Skip to content

Prevent submitting a deposit without a user #1057

Description

@PascalRepond

Context

The deposit API currently allows creating or submitting a deposit without a valid
user reference. This leads to broken records and errors when the deposit
validation workflow tries to read the submitter's data.

Expected behavior

  1. The user field in the deposit marshmallow schema (sonar/modules/deposits/marshmallow/json.py)
    should be required.
  2. On deposit creation/update via REST, if the referenced user does not exist,
    the API should return HTTP 400 with a clear error message.

Acceptance criteria

  • POST /api/deposits/ without a user returns HTTP 400
  • POST /api/deposits/ with a user.$ref pointing to a non-existent user returns HTTP 400
  • Existing valid deposits are not affected

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    correctionAn implemented feature doesn't work as expected

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions