Context
The deposit API currently allows creating or submitting a deposit without a valid
user reference. This leads to broken records and errors when the deposit
validation workflow tries to read the submitter's data.
Expected behavior
- The
user field in the deposit marshmallow schema (sonar/modules/deposits/marshmallow/json.py)
should be required.
- On deposit creation/update via REST, if the referenced user does not exist,
the API should return HTTP 400 with a clear error message.
Acceptance criteria
Context
The deposit API currently allows creating or submitting a deposit without a valid
userreference. This leads to broken records and errors when the depositvalidation workflow tries to read the submitter's data.
Expected behavior
userfield in the deposit marshmallow schema (sonar/modules/deposits/marshmallow/json.py)should be required.
the API should return HTTP 400 with a clear error message.
Acceptance criteria
POST /api/deposits/without auserreturns HTTP 400POST /api/deposits/with auser.$refpointing to a non-existent user returns HTTP 400