Skip to content

fix(logs): enforce documented limit and direction bounds server-side - #35

Open
aniruddhaadak80 wants to merge 1 commit into
render-oss:mainfrom
aniruddhaadak80:fix/logs-param-bounds
Open

aniruddhaadak80 wants to merge 1 commit into
render-oss:mainfrom
aniruddhaadak80:fix/logs-param-bounds

Conversation

@aniruddhaadak80

Copy link
Copy Markdown

What changed

  • list_logs and list_log_label_values now validate direction locally (must be backward/forward) via parseLogDirection instead of forwarding any string.
  • list_logs validates limit locally via parseLogsLimit (whole number, 1-100) instead of truncating and forwarding out-of-range values.
  • Added pkg/logs/tools_test.go with TestParseLogsLimit and TestParseLogDirection.

Why

The tool schemas advertise limit Min 1 Max 100 and direction backward/forward, but the handlers forwarded any numeric limit (truncating fractions via int()) and any direction string to the Render API. Invalid values only failed downstream as opaque API errors.

Repro (before fix): list_logs with limit 1000 forwarded limit=1000; with direction sideways forwarded direction=sideways. After fix both return clear tool errors naming the valid values.

How tested

  • go test ./pkg/logs -count=1 -v (TestParseLogsLimit, TestParseLogDirection pass)
  • go vet ./pkg/logs clean
  • go build ./... clean

Fixes #32

list_logs documents limit 1-100 and direction backward/forward, but the
handlers forwarded any values to the Render API, surfacing opaque
downstream errors. Validate both locally (limit must be a whole number
in 1-100, direction must be backward/forward) in list_logs and
list_log_label_values and return clear tool errors.

Fixes render-oss#32

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

list_logs accepts out-of-range limit and invalid direction, bypassing documented bounds

1 participant