GET /api/events/ returns 500 for a non-numeric ?tags= or a bad ?date= #54

Open
opened 2026-10-03 19:44:41 +00:00 by jalenluorion · 0 comments
Member

What's wrong
GET /api/events/ passes ?tags= and ?date= straight into SQL. On Postgres a tag id that is not an integer (tags=abc, or the empty item in tags=1,,2) fails with "invalid input syntax for type bigint", and a date that is not YYYY-MM-DD fails with "invalid input syntax for type date". Both come back as 500 {"error": "Internal server error"}.

How to reproduce

curl -i 'http://localhost:5001/api/events/?tags=abc'
curl -i 'http://localhost:5001/api/events/?date=notadate'

Both return 500 against Postgres. The SQLite test harness (api/tests/api/conftest.py) does not type-check, so there they return 200: a test that asserts 400 fails today and passes after the fix.

Expected
400 with a clear message, e.g. {"error": "tags must be comma-separated integers"} and {"error": "date must be YYYY-MM-DD"}. Empty tags= and date= (what the web client sends) still mean "no filter".

Where to look

  • api/app/api/events.py get_all_events() (L520-602): tags is split at L524-525 and used at L557-561; date is read at L526 and used at L565-566.
  • Parse both before building the query (int() per tag, datetime.date.fromisoformat()), then filter on the parsed values.
  • Line numbers are from main at 2c5f2e9.

Done when

  • bad tags and date return 400 with a message; empty values still return events
  • tests in api/tests/api/test_events_query_params.py (fixtures client, world, bearer) for tags=abc, tags=1,,2, date=notadate and one valid date
**What's wrong** `GET /api/events/` passes `?tags=` and `?date=` straight into SQL. On Postgres a tag id that is not an integer (`tags=abc`, or the empty item in `tags=1,,2`) fails with "invalid input syntax for type bigint", and a date that is not `YYYY-MM-DD` fails with "invalid input syntax for type date". Both come back as 500 `{"error": "Internal server error"}`. **How to reproduce** ``` curl -i 'http://localhost:5001/api/events/?tags=abc' curl -i 'http://localhost:5001/api/events/?date=notadate' ``` Both return 500 against Postgres. The SQLite test harness (`api/tests/api/conftest.py`) does not type-check, so there they return 200: a test that asserts 400 fails today and passes after the fix. **Expected** 400 with a clear message, e.g. `{"error": "tags must be comma-separated integers"}` and `{"error": "date must be YYYY-MM-DD"}`. Empty `tags=` and `date=` (what the web client sends) still mean "no filter". **Where to look** - `api/app/api/events.py` `get_all_events()` (L520-602): `tags` is split at L524-525 and used at L557-561; `date` is read at L526 and used at L565-566. - Parse both before building the query (`int()` per tag, `datetime.date.fromisoformat()`), then filter on the parsed values. - Line numbers are from main at 2c5f2e9. **Done when** - [ ] bad `tags` and `date` return 400 with a message; empty values still return events - [ ] tests in `api/tests/api/test_events_query_params.py` (fixtures `client`, `world`, `bearer`) for `tags=abc`, `tags=1,,2`, `date=notadate` and one valid date
jalenluorion added this to the Phase 1 milestone 2026-10-03 19:44:41 +00:00
jalenluorion added this to the CMUCal project 2026-10-03 19:45:09 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ScottyLabs/cal#54
No description provided.