fix(#172): API hardening — null-name 500s, duplicate template items, unreachable 404 #325

Merged
timothy merged 2 commits from fix/172-api-hardening into main 2026-07-13 01:27:38 +02:00
2 Commits
Author SHA1 Message Date
timothyandClaude Opus 4.8 2e4e07a207 fix(#172): review B1 — sync 404 metadata test + extend create-group trim to Deco/DecoTemplate
Build ErsatzTV Image / decisions.md append-only (pull_request) Successful in 9s
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 9s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 4m23s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 5m24s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (pull_request) Successful in 1m51s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (pull_request) Successful in 2m41s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (push) Has been skipped
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (push) Has been skipped
Build ErsatzTV Image / Docs update reminder (push) Has been skipped
Build ErsatzTV Image / decisions.md append-only (push) Has been skipped
Build ErsatzTV Image / Build & test (.NET) (push) Successful in 8m7s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (push) Successful in 9m40s
Build ErsatzTV Image / Build & push image (amd64) (push) Successful in 4m56s
Renovate / Renovate (push) Successful in 2m38s
Dependency vulnerability scan / NuGet vulnerable packages (push) Failing after 1m11s
Cold review (PR #325) caught that removing the unreachable 404 from
BlockController/TemplateController.CreateGroup left ApiErrorResponseMetadataTests
still asserting those ops document 404 -> red Build & test. Removed those two stale
assertions. For spec consistency, extended the trim to the two OTHER create-group
actions carrying the same unreachable 404 (DecoController, DecoTemplateController --
their Create*GroupHandler only do a duplicate-name AnyAsync -> 422, never a lookup
that 404s). Net: all four CreateGroup 404 assertions removed (422 siblings kept),
both controllers trimmed, v1.json regenerated (4 unreachable 404 blocks gone total).
PlaylistController.CreateGroup already carried no 404.

Refs #172

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 01:16:52 +02:00
timothyandClaude Opus 4.8 216130b4d7 fix(#172): API hardening — null-name 500s, duplicate template items, unreachable 404
Clears the still-live findings from #172 (verified against main; #2/#4/#7 and the
auth/search/Trakt tail were already deliberate-documented or fixed since 2026-07-07).

- Null/empty Name → 500 (10 create/replace handlers). Block/Template/DecoTemplate/Deco
  Create+Replace/Update + UpdateFFmpegProfile did `request.Name.Length > 50` on a
  client-nullable string → unhandled NullReferenceException → HTTP 500 (no global
  exception filter). Now `string.IsNullOrWhiteSpace(request.Name) || .Length > 50` →
  422; also rejects empty/whitespace names, matching the group-create handlers'
  NotEmpty behavior. CreatePlaylist coalesces null→"" at the DTO so it was an
  empty-name persist, not a 500; guarded the same way.
- ReplaceTemplateItems overlap validation iterated with an `item == otherItem`
  record value-equality skip, so two exact-duplicate items were value-equal and
  bypassed the intersection check (both persisted). Now index-based (i != j) so
  duplicates register as a self-intersection and are rejected 422.
- Trimmed the unreachable 404 ProducesResponseType from POST /api/blocks/groups and
  POST /api/templates/groups (a create has no parent lookup that can 404); v1.json
  regenerated.
- Regression tests: all 10 name-guard paths + the duplicate-items path (19 cases).
- Docs: decisions.md entry + api-conventions.md §3b null-safe-validation bullet.

fixes #172

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 01:16:52 +02:00