create_event, read_gcal_link and PATCH /api/events/<id> return 500 on malformed bodies #55

Open
opened 2026-10-03 19:44:41 +00:00 by jalenluorion · 0 comments
Member

What's wrong

  • POST /api/events/create_event: request.get_json() (L133) runs before the request.is_json check (L135). Flask raises 415 for a non-JSON body and 400 for broken JSON, and the route's except Exception turns both into 500.
  • POST /api/events/read_gcal_link: int(data.get("org_id")) and int(data.get("category_id")) (L264-265) raise on a missing or non-numeric value, so 500.
  • PATCH /api/events/<id>: t["name"] (L827) assumes updated_tags is a list of {"name": ...} objects. A list of strings raises TypeError (not KeyError), so 500. The web client sends objects; scripts and other clients hit this.

How to reproduce
As an org admin (in tests: bearer(**BOB), org1/cat1 from the world fixture):

curl -i -X POST $API/api/events/create_event -H "Authorization: Bearer $TOKEN" -d 'hello'
curl -i -X POST $API/api/events/read_gcal_link -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' -d '{"gcal_link":"https://x.test/a.ics","category_id":1}'
curl -i -X PATCH $API/api/events/1 -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' -d '{"updated_event":{"title":"x"},"updated_tags":["a"]}'

All three return 500.

Expected
400 with a message that names the bad field. A small helper (e.g. request.get_json(silent=True) plus "body must be a JSON object") can be shared by all three.

Where to look

  • api/app/api/events.py: create_event_record() L129-254, read_gcal_link() L257-343, update_event() L792-855.
  • Line numbers are from main at 2c5f2e9.

Done when

  • each case above returns 400 with a message
  • PATCH accepts the web shape ([{"name": "x"}]) and either also accepts plain strings or rejects them with 400
  • tests in api/tests/api/test_events_body_validation.py for each case
**What's wrong** - `POST /api/events/create_event`: `request.get_json()` (L133) runs before the `request.is_json` check (L135). Flask raises 415 for a non-JSON body and 400 for broken JSON, and the route's `except Exception` turns both into 500. - `POST /api/events/read_gcal_link`: `int(data.get("org_id"))` and `int(data.get("category_id"))` (L264-265) raise on a missing or non-numeric value, so 500. - `PATCH /api/events/<id>`: `t["name"]` (L827) assumes `updated_tags` is a list of `{"name": ...}` objects. A list of strings raises TypeError (not KeyError), so 500. The web client sends objects; scripts and other clients hit this. **How to reproduce** As an org admin (in tests: `bearer(**BOB)`, org1/cat1 from the `world` fixture): ``` curl -i -X POST $API/api/events/create_event -H "Authorization: Bearer $TOKEN" -d 'hello' curl -i -X POST $API/api/events/read_gcal_link -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' -d '{"gcal_link":"https://x.test/a.ics","category_id":1}' curl -i -X PATCH $API/api/events/1 -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' -d '{"updated_event":{"title":"x"},"updated_tags":["a"]}' ``` All three return 500. **Expected** 400 with a message that names the bad field. A small helper (e.g. `request.get_json(silent=True)` plus "body must be a JSON object") can be shared by all three. **Where to look** - `api/app/api/events.py`: `create_event_record()` L129-254, `read_gcal_link()` L257-343, `update_event()` L792-855. - Line numbers are from main at 2c5f2e9. **Done when** - [ ] each case above returns 400 with a message - [ ] PATCH accepts the web shape (`[{"name": "x"}]`) and either also accepts plain strings or rejects them with 400 - [ ] tests in `api/tests/api/test_events_body_validation.py` for each case
jalenluorion added this to the Phase 1 milestone 2026-10-03 19:44:41 +00:00
jalenluorion added this to the CMUCal project 2026-10-03 19:45:09 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ScottyLabs/cal#55
No description provided.