Skip to content

feat(api-keys): reject unknown query params, malformed prefixes, blank labels - #412

Open
thlpkee20-wq wants to merge 3 commits into
Agentpay-Org:mainfrom
thlpkee20-wq:feature/api-keys-02-validation
Open

feat(api-keys): reject unknown query params, malformed prefixes, blank labels#412
thlpkee20-wq wants to merge 3 commits into
Agentpay-Org:mainfrom
thlpkee20-wq:feature/api-keys-02-validation

Conversation

@thlpkee20-wq

Copy link
Copy Markdown
Contributor

Closes #383

  • GET /api/v1/api-keys now rejects any query parameter outside
    limit/offset/cursor with a structured 400 invalid_request.
  • DELETE /api/v1/api-keys/:prefix rejects a malformed prefix (must be
    1-64 alphanumeric/underscore chars) with 400 before searching the
    store, instead of always falling through to a 404.
  • POST /api/v1/api-keys rejects a whitespace-only label via a new
    rejectBlank option on the shared stringField schema builder,
    applied only to the label field (other fields using stringField
    are unaffected).

Test plan

  • npm run build
  • npm run lint
  • npm test — targeted run of list-pagination.test.js,
    apikey-recognition.test.js, schema-validation.test.js,
    routes/operational.test.js: 17/17 passing.

Note

Stacked on #410 and #411 (same fork-only caveat as noted on #411 — I
can't target those as the PR base). The validation-specific change is
src/routes/apiKeys.ts and src/schemas/requestBodies.ts.

The GET /api/v1/api-keys handler inlined the same limit/offset parsing
and slicing preamble duplicated in the webhooks list handler. Extracted
it into applyOffsetPage() in src/listPagination.ts as a single reusable
entry point; behavior is unchanged (same defaults, same response shape).
Adds a generic paginateByCursor() helper (src/cursorPagination.ts) and
an applyListPage() wrapper that layers opt-in ?cursor= paging on top of
the existing offset/limit contract: passing cursor takes priority over
offset, and both modes now report a stable nextCursor so existing
offset-based clients can migrate without a contract change. Malformed
or expired cursors return 400 invalid_request. Item shape and existing
offset behavior are unchanged.
…k labels

- GET /api/v1/api-keys now rejects any query parameter outside
  limit/offset/cursor with a structured 400 invalid_request.
- DELETE /api/v1/api-keys/:prefix rejects a malformed prefix (must be
  1-64 alphanumeric/underscore chars) with 400 before searching the
  store, instead of always falling through to a 404.
- POST /api/v1/api-keys rejects a whitespace-only label via a new
  rejectBlank option on stringField, scoped to the label field only.
@mikewheeleer

Copy link
Copy Markdown
Contributor

@thlpkee20-wq clean implementation, merging with thanks 🙌

1 similar comment
@mikewheeleer

Copy link
Copy Markdown
Contributor

@thlpkee20-wq clean implementation, merging with thanks 🙌

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validate and bound api-keys request inputs against malformed payloads

2 participants