lablup / lablup/backend.ai

commit_session endpoint uses QueryParam — optional body fields silently ignored

Open Beginner friendly
#10,681 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
670
Forks
183
Avg merge
15h 13m
Merged PRs (30d)
368

Description

Same regression as BA-5496. POST /session/{session_name}/commit handler uses QueryParam[CommitSessionRequest] instead of BodyParam.

All fields are optional (login_session_token, filename), so validation passes with empty query params — no 400 error. However, if clients send these values in the JSON body (e.g. WebUI), they are silently ignored because the handler only reads from query string.

Root cause: BA-4823 (PR #9588, fc0caf8eb) bulk-changed BodyParam to QueryParam for multiple session endpoints.

Fix:

- handler.py: Change QueryParam[CommitSessionRequest] to BodyParam[CommitSessionRequest], update query.parsed to body.parsed

- client/v2/domains/session.py: Change params= back to request= in commit_session method

Related: BA-5496 (rename_session), BA-5497 (convert_session_to_image)

JIRA Issue: BA-5511

Contributor guide

Open the contributing guide

Research direction

Start in handler.py at the POST /session/{session_name}/commit handler and compare its parameter parsing with the issue description. Then inspect client/v2/domains/session.py and the related session endpoints; done means JSON body values for login_session_token and filename are validated and sent through the client rather than silently ignored as query parameters.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
api, backend
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
76/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.