Appearance API returns 500 instead of 401 without a session #146

Closed
opened 2026-09-25 23:17:36 +00:00 by kayg · 1 comment
Owner

Severity: high (5xx; blocks a merge per the adversarial rule)

Problem

GET/PUT /api/v1/appearance (and the Unsplash routes) without a session returned 500 "Missing request extension: Extension of type calternal_plugin::PluginRequestContext was not found". The routes are merged beside the plugin router, so no gate refused anonymous requests before the handler's Extension extractor. Seen when the break-it sweep deleted the session cookie mid action: the app's appearance refresh got a 500.

Repro

curl -i http://localhost:<port>/api/v1/appearance (no cookie), or with Cookie: calternal_session=garbage.

Expected

401 with the usual error envelope.

Status

Fixed on job/breakit-fixes in af05f8a (a Principal extractor rejects with 401; test anonymous_requests_get_401_not_500; probe section anonymous-appearance in tests/adversarial/attack2.py, 0 findings). Not merged. Worth checking other routers merged outside build_app for the same extractor (the admin routes in wire.rs use their own checks).

Found by the break-it sweep (#117). Re-run: cd apps/web && bun run build && bun e2e/breakit.mjs --keep <dir> (script on branch job/breakit-fixes). Screenshots: /home/kayg/Developer/calternal/target/breakit (run 1 in run1/, fix checks in verify/).

**Severity:** high (5xx; blocks a merge per the adversarial rule) ## Problem `GET`/`PUT /api/v1/appearance` (and the Unsplash routes) without a session returned **500** "Missing request extension: Extension of type `calternal_plugin::PluginRequestContext` was not found". The routes are merged beside the plugin router, so no gate refused anonymous requests before the handler's `Extension` extractor. Seen when the break-it sweep deleted the session cookie mid action: the app's appearance refresh got a 500. ## Repro `curl -i http://localhost:<port>/api/v1/appearance` (no cookie), or with `Cookie: calternal_session=garbage`. ## Expected 401 with the usual error envelope. ## Status Fixed on `job/breakit-fixes` in af05f8a (a `Principal` extractor rejects with 401; test `anonymous_requests_get_401_not_500`; probe section `anonymous-appearance` in tests/adversarial/attack2.py, 0 findings). Not merged. Worth checking other routers merged outside `build_app` for the same extractor (the admin routes in wire.rs use their own checks). Found by the break-it sweep (#117). Re-run: `cd apps/web && bun run build && bun e2e/breakit.mjs --keep <dir>` (script on branch `job/breakit-fixes`). Screenshots: `/home/kayg/Developer/calternal/target/breakit` (run 1 in `run1/`, fix checks in `verify/`).
Author
Owner

#146 is already fixed on this branch: the existing server regression test passes and confirms anonymous Appearance requests return 401 instead of 500. Focused command: cargo test -p calternal-server anonymous_requests_get_401_not_500 (1 passed; 0 failed). No code change was needed.

#146 is already fixed on this branch: the existing server regression test passes and confirms anonymous Appearance requests return 401 instead of 500. Focused command: cargo test -p calternal-server anonymous_requests_get_401_not_500 (1 passed; 0 failed). No code change was needed.
kayg closed this issue 2026-09-29 08:29:21 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#146
No description provided.