Skip to content

v0.17.7 — export data no longer lost; API validation fixes

Choose a tag to compare

@slimatic slimatic released this 28 Sep 15:57
· 235 commits to main since this release
241d781

A patch release — data export, API validation, and session honesty

Fixes a silent data-loss bug in the data export, plus the API findings left open from the v1.0 acceptance run on develop. Several fixes rather than one, as a patch should be.

⚠️ Upgrade recommended promptly — the export was losing data

POST /api/user/export-request returned a file with no asset values in it. The mapper read field names that do not exist on the models (currentValue for value, zakatDue for zakatAmount, recipient for recipients), so every value came back undefined and JSON.stringify dropped it. The file stayed valid JSON and parsed cleanly — the money was simply absent, for every user, on every export, since the field was renamed. The same handler answered 200 {success: true, status: 'processing'} in place of any failure, including a genuine database error, and no endpoint serves that status — so a user whose export threw waited for a file that was never coming.

If you exported your data from a version between the value rename and this release, re-export after upgrading. Asset values, calculation zakatAmount, and payment recipients were omitted from those files.

Data

  • Export now reads the real schema fields; asset value, calculation zakatAmount, and payment recipients are present in the file.
  • A failed export reports the failure instead of returning a fabricated success.
  • format=csv is refused with 400 rather than silently returning JSON.

Calculation correctness

  • Negative and zero asset values are rejected. POST/PUT /api/assets accepted -500 and 0, which persisted and silently reduced zakatable wealth for every consumer.
  • One asset-category vocabulary instead of two. The shared constants carried a lowercase list alongside the canonical fifteen UPPERCASE values, so a category could pass one validation layer and be rejected by the next.

Sessions and errors

  • Logout now invalidates the access token. Revocation was recorded but never read, so a logged-out token stayed usable for its full 15-minute lifetime.
  • GET /api/zakat/methodologies returns 200 instead of 500 (it imported a source path absent from the built image).
  • Error responses no longer disclose server file paths.
  • Malformed JSON returns 400, not 500.

Restore

  • A restore no longer rejects the entire payload over one stray field (zakatEligible, which AssetSchema disallows under additionalProperties: false). The legacy value is preserved in metadata.

Notes

No breaking API changes. Error details are now redacted, and an unsupported export format returns 400 instead of a body labelled processing. Both correct previously incorrect behaviour.

Full changelog: CHANGELOG.md