Skip to content

VCST-5623: Fixed null credential fields bug - #3100

Merged
DmitryGrishinVirtoworks merged 1 commit into
devfrom
feat/VCST-5623
Aug 14, 2026
Merged

VCST-5623: Fixed null credential fields bug#3100
DmitryGrishinVirtoworks merged 1 commit into
devfrom
feat/VCST-5623

Conversation

@DmitryGrishinVirtoworks

@DmitryGrishinVirtoworks DmitryGrishinVirtoworks commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Description

POST /api/platform/security/login returned an unhandled 500 Internal Server Error (instead of 400 Bad Request) whenever userName and/or password were null or missing from the request body. Since the endpoint is [AllowAnonymous], any unauthenticated caller could trigger this at will, polluting 5xx dashboards/alerting. Root cause: UserManager.FindByNameAsync and SignInManager.PasswordSignInAsync throw ArgumentNullException on null input, and ApiErrorWrappingMiddleware maps any unhandled exception to a blanket 500.

What's added
Added an explicit null check at the top of SecurityController.Login for request, request.UserName, and request.Password, returning 400 Bad Request before any downstream call can throw (SecurityController.cs).
Added unit tests covering null request body, null UserName, and null Password, verifying 400 Bad Request is returned; existing tests confirm empty-string userName and non-existent users still return 200 OK with succeeded: false (SecurityControllerTests.cs).
Breaking changes
None.

References

QA-test:

Jira-link:

https://virtocommerce.atlassian.net/browse/VCST-5623

Artifact URL:

Image tag:
ghcr.io/VirtoCommerce/platform:3.1059.0-pr-3100-1f33-vcst-5623-1f33fba0

@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants