QID 570074
QID 570074: Schemas Not Defined for Response Code 429
OWASP API Security recommends defining schemas for all responses. 429 response code should have definition on all endpoints. Analysis of swagger file resulted in an observation that one or more of your operations do not have schemas for 429 response code .
When user submits a request that results in 429 they do not have clarity from the API. The lack of schema definition for error code results in a warning.
Solution
Ensure the responses of all operations to include 429 response error codes.
Example:
get:
summary: Get User Info by User ID
tags: []
responses:
'200':
...
'400':
...
'429':
description: Too Many Requests
headers:
...
Vendor References
CVEs related to QID 570074
Software Advisories
| Advisory ID | Software | Component | Link |
|---|