Skip to content

POST /packs accepts null name, creating a pack with empty string name #43032

Description

@getvictor

Found by inspection


💥 Actual behavior

Sending POST /api/v1/fleet/packs with {"name": null} creates a pack with an empty string name and returns HTTP 200. In contrast, sending {"name": ""} correctly returns HTTP 400 with "pack payload verification: pack name cannot be empty".

The root cause is the same pattern as the query creation bug #43031: PackPayload.Name is a *string, and when JSON null is sent it becomes nil. The validation check for empty name only fires for non-nil values, so the nil pointer bypasses validation and an empty string reaches the database.

🛠️ To fix

Add a nil check for the Name field in the pack creation service method, returning a BadRequestError if Name is nil. This mirrors the existing empty-string validation.

🧑‍💻 Steps to reproduce

These steps:

  • Have been confirmed to consistently lead to reproduction in multiple Fleet instances.
  • Describe the workflow that led to the error, but have not yet been reproduced in multiple Fleet instances.
  1. Authenticate as a user with pack-creation permissions
  2. Send POST /api/v1/fleet/packs with body {"name": null}
  3. Observe HTTP 200 and a pack created with an empty string name
  4. Confirm that POST /api/v1/fleet/packs with {"name": ""} correctly returns HTTP 400

🕯️ More info (optional)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

#g-orchestrationOrchestration product groupbugSomething isn't working as documented~released bugThis bug was found in a stable release.

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions