Array with unspecified item specification passes validation

Open
#55 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
45/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
python
Domain
api

Research direction

Start by locating the OpenAPI array validation entry point and compare its behavior with the specification cited in the issue. Use the supplied valid and misindented YAML examples as a regression case; done means an array without an items specification is rejected while the correctly nested version remains valid.

Written by the indexing model from the issue text.

Description

An array without specified items: passes validation.

From swagger.io:

the items keyword is required in arrays

Example

(correct version)

definitions:
  Pet:
    required:
      - id
      - name
    properties:
      id:
        type: integer
        format: int64
      name:
        type: string
      tag:
        type: string
  Pets:
    type: object
    properties:
      payload:
        type: array
        items:
          $ref: '#/definitions/Pet'

(buggy version, shares the same Pet definition)

  Pets:
    type: object
    properties:
      payload:
        type: array
      items:
        $ref: '#/definitions/Pet'

Due to bad indentation, items is interpreted as another property of Pets and payload array is without item specification.
This schema passes through validator, but can't be used in (eg. swagger-ui).
Since the validator let's this pass, a bug like this can be very difficult to find, especially if it's part of a big code diff.

Dominant language
Python
Stars
409
Forks
73
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from python-openapi/openapi-spec-validator

All issues in python-openapi/openapi-spec-validator

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.