Found by inspection
💥 Actual behavior
Sending POST /api/v1/fleet/packs with {"name": null} creates a pack with an empty string name and returns HTTP 200. In contrast, sending {"name": ""} correctly returns HTTP 400 with "pack payload verification: pack name cannot be empty".
The root cause is the same pattern as the query creation bug #43031: PackPayload.Name is a *string, and when JSON null is sent it becomes nil. The validation check for empty name only fires for non-nil values, so the nil pointer bypasses validation and an empty string reaches the database.
🛠️ To fix
Add a nil check for the Name field in the pack creation service method, returning a BadRequestError if Name is nil. This mirrors the existing empty-string validation.
🧑💻 Steps to reproduce
These steps:
- Authenticate as a user with pack-creation permissions
- Send
POST /api/v1/fleet/packs with body {"name": null}
- Observe HTTP 200 and a pack created with an empty string name
- Confirm that
POST /api/v1/fleet/packs with {"name": ""} correctly returns HTTP 400
🕯️ More info (optional)
Found by inspection
💥 Actual behavior
Sending
POST /api/v1/fleet/packswith{"name": null}creates a pack with an empty string name and returns HTTP 200. In contrast, sending{"name": ""}correctly returns HTTP 400 with "pack payload verification: pack name cannot be empty".The root cause is the same pattern as the query creation bug #43031:
PackPayload.Nameis a*string, and when JSONnullis sent it becomes nil. The validation check for empty name only fires for non-nil values, so the nil pointer bypasses validation and an empty string reaches the database.🛠️ To fix
Add a nil check for the
Namefield in the pack creation service method, returning aBadRequestErrorifNameis nil. This mirrors the existing empty-string validation.🧑💻 Steps to reproduce
These steps:
POST /api/v1/fleet/packswith body{"name": null}POST /api/v1/fleet/packswith{"name": ""}correctly returns HTTP 400🕯️ More info (optional)