fix(providers): reject silent validation degradation with 400 and rejected keys - #11101
Merged
diegosouzapw merged 1 commit intoAug 22, 2026
Conversation
…ected keys
Unknown rateLimitOverrides keys (e.g. a typo'd tpm) and empty/non-numeric
values were silently stripped by z.coerce.number() + non-strict object
parsing, so an operator's intent vanished with a 200 OK. The schema now
uses a .strict() object with a preprocess step that rejects empty strings
and non-numeric input, and the DB sanitizers return {sanitized, rejected}
and refuse the write on any rejected key. The 400 response surfaces the
rejected key names.
maxmad64bis
force-pushed
the
fix/05-ctr3-silent-validation
branch
from
August 22, 2026 08:38
3c9c269 to
885c6d7
Compare
diegosouzapw
merged commit Aug 22, 2026
f3b190b
into
diegosouzapw:release/v3.8.50
9 of 16 checks passed
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…ected keys (diegosouzapw#11101) Validated on the combined batch board over release/v3.8.50 tip 0f43f0f: static gates clean, typecheck:core clean, focused tests green. Strict schema + {sanitized, rejected} DB boundary — silent validation degradation now answers 400 with the offending keys. Caller audit done: only the providers write path consumes the sanitizers. Thank you @maxmad64bis!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Unknown
rateLimitOverrideskeys (e.g. a typo'dtpm) and empty/non-numeric values were silently stripped byz.coerce.number()+ non-strict object parsing, so an operator's intent vanished with a 200 OK. The schema now uses a.strict()object with a preprocess step that rejects empty strings and non-numeric input, and the DB sanitizers return{sanitized, rejected}and refuse the write on any rejected key. The 400 response surfaces the rejected key names.Related Issues
Validation
node --import tsx/esm --test tests/unit/providers-patch-400.test.ts tests/unit/columns-validation.test.ts→ 22 pass / 0 fail;npm run lint;npm run typecheck:core;npm run check:cyclesnpm run lintupstream/release/v3.8.503caa59107), focused checks rerunTests Added Or Updated
tests/unit/providers-patch-400.test.ts(new, 6 tests: coerce valid, unknown key rejected, >64 rejected, "" rejected, non-numeric rejected, quota 101 rejected)tests/unit/columns-validation.test.ts(new, 3 tests: sanitizers surface rejected keys)Coverage Notes
src/line coverage regression; the validation path and DB sanitizers are covered by the new unit tests.Reviewer Notes
sanitizeRateLimitOverrides/sanitizeQuotaWindowThresholdsnow throw on rejected keys instead of pruning (API path unaffected since zod validates first).{error:{message,details}}shape and addsrejected(field paths + unrecognized key names) so the frontend consumer readingdata.error?.messageis unaffected.