Reject NUL characters in scrobble imports with a 400 - #215
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
Reviewed head a641db7 (on main ac48ed1). Approved. All 54 test files and 363 tests pass. The three new NUL tests (artistName, trackTitle, albumTitle) fail against main's contracts schema. I sent 12 payloads through the real route, with a mocked database:
The refine is on the shared ScrobbleItemSchema, whose only use is this route. Non-blocking: the 400 body is the route's generic "Provide a valid list of scrobbles" message, so the caller isn't told which field had the NUL. CI at the time I checked: all nine checks completed successfully (worker, api, migrate and web container builds, TypeScript workspace, Compose config, CodeFactor, codecov/patch, ghostdeps). |
A scrobble whose artistName, trackTitle or albumTitle contained a NUL character passed validation and then failed inside Postgres (text cannot hold 0x00), so the API answered 500. Login already guards this for the username. The scrobble schema now refuses NUL, so the request gets the existing 400 INVALID_REQUEST before any query runs. Test: three cases (one per field) answer 500 on main and 400 with the change, and assert the database is never called. Behaviour change: an invalid payload now returns 400 instead of 500.