Description
The owner path segment is passed through unvalidated, so a malformed username produces a 500 and an internal-error log line for what is plain user input.
internal/server/ui_home_pages.go:72 (and the same shape at :391):
panel, err := s.uiBuildOwnerProjectsPanel(r.Context(), currentUser(r), chi.URLParam(r, "owner"))
uiBuildOwnerProjectsPanel (ui_project_pages.go:247-250) returns GetUserByUsername's error verbatim. For an invalid username shape that is a bare error from store.NormalizeUsername — neither store.ErrNotFound nor errUIBadRequest — so writeUIStoreError falls to default (ui_templates.go:235-236) → writeUIInternalError → 500.
Steps to reproduce
As a signed-in user, request GET /ab/projects (2-char owner), GET /bad.user/projects, GET /-x/projects, or GET /ab/projects/panel.
Actual
500 plus a spurious internal error: source="ui store" log line.
Expected
400 or 404. The sibling route already does this correctly — uiProjectFromRoute (ui_access.go:231-235) normalizes first and returns 400.
Fix
Normalize before the call at both sites:
owner, err := store.NormalizeUsername(chi.URLParam(r, "owner"))
if err != nil {
writeUIStoreError(w, errUIBadRequest)
return
}
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.