Skip to content

fix: consolidate /api/health to a single enveloped handler - #1406

Open
Obaara293 wants to merge 1 commit into
CalloraOrg:mainfrom
Obaara293:security/issue-1319-detect-which-handler-serves-api-health
Open

Obaara293 wants to merge 1 commit into
CalloraOrg:mainfrom
Obaara293:security/issue-1319-detect-which-handler-serves-api-health

Conversation

@Obaara293

Copy link
Copy Markdown

Overview

This PR resolves the duplicate /api/health handler conflict by consolidating health configuration into a single shared module and ensuring both createApp and the src/index.ts entrypoint serve the same enveloped response shape from the same source of truth.

Related Issue

Changes

🩺 Health Handler Consolidation

  • [ADD] src/config/health.ts

    • Centralizes the health response shape (enveloped body) and shared headers so both entrypoints produce identical output.
    • Provides the single source of truth consumed by createApp and the index app.
  • [MODIFY] src/app.ts

    • Replaces the directly-registered app.get('/api/health') handler with the shared health configuration so the response shape and headers come from src/config/health.ts.
  • [MODIFY] src/index.ts

    • Removes the redundant inline /api/health handler returning an unenveloped body and routes through the shared health configuration instead.

Verification Results

npm test -- tests/integration/health.test.ts src/routes/health/health.test.ts

Both entrypoints now return the same enveloped shape and headers for GET /api/health, and the redundant handler has been removed so exactly one implementation remains.

Acceptance Criteria Status
The test documents the single handler serving /api/health ✅ Integration test asserts shape/headers through both entrypoints
Both entrypoints return the same enveloped shape ✅ createApp and index app share src/config/health.ts
src/routes/health.ts is either the handler or deleted ✅ Redundant inline handler removed; shared config is the single handler
tests/integration/health.test.ts snapshot is updated ✅ Snapshot reflects the consolidated enveloped response

Security and Failure-Mode Handling

  • No safeguards or validation were weakened; the change only removes a duplicate handler.
  • Monitoring now observes a consistent response shape regardless of which app is used, avoiding silent divergence.
  • Failure modes (missing fields, unexpected shape) surface through the shared config rather than being masked by a second handler.

Compatibility Considerations

  • Response body remains enveloped and headers are preserved, so existing consumers of /api/health are unaffected.
  • Changes to src/routes/health.ts now take effect as expected since the duplicate handler is gone.

Closes #1319

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Detect which handler serves /api/health

1 participant