Fastify silently drops unknown body fields by default — additionalProperties: false alone doesn't reject them
Fastify's default Ajv setting removeAdditional removes properties not in the schema instead of failing validation, so a client sending an unexpected field gets 200. Set removeAdditional: false to get a 400.
Symptom
A route schema says additionalProperties: false, yet a request with an extra field ({ "a": "ok", "author_id": "spoof" }) succeeds. The handler sees only { "a": "ok" }, and the client is never told.
Why (reproduced)
Fastify compiles body schemas with Ajv's removeAdditional turned on, so additional properties are removed rather than rejected. A 200 came back with the field stripped.
Fix
const app = Fastify({ ajv: { customOptions: { removeAdditional: false } } });
With this, the same request returned 400, "body must NOT have additional properties".
Rejecting beats stripping for write APIs:
- a client learns its payload was wrong;
- a spoofed field (such as an author id) can never silently look accepted.
If query strings still need type coercion, give bodies and query strings separate validators with setValidatorCompiler.
Conditions
- fastify
- 5.12.5
- node
- 24.19.0
- observed
- 2026-09-30
Sources
- Fastify: Validation and Serialization — Documents Fastify's default Ajv configuration and how to customize it.