Skip to content

fix(event_handler): preserve comma-separated values in scalar parameters and model fields - #8514

Open
DYNOSuprovo wants to merge 1 commit into
aws-powertools:developfrom
DYNOSuprovo:fix/openapi-preserve-commas-8508
Open

DYNOSuprovo wants to merge 1 commit into
aws-powertools:developfrom
DYNOSuprovo:fix/openapi-preserve-commas-8508

Conversation

@DYNOSuprovo

Copy link
Copy Markdown

Issue number: closes #8508

Summary

Changes

In the OpenAPI validation middleware:

  • Updated _process_scalar_param to check if a parameter's value was split into a list of strings (by proxies such as API Gateway HTTP API v2 or Lambda Function URLs representing multi-value query or header parameters) and rejoin them with ",".join(value) when expecting a scalar string. Previously, _process_scalar_param only unwrapped single-element lists (len(value) == 1), leaving multi-item lists intact and causing Pydantic to reject valid comma-containing queries or headers with a 422 string_type validation error.
  • Updated _normalize_field_value for Pydantic model fields to rejoin string lists with ",".join(value) when the target field annotation is not a sequence, instead of returning value[0] which caused strings containing commas to be silently truncated.
  • Added comprehensive unit tests in tests/functional/event_handler/_pydantic/test_openapi_validation_middleware.py verifying comma preservation for scalar query parameters, headers (e.g. X-Forwarded-For), and Pydantic models.

User experience

Before:

  1. A scalar query parameter containing commas (e.g. GET /search?search=hello,world where search: Annotated[str, Query()]) was rejected with HTTP 422:
    {"statusCode": 422, "body": "[{\"type\":\"string_type\",\"loc\":[\"query\",\"search\"],\"msg\":\"Input should be a valid string\",\"input\":[\"hello\",\"world\"]}]"}
  2. A header containing commas (e.g. X-Forwarded-For: 203.0.113.9, 10.0.0.1 where x_forwarded_for: Annotated[str, Header()]) was rejected with HTTP 422 string_type.
  3. A query parameter mapped to a Pydantic model with a string field (e.g. search: str) was truncated to only the first segment before the comma ("hello" instead of "hello,world").

After:
All query parameters and headers containing commas are properly validated and preserved as full strings ("hello,world", "203.0.113.9, 10.0.0.1") across scalar parameters and Pydantic models, while sequence fields continue to be parsed as list items.


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@DYNOSuprovo
DYNOSuprovo requested a review from a team as a code owner October 3, 2026 15:59
@DYNOSuprovo
DYNOSuprovo requested a review from hjgraca October 3, 2026 15:59
@boring-cyborg

boring-cyborg Bot commented Oct 3, 2026

Copy link
Copy Markdown

Thanks a lot for your first contribution! Please check out our contributing guidelines and don't hesitate to ask whatever you need.
In the meantime, check out the #python channel on our Powertools for AWS Lambda Discord: Invite link

@powertools-for-aws-oss-automation powertools-for-aws-oss-automation Bot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Oct 3, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 3, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

event_handlers size/M Denotes a PR that changes 30-99 lines, ignoring generated files. tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: OpenAPI validation rejects or truncates query and header values that contain commas

1 participant