Skip to content

INTER-2511: [api-v3] Reject doth parameters for request and visitor IDs - #232

Merged
erayaydin merged 3 commits into
api-v3from
fix/reject-dot-segment-path-params-inter-2511
Sep 28, 2026
Merged

erayaydin merged 3 commits into
api-v3from
fix/reject-dot-segment-path-params-inter-2511

Conversation

@erayaydin

@erayaydin erayaydin commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Problem

Passing . or .. as a request or visitor ID reaches a different endpoint than the caller asked for.

Values are already encoded into a single segment, so get_event('../events') correctly requests /events/..%2Fevents. But . and .. survive that encoding.

request_id request actually sent
.. GET /
. GET /events/

So get_event('..') silently returns data from an endpoint that was never requested.

Changes

  • New InvalidArgumentError (w/ the rejected parameter and value). It subclasses ValueError.
invalid value '..' for request_id: not a valid identifier
  • __call_api raises it before sending when an ID is exactly . or .., covering get_event, update_event, get_visits, and delete_visitor_data.
  • A warning callout per operation in docs/FingerprintApi.md.

Tests assert against the literal request target a local HTTP server receives, not a URL built.

`.` and `..` survive percent-encoding as literal dots, so urllib3 normalizes them out
of the path before the request leaves. Passing `..` as an ID turned `GET /events/..`
into a request for `/`, reaching an endpoint the caller never asked for.

`get_event`, `update_event`, `get_visits`, and `delete_visitor_data` now raise the new
`InvalidPathParameterError` before sending, exposing the rejected `parameter` and
`value`. It subclasses `ValueError`.

Related-Task: INTER-2511
@erayaydin
erayaydin requested a balanced review from Copilot September 22, 2026 12:27
@erayaydin erayaydin self-assigned this Sep 22, 2026
@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

☂️ Python Coverage

current status: ✅

Overall Coverage

Lines Covered Coverage Threshold Status
6308 5299 84% 0% 🟢

New Files

No new covered files...

Modified Files

File Coverage Status
fingerprint_pro_server_api_sdk/init.py 100% 🟢
fingerprint_pro_server_api_sdk/api_client.py 67% 🟢
fingerprint_pro_server_api_sdk/rest.py 72% 🟢
TOTAL 80% 🟢

updated for commit: c8a0563 by action🐍

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation consistently updates generated sources and templates, with comprehensive request-target tests covering all affected operations.

Review effort: Balanced
Findings: None

What changed in this PR

Rejects dot-segment request and visitor IDs before HTTP dispatch, preventing URL normalization from targeting unintended endpoints.

Changes:

  • Adds and exports InvalidParameterError.
  • Validates encoded path parameters against . and ...
  • Adds endpoint documentation, tests, and release notes.
File Description
test/​test_path_params.py Tests encoding and dot-segment rejection using a local server.
template/​rest.mustache Generates the new exception.
template/​api_doc.mustache Generates path-parameter warnings.
template/​api_client.mustache Generates path validation.
template/​__init__package.mustache Generates the public exception export.
fingerprint_pro_server_api_sdk/​rest.py Defines InvalidParameterError.
fingerprint_pro_server_api_sdk/​api_client.py Rejects dot segments before dispatch.
fingerprint_pro_server_api_sdk/​__init__.py Exports the exception publicly.
docs/​FingerprintApi.md Documents invalid identifiers per operation.
.changeset/​reject-dot-segment-path-parameters.md Records the patch-level change.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@erayaydin
erayaydin marked this pull request as ready for review September 22, 2026 12:31
TheUnderScorer
TheUnderScorer previously approved these changes Sep 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Following releases will be created using changesets from this PR:

fingerprint-pro-server-api-python-sdk@8.15.1

Patch Changes

  • Reject . and .. as request and visitor IDs. get_event, update_event, get_visits, and delete_visitor_data now raise the new InvalidArgumentError without sending a request. (a56e351)

@erayaydin
erayaydin marked this pull request as draft September 22, 2026 15:58
@erayaydin
erayaydin marked this pull request as ready for review September 23, 2026 11:30
@erayaydin
erayaydin merged commit 553a218 into api-v3 Sep 28, 2026
22 checks passed
@erayaydin
erayaydin deleted the fix/reject-dot-segment-path-params-inter-2511 branch September 28, 2026 13:13

This branch was successfully deployed

1 active deployment
test — c8a05634 Deployed Sep 22, 2026 by erayaydin via Functional tests for Python pypy3.11 #1776
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants