apache / apache/cloudstack

Leading/trailing spaces are allowed in string fields for some API endpoints

Aperta
#12,506 7 commenti 0 reazioni 0 assegnatari Vedi su GitHub
component:api type:improvement
Lingua principale
Java
Stelle
3.1k
Fork
1.4k
Merge medio
6g 19h
PR unite (30g)
32

Descrizione

### problem

Currently, some API endpoints allow saving string fields with leading or trailing spaces. This behavior can lead to inconsistent data and unexpected UI/API issues.

For example, when creating or updating certain resources (e.g. volumes, templates, ISOs), values with spaces at the beginning or end of the string are accepted and stored successfully, while they should instead be rejected with a validation error.

Here is the list of API endpoints where the issue occurs for the name and description fields:
- registerIso / updateIso
- createVolume / updateVolume / uploadVolume
- registerTemplate / updateTemplate
- updateNetwork / createNetwork / createNetworkACL / updateNetworkACLList
- createVPC / updateVPC
- createVpnCustomerGateway / createVpnGateway / createVpnCustomerGateway

Please also check other endpoints where this issue might occur, as similar validation problems may exist elsewhere.

### versions

CloudStack 4.20.2.0

### The steps to reproduce the bug

1. Call one of the affected endpoints (for example: ISO creation or update).
2. Provide string fields with leading or trailing spaces.
3. Observe that the request is accepted and the data is stored.

```
{
"listisosresponse": {
"count": 1,
"iso": [
{
"id": "fee7a4be-b9cd-41d9-81c9-e948332e605b",
"name": " test name ",
"displaytext": " text ",
"isready": true,
"url": "my_url",
....
}
]
}
}
```

### What to do about it?

The API should not allow leading or trailing spaces in string fields. It would be preferable to introduce this validation globally for all string fields across the API

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Inizia tracciando la validazione degli entry point API indicati, usando registerIso o updateIso per riprodurre l’accettazione degli spazi iniziali e finali. Controlla gli altri endpoint denominati relativi a volume, template, rete, VPC e VPN per verificare lo stesso comportamento; il lavoro è completato quando i campi string interessati rifiutano tali valori con un errore di validazione, inclusi eventuali endpoint aggiuntivi individuati.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
java
Ambito
api, backend, cloud
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
45/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.