An Azure service that provides a hybrid, multi-cloud management platform for APIs.
hi Casper,
you are absolutely right. a missing required parameter should be a 400 bad request, not a 404 not found. the 404 makes it look like the api endpoint itself doesn't exist, which is just wrong and confuses everyone.
the root cause is how apim handles the openapi import. it sees a required parameter and, for its own internal routing, makes it a template parameter. this happens deep in the import process.
here is how u can fix it. u need to override the operation policy for that specific api. u can use a policy to validate the query parameters manually and return the correct 400 error.
go to your apim instance in the azure portal, select your api, and then choose the operation that has the required query parameters. in the 'inbound processing' section, u can add an xml policy.
add a policy snippet like this to check for the existence of the parameter.
<choose> <when condition="@(context.Request.Url.Query.GetValueOrDefault("yourRequiredParam", "") == "")"> <return-response> <set-status code="400" reason="Bad Request" /> <set-body>{"error": "Missing required query parameter: 'yourRequiredParam'"}</set-body> </return-response> </when> </choose>
u will have to do this for each required parameter. it is a bit of manual work, but it gives u complete control over the error response.
if u have many apis, u can also look into using a base policy or writing a script to automate adding these policy checks during your iac deployment.
hope this gets your error responses back on track. that 404 behavior is truly misleading for api consumers.
Best regards,
Alex
and "yes" if you would follow me at Q&A - personaly thx.
P.S. If my answer help to you, please Accept my answer