Skip to content

POST /queries returns HTTP 500 when name or query is JSON null #43031

Description

@getvictor

Found by inspection


💥 Actual behavior

Sending POST /api/v1/fleet/queries with JSON null for the name or query field returns HTTP 500 Internal Server Error instead of a proper 400/422 validation error. For example:

{"name": null, "query": "SELECT 1;"}

Returns:

{
  "message": "report name cannot be empty",
  "errors": [{"name": "base", "reason": "report name cannot be empty"}]
}

The root cause is in server/fleet/queries.go. QueryPayload uses pointer fields (Name *string, Query *string). The Verify() method only validates non-nil fields, which is correct for PATCH (update) operations where nil means "don't change". However, for POST (create) operations, nil name/query should be rejected at the service layer before reaching the datastore. The error is eventually caught by the DB layer but surfaced as a 500.

In contrast, POST /api/v1/fleet/global/policies correctly returns 400 for null name/query.

🛠️ To fix

In the NewQuery service method (server/service/queries.go), add explicit nil checks for required fields (Name and Query) before calling Verify(), returning a BadRequestError if either is nil.

🧑‍💻 Steps to reproduce

These steps:

  • Have been confirmed to consistently lead to reproduction in multiple Fleet instances.
  • Describe the workflow that led to the error, but have not yet been reproduced in multiple Fleet instances.
  1. Authenticate as any user with query-creation permissions
  2. Send POST /api/v1/fleet/queries with body {"name": null, "query": "SELECT 1;"}
  3. Observe HTTP 500 instead of HTTP 400/422
  4. Also reproduces with {"name": "Test", "query": null} or {"name": null, "query": null}

🕯️ More info (optional)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

#g-orchestrationOrchestration product groupbugSomething isn't working as documented~released bugThis bug was found in a stable release.

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions