Skip to content

fix(report-api): return 400 instead of 500 for invalid technology and date input - #156

Merged
max-ostapenko merged 1 commit into
mainfrom
fix/report-api-input-validation
Sep 30, 2026
Merged

max-ostapenko merged 1 commit into
mainfrom
fix/report-api-input-validation

Conversation

@max-ostapenko

Copy link
Copy Markdown
Contributor

Summary

Two input bugs made report-api return 500 for bad client input. Between them they caused 7 of the 9 500 responses in the last 14 days of production logs.

/v1/technologies with more than 30 technologies (6 of the 500s)

validateTechnologyArray() returns null when the list is longer than Firestore's in limit of 30. queryTechnologies read technologies.length before checking for null, so it crashed with TypeError: Cannot read properties of null (reading 'length'), and the existing 400 error never ran. It now checks for null first, the same way queryVersions already does.

Example failing request: /v1/technologies?technology=WordPress,Joomla,Drupal,… (33 technologies).

/v1/cwv-distribution?date=undefined (1 of the 500s)

The string "undefined" was passed to BigQuery as @date, and the query failed with Cannot query over table 'httparchive.crawl.pages' without a filter over column(s) 'date' that can be used for partition elimination. The controller now accepts only YYYY-MM-DD or latest and returns a 400 validation error for anything else.

Whatever sends date=undefined (probably the Tech Report frontend building the URL before it has a date) should be fixed separately.

Tests

  • Added a route test for each case. Both fail without the fix (500 and 200 instead of 400).
  • report-api: 120/120 tests pass, lint clean.

… date input

- /v1/technologies: check for null (more than 30 technologies) before
  reading .length, so the request gets a 400 instead of a TypeError 500
- /v1/cwv-distribution: reject a malformed date (e.g. "undefined") with a
  400 instead of passing it to BigQuery, which fails partition elimination
@max-ostapenko
max-ostapenko merged commit 6a85fab into main Sep 30, 2026
5 checks passed
@max-ostapenko
max-ostapenko deleted the fix/report-api-input-validation branch September 30, 2026 19:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant