GET /api/events/ returns 500 for a non-numeric ?tags= or a bad ?date= #54
Labels
No labels
bug
chore
data
feature
frontend
good first issue
intermediate
needs/docs
needs/research
needs/upstream
type/bug
type/external
type/feature
type/refactor
urgency
high
urgency
immediate
urgency
low
urgency
medium
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
ScottyLabs/cal#54
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What's wrong
GET /api/events/passes?tags=and?date=straight into SQL. On Postgres a tag id that is not an integer (tags=abc, or the empty item intags=1,,2) fails with "invalid input syntax for type bigint", and a date that is notYYYY-MM-DDfails with "invalid input syntax for type date". Both come back as 500{"error": "Internal server error"}.How to reproduce
Both return 500 against Postgres. The SQLite test harness (
api/tests/api/conftest.py) does not type-check, so there they return 200: a test that asserts 400 fails today and passes after the fix.Expected
400 with a clear message, e.g.
{"error": "tags must be comma-separated integers"}and{"error": "date must be YYYY-MM-DD"}. Emptytags=anddate=(what the web client sends) still mean "no filter".Where to look
api/app/api/events.pyget_all_events()(L520-602):tagsis split at L524-525 and used at L557-561;dateis read at L526 and used at L565-566.int()per tag,datetime.date.fromisoformat()), then filter on the parsed values.2c5f2e9.Done when
tagsanddatereturn 400 with a message; empty values still return eventsapi/tests/api/test_events_query_params.py(fixturesclient,world,bearer) fortags=abc,tags=1,,2,date=notadateand one valid date