Skip to content

AC-2596: Return 400 for unsupported sort field - #18

Merged
MantasAndrikis merged 3 commits into
paysera:masterfrom
Okspen:sort-exception-handling
Sep 22, 2026
Merged

MantasAndrikis merged 3 commits into
paysera:masterfrom
Okspen:sort-exception-handling

Conversation

@Okspen

@Okspen Okspen commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Paginated endpoints return 500 internal_server_error when the sort parameter names a field that is not configured for ordering, e.g. ?sort=bogus_field.

ConfiguredQuery::getOrderingConfigurationFor() from paysera/lib-pagination throws InvalidOrderByException in this case. ErrorBuilder already maps the other client-side pagination exceptions (TooLargeOffsetException, InvalidCursorException), but not this one, so it fell through to the generic 500.

The sort value is client input, so InvalidOrderByException is now mapped to invalid_parameters (400):

{"error":"invalid_parameters","error_description":"Unsupported order-by field: \"bogus_field\""}

InvalidGroupByException still returns 500: it is caused by how the query is built on the server, not by client input.

InvalidOrderByException exists since paysera/lib-pagination 1.0.0, so the dependency constraint is unchanged.

CI fix

Composer 2.10 refuses to install packages with security advisories by default. All symfony/cache releases for Symfony 3.4 and 4.4 (end-of-life) are affected, so those matrix jobs failed at dependency install. The workflow now sets policy.advisories.block to false before installing. This only affects the library's own test installs; projects using the bundle keep their own Composer settings. The step is skipped on PHP 7.1, which gets Composer 2.2: it does not block advisories and does not know this setting.

Test Plan

  • New functional case in FunctionalPagedQueryTest: GET /paged-query/simple?sort=bogus_field returns 400 invalid_parameters. It fails with the 500 body before the fix.
  • Full suite passes locally (PHP 8.5, Symfony 6.*): 259 tests, 506 assertions.
  • CI matrix passes (all 23 jobs).

Andrii Krasnoholovets added 3 commits September 22, 2026 14:01
Map InvalidOrderByException to invalid_parameters (400) in ErrorBuilder.
Before this change an unsupported sort value fell through to a 500 error.
Composer 2.10 blocks packages with security advisories by default.
All symfony/cache releases for Symfony 3.4 and 4.4 are affected, so
those matrix jobs failed at dependency install.
@MantasAndrikis
MantasAndrikis merged commit f5aa832 into paysera:master Sep 22, 2026
23 checks passed
vinayak-iyer-paysera added a commit to vinayak-iyer-paysera/lib-lock-bundle that referenced this pull request Sep 28, 2026
Composer 2.10, which setup-php installs for PHP 7.2 and later, skips
releases with known security advisories. With --prefer-lowest that lifted
8 of the 9 lowest jobs above the floors: run 36411291229 installed
symfony/dependency-injection 5.3.0, http-kernel 5.4.20 and PHPUnit 8.5.52
on PHP 7.2 to 8.4, so no job tested Symfony 3.4 or 4.4 on those versions.

A step before the install runs `composer config --global
policy.advisories.block false`, the setting paysera/lib-api-bundle#18
uses, on the lowest jobs only. It skips PHP 7.1: setup-php installs
Composer 2.2 there, which rejects the key ("Setting
policy.advisories.block does not exist", exit 1) and blocks nothing
anyway (the PHP 7.1 lowest job of run 36411291229 installed Symfony
3.4.0, symfony/lock 4.4.0 and symfony/yaml 4.0.0).

Measured locally with the workflow's own commands on a tree identical to
this commit: all 9 lowest jobs pass with 20 tests each and install
Symfony 3.4.47 and predis 1.1.10; symfony/lock 4.4.2 and PHPUnit 7.5.15 on
PHP 7.1 to 7.4; symfony/lock 4.4.9 and PHPUnit 8.5.21 on PHP 8.0 to 8.4.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
mSprunskas pushed a commit to paysera/lib-normalization-bundle that referenced this pull request Sep 30, 2026
… install again

The matrix gains Symfony 7.* on PHP 8.2 to 8.4; Symfony 7.4 needs PHP 8.2, so the older PHP lines exclude it.

Composer 2.10, which setup-php installs for PHP 7.2 and later, refuses packages with security advisories,
and every symfony/cache release of Symfony 3.4 and 4.4 has one, so those jobs failed at install. The step
paysera/lib-api-bundle#18 added turns the blocking off for this test install only; PHP 7.0 and 7.1 get
Composer 2.2, which neither blocks advisories nor knows the setting, so the step skips them.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants