Skip to content

fix: reject over-length intake issue names with 400 - #9940

Open
pablohashescobar wants to merge 1 commit into
previewfrom
fix/v1-intake-name-length
Open

pablohashescobar wants to merge 1 commit into
previewfrom
fix/v1-intake-name-length

Conversation

@pablohashescobar

@pablohashescobar pablohashescobar commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Description

POST /api/v1/workspaces/<slug>/projects/<id>/intake-issues/ passed the issue name straight to Issue.objects.create. A name over 255 characters made Postgres raise DataError: value too long for type character varying(255), which surfaced as an HTTP 500.

  • The endpoint now checks the name against Issue._meta.get_field("name").max_length and returns a 400 with Name must be at most 255 characters. The limit is read from the model, so it won't drift from the column.
  • Adds contract tests for a 256-character name (400, no issue created) and a 255-character name (201).
  • Includes an incidental formatter-style reflow of the on_results lambda in the list endpoint (no behavior change).

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • Feature (non-breaking change which adds functionality)
  • Improvement (change that would cause existing functionality to not work as expected)
  • Code refactoring
  • Performance improvements
  • Documentation update

Screenshots and Media (if applicable)

Test Scenarios

  • POST an intake issue with a 256-character name and verify a 400 response and that no issue is created.
  • POST an intake issue with a 255-character name and verify a 201 response.
  • Run pytest plane/tests/contract/api/test_intake_name_length.py via docker-compose-test.yml.

References

No work item.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Intake submissions with issue names longer than 255 characters now return an error instead of being accepted.
    • Issue names up to 255 characters continue to be accepted.

- POST /api/v1/.../intake-issues/ passed the name straight to
  Issue.objects.create, so a name over 255 chars raised a Postgres
  DataError and returned HTTP 500.
- Validate against the Issue.name max_length before creating and return
  a 400 with a clear error message.
- Add contract tests for names just over and exactly at the limit.
- Reformat the on_results lambda in the list endpoint.
Copilot AI balanced review requested due to automatic review settings October 4, 2026 17:58
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 3b24c05c-95d1-4701-84d0-50e8c6e00e78
📥 Commits

Reviewing files that changed from the base of the PR and between c7a5afe and f8d061b.

📒 Files selected for processing (2)
  • apps/api/plane/api/views/intake.py
  • apps/api/plane/tests/contract/api/test_intake_name_length.py

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The intake POST endpoint rejects issue names that exceed the model’s maximum length with HTTP 400. Contract tests verify that a 256-character name is rejected without creating an issue and that a 255-character name is accepted.

Changes

Intake issue name validation

Layer / File(s) Summary
Validate intake issue names
apps/api/plane/api/views/intake.py, apps/api/plane/tests/contract/api/test_intake_name_length.py
The endpoint checks the submitted name against the Issue.name maximum length. Contract tests cover rejection at 256 characters and acceptance at 255 characters. The pagination callback formatting also changes.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to f8d06

The change adds the requested name-length rejection while preserving the 255-character boundary. No concrete merge-blocking regression was found; normal test checks should still run.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: rejecting over-length intake issue names with HTTP 400.
Description check ✅ Passed The description covers the change, marks it as a bug fix, lists the boundary-case tests and test command, and addresses references. Screenshots are not needed for this API change.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The validation matches the model constraint and is covered by appropriate boundary tests.

Review effort: Balanced
Findings: None

What changed in this PR

Adds model-aligned validation to prevent over-length intake issue names from causing HTTP 500 errors.

Changes:

  • Rejects names exceeding the model limit with HTTP 400.
  • Adds regression and boundary tests.
  • Reformats the intake list serializer lambda.
File Description
apps/​api/​plane/​api/​views/​intake.py Validates intake issue name length before creation.
apps/​api/​plane/​tests/​contract/​api/​test_intake_name_length.py Tests 255- and 256-character names.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants