fix: skip request body validation gracefully instead of throwing error - #2188

Closed
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation
Closed

fix: skip request body validation gracefully instead of throwing error#2188
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation

Conversation

@bobbiejaxn

Copy link
Copy Markdown

Fixes#1987

The Bug

When using request validation in the CLI, request body validation is skipped or reported as unsupported for certain paths or HTTP methods, even when a valid request body schema is defined. Two specific issues:

Bug 1: Unsafe property access crashes validation

requestBody.content["'application/json'].schema throws TypeError: Cannot read properties of undefined when the content type is not application/json (e.g., multipart/form-data, text/plain, or missing entirely).

Before: Direct property access crashes or returns undefined
After: Optional chaining requestBody.content?.["application/json"]?.schema safely handles missing content types

Bug 2: Incorrect error for endpoints without request bodies

When compileAjv() returns undefined (because the method has no requestBody, like GET/DELETE, or the requestBody has no JSON schema), the middleware threw:

Request body validation is not supported for "/path" path with "method" method.

This is wrong. Methods without request bodies simply don't need body validation — it's not an error condition. Endpoints with non-JSON content types should silently skip rather than error.

Before: Throws 422 error
After: Silently passes through to document validation

Testing

This mirrors the fix in #2128 but is more surgical — only touches validation.middleware.ts and does not include the unrelated URL parsing changes from #1940 (which is addressed separately in #2187).

Scope

This PR only fixes the request body validation bug (#1987). It does not touch the URL parsing or file extension detection (those are in #2187 for #1940).

@changeset-bot

changeset-botBot commented May 6, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4e5dcad

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@asyncapi/cliPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Fixesasyncapi/cli#1987
Two bugs fixed:
1. Unsafe access to requestBody.content['application/json'].schema
crashes with TypeError when application/json is not a content type
(e.g., multipart/form-data, text/plain). Fixed with optional
chaining to safely check content type before accessing schema.
2. When compileAjv returns undefined (no requestBody or no JSON schema),
the middleware incorrectly threw 'Request body validation is not
supported' error. This is wrong - methods without request bodies
(like GET, DELETE) simply don't need body validation, and endpoints
with non-JSON content types should silently skip rather than error.
Fixed to pass through instead of throwing.
@bobbiejaxn
bobbiejaxnforce-pushed the fix/issue-1987-request-body-validation branch from d6053e5 to 8dee99fCompareMay 7, 2026 20:11
@bobbiejaxn

Copy link
Copy Markdown
Author

Rebased on latest master and added changeset as requested by the changeset bot. All checks pass, SonarCloud clean.

Ready for review: @Souvikns@Shurtu-gal@AayushSaini101

This is part of the MICROGRANT Program 2026-05.

@sonarqubecloud

Copy link
Copy Markdown

AayushSaini101 added a commit to AayushSaini101/cli that referenced this pull request Jun 5, 2026
Replace the expanded findContentSchema approach with the minimal fix from
PR asyncapi#2188: optional chaining for application/json schema access and pass
through when no validator is compiled. Remove extra unit tests added on
this branch and add the changeset.
Fixesasyncapi#1987
Co-authored-by: Cursor <cursoragent@cursor.com>
@github-project-automationgithub-project-automationBot moved this from To Triage to Done in CLI - KanbanJun 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

[BUG] Request body validation is skipped for some paths or HTTP methods

2 participants

@bobbiejaxn@AayushSaini101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: skip request body validation gracefully instead of throwing error - #2188

Closed
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation
Closed

fix: skip request body validation gracefully instead of throwing error#2188
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation

Conversation

@bobbiejaxn

Copy link
Copy Markdown

Fixes#1987

The Bug

When using request validation in the CLI, request body validation is skipped or reported as unsupported for certain paths or HTTP methods, even when a valid request body schema is defined. Two specific issues:

Bug 1: Unsafe property access crashes validation

requestBody.content["'application/json'].schema throws TypeError: Cannot read properties of undefined when the content type is not application/json (e.g., multipart/form-data, text/plain, or missing entirely).

Before: Direct property access crashes or returns undefined
After: Optional chaining requestBody.content?.["application/json"]?.schema safely handles missing content types

Bug 2: Incorrect error for endpoints without request bodies

When compileAjv() returns undefined (because the method has no requestBody, like GET/DELETE, or the requestBody has no JSON schema), the middleware threw:

Request body validation is not supported for "/path" path with "method" method.

This is wrong. Methods without request bodies simply don't need body validation — it's not an error condition. Endpoints with non-JSON content types should silently skip rather than error.

Before: Throws 422 error
After: Silently passes through to document validation

Testing

This mirrors the fix in #2128 but is more surgical — only touches validation.middleware.ts and does not include the unrelated URL parsing changes from #1940 (which is addressed separately in #2187).

Scope

This PR only fixes the request body validation bug (#1987). It does not touch the URL parsing or file extension detection (those are in #2187 for #1940).

@changeset-bot

changeset-botBot commented May 6, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4e5dcad

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@asyncapi/cliPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Fixesasyncapi/cli#1987
Two bugs fixed:
1. Unsafe access to requestBody.content['application/json'].schema
crashes with TypeError when application/json is not a content type
(e.g., multipart/form-data, text/plain). Fixed with optional
chaining to safely check content type before accessing schema.
2. When compileAjv returns undefined (no requestBody or no JSON schema),
the middleware incorrectly threw 'Request body validation is not
supported' error. This is wrong - methods without request bodies
(like GET, DELETE) simply don't need body validation, and endpoints
with non-JSON content types should silently skip rather than error.
Fixed to pass through instead of throwing.
@bobbiejaxn
bobbiejaxnforce-pushed the fix/issue-1987-request-body-validation branch from d6053e5 to 8dee99fCompareMay 7, 2026 20:11
@bobbiejaxn

Copy link
Copy Markdown
Author

Rebased on latest master and added changeset as requested by the changeset bot. All checks pass, SonarCloud clean.

Ready for review: @Souvikns@Shurtu-gal@AayushSaini101

This is part of the MICROGRANT Program 2026-05.

@sonarqubecloud

Copy link
Copy Markdown

AayushSaini101 added a commit to AayushSaini101/cli that referenced this pull request Jun 5, 2026
Replace the expanded findContentSchema approach with the minimal fix from
PR asyncapi#2188: optional chaining for application/json schema access and pass
through when no validator is compiled. Remove extra unit tests added on
this branch and add the changeset.
Fixesasyncapi#1987
Co-authored-by: Cursor <cursoragent@cursor.com>
@github-project-automationgithub-project-automationBot moved this from To Triage to Done in CLI - KanbanJun 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

[BUG] Request body validation is skipped for some paths or HTTP methods

2 participants

@bobbiejaxn@AayushSaini101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: skip request body validation gracefully instead of throwing error - #2188

Closed
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation
Closed

fix: skip request body validation gracefully instead of throwing error#2188
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation

Conversation

@bobbiejaxn

Copy link
Copy Markdown

Fixes#1987

The Bug

When using request validation in the CLI, request body validation is skipped or reported as unsupported for certain paths or HTTP methods, even when a valid request body schema is defined. Two specific issues:

Bug 1: Unsafe property access crashes validation

requestBody.content["'application/json'].schema throws TypeError: Cannot read properties of undefined when the content type is not application/json (e.g., multipart/form-data, text/plain, or missing entirely).

Before: Direct property access crashes or returns undefined
After: Optional chaining requestBody.content?.["application/json"]?.schema safely handles missing content types

Bug 2: Incorrect error for endpoints without request bodies

When compileAjv() returns undefined (because the method has no requestBody, like GET/DELETE, or the requestBody has no JSON schema), the middleware threw:

Request body validation is not supported for "/path" path with "method" method.

This is wrong. Methods without request bodies simply don't need body validation — it's not an error condition. Endpoints with non-JSON content types should silently skip rather than error.

Before: Throws 422 error
After: Silently passes through to document validation

Testing

This mirrors the fix in #2128 but is more surgical — only touches validation.middleware.ts and does not include the unrelated URL parsing changes from #1940 (which is addressed separately in #2187).

Scope

This PR only fixes the request body validation bug (#1987). It does not touch the URL parsing or file extension detection (those are in #2187 for #1940).

@changeset-bot

changeset-botBot commented May 6, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4e5dcad

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@asyncapi/cliPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Fixesasyncapi/cli#1987
Two bugs fixed:
1. Unsafe access to requestBody.content['application/json'].schema
crashes with TypeError when application/json is not a content type
(e.g., multipart/form-data, text/plain). Fixed with optional
chaining to safely check content type before accessing schema.
2. When compileAjv returns undefined (no requestBody or no JSON schema),
the middleware incorrectly threw 'Request body validation is not
supported' error. This is wrong - methods without request bodies
(like GET, DELETE) simply don't need body validation, and endpoints
with non-JSON content types should silently skip rather than error.
Fixed to pass through instead of throwing.
@bobbiejaxn
bobbiejaxnforce-pushed the fix/issue-1987-request-body-validation branch from d6053e5 to 8dee99fCompareMay 7, 2026 20:11
@bobbiejaxn

Copy link
Copy Markdown
Author

Rebased on latest master and added changeset as requested by the changeset bot. All checks pass, SonarCloud clean.

Ready for review: @Souvikns@Shurtu-gal@AayushSaini101

This is part of the MICROGRANT Program 2026-05.

@sonarqubecloud

Copy link
Copy Markdown

AayushSaini101 added a commit to AayushSaini101/cli that referenced this pull request Jun 5, 2026
Replace the expanded findContentSchema approach with the minimal fix from
PR asyncapi#2188: optional chaining for application/json schema access and pass
through when no validator is compiled. Remove extra unit tests added on
this branch and add the changeset.
Fixesasyncapi#1987
Co-authored-by: Cursor <cursoragent@cursor.com>
@github-project-automationgithub-project-automationBot moved this from To Triage to Done in CLI - KanbanJun 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

[BUG] Request body validation is skipped for some paths or HTTP methods

2 participants

@bobbiejaxn@AayushSaini101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: skip request body validation gracefully instead of throwing error - #2188

Closed
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation
Closed

fix: skip request body validation gracefully instead of throwing error#2188
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation

Conversation

@bobbiejaxn

Copy link
Copy Markdown

Fixes#1987

The Bug

When using request validation in the CLI, request body validation is skipped or reported as unsupported for certain paths or HTTP methods, even when a valid request body schema is defined. Two specific issues:

Bug 1: Unsafe property access crashes validation

requestBody.content["'application/json'].schema throws TypeError: Cannot read properties of undefined when the content type is not application/json (e.g., multipart/form-data, text/plain, or missing entirely).

Before: Direct property access crashes or returns undefined
After: Optional chaining requestBody.content?.["application/json"]?.schema safely handles missing content types

Bug 2: Incorrect error for endpoints without request bodies

When compileAjv() returns undefined (because the method has no requestBody, like GET/DELETE, or the requestBody has no JSON schema), the middleware threw:

Request body validation is not supported for "/path" path with "method" method.

This is wrong. Methods without request bodies simply don't need body validation — it's not an error condition. Endpoints with non-JSON content types should silently skip rather than error.

Before: Throws 422 error
After: Silently passes through to document validation

Testing

This mirrors the fix in #2128 but is more surgical — only touches validation.middleware.ts and does not include the unrelated URL parsing changes from #1940 (which is addressed separately in #2187).

Scope

This PR only fixes the request body validation bug (#1987). It does not touch the URL parsing or file extension detection (those are in #2187 for #1940).

@changeset-bot

changeset-botBot commented May 6, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4e5dcad

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@asyncapi/cliPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Fixesasyncapi/cli#1987
Two bugs fixed:
1. Unsafe access to requestBody.content['application/json'].schema
crashes with TypeError when application/json is not a content type
(e.g., multipart/form-data, text/plain). Fixed with optional
chaining to safely check content type before accessing schema.
2. When compileAjv returns undefined (no requestBody or no JSON schema),
the middleware incorrectly threw 'Request body validation is not
supported' error. This is wrong - methods without request bodies
(like GET, DELETE) simply don't need body validation, and endpoints
with non-JSON content types should silently skip rather than error.
Fixed to pass through instead of throwing.
@bobbiejaxn
bobbiejaxnforce-pushed the fix/issue-1987-request-body-validation branch from d6053e5 to 8dee99fCompareMay 7, 2026 20:11
@bobbiejaxn

Copy link
Copy Markdown
Author

Rebased on latest master and added changeset as requested by the changeset bot. All checks pass, SonarCloud clean.

Ready for review: @Souvikns@Shurtu-gal@AayushSaini101

This is part of the MICROGRANT Program 2026-05.

@sonarqubecloud

Copy link
Copy Markdown

AayushSaini101 added a commit to AayushSaini101/cli that referenced this pull request Jun 5, 2026
Replace the expanded findContentSchema approach with the minimal fix from
PR asyncapi#2188: optional chaining for application/json schema access and pass
through when no validator is compiled. Remove extra unit tests added on
this branch and add the changeset.
Fixesasyncapi#1987
Co-authored-by: Cursor <cursoragent@cursor.com>
@github-project-automationgithub-project-automationBot moved this from To Triage to Done in CLI - KanbanJun 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

[BUG] Request body validation is skipped for some paths or HTTP methods

2 participants

@bobbiejaxn@AayushSaini101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: skip request body validation gracefully instead of throwing error - #2188

Closed
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation
Closed

fix: skip request body validation gracefully instead of throwing error#2188
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation

Conversation

@bobbiejaxn

Copy link
Copy Markdown

Fixes#1987

The Bug

When using request validation in the CLI, request body validation is skipped or reported as unsupported for certain paths or HTTP methods, even when a valid request body schema is defined. Two specific issues:

Bug 1: Unsafe property access crashes validation

requestBody.content["'application/json'].schema throws TypeError: Cannot read properties of undefined when the content type is not application/json (e.g., multipart/form-data, text/plain, or missing entirely).

Before: Direct property access crashes or returns undefined
After: Optional chaining requestBody.content?.["application/json"]?.schema safely handles missing content types

Bug 2: Incorrect error for endpoints without request bodies

When compileAjv() returns undefined (because the method has no requestBody, like GET/DELETE, or the requestBody has no JSON schema), the middleware threw:

Request body validation is not supported for "/path" path with "method" method.

This is wrong. Methods without request bodies simply don't need body validation — it's not an error condition. Endpoints with non-JSON content types should silently skip rather than error.

Before: Throws 422 error
After: Silently passes through to document validation

Testing

This mirrors the fix in #2128 but is more surgical — only touches validation.middleware.ts and does not include the unrelated URL parsing changes from #1940 (which is addressed separately in #2187).

Scope

This PR only fixes the request body validation bug (#1987). It does not touch the URL parsing or file extension detection (those are in #2187 for #1940).

@changeset-bot

changeset-botBot commented May 6, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4e5dcad

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@asyncapi/cliPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Fixesasyncapi/cli#1987
Two bugs fixed:
1. Unsafe access to requestBody.content['application/json'].schema
crashes with TypeError when application/json is not a content type
(e.g., multipart/form-data, text/plain). Fixed with optional
chaining to safely check content type before accessing schema.
2. When compileAjv returns undefined (no requestBody or no JSON schema),
the middleware incorrectly threw 'Request body validation is not
supported' error. This is wrong - methods without request bodies
(like GET, DELETE) simply don't need body validation, and endpoints
with non-JSON content types should silently skip rather than error.
Fixed to pass through instead of throwing.
@bobbiejaxn
bobbiejaxnforce-pushed the fix/issue-1987-request-body-validation branch from d6053e5 to 8dee99fCompareMay 7, 2026 20:11
@bobbiejaxn

Copy link
Copy Markdown
Author

Rebased on latest master and added changeset as requested by the changeset bot. All checks pass, SonarCloud clean.

Ready for review: @Souvikns@Shurtu-gal@AayushSaini101

This is part of the MICROGRANT Program 2026-05.

@sonarqubecloud

Copy link
Copy Markdown

AayushSaini101 added a commit to AayushSaini101/cli that referenced this pull request Jun 5, 2026
Replace the expanded findContentSchema approach with the minimal fix from
PR asyncapi#2188: optional chaining for application/json schema access and pass
through when no validator is compiled. Remove extra unit tests added on
this branch and add the changeset.
Fixesasyncapi#1987
Co-authored-by: Cursor <cursoragent@cursor.com>
@github-project-automationgithub-project-automationBot moved this from To Triage to Done in CLI - KanbanJun 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

[BUG] Request body validation is skipped for some paths or HTTP methods

2 participants

@bobbiejaxn@AayushSaini101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: skip request body validation gracefully instead of throwing error - #2188

Closed
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation
Closed

fix: skip request body validation gracefully instead of throwing error#2188
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation

Conversation

@bobbiejaxn

Copy link
Copy Markdown

Fixes#1987

The Bug

When using request validation in the CLI, request body validation is skipped or reported as unsupported for certain paths or HTTP methods, even when a valid request body schema is defined. Two specific issues:

Bug 1: Unsafe property access crashes validation

requestBody.content["'application/json'].schema throws TypeError: Cannot read properties of undefined when the content type is not application/json (e.g., multipart/form-data, text/plain, or missing entirely).

Before: Direct property access crashes or returns undefined
After: Optional chaining requestBody.content?.["application/json"]?.schema safely handles missing content types

Bug 2: Incorrect error for endpoints without request bodies

When compileAjv() returns undefined (because the method has no requestBody, like GET/DELETE, or the requestBody has no JSON schema), the middleware threw:

Request body validation is not supported for "/path" path with "method" method.

This is wrong. Methods without request bodies simply don't need body validation — it's not an error condition. Endpoints with non-JSON content types should silently skip rather than error.

Before: Throws 422 error
After: Silently passes through to document validation

Testing

This mirrors the fix in #2128 but is more surgical — only touches validation.middleware.ts and does not include the unrelated URL parsing changes from #1940 (which is addressed separately in #2187).

Scope

This PR only fixes the request body validation bug (#1987). It does not touch the URL parsing or file extension detection (those are in #2187 for #1940).

@changeset-bot

changeset-botBot commented May 6, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4e5dcad

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@asyncapi/cliPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Fixesasyncapi/cli#1987
Two bugs fixed:
1. Unsafe access to requestBody.content['application/json'].schema
crashes with TypeError when application/json is not a content type
(e.g., multipart/form-data, text/plain). Fixed with optional
chaining to safely check content type before accessing schema.
2. When compileAjv returns undefined (no requestBody or no JSON schema),
the middleware incorrectly threw 'Request body validation is not
supported' error. This is wrong - methods without request bodies
(like GET, DELETE) simply don't need body validation, and endpoints
with non-JSON content types should silently skip rather than error.
Fixed to pass through instead of throwing.
@bobbiejaxn
bobbiejaxnforce-pushed the fix/issue-1987-request-body-validation branch from d6053e5 to 8dee99fCompareMay 7, 2026 20:11
@bobbiejaxn

Copy link
Copy Markdown
Author

Rebased on latest master and added changeset as requested by the changeset bot. All checks pass, SonarCloud clean.

Ready for review: @Souvikns@Shurtu-gal@AayushSaini101

This is part of the MICROGRANT Program 2026-05.

@sonarqubecloud

Copy link
Copy Markdown

AayushSaini101 added a commit to AayushSaini101/cli that referenced this pull request Jun 5, 2026
Replace the expanded findContentSchema approach with the minimal fix from
PR asyncapi#2188: optional chaining for application/json schema access and pass
through when no validator is compiled. Remove extra unit tests added on
this branch and add the changeset.
Fixesasyncapi#1987
Co-authored-by: Cursor <cursoragent@cursor.com>
@github-project-automationgithub-project-automationBot moved this from To Triage to Done in CLI - KanbanJun 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

[BUG] Request body validation is skipped for some paths or HTTP methods

2 participants

@bobbiejaxn@AayushSaini101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: skip request body validation gracefully instead of throwing error - #2188

Closed
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation
Closed

fix: skip request body validation gracefully instead of throwing error#2188
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation

Conversation

@bobbiejaxn

Copy link
Copy Markdown

Fixes#1987

The Bug

When using request validation in the CLI, request body validation is skipped or reported as unsupported for certain paths or HTTP methods, even when a valid request body schema is defined. Two specific issues:

Bug 1: Unsafe property access crashes validation

requestBody.content["'application/json'].schema throws TypeError: Cannot read properties of undefined when the content type is not application/json (e.g., multipart/form-data, text/plain, or missing entirely).

Before: Direct property access crashes or returns undefined
After: Optional chaining requestBody.content?.["application/json"]?.schema safely handles missing content types

Bug 2: Incorrect error for endpoints without request bodies

When compileAjv() returns undefined (because the method has no requestBody, like GET/DELETE, or the requestBody has no JSON schema), the middleware threw:

Request body validation is not supported for "/path" path with "method" method.

This is wrong. Methods without request bodies simply don't need body validation — it's not an error condition. Endpoints with non-JSON content types should silently skip rather than error.

Before: Throws 422 error
After: Silently passes through to document validation

Testing

This mirrors the fix in #2128 but is more surgical — only touches validation.middleware.ts and does not include the unrelated URL parsing changes from #1940 (which is addressed separately in #2187).

Scope

This PR only fixes the request body validation bug (#1987). It does not touch the URL parsing or file extension detection (those are in #2187 for #1940).

@changeset-bot

changeset-botBot commented May 6, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4e5dcad

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@asyncapi/cliPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Fixesasyncapi/cli#1987
Two bugs fixed:
1. Unsafe access to requestBody.content['application/json'].schema
crashes with TypeError when application/json is not a content type
(e.g., multipart/form-data, text/plain). Fixed with optional
chaining to safely check content type before accessing schema.
2. When compileAjv returns undefined (no requestBody or no JSON schema),
the middleware incorrectly threw 'Request body validation is not
supported' error. This is wrong - methods without request bodies
(like GET, DELETE) simply don't need body validation, and endpoints
with non-JSON content types should silently skip rather than error.
Fixed to pass through instead of throwing.
@bobbiejaxn
bobbiejaxnforce-pushed the fix/issue-1987-request-body-validation branch from d6053e5 to 8dee99fCompareMay 7, 2026 20:11
@bobbiejaxn

Copy link
Copy Markdown
Author

Rebased on latest master and added changeset as requested by the changeset bot. All checks pass, SonarCloud clean.

Ready for review: @Souvikns@Shurtu-gal@AayushSaini101

This is part of the MICROGRANT Program 2026-05.

@sonarqubecloud

Copy link
Copy Markdown

AayushSaini101 added a commit to AayushSaini101/cli that referenced this pull request Jun 5, 2026
Replace the expanded findContentSchema approach with the minimal fix from
PR asyncapi#2188: optional chaining for application/json schema access and pass
through when no validator is compiled. Remove extra unit tests added on
this branch and add the changeset.
Fixesasyncapi#1987
Co-authored-by: Cursor <cursoragent@cursor.com>
@github-project-automationgithub-project-automationBot moved this from To Triage to Done in CLI - KanbanJun 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

[BUG] Request body validation is skipped for some paths or HTTP methods

2 participants

@bobbiejaxn@AayushSaini101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: skip request body validation gracefully instead of throwing error - #2188

Closed
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation
Closed

fix: skip request body validation gracefully instead of throwing error#2188
bobbiejaxn wants to merge 3 commits into
asyncapi:masterfrom
bobbiejaxn:fix/issue-1987-request-body-validation

Conversation

@bobbiejaxn

Copy link
Copy Markdown

Fixes#1987

The Bug

When using request validation in the CLI, request body validation is skipped or reported as unsupported for certain paths or HTTP methods, even when a valid request body schema is defined. Two specific issues:

Bug 1: Unsafe property access crashes validation

requestBody.content["'application/json'].schema throws TypeError: Cannot read properties of undefined when the content type is not application/json (e.g., multipart/form-data, text/plain, or missing entirely).

Before: Direct property access crashes or returns undefined
After: Optional chaining requestBody.content?.["application/json"]?.schema safely handles missing content types

Bug 2: Incorrect error for endpoints without request bodies

When compileAjv() returns undefined (because the method has no requestBody, like GET/DELETE, or the requestBody has no JSON schema), the middleware threw:

Request body validation is not supported for "/path" path with "method" method.

This is wrong. Methods without request bodies simply don't need body validation — it's not an error condition. Endpoints with non-JSON content types should silently skip rather than error.

Before: Throws 422 error
After: Silently passes through to document validation

Testing

This mirrors the fix in #2128 but is more surgical — only touches validation.middleware.ts and does not include the unrelated URL parsing changes from #1940 (which is addressed separately in #2187).

Scope

This PR only fixes the request body validation bug (#1987). It does not touch the URL parsing or file extension detection (those are in #2187 for #1940).

@changeset-bot

changeset-botBot commented May 6, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4e5dcad

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@asyncapi/cliPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Fixesasyncapi/cli#1987
Two bugs fixed:
1. Unsafe access to requestBody.content['application/json'].schema
crashes with TypeError when application/json is not a content type
(e.g., multipart/form-data, text/plain). Fixed with optional
chaining to safely check content type before accessing schema.
2. When compileAjv returns undefined (no requestBody or no JSON schema),
the middleware incorrectly threw 'Request body validation is not
supported' error. This is wrong - methods without request bodies
(like GET, DELETE) simply don't need body validation, and endpoints
with non-JSON content types should silently skip rather than error.
Fixed to pass through instead of throwing.
@bobbiejaxn
bobbiejaxnforce-pushed the fix/issue-1987-request-body-validation branch from d6053e5 to 8dee99fCompareMay 7, 2026 20:11
@bobbiejaxn

Copy link
Copy Markdown
Author

Rebased on latest master and added changeset as requested by the changeset bot. All checks pass, SonarCloud clean.

Ready for review: @Souvikns@Shurtu-gal@AayushSaini101

This is part of the MICROGRANT Program 2026-05.

@sonarqubecloud

Copy link
Copy Markdown

AayushSaini101 added a commit to AayushSaini101/cli that referenced this pull request Jun 5, 2026
Replace the expanded findContentSchema approach with the minimal fix from
PR asyncapi#2188: optional chaining for application/json schema access and pass
through when no validator is compiled. Remove extra unit tests added on
this branch and add the changeset.
Fixesasyncapi#1987
Co-authored-by: Cursor <cursoragent@cursor.com>
@github-project-automationgithub-project-automationBot moved this from To Triage to Done in CLI - KanbanJun 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

[BUG] Request body validation is skipped for some paths or HTTP methods

2 participants

@bobbiejaxn@AayushSaini101