Non-numeric org_id or schedule_id query params return 500 #57
Labels
No labels
bug
chore
data
feature
frontend
good first issue
intermediate
needs/docs
needs/research
needs/upstream
type/bug
type/external
type/feature
type/refactor
urgency
high
urgency
immediate
urgency
low
urgency
medium
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
ScottyLabs/cal#57
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What's wrong
GET /api/organizations/get_user_role_in_org?org_id=abc:int(org_id)(L655) raises ValueError, so 500 for any signed-in user.GET /api/organizations/get_admins_in_org?org_id=abc:int(org_id)(L620) raises for site admins. Other callers get 403 first, becauseis_org_member()treats a bad id as "not a member".GET /api/schedule/?schedule_id=abc: the raw string is compared with an integer column (L49). Postgres raises "invalid input syntax for type bigint", so 500.How to reproduce
In tests use
bearer(**ALICE)andbearer(**SITE_ADMIN). The schedule case returns 200 on SQLite, so assert 400.Expected
400
{"error": "org_id must be an integer"}(and the same forschedule_id). A missing value keeps its current 400 or default behavior.request.args.get("org_id", type=int)returns None for bad input; check for that separately from "missing".Where to look
api/app/api/organizations.py:get_admins_in_org()L610-642,get_user_role_in_org()L645-662.api/app/api/schedule.py:get_schedule_route()L38-51.2c5f2e9.Done when
api/tests/api/test_query_id_parsing.py