Skip to content

[Bug]: update_event/v1 persists unexpected top-level event field from API wrapper #400

Description

@matt-rgx

Is there an existing issue for this?

  • I have searched the existing issues

What happened?

Summary

update_event/v1 accepts and persists an unexpected top-level event property when it is included in the update payload.

This can happen accidentally when a client fetches an event with get_event/v1, manipulates the returned object, and sends it back to update_event/v1 without fully stripping response wrapper data.

Observed Behavior

get_event/v1 returns a response shaped like:

{
  "code": 0,
  "event": {
    "id": "event_id",
    "title": "Example Event",
    "workflow": {},
    "revision": 1
  },
  "jobs": [],
  "queued": 0
}

If an update payload contains an unexpected top-level event property inside the event object, for example:

{
  "id": "event_id",
  "title": "Example Event",
  "workflow": {},
  "revision": 1,
  "event": {
    "id": "event_id",
    "title": "Old Nested Event"
  }
}

then update_event/v1 stores that nested event object as part of the event record.
A later clean update that omits the event property does not remove it, because the endpoint performs a shallow merge.

Expected Behavior

update_event/v1 should not persist unknown top-level fields that are not part of the Event data model.
Ideally, the endpoint should either:

  • reject unknown top-level properties with a validation error, or
  • ignore/drop unknown top-level properties before persisting the update.
    At minimum, wrapper-related fields such as event, jobs, queued, and code should never be persistable into an event record.

Operating System

Deb 13

Node.js Version

22

xyOps Version

1.0.85

Server Setup

Single Conductor

Storage Setup

Default (SQLite + Filesystem)

Relevant log output

Code of Conduct

  • I agree to follow this project's Code of Conduct

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingv2Will be added in v2

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions