
"operationId": "updateItem",
"summary": "Updated item",
"responses": {
"default": {
"description": "Error"
}
}
}
}
}
}
After
json
{
"openapi": "3.0.0",
"paths": {
"/item": {
"patch": {
"operationId": "updateItem",
"summary": "Update item",
"responses": {
"204": {
"description": "Item updated successfully"
},
"default": {
"description": "Error"
}
}
}
}
}
}