Skip to content

fix #135 Reject a JSON context that does not decode to an array in the HTTP API - #136

Merged
njoubert-cleverage merged 1 commit into
mainfrom
135
Oct 9, 2026
Merged

njoubert-cleverage merged 1 commit into
mainfrom
135

Conversation

@njoubert-cleverage

Copy link
Copy Markdown
Member

Description

Fixes #135

HTTP API: a context given as a JSON string that is valid but does not decode to an array ("1", "true", "\"abc\"", "null") passed the validation, then json_decode() returned a scalar (or null) passed to ProcessExecuteMessage / ProcessManager::execute() (typed array): TypeError, 500. With a synchronous execution, the response was the TypeError message, exposing the server paths. It is now rejected with a 422.

Changes

  • HttpProcessExecution::validateContext() (#[Callback]): a string context must decode to an array, else violation Context must be a JSON object or array. on context.
    • The AtLeastOneOf([Json, Type('array')]) constraint is kept: an invalid JSON context still gives a single violation, with the same message as before (the callback skips it).
    • "" is rejected too: the Json constraint accepts the empty string, which gave the same 500.
    • JSON objects and lists ({}, ["value"]) are still accepted.
    • Decoded with JSON_THROW_ON_ERROR, json_validate() being PHP 8.3+ (the bundle supports PHP 8.2).
  • Docs: reference/06-http_api.md (context parameter, 422 response). CHANGELOG: HTTP API: a scalar JSON context gives a 500 #135 entry under "Latest" / "Fixes".

Tests

  • HttpProcessExecutionTest::testValidation: integer, boolean, string, null and empty JSON contexts rejected; empty object and list accepted.
  • HttpProcessExecuteTest::testScalarJsonContext: the 5 contexts, queued and synchronous: 422, no message dispatched, no process execution created.
  • The 15 rejection cases fail without the fix. 355 tests OK; PHPStan (level 10), PHP-CS-Fixer, Rector OK. The 2 PHPUnit deprecations (phpunit.xml.dist) already exist on main.

Not changed

  • A failed synchronous execution still returns the raw exception message (optional point of the issue, out of scope): the case exposing the server paths described in HTTP API: a scalar JSON context gives a 500 #135 can no longer happen, the request being rejected before the execution.

Requirements

  • Documentation updates
    • Reference
    • Changelog
  • Unit tests

Breaking changes

None: these requests failed with a 500, they are now rejected with a 422.

🤖 Generated with Claude Code

…e HTTP API

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@njoubert-cleverage
njoubert-cleverage merged commit a4b420f into main Oct 9, 2026
24 checks passed
@njoubert-cleverage
njoubert-cleverage deleted the 135 branch October 9, 2026 08:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

HTTP API: a scalar JSON context gives a 500

1 participant