fix(api): generic 500 bodies and typed id params #21

Merged
jalenluorion merged 3 commits from chore/api-errors into main 2026-10-03 02:52:04 +00:00
Member
  • 40 handlers returned str(e) in 500 bodies, which leaked SQL and stack details to clients. They now log the exception and return {"error": "Internal server error"}. /test_db keeps {"status": "error"} (the keepalive job only reads status).
  • Event id routes use int:... converters, so a non-numeric id is a 404 instead of a 500 carrying SQL text. The url map is otherwise unchanged (checked before and after).
  • PATCH on a missing event is 404 instead of 400; google.py logs the exceptions it used to swallow; a duplicate org lookup and two routes missing a leading slash are tidied.

263 API tests pass, including new ones for the 404 and for 500 bodies carrying no exception text. 4xx messages are unchanged.

- 40 handlers returned str(e) in 500 bodies, which leaked SQL and stack details to clients. They now log the exception and return {"error": "Internal server error"}. /test_db keeps {"status": "error"} (the keepalive job only reads status). - Event id routes use <int:...> converters, so a non-numeric id is a 404 instead of a 500 carrying SQL text. The url map is otherwise unchanged (checked before and after). - PATCH on a missing event is 404 instead of 400; google.py logs the exceptions it used to swallow; a duplicate org lookup and two routes missing a leading slash are tidied. 263 API tests pass, including new ones for the 404 and for 500 bodies carrying no exception text. 4xx messages are unchanged.
Handlers returned str(e) in their 500 responses, which leaked SQL, table
names and other internals to callers. They now log the exception and
return {"error": "Internal server error"}. 4xx bodies are unchanged.

- /test_db keeps {"status": "error"} for the keepalive workflow, which
  only reads .status, but no longer returns details.
- read_gcal_link used its own {"success", "error", "message"} 500 shape;
  no web client reads those fields, so it now matches the rest.
- google.py swallowed exceptions without logging; each handler now calls
  log.exception. /unauthorize keeps its 400.
Use <int:...> for the event and category ids in events.py, so a
non-numeric id is a routing 404 instead of reaching the query. Static
routes such as /tags and /user_saved_events resolve to the same views as
before; only paths that the untyped <event_id> used to swallow (for
example PATCH /tags) now get 404 or 405.

google.py /calendar/events/<local_event_id> stays untyped:
synced_events.local_event_id is a text column.
chore(api): small route cleanups
All checks were successful
kennel/build build succeeded
CI / check-1 (pull_request) Successful in 2m44s
CI / build (pull_request) Successful in 4m30s
CI / check (pull_request) Successful in 0s
745630aae6
- PATCH /events/<id> returns 404, not 400, when the event does not exist.
- Give the user_saved_events and user_saved_event_occurrences GET routes
  a leading slash. The URL map is unchanged; Flask joined the blueprint
  prefix either way.
- bulk_create_admins reuses the org it already looked up by name instead
  of querying for it a second time.
jalenluorion deleted branch chore/api-errors 2026-10-03 02:52:04 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ScottyLabs/cal!21
No description provided.