api(arweave): negative limit reaches SQL LIMIT and surfaces as 503 db_unavailable #490
Copy link
Copy link
Open
Labels
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surface
Description
Activity
- addedcrate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surface
on Sep 26, 2026
Metadata
Metadata
Assignees
Labels
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:bugDefect fix — wrong or unsafe behaviorDefect fix — wrong or unsafe behaviorsev:lowCosmetic, cleanup, or nice-to-haveCosmetic, cleanup, or nice-to-havesubsystem:apiNode REST API request/response surfaceNode REST API request/response surface
Summary
GET /api/v1/arweave/anchorsclamps only the top of the limit (crates/gitlawb-node/src/api/arweave.rs:28,q.limit.min(200)) and binds it straight intoLIMIT $2(db/mod.rs:3836).?limit=-1produces a database error that the bare?mapping (#251) classifies as 503db_unavailable.Impact
A client-input bug surfaces as a database-availability error on an anonymous route, and negative values skip the intended pagination contract entirely. Cosmetic per the rubric.
Remediation
[1, 200]like the sibling list endpoints (compare GET /api/v1/tasks: clamp limit to match siblings; negative limit returns 500 with raw DB error #399/Fix #399: GET /api/v1/tasks: clamp limit to match siblings; negative limit returns 500 with raw DB error #405).Proposed labels: kind:bug, crate:node, subsystem:api.