Repository navigation
AC-2596: Return 400 for unsupported sort field - #18
Merged
Merged
Conversation
added 3 commits
September 22, 2026 14:01
Map InvalidOrderByException to invalid_parameters (400) in ErrorBuilder. Before this change an unsupported sort value fell through to a 500 error.
Composer 2.10 blocks packages with security advisories by default. All symfony/cache releases for Symfony 3.4 and 4.4 are affected, so those matrix jobs failed at dependency install.
MantasAndrikis
approved these changes
Sep 22, 2026
7 tasks done
vinayak-iyer-paysera
added a commit
to vinayak-iyer-paysera/lib-lock-bundle
that referenced
this pull request
Sep 28, 2026
Composer 2.10, which setup-php installs for PHP 7.2 and later, skips releases with known security advisories. With --prefer-lowest that lifted 8 of the 9 lowest jobs above the floors: run 36411291229 installed symfony/dependency-injection 5.3.0, http-kernel 5.4.20 and PHPUnit 8.5.52 on PHP 7.2 to 8.4, so no job tested Symfony 3.4 or 4.4 on those versions. A step before the install runs `composer config --global policy.advisories.block false`, the setting paysera/lib-api-bundle#18 uses, on the lowest jobs only. It skips PHP 7.1: setup-php installs Composer 2.2 there, which rejects the key ("Setting policy.advisories.block does not exist", exit 1) and blocks nothing anyway (the PHP 7.1 lowest job of run 36411291229 installed Symfony 3.4.0, symfony/lock 4.4.0 and symfony/yaml 4.0.0). Measured locally with the workflow's own commands on a tree identical to this commit: all 9 lowest jobs pass with 20 tests each and install Symfony 3.4.47 and predis 1.1.10; symfony/lock 4.4.2 and PHPUnit 7.5.15 on PHP 7.1 to 7.4; symfony/lock 4.4.9 and PHPUnit 8.5.21 on PHP 8.0 to 8.4. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
11 tasks done
mSprunskas
pushed a commit
to paysera/lib-normalization-bundle
that referenced
this pull request
Sep 30, 2026
… install again The matrix gains Symfony 7.* on PHP 8.2 to 8.4; Symfony 7.4 needs PHP 8.2, so the older PHP lines exclude it. Composer 2.10, which setup-php installs for PHP 7.2 and later, refuses packages with security advisories, and every symfony/cache release of Symfony 3.4 and 4.4 has one, so those jobs failed at install. The step paysera/lib-api-bundle#18 added turns the blocking off for this test install only; PHP 7.0 and 7.1 get Composer 2.2, which neither blocks advisories nor knows the setting, so the step skips them. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Paginated endpoints return
500 internal_server_errorwhen thesortparameter names a field that is not configured for ordering, e.g.?sort=bogus_field.ConfiguredQuery::getOrderingConfigurationFor()frompaysera/lib-paginationthrowsInvalidOrderByExceptionin this case.ErrorBuilderalready maps the other client-side pagination exceptions (TooLargeOffsetException,InvalidCursorException), but not this one, so it fell through to the generic 500.The sort value is client input, so
InvalidOrderByExceptionis now mapped toinvalid_parameters(400):{"error":"invalid_parameters","error_description":"Unsupported order-by field: \"bogus_field\""}InvalidGroupByExceptionstill returns 500: it is caused by how the query is built on the server, not by client input.InvalidOrderByExceptionexists sincepaysera/lib-pagination1.0.0, so the dependency constraint is unchanged.CI fix
Composer 2.10 refuses to install packages with security advisories by default. All
symfony/cachereleases for Symfony 3.4 and 4.4 (end-of-life) are affected, so those matrix jobs failed at dependency install. The workflow now setspolicy.advisories.blocktofalsebefore installing. This only affects the library's own test installs; projects using the bundle keep their own Composer settings. The step is skipped on PHP 7.1, which gets Composer 2.2: it does not block advisories and does not know this setting.Test Plan
FunctionalPagedQueryTest:GET /paged-query/simple?sort=bogus_fieldreturns 400invalid_parameters. It fails with the 500 body before the fix.