> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-openapi-17.md).

# Operation objects for PUT, POST, and PATCH operations do not have a 'consumes' field defined misconf

## Rule Details

|                        |                        |
| ---------------------- | ---------------------- |
| Cortex AppSec Rule ID  | APPSEC\_OPENAPI\_17    |
| Category - Subcategory | Public Exposure - APIs |
| Provider               | OTHER                  |
| Severity               | MEDIUM                 |
| Framework              | OpenAPI                |

## Impact

This rule checks if operation objects in the API version 2.0 files have the 'consumes' field defined for PUT, POST and PATCH operations. The 'consumes' field is important because it specifies the MIME types that the operation or endpoint can handle. If this field is not defined, the API may process requests with unspecified or incorrect content types, leading to errors or security vulnerabilities. It may also invite compatibility issues, as some clients may send requests in a format that the API does not support. Therefore, it's crucial to define the 'consumes' field for ensuring the correct operation of the API and safeguarding it from potential threats.

## How to Fix

## Ensure that you have an authentication type in the security section of your path. For example: \[source,go]

paths: "/": get: operationId: id summary: example

* ```
  security: []
  ```
* ```
  security:
  ```
* ```
    - OAuth2:
  ```
* ```
        - write
  ```

***


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-openapi-17.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
