Pagination limit parameter maximum constraint in OpenAPI 3.x
0 reputation · 16 Oct 2023, 10:30 UTC
Goal: ensure that a pagination limit query parameter never exceeds a safe threshold that could cause memory exhaustion or excessive database load.
Constraint: the OpenAPI 3.x specification provides no native keyword to enforce a server‑side maximum on an integer query parameter; validation must be added by the implementation or API gateway.
Uncertainty: designers must decide whether to rely on the JSON Schema maximum property, a vendor extension such as x‑max‑limit, or external documentation, and how to guarantee that gateways and frameworks actually apply the bound.
What is the recommended way to express a maximum allowable value for a limit parameter within an OpenAPI 3.x document? Should teams use the schema maximum keyword or a custom extension like x‑max‑limit? How can API gateways be configured to enforce this constraint without duplicating logic in each service?