format keywords (uuid, date-time, email) must be enforced during instance validation
Problem
The JSON Schema format keyword must not be treated as an annotation only — values like "not-a-uuid" pass validation against a schema with "format": "uuid".
All implementations must check it properly
gts-python
The root cause is in store.py (validate_instance): the jsonschema validator is constructed without a FormatChecker:
validator_class = validator_for(schema_for_validation)
validator = validator_class(
schema_for_validation, registry=self._create_reference_registry()
)
validator.validate(obj.content)
Per the jsonschema library, format validation is opt-in — a format_checker= argument must be passed to the validator constructor. Without it, format is purely informational regardless of the JSON Schema draft.
Impact
- Schemas that use bare
format constraints (e.g. "format": "uuid" without a companion pattern) do not reject malformed values.
- The spec test
TestCaseTestOp6Validation_FormatValidation only registers a valid instance, so the gap is not caught — there is no negative test that submits an invalid format value and asserts rejection.
Expected behavior
Instance validation should reject values that do not conform to the declared format.
At minimum, the standard formats defined by JSON Schema (date-time, date, time, email, hostname, ipv4, ipv6, uri, uuid) should be enforced.
Suggested fix
Pass FormatChecker() when constructing validators in store.py:
from jsonschema import FormatChecker
validator = validator_class(
schema_for_validation,
registry=self._create_reference_registry(),
format_checker=FormatChecker(),
)
The jsonschema[format] extra (or individual format extras) should be added to pyproject.toml dependencies to ensure the format-checking backends are installed:
"jsonschema[format]>=4.18,<5",
A negative spec test should also be added to confirm that invalid format values are rejected.
Implementation fix
formatkeywords (uuid, date-time, email) must be enforced during instance validationProblem
The JSON Schema
formatkeyword must not be treated as an annotation only — values like"not-a-uuid"pass validation against a schema with"format": "uuid".All implementations must check it properly
gts-python
The root cause is in
store.py(validate_instance): thejsonschemavalidator is constructed without aFormatChecker:Per the
jsonschemalibrary, format validation is opt-in — aformat_checker=argument must be passed to the validator constructor. Without it,formatis purely informational regardless of the JSON Schema draft.Impact
formatconstraints (e.g."format": "uuid"without a companionpattern) do not reject malformed values.TestCaseTestOp6Validation_FormatValidationonly registers a valid instance, so the gap is not caught — there is no negative test that submits an invalid format value and asserts rejection.Expected behavior
Instance validation should reject values that do not conform to the declared
format.At minimum, the standard formats defined by JSON Schema (
date-time,date,time,email,hostname,ipv4,ipv6,uri,uuid) should be enforced.Suggested fix
Pass
FormatChecker()when constructing validators instore.py:The
jsonschema[format]extra (or individual format extras) should be added topyproject.tomldependencies to ensure the format-checking backends are installed:"jsonschema[format]>=4.18,<5",A negative spec test should also be added to confirm that invalid format values are rejected.
Implementation fix