wso2 / wso2/api-platform

Add input validation for deploymentId and gatewayId in RestoreDeployment handler

Open
#1,996 0 comments 0 reactions 1 assignee View on GitHub

@senthuran16 is already working on this.

Since May 20, 2026.

Dominant language
Go
Stars
71
Forks
111
Avg merge
1d 14h
Merged PRs (30d)
110

Description

Summary

The RestoreDeployment handler in platform-api/src/internal/handler/webbroker_api_deployment.go does not validate that deploymentId and gatewayId are non-empty before invoking the service layer. This can result in unclear errors reaching the client instead of an explicit 400 Bad Request response.

The UndeployDeployment handler in the same file already performs these checks and can serve as the reference implementation.

Expected Behavior

If deploymentId or gatewayId is empty, the handler should return HTTP 400 with a descriptive error message before calling RestoreWebBrokerAPIDeploymentByHandle.

References

Requested by @senthuran16

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.