Skip to content

fix(openapi2jsonschema): only add additionalProperties if type also present - #964

Open
waciejm wants to merge 1 commit into
datreeio:mainfrom
waciejm:fix-openapi2jsonschema
Open

waciejm wants to merge 1 commit into
datreeio:mainfrom
waciejm:fix-openapi2jsonschema

Conversation

@waciejm

@waciejm waciejm commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

The openapi2jsonschema.py script assumes that a properties field will never appear in a CRD and produces invalid schemas if it does.

The following OpenAPI schema

{
  "type": "object",
  "properties": {
    "properties": {
      "type": "object",
      "additionalProperties": {
        "type": "string"
      }
    }
  }
}

is transformed into

{
  "type": "object",
  "properties": {
    "properties": {
      "type": "object",
      "additionalProperties": {
        "type": "string"
      }
    },
    "additionalProperties": false
  }
  "additionalProperties": false
} 

when it should be just

{
  "type": "object",
  "properties": {
    "properties": {
      "type": "object",
      "additionalProperties": {
        "type": "string"
      }
    }
  }
  "additionalProperties": false
} 

You can see this happening in policies.kyverno.io/policyexception_v1.json where the addition of a spec.properties field in the PolicyException CRD caused the script to generate an invalid schema.

"additionalProperties": false

…so present

When encountering a CRD that has a 'properties' field in its spec
the script would incorrectly add an `"additionalProperties": false` field,
which made the generated jsonschema and invalid draft 04 schema.

The script now checks that there is a `type` field next to `properties`
with the value either "object" or an array containing "object",
before adding the `additionalProperties` field.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant