Skip to content

Malformed UUID in /invite/:id returns 500 instead of 404 #152

Description

@can3p

GET /invite/:id passes the path parameter straight into a query on a UUID column. When the id isn't a valid UUID, Postgres returns an invalid-input error rather than sql.ErrNoRows, and the handler panics (cmd/web/main.go, around line 271), so the response is 500.

Reproduction: GET /invite/not-a-uuid returns 500. An unknown but well-formed UUID correctly returns 404.

Expected: 404 for any id that doesn't name an unused invitation. Other handlers that take a UUID path parameter probably behave the same way, so they're worth checking when this is fixed.

Pinned by the skipped test TestE3_InviteInvalidUUID in e2e/accounts_test.go (W3).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions