Skip to content

Return 400 for missing or invalid query and path parameters #387

Description

@nielsenko

A missing or undecodable query or path parameter produces a 500 today. For query parameters it is a client error and should be a 400.

Current behavior

const pageParam = IntQueryParam('page');

router.get('/items', (req) {
  final page = req.queryParameters.get(pageParam);
  return Response.ok();
});
  • GET /items throws StateError('Missing value for key: page') from AccessorState.get. The server answers 500.
  • GET /items?page=abc throws FormatException from int.parse. The server answers 500.

Both show up as server errors in logs and alerting, even though the client sent the bad input.

Proposal

Throw a dedicated exception for a missing or undecodable parameter and map it to 400 in RelicServer, the same way form parsing does. The forms work (FormFields on AccessorState, MissingFormFieldException, InvalidFormFieldException, one on FormException catch that uses statusCode) is a working example of the pattern.

Open questions

  • Path parameters: a missing path parameter usually means the route pattern and the accessor disagree, which is a server bug. A 500 may be right there, with only undecodable values becoming 400.
  • This is breaking for code that catches StateError or FormatException from .get(). Relic is at 2.0.0-rc.1, so it could still go into 2.0.
  • Whether to share one base exception between forms, query parameters and path parameters.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions