From 8674afa16e8e75236dae4bd66114f70efe9575aa Mon Sep 17 00:00:00 2001 From: Maximilian Kaske <56969857.0+mxkaske@users.noreply.github.com> Date: Mon, 14 Sep 2026 17:01:49 +0000 Subject: [PATCH] fix(api): reject non-numeric notification id path params A GET /v1/notification/{id} with a non-numeric id passed ParamsSchema's z.string().min(1) check, then Number(id) produced NaN which the libSQL client rejects before the query reaches Turso, surfacing as a 500 and a "Failed query" Sentry event. incidents and maintenances routes already validate id with /^\d+$/; apply the same regex here. Co-authored-by: polylane[bot] <277585245+polylane[bot]@users.noreply.github.com> --- apps/server/src/routes/v1/notifications/schema.ts | 1 + 1 file changed, 1 insertion(+) diff --git a/apps/server/src/routes/v1/notifications/schema.ts b/apps/server/src/routes/v1/notifications/schema.ts index 5ade48ac3..3b4344586 100644 --- a/apps/server/src/routes/v1/notifications/schema.ts +++ b/apps/server/src/routes/v1/notifications/schema.ts @@ -5,6 +5,7 @@ export const ParamsSchema = z.object({ id: z .string() .min(1) + .regex(/^\d+$/, "ID must be a numeric string") .openapi({ param: { name: "id", -- 2.51.2