fix: serve public offerings catalog without listPublic - #1229
Merged
thlpkee20-wq merged 1 commit intoSep 29, 2026
Merged
thlpkee20-wq merged 1 commit into
thlpkee20-wq merged 1 commit into
Conversation
The catalog route treated a missing `listPublic` as an unimplemented path and returned a 500, so repositories exposing only raw rows could never serve the public catalog. Add a documented `list` fallback that filters, stably orders and paginates rows route-side, then projects each row to the public shape so issuer-only fields cannot leak. Totals stay page-independent and the missing- source case remains a deterministic generic 500. 🤖 Generated with Codebuff Co-Authored-By: Codebuff <noreply@codebuff.com>
|
@Deyanju23 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1073
What was incomplete
GET /api/offeringscalledofferingRepo.listPublicbehind an optional check and answered a 500 (offeringRepo.listPublic not implemented) whenever a repository did not implement it, so the public catalog could never be served by repositories that only expose raw rows.Change (src/routes/offerings.ts only)
list(opts?: { status?: string }) => Promise<Offering[]>toOfferingRepoas a documented raw-row catalog source.listPublicremains preferred and unchanged.created_at DESC, id ASCordering,offset/limitwindowing, and projects every row throughtoPublicOffering, soissuer_id,private_noteand any other issuer-only field can never leak — even if a repository returns full rows.totalis now always page-independent on the fallback path:countPublicwhen available, otherwise the pre-pagination filtered count.PUBLIC_CATALOG_DEFAULT_LIMIT(100);limitabovePUBLIC_CATALOG_MAX_LIMIT(1000) is rejected with 400 rather than silently clamped.listPublicandlistboth absent/non-function) logs at error level and returns a genericINTERNAL_ERROR500, so repository topology is not disclosed.Public contract
Response shape
{ offerings, total? },200on success,400 BAD_REQUESTfor invalid/out-of-rangelimit/offset, generic500when no catalog source is wired are all unchanged. The only addition is thelistfallback, which is additive and backwards compatible.Security notes
Test evidence
npx jest src/routes/offerings.catalog.test.ts src/routes/offerings.test.ts→ 2 suites passed, 14 tests passedFocused file (
src/routes/offerings.catalog.test.ts, 11 tests):npx tsc --noEmit→ no diagnostics insrc/routes/offerings.ts(repo-wide pre-existing errors in unrelated files are untouched).npx eslint src/routes/offerings.ts→ no new findings (remainingno-explicit-anyfindings are pre-existing and unchanged).