Skip to content

fix(api_v3): validate PURLs in packages and advisories query serializers - #2468

Open
shubhamrai9122-creator wants to merge 1 commit into
aboutcode-org:mainfrom
shubhamrai9122-creator:fix/api-v3-validate-advisory-purl
Open

shubhamrai9122-creator wants to merge 1 commit into
aboutcode-org:mainfrom
shubhamrai9122-creator:fix/api-v3-validate-advisory-purl

Conversation

@shubhamrai9122-creator

Copy link
Copy Markdown

Summary

In API v3 (POST /api/v3/packages and POST /api/v3/advisories), passing malformed or invalid Package URLs (PURLs) causes either:

  1. An unhandled ValueError from PackageURL.from_string resulting in an HTTP 500 Internal Server Error when ignore_qualifiers_subpath or detailed package processing is enabled.
  2. Silent no-op / empty results concealing invalid input when queried against endpoints without parsing.

Changes

  • Added validate_purls() validator to PackageQuerySerializer to ensure all elements in purls are valid Package URLs according to the packageurl specification, raising serializers.ValidationError on malformed inputs.
  • Added matching validate_purls() validator to AdvisoryQuerySerializer ensuring consistent behavior and validation across the v3 API endpoints.
  • Added tests in vulnerabilities/tests/test_api_v3.py (test_packages_post_with_invalid_purl and test_advisories_post_with_invalid_purl) verifying that HTTP 400 with descriptive error details is returned for malformed PURLs.

Builds upon and completes the API validation improvements proposed in #2466.

In api_v3, passing malformed or invalid Package URLs to POST /api/v3/packages
or POST /api/v3/advisories either causes an unhandled ValueError (500 Internal
Server Error) when details/ignore_qualifiers_subpath is set, or silently returns
empty results.

Add validate_purls validation methods to both PackageQuerySerializer and
AdvisoryQuerySerializer using PackageURL.from_string, ensuring consistent
HTTP 400 Bad Request responses with descriptive validation error messages for
malformed PURLs across all v3 query endpoints.

Add test cases in test_api_v3 covering invalid PURL submissions for both
endpoints.

Signed-off-by: Shubham Rai <shubhamrai9122@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant