Conversation
ApiScopeGroupService threw InvalidApiScopeGroup on a name collision, which
ApiScopeGroupController does not catch, so PUT /admin/api/v1/api-scope-groups/{id}
and POST /admin/api/v1/api-scope-groups answered 500. Throw ValidationException,
which the controller already maps to 412.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughDuplicate group-name checks in ChangesScope group validation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to Duplicate-name requests receive the intended 412 response, with the separate invalid-ID behavior unchanged. No actionable merge risk is established. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to This is a narrow error-contract correction within existing administrator endpoints. Authorization and mutation ordering remain unchanged. The response now confirms a duplicate name to authorized administrators; external consumer compatibility and deployed database guarantees were not verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
📘 OpenAPI / Swagger preview ➡️ https://OpenStackweb.github.io/openstackid/openapi/pr-164/ This page is automatically updated on each push to this PR. |
Summary
PUT /admin/api/v1/api-scope-groups/{id}(andPOST) returned 500 when the name was already used by another group.ApiScopeGroupServicethrewOAuth2\Exceptions\InvalidApiScopeGroup, whichApiScopeGroupControllerdoes not catch (it only mapsValidationException-> 412 andEntityNotFoundException-> 404), so it fell into the generic 500 handler.The service now throws
models\exceptions\ValidationExceptionfor both name-collision checks (update and create), so the API answers 412 with the message.The "group id does not exist" case still throws
InvalidApiScopeGroup; left untouched to keep this fix scoped.Tests
tests/unit/ApiScopeGroupServiceTest.php: update and create with an already used name expectValidationException. The update case failed before the fix withInvalidApiScopeGroup.Summary by CodeRabbit