Found by inspection
💥 Actual behavior
Sending POST /api/v1/fleet/queries with JSON null for the name or query field returns HTTP 500 Internal Server Error instead of a proper 400/422 validation error. For example:
{"name": null, "query": "SELECT 1;"}
Returns:
{
"message": "report name cannot be empty",
"errors": [{"name": "base", "reason": "report name cannot be empty"}]
}
The root cause is in server/fleet/queries.go. QueryPayload uses pointer fields (Name *string, Query *string). The Verify() method only validates non-nil fields, which is correct for PATCH (update) operations where nil means "don't change". However, for POST (create) operations, nil name/query should be rejected at the service layer before reaching the datastore. The error is eventually caught by the DB layer but surfaced as a 500.
In contrast, POST /api/v1/fleet/global/policies correctly returns 400 for null name/query.
🛠️ To fix
In the NewQuery service method (server/service/queries.go), add explicit nil checks for required fields (Name and Query) before calling Verify(), returning a BadRequestError if either is nil.
🧑💻 Steps to reproduce
These steps:
- Authenticate as any user with query-creation permissions
- Send
POST /api/v1/fleet/queries with body {"name": null, "query": "SELECT 1;"}
- Observe HTTP 500 instead of HTTP 400/422
- Also reproduces with
{"name": "Test", "query": null} or {"name": null, "query": null}
🕯️ More info (optional)
Found by inspection
💥 Actual behavior
Sending
POST /api/v1/fleet/querieswith JSONnullfor thenameorqueryfield returns HTTP 500 Internal Server Error instead of a proper 400/422 validation error. For example:{"name": null, "query": "SELECT 1;"}Returns:
{ "message": "report name cannot be empty", "errors": [{"name": "base", "reason": "report name cannot be empty"}] }The root cause is in
server/fleet/queries.go.QueryPayloaduses pointer fields (Name *string,Query *string). TheVerify()method only validates non-nil fields, which is correct for PATCH (update) operations where nil means "don't change". However, for POST (create) operations, nil name/query should be rejected at the service layer before reaching the datastore. The error is eventually caught by the DB layer but surfaced as a 500.In contrast,
POST /api/v1/fleet/global/policiescorrectly returns 400 for null name/query.🛠️ To fix
In the
NewQueryservice method (server/service/queries.go), add explicit nil checks for required fields (NameandQuery) before callingVerify(), returning aBadRequestErrorif either is nil.🧑💻 Steps to reproduce
These steps:
POST /api/v1/fleet/querieswith body{"name": null, "query": "SELECT 1;"}{"name": "Test", "query": null}or{"name": null, "query": null}🕯️ More info (optional)