Leading/trailing spaces are allowed in string fields for some API endpoints
- 主要言語
- Java
- スター
- 3.1k
- フォーク
- 1.4k
- 平均マージ
- 6日 19時間
- マージ済み PR(30日)
- 32
説明
### problem
Currently, some API endpoints allow saving string fields with leading or trailing spaces. This behavior can lead to inconsistent data and unexpected UI/API issues.
For example, when creating or updating certain resources (e.g. volumes, templates, ISOs), values with spaces at the beginning or end of the string are accepted and stored successfully, while they should instead be rejected with a validation error.
Here is the list of API endpoints where the issue occurs for the name and description fields:
- registerIso / updateIso
- createVolume / updateVolume / uploadVolume
- registerTemplate / updateTemplate
- updateNetwork / createNetwork / createNetworkACL / updateNetworkACLList
- createVPC / updateVPC
- createVpnCustomerGateway / createVpnGateway / createVpnCustomerGateway
Please also check other endpoints where this issue might occur, as similar validation problems may exist elsewhere.
### versions
CloudStack 4.20.2.0
### The steps to reproduce the bug
1. Call one of the affected endpoints (for example: ISO creation or update).
2. Provide string fields with leading or trailing spaces.
3. Observe that the request is accepted and the data is stored.
```
{
"listisosresponse": {
"count": 1,
"iso": [
{
"id": "fee7a4be-b9cd-41d9-81c9-e948332e605b",
"name": " test name ",
"displaytext": " text ",
"isready": true,
"url": "my_url",
....
}
]
}
}
```
### What to do about it?
The API should not allow leading or trailing spaces in string fields. It would be preferable to introduce this validation globally for all string fields across the API
コントリビューションガイド
調査の方向性
まず、記載された API エントリポイントのバリデーションを追跡し、registerIso または updateIso を使って、先頭および末尾の空白が受け入れられることを再現します。名前が挙げられている他の volume、template、network、VPC、VPN のエンドポイントについても同じ挙動を確認します。影響を受ける string フィールドがそのような値をバリデーションエラーで拒否し、追加で見つかったエンドポイントも含めて対応できれば完了です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- java
- 領域
- api, backend, cloud
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 45/100