feat(api-keys): reject unknown query params, malformed prefixes, blank labels - #412
Open
thlpkee20-wq wants to merge 3 commits into
Open
feat(api-keys): reject unknown query params, malformed prefixes, blank labels#412thlpkee20-wq wants to merge 3 commits into
thlpkee20-wq wants to merge 3 commits into
Conversation
The GET /api/v1/api-keys handler inlined the same limit/offset parsing and slicing preamble duplicated in the webhooks list handler. Extracted it into applyOffsetPage() in src/listPagination.ts as a single reusable entry point; behavior is unchanged (same defaults, same response shape).
Adds a generic paginateByCursor() helper (src/cursorPagination.ts) and an applyListPage() wrapper that layers opt-in ?cursor= paging on top of the existing offset/limit contract: passing cursor takes priority over offset, and both modes now report a stable nextCursor so existing offset-based clients can migrate without a contract change. Malformed or expired cursors return 400 invalid_request. Item shape and existing offset behavior are unchanged.
…k labels - GET /api/v1/api-keys now rejects any query parameter outside limit/offset/cursor with a structured 400 invalid_request. - DELETE /api/v1/api-keys/:prefix rejects a malformed prefix (must be 1-64 alphanumeric/underscore chars) with 400 before searching the store, instead of always falling through to a 404. - POST /api/v1/api-keys rejects a whitespace-only label via a new rejectBlank option on stringField, scoped to the label field only.
This was referenced Jul 28, 2026
Contributor
|
@thlpkee20-wq clean implementation, merging with thanks 🙌 |
1 similar comment
Contributor
|
@thlpkee20-wq clean implementation, merging with thanks 🙌 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #383
GET /api/v1/api-keysnow rejects any query parameter outsidelimit/offset/cursorwith a structured400 invalid_request.DELETE /api/v1/api-keys/:prefixrejects a malformed prefix (must be1-64 alphanumeric/underscore chars) with
400before searching thestore, instead of always falling through to a
404.POST /api/v1/api-keysrejects a whitespace-only label via a newrejectBlankoption on the sharedstringFieldschema builder,applied only to the
labelfield (other fields usingstringFieldare unaffected).
Test plan
npm run buildnpm run lintnpm test— targeted run oflist-pagination.test.js,apikey-recognition.test.js,schema-validation.test.js,routes/operational.test.js: 17/17 passing.Note
Stacked on #410 and #411 (same fork-only caveat as noted on #411 — I
can't target those as the PR base). The validation-specific change is
src/routes/apiKeys.tsandsrc/schemas/requestBodies.ts.