Skip to content

fix(api-gateway): prevent file download headers on template validatio… - #1770

Open
Aadiii00 wants to merge 1 commit into
credebl:mainfrom
Aadiii00:fix/1225-template-validation
Open

Aadiii00 wants to merge 1 commit into
credebl:mainfrom
Aadiii00:fix/1225-template-validation

Conversation

@Aadiii00

@Aadiii00 Aadiii00 commented Oct 1, 2026

Copy link
Copy Markdown

Closes #1225

Description

When calling POST /v1/orgs/{orgId}/credentials/bulk/template with invalid or empty templateId / schemaType, the endpoint returned a file download (schema.csv) containing the error message rather than returning a standard JSON 400 Bad Request response.

This occurred because static @Header('Content-Disposition', ...) decorators at the controller method level forced attachment headers on all responses, including validation failures. Additionally, templateId had @IsOptional(), which interfered with validation.

This PR removes the static @Header decorators in favor of dynamic response headers on success and ensures TemplateDetails enforces required templateId and valid schemaType.

Changes

  • Removed static @Header decorators from downloadBulkIssuanceCSVTemplate in issuance.controller.ts and set dynamic headers on successful CSV export.
  • Removed @IsOptional() from templateId in TemplateDetails (issuance.dto.ts).
  • Added unit tests in template-details.dto.spec.ts covering valid, empty, whitespace-only, and omitted parameter validation.

…n error

Signed-off-by: Aadiii00 <adityapammannavaryt@gmail.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 12 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 3f428204-4ae8-4f90-b6f8-15cc07084b69

📥 Commits

Reviewing files that changed from the base of the PR and between 3046294 and 5c5a3df.

📒 Files selected for processing (3)
  • apps/api-gateway/src/issuance/dtos/issuance.dto.ts
  • apps/api-gateway/src/issuance/dtos/template-details.dto.spec.ts
  • apps/api-gateway/src/issuance/issuance.controller.ts
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: API returns download link instead of error message for invalid or empty templateId / schemaType

1 participant