Non-numeric org_id or schedule_id query params return 500 #57

Open
opened 2026-10-03 19:44:41 +00:00 by jalenluorion · 0 comments
Member

What's wrong

  • GET /api/organizations/get_user_role_in_org?org_id=abc: int(org_id) (L655) raises ValueError, so 500 for any signed-in user.
  • GET /api/organizations/get_admins_in_org?org_id=abc: int(org_id) (L620) raises for site admins. Other callers get 403 first, because is_org_member() treats a bad id as "not a member".
  • GET /api/schedule/?schedule_id=abc: the raw string is compared with an integer column (L49). Postgres raises "invalid input syntax for type bigint", so 500.

How to reproduce

curl -i -H "Authorization: Bearer $TOKEN" "$API/api/organizations/get_user_role_in_org?org_id=abc"
curl -i -H "Authorization: Bearer $SITE_ADMIN_TOKEN" "$API/api/organizations/get_admins_in_org?org_id=abc"
curl -i -H "Authorization: Bearer $TOKEN" "$API/api/schedule/?schedule_id=abc"

In tests use bearer(**ALICE) and bearer(**SITE_ADMIN). The schedule case returns 200 on SQLite, so assert 400.

Expected
400 {"error": "org_id must be an integer"} (and the same for schedule_id). A missing value keeps its current 400 or default behavior. request.args.get("org_id", type=int) returns None for bad input; check for that separately from "missing".

Where to look

  • api/app/api/organizations.py: get_admins_in_org() L610-642, get_user_role_in_org() L645-662.
  • api/app/api/schedule.py: get_schedule_route() L38-51.
  • Line numbers are from main at 2c5f2e9.

Done when

  • all three return 400 for a non-numeric id
  • tests in api/tests/api/test_query_id_parsing.py
**What's wrong** - `GET /api/organizations/get_user_role_in_org?org_id=abc`: `int(org_id)` (L655) raises ValueError, so 500 for any signed-in user. - `GET /api/organizations/get_admins_in_org?org_id=abc`: `int(org_id)` (L620) raises for site admins. Other callers get 403 first, because `is_org_member()` treats a bad id as "not a member". - `GET /api/schedule/?schedule_id=abc`: the raw string is compared with an integer column (L49). Postgres raises "invalid input syntax for type bigint", so 500. **How to reproduce** ``` curl -i -H "Authorization: Bearer $TOKEN" "$API/api/organizations/get_user_role_in_org?org_id=abc" curl -i -H "Authorization: Bearer $SITE_ADMIN_TOKEN" "$API/api/organizations/get_admins_in_org?org_id=abc" curl -i -H "Authorization: Bearer $TOKEN" "$API/api/schedule/?schedule_id=abc" ``` In tests use `bearer(**ALICE)` and `bearer(**SITE_ADMIN)`. The schedule case returns 200 on SQLite, so assert 400. **Expected** 400 `{"error": "org_id must be an integer"}` (and the same for `schedule_id`). A missing value keeps its current 400 or default behavior. `request.args.get("org_id", type=int)` returns None for bad input; check for that separately from "missing". **Where to look** - `api/app/api/organizations.py`: `get_admins_in_org()` L610-642, `get_user_role_in_org()` L645-662. - `api/app/api/schedule.py`: `get_schedule_route()` L38-51. - Line numbers are from main at 2c5f2e9. **Done when** - [ ] all three return 400 for a non-numeric id - [ ] tests in `api/tests/api/test_query_id_parsing.py`
jalenluorion added this to the Phase 1 milestone 2026-10-03 19:44:41 +00:00
jalenluorion added this to the CMUCal project 2026-10-03 19:45:09 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ScottyLabs/cal#57
No description provided.