Skip to content

fix: return 400 for invalid purls in the v3 packages API - #2466

Open
Sahil-u07 wants to merge 1 commit into
aboutcode-org:mainfrom
Sahil-u07:fix-api-v3-invalid-purl
Open

Sahil-u07 wants to merge 1 commit into
aboutcode-org:mainfrom
Sahil-u07:fix-api-v3-invalid-purl

Conversation

@Sahil-u07

Copy link
Copy Markdown

Sending a malformed purl to POST /api/v3/packages either crashes or gets silently ignored, depending on ignore_qualifiers_subpath:

POST /api/v3/packages
{"purls": ["not-a-purl"], "details": true, "ignore_qualifiers_subpath": true}
  • with ignore_qualifiers_subpath: true, the view calls PackageURL.from_string on it and the ValueError isn't caught, so it's a 500
  • with ignore_qualifiers_subpath: false, the bad purl just doesn't match anything and the response is a 200 with no results, which hides the mistake from the caller

PackageQuerySerializer accepted any string as a purl, so I added a validate_purls check there. Since the view already calls is_valid(raise_exception=True), both cases now return a 400 with the parse error, e.g.

{"purls": ["purl is missing the required \"pkg\" scheme component: 'not-a-purl'."]}

The advisories endpoint (AdvisoryQuerySerializer) also takes purls, but it only uses them in a DB lookup and never parses them, so I left it alone to keep this focused. Happy to add the same check there if you'd like the two to behave the same.

Added a test that posts an invalid purl with the flag both on and off and expects a 400. All the tests in test_api_v3.py pass locally.

PackageQuerySerializer accepted any string as a purl. With
ignore_qualifiers_subpath set, the view then called
PackageURL.from_string on it and the ValueError surfaced as a 500.
Without that flag the bad purl was silently ignored and the request
returned 200 with no results.

Validate each purl in the serializer so both cases get a 400 that
says which purl is wrong.

Signed-off-by: Sahil Lenka <76817449+Sahil-u07@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant