Repository navigation
v0.17.7 — export data no longer lost; API validation fixes
A patch release — data export, API validation, and session honesty
Fixes a silent data-loss bug in the data export, plus the API findings left open from the v1.0 acceptance run on develop. Several fixes rather than one, as a patch should be.
⚠️ Upgrade recommended promptly — the export was losing data
POST /api/user/export-request returned a file with no asset values in it. The mapper read field names that do not exist on the models (currentValue for value, zakatDue for zakatAmount, recipient for recipients), so every value came back undefined and JSON.stringify dropped it. The file stayed valid JSON and parsed cleanly — the money was simply absent, for every user, on every export, since the field was renamed. The same handler answered 200 {success: true, status: 'processing'} in place of any failure, including a genuine database error, and no endpoint serves that status — so a user whose export threw waited for a file that was never coming.
If you exported your data from a version between the value rename and this release, re-export after upgrading. Asset values, calculation zakatAmount, and payment recipients were omitted from those files.
Data
- Export now reads the real schema fields; asset
value, calculationzakatAmount, and paymentrecipientsare present in the file. - A failed export reports the failure instead of returning a fabricated success.
format=csvis refused with 400 rather than silently returning JSON.
Calculation correctness
- Negative and zero asset values are rejected.
POST/PUT /api/assetsaccepted-500and0, which persisted and silently reduced zakatable wealth for every consumer. - One asset-category vocabulary instead of two. The shared constants carried a lowercase list alongside the canonical fifteen UPPERCASE values, so a category could pass one validation layer and be rejected by the next.
Sessions and errors
- Logout now invalidates the access token. Revocation was recorded but never read, so a logged-out token stayed usable for its full 15-minute lifetime.
GET /api/zakat/methodologiesreturns 200 instead of 500 (it imported a source path absent from the built image).- Error responses no longer disclose server file paths.
- Malformed JSON returns 400, not 500.
Restore
- A restore no longer rejects the entire payload over one stray field (
zakatEligible, whichAssetSchemadisallows underadditionalProperties: false). The legacy value is preserved inmetadata.
Notes
No breaking API changes. Error details are now redacted, and an unsupported export format returns 400 instead of a body labelled processing. Both correct previously incorrect behaviour.
Full changelog: CHANGELOG.md