QID 580513
QID 580513: Required String Fields Matches Schema
In this scenario required string fields are tested. Empty values for string fields are sent to the server for the endpoint being tested.The expectation is that APIs will reject the request as invalid for required fields. Based on testing done using requests with empty values it is determined that the required strings as defined in the swagger file are enforced successfully. The response code received for the request with empty values for required string fields is expected and matches the response documented in the swagger file schema.
Enforcing valid value for required string field based on limits defined in swagger file will help provide clarity to the API users and avoid abuse of the API by hackers.
Solution
N/A
Vendor References
CVEs related to QID 580513
Software Advisories
| Advisory ID | Software | Component | Link |
|---|