Skip to content

fix(api-gateway): prevent file download headers on template validatio… - #1770

Open
Aadiii00 wants to merge 86 commits into
credebl:mainfrom
Aadiii00:fix/1225-template-validation
Open

Aadiii00 wants to merge 86 commits into
credebl:mainfrom
Aadiii00:fix/1225-template-validation

Conversation

@Aadiii00

@Aadiii00 Aadiii00 commented Oct 1, 2026

Copy link
Copy Markdown

Closes #1225

Description

When calling POST /v1/orgs/{orgId}/credentials/bulk/template with invalid or empty templateId / schemaType, the endpoint returned a file download (schema.csv) containing the error message rather than returning a standard JSON 400 Bad Request response.

This occurred because static @Header('Content-Disposition', ...) decorators at the controller method level forced attachment headers on all responses, including validation failures. Additionally, templateId had @IsOptional(), which interfered with validation.

This PR removes the static @Header decorators in favor of dynamic response headers on success and ensures TemplateDetails enforces required templateId and valid schemaType.

Changes

  • Removed static @Header decorators from downloadBulkIssuanceCSVTemplate in issuance.controller.ts and set dynamic headers on successful CSV export.
  • Removed @IsOptional() from templateId in TemplateDetails (issuance.dto.ts).
  • Added unit tests in template-details.dto.spec.ts covering valid, empty, whitespace-only, and omitted parameter validation.

sujitaw and others added 30 commits June 16, 2026 13:57
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Bumps [nodemailer](https://github.com/nodemailer/nodemailer) from 7.0.13 to 9.0.1.
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v7.0.13...v9.0.1)

---
updated-dependencies:
- dependency-name: nodemailer
  dependency-version: 9.0.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Signed-off-by: M Abdullah <insights.abdullah@gmail.com>
Signed-off-by: M Abdullah <insights.abdullah@gmail.com>
Fix: successful response for empty attributes when creating shortening URLs
* empty attribute response

Signed-off-by: M Abdullah <insights.abdullah@gmail.com>
Signed-off-by: Tipu_Singh <tipu.singh@ayanworks.com>

* match issuance pattern

Signed-off-by: M Abdullah <insights.abdullah@gmail.com>
Signed-off-by: Tipu_Singh <tipu.singh@ayanworks.com>

---------

Signed-off-by: M Abdullah <insights.abdullah@gmail.com>
Signed-off-by: Tipu_Singh <tipu.singh@ayanworks.com>
Co-authored-by: M Abdullah <insights.abdullah@gmail.com>
Bumps [body-parser](https://github.com/expressjs/body-parser) from 1.20.5 to 1.20.6.
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](expressjs/body-parser@1.20.5...1.20.6)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 1.20.6
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [typeorm](https://github.com/typeorm/typeorm) from 0.3.28 to 0.3.31.
- [Release notes](https://github.com/typeorm/typeorm/releases)
- [Changelog](https://github.com/typeorm/typeorm/blob/0.3.31/CHANGELOG.md)
- [Commits](typeorm/typeorm@0.3.28...0.3.31)

---
updated-dependencies:
- dependency-name: typeorm
  dependency-version: 0.3.31
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: sujitaw <sujit.sutar@ayanworks.com>
Bumps redis from 6.2-alpine to 8.0-alpine.

---
updated-dependencies:
- dependency-name: redis
  dependency-version: 8.0-alpine
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…e/main/redis-8.0-alpine

build: bump redis from 6.2-alpine to 8.0-alpine
…typeorm-0.3.31

chore(deps): bump typeorm from 0.3.28 to 0.3.31
RinkalBhojani and others added 27 commits August 19, 2026 16:41
* fix: refactored openBao and secret-provider logic

Signed-off-by: RinkalBhojani <rinkal.bhojani@ayanworks.com>

* test: update secret-provider specs for bare secretKey contract

Signed-off-by: Ajay Jadhav <ajay@ayanworks.com>

* fix: reduce cognitive complexity of OpenBao loadSecrets

Signed-off-by: Ajay Jadhav <ajay@ayanworks.com>

---------

Signed-off-by: RinkalBhojani <rinkal.bhojani@ayanworks.com>
Signed-off-by: Ajay Jadhav <ajay@ayanworks.com>
Co-authored-by: Ajay Jadhav <ajay@ayanworks.com>
…l#1608)

* Enhance Swagger setup with API filtering and grouping

Added a helper function to filter APIs by tags and created separate Swagger documents for different API groups.

Signed-off-by: Kumari Vaishnavi <145796948+vaishnavijha12@users.noreply.github.com>

* fix: correct swagger tag names for proper API grouping

Signed-off-by: Kumari Vaishnavi <145796948+vaishnavijha12@users.noreply.github.com>

* refactor: improve filterByTags typing and fix import placement

Signed-off-by: Kumari Vaishnavi <145796948+vaishnavijha12@users.noreply.github.com>

* fix: address review feedback on Swagger grouping

Signed-off-by: Tipu_Singh <tipu.singh@ayanworks.com>

---------

Signed-off-by: Kumari Vaishnavi <145796948+vaishnavijha12@users.noreply.github.com>
Signed-off-by: Tipu_Singh <tipu.singh@ayanworks.com>
Co-authored-by: Tipu_Singh <tipu.singh@ayanworks.com>
Signed-off-by: shitrerohit <rohit.shitre@ayanworks.com>
…ion handling

Signed-off-by: shitrerohit <rohit.shitre@ayanworks.com>
…tation-response

fix: update invitation creation to return org_invitations array
* fix: redirect swagger fixed

Signed-off-by: joaoMiraya <joaomiraya01@gmail.com>

* fix: set env var to expose swagger endpoint

Signed-off-by: joaoMiraya <joaomiraya01@gmail.com>

* fix: fix redirect status and bool check

Signed-off-by: joaoMiraya <joaomiraya01@gmail.com>

* chore: add env var on .env.demo

Signed-off-by: joaoMiraya <joaomiraya01@gmail.com>

---------

Signed-off-by: joaoMiraya <joaomiraya01@gmail.com>
Signed-off-by: João  Victor B Miraya <108498460+joaoMiraya@users.noreply.github.com>
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 4.3.0 to 6.0.10.
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@b906aff...0977fd9)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: 6.0.10
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [nodemailer](https://github.com/nodemailer/nodemailer) from 9.0.5 to 9.1.1.
- [Release notes](https://github.com/nodemailer/nodemailer/releases)
- [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md)
- [Commits](nodemailer/nodemailer@v9.0.5...v9.1.1)

---
updated-dependencies:
- dependency-name: nodemailer
  dependency-version: 9.1.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [qs](https://github.com/ljharb/qs) from 6.15.3 to 6.16.0.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.15.3...v6.16.0)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…debl#1742)

Add unit coverage for CommonService error translation (handleCommonErrors,
sendError, filterResponse) and extend the integration suite with real
PATCH/PUT/DELETE, 4xx error mapping, and proxy/NO_PROXY cases, so the
axios 1.20 backed HTTP client is guarded in CI. Remove the now-healthy
common.service.spec from the jest CI exclusion list.

Fix sendError() throwing a TypeError when error.response is undefined by
using optional chaining, falling back to a 500 HttpException.

Signed-off-by: Ajay Jadhav <ajay@ayanworks.com>
Bumps [axios](https://github.com/axios/axios) from 0.26.1 to 1.20.0.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v0.26.1...v1.20.0)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.20.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Guard all error dereferences in sendError so an undefined argument does
not throw a TypeError before the 500 fallback. Add a regression test for
service.sendError(undefined). Addresses CodeRabbit feedback on credebl#1742.

Signed-off-by: Ajay Jadhav <ajay@ayanworks.com>
Address all 7 SonarQube security hotspots reported on main:

- typescript:S5332 (2): use https:// in the @ApiProperty examples of
  configure-base-wallet.dto.ts and update-revocation-registry.dto.ts
- githubactions:S7637 (4): pin setup-qemu-action, setup-buildx-action,
  login-action and build-push-action to full commit SHAs instead of
  mutable v3/v6 tags
- docker:S6470 (1): expand .dockerignore to exclude version control,
  local env/secrets (agent.env, .env*), build artifacts and docs so the
  recursive COPY in Dockerfile.seed no longer risks leaking sensitive data

Also add a local eslint-disable-next-line camelcase for the intentionally
snake-cased revoc_reg_id contract field which was blocking the pre-commit
hook.

Signed-off-by: Ajay Jadhav <ajay@ayanworks.com>
…first

Signed-off-by: shitrerohit <rohit.shitre@ayanworks.com>
…-invitation

fix(invitation): update logic to fetch last invitationDid instead of first
Bumps the minor-actions group with 1 update: [pnpm/action-setup](https://github.com/pnpm/action-setup).


Updates `pnpm/action-setup` from 6.0.10 to 6.1.0
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@0977fd9...ea17c68)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3.12.0 to 4.3.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@8d2750c...37fe631)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 6.19.2 to 7.3.0.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@10e90e3...53b7df9)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-version: 7.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [docker/login-action](https://github.com/docker/login-action) from 3.7.0 to 4.6.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@c94ce9f...dbcb813)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 3.7.0 to 4.3.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@c7c5346...1f40c72)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the patch-updates group with 1 update: [morgan](https://github.com/expressjs/morgan).


Updates `morgan` from 1.12.0 to 1.12.1
- [Release notes](https://github.com/expressjs/morgan/releases)
- [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md)
- [Commits](expressjs/morgan@1.12.0...1.12.1)

---
updated-dependencies:
- dependency-name: morgan
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the minor-actions group with 3 updates: [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action), [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) and [docker/build-push-action](https://github.com/docker/build-push-action).


Updates `docker/setup-qemu-action` from 4.3.0 to 4.4.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@1f40c72...9901266)

Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@37fe631...f87e599)

Updates `docker/build-push-action` from 7.3.0 to 7.4.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@53b7df9...c3c9e26)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-actions
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-actions
- dependency-name: docker/build-push-action
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [multer](https://github.com/expressjs/multer) from 2.3.0 to 2.4.0.
- [Release notes](https://github.com/expressjs/multer/releases)
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md)
- [Commits](expressjs/multer@v2.3.0...v2.4.0)

---
updated-dependencies:
- dependency-name: multer
  dependency-version: 2.4.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…n error

Signed-off-by: Aadiii00 <adityapammannavaryt@gmail.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 12 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 3f428204-4ae8-4f90-b6f8-15cc07084b69

📥 Commits

Reviewing files that changed from the base of the PR and between 3046294 and 5c5a3df.

📒 Files selected for processing (3)
  • apps/api-gateway/src/issuance/dtos/issuance.dto.ts
  • apps/api-gateway/src/issuance/dtos/template-details.dto.spec.ts
  • apps/api-gateway/src/issuance/issuance.controller.ts
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: API returns download link instead of error message for invalid or empty templateId / schemaType

8 participants