trackslash
TRACK-54 P3

Malformed owner in /{owner}/projects returns 500 instead of 400

0
All issues

Description

The owner path segment is passed through unvalidated, so a malformed username produces a 500 and an internal-error log line for what is plain user input.

internal/server/ui_home_pages.go:72 (and the same shape at :391):

panel, err := s.uiBuildOwnerProjectsPanel(r.Context(), currentUser(r), chi.URLParam(r, "owner"))

uiBuildOwnerProjectsPanel (ui_project_pages.go:247-250) returns GetUserByUsername's error verbatim. For an invalid username shape that is a bare error from store.NormalizeUsername — neither store.ErrNotFound nor errUIBadRequest — so writeUIStoreError falls to default (ui_templates.go:235-236) → writeUIInternalError → 500.

Steps to reproduce

As a signed-in user, request GET /ab/projects (2-char owner), GET /bad.user/projects, GET /-x/projects, or GET /ab/projects/panel.

Actual

500 plus a spurious internal error: source="ui store" log line.

Expected

400 or 404. The sibling route already does this correctly — uiProjectFromRoute (ui_access.go:231-235) normalizes first and returns 400.

Fix

Normalize before the call at both sites:

owner, err := store.NormalizeUsername(chi.URLParam(r, "owner"))
if err != nil {
	writeUIStoreError(w, errUIBadRequest)
	return
}

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.