Allow "required" list to have undefined properties

Open
#97 4 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
openapi, python
Domain
api, testing-qa

Research direction

Start in openapi_spec_validator/validators.py around the require_properties argument and the linked validation block, then read tests/integration/test_validators.py around the existing case. Check the relevant OpenAPI and JSON Schema behavior before deciding the expected result; done means the validator and integration tests consistently accept or reject the undefined required properties case.

Written by the indexing model from the issue text.

Description

I think requiring property names listed in required to be defined in properties is too strict. I also couldn't find this requirement in the JSON Schema or OpenAPI specs. JSON Schema validators and the Swagger Editor are fine with property names listed in required that are not defined in properties.

It makes sense to list required properties without defining them in properties when using allOf where one sub-schema requires some properties but does not specify them while another sub-schema only provides the specifications of the properties (possibly even without stating which ones are required and which ones aren't). This is especially useful when referencing and merging schema definitions or when expressing discriminated unions with some properties that are common to all union members.

I suggest to remove the following code block

https://github.com/p1c2u/openapi-spec-validator/blob/3f53e957812a9c545d71226e3a4d696240e2cee6/openapi_spec_validator/validators.py#L134-L142

and the require_properties argument:

https://github.com/p1c2u/openapi-spec-validator/blob/3f53e957812a9c545d71226e3a4d696240e2cee6/openapi_spec_validator/validators.py#L123

I have seen the test case

https://github.com/p1c2u/openapi-spec-validator/blob/3f53e957812a9c545d71226e3a4d696240e2cee6/tests/integration/test_validators.py#L83-L115

but it also seems to be valid to express this schema like this:

{
    'Credit': {
        'type': 'object',
        'properties': {
            'clientId': {'type': 'string'},
        }
    },
    'CreditCreate': {
        'type': 'object',
        'required': ['clientId'],
        'allOf': [
            {
                '$ref': '#/components/schemas/Credit'
            },
            # possibly more schemas to merge ...
        ]
    }
}

Or did I miss this rule somewhere in the spec?

Dominant language
Python
Stars
409
Forks
73
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from python-openapi/openapi-spec-validator

All issues in python-openapi/openapi-spec-validator

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.