Skip to content

fix(api): refuse an integer parameter above the safe integer range with a 400 - #238

Merged
robrigo merged 1 commit into
mainfrom
fix/eng-1518-integer-parameter-upper-bound
Oct 8, 2026
Merged

robrigo merged 1 commit into
mainfrom
fix/eng-1518-integer-parameter-upper-bound

Conversation

@robrigo

@robrigo robrigo commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Several integer request parameters had no upper bound. A digit string above the bigint range passed validateInt, parseInt returned a float such as 1e+23, and PostgreSQL refused the bound value. The caller got a generic 500 in place of a 400, and each request wrote a warn log line. No data leaks. Tracking: ENG-1518. Lane S.

Each type: 'int' filter under src/api now carries max: Number.MAX_SAFE_INTEGER, the limit that the effective mint parameters already have. That covers the template mint filters of the asset and market endpoints, the asset count filters of the market endpoints, the supply filters of /v1/templates, the before and after filters, the integer forms of lower_bound and upper_bound, page, and the limit of the asset sales history. Every other limit already had the configured maximum. No default, no lower bound, and no behavior for a value inside the safe integer range changes.

One residual case stays: the offset is (page - 1) * limit, so a page near the new maximum with a configured limit above about 1024 can still pass the bigint range. The default limits of 100 and 1000 stay inside it.

Validation. pnpm check-types and pnpm lint pass. pnpm test passes with 607 tests, against 596 before. Of the 11 new tests, the 9 that send a value above the limit failed before the change, and 2 prove that the limit itself is accepted. The tests cover the asset handler, the shared market filter, and the /v2/sales handler. The integration suite did not run locally.

The CHANGELOG.md entry opens ## [2.6.1].

…th a 400

Several integer request parameters had no upper bound. A digit string
above the bigint range passed the validation, the parser turned it
into a float, and the database refused the bound value, so the caller
got a 500 and each request wrote a warn log line.

Each integer filter of the API now has the safe integer limit that
the effective mint parameters already carry. A value inside that
range keeps its behavior.

Signed-off-by: Rob Konsdorf <rob@facings.io>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes reuse existing HTTP 400 validation without identified blocking regressions within the stated scope.

0 open findings

What changed in this PR

Adds safe-integer bounds to API request validation so oversized integer parameters return HTTP 400 instead of database-driven 500 errors.

Changes:

  • Bounds integer filters and pagination parameters while preserving defaults and lower bounds.
  • Adds 11 regression tests covering asset and market validation.
  • Documents the fix in the 2.6.1 changelog.
File Description
src/​api/​namespaces/​utils.ts Bounds numeric cursors and timestamps.
src/​api/​namespaces/​atomictools/​handlers/​links.ts Bounds link pagination.
src/​api/​namespaces/​atomicmarket/​utils.ts Bounds mint and asset-count filters.
src/​api/​namespaces/​atomicmarket/​utils.mint-bound.test.ts Tests shared mint bounds.
src/​api/​namespaces/​atomicmarket/​handlers/​template-buyoffers.ts Bounds template buy-offer pagination.
src/​api/​namespaces/​atomicmarket/​handlers/​stats.ts Bounds timestamps and pagination.
src/​api/​namespaces/​atomicmarket/​handlers/​sales2.ts Bounds pagination, mint and asset-count filters.
src/​api/​namespaces/​atomicmarket/​handlers/​sales2.mint-bound.test.ts Tests oversized sales filters.
src/​api/​namespaces/​atomicmarket/​handlers/​sales.ts Bounds sales pagination.
src/​api/​namespaces/​atomicmarket/​handlers/​royalties.ts Bounds royalty integer parameters.
src/​api/​namespaces/​atomicmarket/​handlers/​prices.ts Bounds history limits, timestamps and pagination.
src/​api/​namespaces/​atomicmarket/​handlers/​buyoffers.ts Bounds buy-offer pagination.
src/​api/​namespaces/​atomicmarket/​handlers/​auctions.ts Bounds auction pagination.
src/​api/​namespaces/​atomicassets/​handlers/​transfers.ts Bounds transfer pagination.
src/​api/​namespaces/​atomicassets/​handlers/​templates.ts Bounds supply filters and pagination.
src/​api/​namespaces/​atomicassets/​handlers/​schemas.ts Bounds schema pagination.
src/​api/​namespaces/​atomicassets/​handlers/​offers.ts Bounds offer pagination.
src/​api/​namespaces/​atomicassets/​handlers/​collections.ts Bounds collection pagination.
src/​api/​namespaces/​atomicassets/​handlers/​burns.ts Bounds burn pagination.
src/​api/​namespaces/​atomicassets/​handlers/​assets.ts Bounds mint filters and pagination.
src/​api/​namespaces/​atomicassets/​handlers/​assets-mint-bound.test.ts Tests asset mint bounds.
src/​api/​namespaces/​atomicassets/​handlers/​accounts.ts Bounds account pagination.
CHANGELOG.md Documents the 2.6.1 validation fix.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@robrigo
robrigo merged commit 1add512 into main Oct 8, 2026
8 checks passed
@robrigo
robrigo deleted the fix/eng-1518-integer-parameter-upper-bound branch October 8, 2026 19:28
@robrigo robrigo mentioned this pull request Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants