create_event, read_gcal_link and PATCH /api/events/<id> return 500 on malformed bodies #55
Labels
No labels
bug
chore
data
feature
frontend
good first issue
intermediate
needs/docs
needs/research
needs/upstream
type/bug
type/external
type/feature
type/refactor
urgency
high
urgency
immediate
urgency
low
urgency
medium
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
ScottyLabs/cal#55
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What's wrong
POST /api/events/create_event:request.get_json()(L133) runs before therequest.is_jsoncheck (L135). Flask raises 415 for a non-JSON body and 400 for broken JSON, and the route'sexcept Exceptionturns both into 500.POST /api/events/read_gcal_link:int(data.get("org_id"))andint(data.get("category_id"))(L264-265) raise on a missing or non-numeric value, so 500.PATCH /api/events/<id>:t["name"](L827) assumesupdated_tagsis a list of{"name": ...}objects. A list of strings raises TypeError (not KeyError), so 500. The web client sends objects; scripts and other clients hit this.How to reproduce
As an org admin (in tests:
bearer(**BOB), org1/cat1 from theworldfixture):All three return 500.
Expected
400 with a message that names the bad field. A small helper (e.g.
request.get_json(silent=True)plus "body must be a JSON object") can be shared by all three.Where to look
api/app/api/events.py:create_event_record()L129-254,read_gcal_link()L257-343,update_event()L792-855.2c5f2e9.Done when
[{"name": "x"}]) and either also accepts plain strings or rejects them with 400api/tests/api/test_events_body_validation.pyfor each case