Skip to content

INTER-2505: Reject dot parameters for event and visitor IDs - #231

Merged
erayaydin merged 3 commits into
mainfrom
fix/reject-dot-segment-path-params-inter-2505
Sep 28, 2026
Merged

erayaydin merged 3 commits into
mainfrom
fix/reject-dot-segment-path-params-inter-2505

Conversation

@erayaydin

@erayaydin erayaydin commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Problem

Passing . or .. as an event or visitor ID reaches a different endpoint than the caller asked for.

Values are already encoded into a single segment, so get_event('../events') correctly requests /v4/events/..%2Fevents. But . and .. survive that encoding.

event_id request actually sent
.. GET /v4/
. GET /v4/events/

So get_event('..') silently returns data from an endpoint that was never requested.

Changes

  • New InvalidArgumentError (w/ the rejected parameter and value). It subclasses ApiValueError.
invalid value '..' for event_id: not a valid identifier
  • param_serialize raises it before sending when an ID is exactly . or ...
  • A warning callout per operation in docs/FingerprintApi.md.

Tests assert against the literal request target a local HTTP server receives, not a URL built.

`.` and `..` survive percent-encoding as literal dots, so urllib3 normalizes them out
of the path before the request leaves. Passing `..` as an ID turned `GET /v4/events/..`
into a request for `/v4/`, reaching an endpoint the caller never asked for.

`get_event`, `update_event`, and `delete_visitor_data` now raise the new
`InvalidPathParameterError` before sending, exposing the rejected `parameter` and
`value`. It subclasses `ApiValueError`.

Related-Task: INTER-2505
@erayaydin
erayaydin requested a balanced review from Copilot September 22, 2026 12:26
@erayaydin erayaydin self-assigned this Sep 22, 2026
@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

☂️ Code Coverage

current status: ✅

Overall Coverage

Statements Covered Coverage Threshold Status
3276 2360 72% 0% 🟢

New Files

No new covered files...

Modified Files

File Coverage Status
fingerprint_server_sdk/init.py 100% 🟢
fingerprint_server_sdk/api_client.py 60% 🟢
fingerprint_server_sdk/exceptions.py 65% 🟢
TOTAL 75% 🟢

updated for commit: 57c23c8 by action🐍

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The validation, generated templates, public exports, documentation, and request-level tests consistently implement the intended protection.

Review effort: Balanced
Findings: None

What changed in this PR

Rejects unsafe dot-segment identifiers before requests are sent.

Changes:

  • Adds and exports InvalidParameterError.
  • Validates encoded path parameters and documents invalid values.
  • Adds end-to-end request-target coverage for all affected operations.
File Description
test/​test_path_params.py Tests encoding and dot rejection.
template/​exports_package.mustache Exports the new exception.
template/​exceptions.mustache Defines the generated exception.
template/​api_doc.mustache Generates path-parameter warnings.
template/​api_client.mustache Generates dot-segment validation.
template/​__init__package.mustache Adds the public export.
fingerprint_server_sdk/​exceptions.py Defines InvalidParameterError.
fingerprint_server_sdk/​api_client.py Rejects dot path segments.
fingerprint_server_sdk/​__init__.py Exposes the exception publicly.
docs/​FingerprintApi.md Documents affected operations.
.changeset/​reject-dot-segment-path-parameters.md Records the patch-level change.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@erayaydin
erayaydin marked this pull request as ready for review September 22, 2026 12:29
TheUnderScorer
TheUnderScorer previously approved these changes Sep 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Following releases will be created using changesets from this PR:

@fingerprint/python-sdk@9.7.2

Patch Changes

  • Reject . and .. as event and visitor IDs. get_event, update_event, and delete_visitor_data now raise the new InvalidArgumentError without sending a request. (4b7f5b6)

@erayaydin
erayaydin marked this pull request as draft September 22, 2026 15:58
@erayaydin
erayaydin marked this pull request as ready for review September 23, 2026 11:30
@erayaydin
erayaydin merged commit dc45530 into main Sep 28, 2026
35 checks passed
@erayaydin
erayaydin deleted the fix/reject-dot-segment-path-params-inter-2505 branch September 28, 2026 13:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants