Is there an existing issue for this?
What happened?
Summary
update_event/v1 accepts and persists an unexpected top-level event property when it is included in the update payload.
This can happen accidentally when a client fetches an event with get_event/v1, manipulates the returned object, and sends it back to update_event/v1 without fully stripping response wrapper data.
Observed Behavior
get_event/v1 returns a response shaped like:
{
"code": 0,
"event": {
"id": "event_id",
"title": "Example Event",
"workflow": {},
"revision": 1
},
"jobs": [],
"queued": 0
}
If an update payload contains an unexpected top-level event property inside the event object, for example:
{
"id": "event_id",
"title": "Example Event",
"workflow": {},
"revision": 1,
"event": {
"id": "event_id",
"title": "Old Nested Event"
}
}
then update_event/v1 stores that nested event object as part of the event record.
A later clean update that omits the event property does not remove it, because the endpoint performs a shallow merge.
Expected Behavior
update_event/v1 should not persist unknown top-level fields that are not part of the Event data model.
Ideally, the endpoint should either:
- reject unknown top-level properties with a validation error, or
- ignore/drop unknown top-level properties before persisting the update.
At minimum, wrapper-related fields such as event, jobs, queued, and code should never be persistable into an event record.
Operating System
Deb 13
Node.js Version
22
xyOps Version
1.0.85
Server Setup
Single Conductor
Storage Setup
Default (SQLite + Filesystem)
Relevant log output
Code of Conduct
Is there an existing issue for this?
What happened?
Summary
update_event/v1accepts and persists an unexpected top-leveleventproperty when it is included in the update payload.This can happen accidentally when a client fetches an event with
get_event/v1, manipulates the returned object, and sends it back toupdate_event/v1without fully stripping response wrapper data.Observed Behavior
get_event/v1returns a response shaped like:{ "code": 0, "event": { "id": "event_id", "title": "Example Event", "workflow": {}, "revision": 1 }, "jobs": [], "queued": 0 }If an update payload contains an unexpected top-level event property inside the event object, for example:
{ "id": "event_id", "title": "Example Event", "workflow": {}, "revision": 1, "event": { "id": "event_id", "title": "Old Nested Event" } }then update_event/v1 stores that nested event object as part of the event record.
A later clean update that omits the event property does not remove it, because the endpoint performs a shallow merge.
Expected Behavior
update_event/v1 should not persist unknown top-level fields that are not part of the Event data model.
Ideally, the endpoint should either:
At minimum, wrapper-related fields such as event, jobs, queued, and code should never be persistable into an event record.
Operating System
Deb 13
Node.js Version
22
xyOps Version
1.0.85
Server Setup
Single Conductor
Storage Setup
Default (SQLite + Filesystem)
Relevant log output
Code of Conduct