From 399c37d943a90d45847fe9d70cd76c8c6a118173 Mon Sep 17 00:00:00 2001 From: Chirag Aggarwal Date: Tue, 7 Apr 2026 14:33:43 +0530 Subject: [PATCH 1/3] fix console null route handling --- app/controllers/shared/api.php | 8 ++++++++ tests/e2e/General/HTTPTest.php | 7 +++++++ 2 files changed, 15 insertions(+) diff --git a/app/controllers/shared/api.php b/app/controllers/shared/api.php index 5166429e32..bdcbe70b83 100644 --- a/app/controllers/shared/api.php +++ b/app/controllers/shared/api.php @@ -401,6 +401,10 @@ Http::init() } } + if ($route === null) { + throw new AppwriteException(AppwriteException::GENERAL_ROUTE_NOT_FOUND); + } + // Steps 7-9: Access Control - Method, Namespace and Scope Validation /** * @var ?Method $method @@ -489,6 +493,10 @@ Http::init() $request->setUser($user); $route = $utopia->getRoute(); + if ($route === null) { + throw new AppwriteException(AppwriteException::GENERAL_ROUTE_NOT_FOUND); + } + $path = $route->getMatchedPath(); $databaseType = match (true) { str_contains($path, '/documentsdb') => DATABASE_TYPE_DOCUMENTSDB, diff --git a/tests/e2e/General/HTTPTest.php b/tests/e2e/General/HTTPTest.php index 450e4f2378..ab389850ce 100644 --- a/tests/e2e/General/HTTPTest.php +++ b/tests/e2e/General/HTTPTest.php @@ -122,6 +122,13 @@ class HTTPTest extends Scope $this->assertEquals(200, $response['headers']['status-code']); } + public function testConsoleRootWithoutRouteDoesNotFatal() + { + $response = $this->client->call(Client::METHOD_GET, '/console/', $this->getHeaders()); + + $this->assertEquals(404, $response['headers']['status-code']); + } + public function testCors() { From 6c56eee0f4c41ae7d3f6b41161b7326e6e549713 Mon Sep 17 00:00:00 2001 From: Chirag Aggarwal Date: Tue, 7 Apr 2026 14:39:48 +0530 Subject: [PATCH 2/3] test console route not found error type --- tests/e2e/General/HTTPTest.php | 1 + 1 file changed, 1 insertion(+) diff --git a/tests/e2e/General/HTTPTest.php b/tests/e2e/General/HTTPTest.php index ab389850ce..38137b1320 100644 --- a/tests/e2e/General/HTTPTest.php +++ b/tests/e2e/General/HTTPTest.php @@ -127,6 +127,7 @@ class HTTPTest extends Scope $response = $this->client->call(Client::METHOD_GET, '/console/', $this->getHeaders()); $this->assertEquals(404, $response['headers']['status-code']); + $this->assertEquals('general_route_not_found', $response['body']['type']); } public function testCors() From 92abfb31aa1a8c092696502046370d7f9963d022 Mon Sep 17 00:00:00 2001 From: Chirag Aggarwal Date: Tue, 7 Apr 2026 14:40:18 +0530 Subject: [PATCH 3/3] fix null route guard placement --- app/controllers/shared/api.php | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/app/controllers/shared/api.php b/app/controllers/shared/api.php index bdcbe70b83..8254a22ac0 100644 --- a/app/controllers/shared/api.php +++ b/app/controllers/shared/api.php @@ -98,6 +98,9 @@ Http::init() ->inject('authorization') ->action(function (Http $utopia, Request $request, Database $dbForPlatform, Database $dbForProject, Audit $queueForAudits, Document $project, User $user, ?Document $session, array $servers, string $mode, Document $team, ?Key $apiKey, Authorization $authorization) { $route = $utopia->getRoute(); + if ($route === null) { + throw new AppwriteException(AppwriteException::GENERAL_ROUTE_NOT_FOUND); + } /** * Handle user authentication and session validation. @@ -401,10 +404,6 @@ Http::init() } } - if ($route === null) { - throw new AppwriteException(AppwriteException::GENERAL_ROUTE_NOT_FOUND); - } - // Steps 7-9: Access Control - Method, Namespace and Scope Validation /** * @var ?Method $method