# POST and required fields

**URL:** <https://discuss.jsonapi.org/t/post-and-required-fields/2941>\
**Category:** Uncategorized\
**Created:** [October 4, 2024, 6:58am UTC](https://discuss.jsonapi.org/t/post-and-required-fields/2941 "2024-10-04T06:58:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![skaaptjop](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.jsonapi.org/skaaptjop/32/619_2.png) [@skaaptjop](https://discuss.jsonapi.org/u/skaaptjop)\
**Post date:** [October 4, 2024, 6:58am UTC](https://discuss.jsonapi.org/t/post-and-required-fields/2941/1 "2024-10-04T06:58:46Z")

</div>

Hi,  
Would love to hear thoughts or clarification on something possibly quite simple.

For creating a resource (POST) the spec (9.1) says:

> The request **MUST** include a single [resource object](https://jsonapi.org/format/#document-resource-objects) as primary data. The [resource object](https://jsonapi.org/format/#document-resource-objects) **MUST** contain at least a `type` member.

Then in 7.2:

> In addition, a resource object **MAY** contain any of these top-level members:
> 
> - `attributes`: an [attributes object](https://jsonapi.org/format/#document-resource-object-attributes) representing some of the resource’s data.

So my question is quite simply should we handle scenarios where a POST request does not include attributes (or meta) in the resource object? Essentially this would be a POST to create a resource where no resource attribute fields was given (only ‘type’) and the created resources would use whatever defaults are defined. This might not make sense for specific resources.

Or, can we interpret the **MAY** statement to be that we may require attributes to be provided?

---

<div class="post-metadata">

**Author:** ![jelhan](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.jsonapi.org/jelhan/32/822_2.png) [@jelhan](https://discuss.jsonapi.org/u/jelhan)\
**Post date:** [October 6, 2024, 1:36pm UTC](https://discuss.jsonapi.org/t/post-and-required-fields/2941/2 "2024-10-06T13:36:54Z")

</div>

The server can enforce additional constraints on the resources typically discussed as validation. E.g. it can enforce some attributes to exist in requests to create a resource.

---

<div class="post-metadata">

**Author:** ![skaaptjop](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.jsonapi.org/skaaptjop/32/619_2.png) [@skaaptjop](https://discuss.jsonapi.org/u/skaaptjop)\
**Post date:** [October 10, 2024, 8:29am UTC](https://discuss.jsonapi.org/t/post-and-required-fields/2941/3 "2024-10-10T08:29:44Z")

</div>

Thanks jelhan,  
I’m actually looking at the whole ‘attributes’ member in the ‘data’ object.  
I realise that fields inside the ‘attributes’ object are up to us to define but the specification says that a resource object MAY contain an attributes member.

This seems to imply that one should support the creation of resources (via a POST) where the ‘attributes’ member is not supplied at all, like:

```auto
...
data: {
  type: 'mytype'
  # no attributes: {...}
}

```

I was wondering about the definition of “MAY” in this case, meaning can we actually require the attributes member to be present?

---

<div class="post-metadata">

**Author:** ![jelhan](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.jsonapi.org/jelhan/32/822_2.png) [@jelhan](https://discuss.jsonapi.org/u/jelhan)\
**Post date:** [October 10, 2024, 9:09am UTC](https://discuss.jsonapi.org/t/post-and-required-fields/2941/4 "2024-10-10T09:09:28Z")

</div>

> [@skaaptjop](#):
>
> I was wondering about the definition of “MAY” in this case, meaning can we actually require the attributes member to be present?

Yes. You can enforce the `attributes` member to be present _implicitly_ by requiring a specific attribute to be present. I think in practice that’s the most common use case by far. Allowing a resource to be created without enforcing any attribute to be set is an edge case.

Having the `attributes` member as optional allows clients and servers to avoid unnecessary characters. Instead of having an empty object as value of the `attributes` member, they can skip the `attributes` member entirely.

---

<div class="post-metadata">

**Author:** ![skaaptjop](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.jsonapi.org/skaaptjop/32/619_2.png) [@skaaptjop](https://discuss.jsonapi.org/u/skaaptjop)\
**Post date:** [October 14, 2024, 8:32am UTC](https://discuss.jsonapi.org/t/post-and-required-fields/2941/5 "2024-10-14T08:32:02Z")

</div>

Thanks, that’s how I saw things. It was just the use of the word “MAY” in that context seemed to imply that we should support a POST request without “content”.  
Makes sense, of course, that this is an implementation specific requirement.
