Skip to content

fix(commerce-server): return 400/404 from order-status instead of 500 - #1488

Draft
anam-godaddy wants to merge 1 commit into
godaddy:mainfrom
anam-godaddy:fix/order-status-http-errors
Draft

anam-godaddy wants to merge 1 commit into
godaddy:mainfrom
anam-godaddy:fix/order-status-http-errors

Conversation

@anam-godaddy

Copy link
Copy Markdown

What changed

GET /api/commerce/order-status returned 500 for every failure, so a bad order ID or a missing order looked the same as a credential or upstream outage.

Case Before After
Missing, blank, whitespace-padded, . or .. orderId 500 (or 400 only when absent) 400
Orders API returns 404 500 404
Returned order has a different id, store, or channel 500 404 — doesn't reveal the order exists elsewhere
Incomplete order response, token failure, other upstream status 500 500 (unchanged)
  • getOrderStatus() throws InvalidOrderIdError / OrderNotFoundError (both exported) so in-process callers can branch without parsing messages. The 404 body stays generic and never includes upstream content.
  • Padded IDs are rejected rather than trimmed, so the lookup never targets an ID other than the one supplied. Previously ' abc' passed validation, was sent upstream untrimmed, and failed the binding check as a 500.

Why

Found while triaging an App Builder bug-scan PR (gdcorp-partners/airo-app-builder#11013) against this package. That PR's GraphQL statuses fix is already superseded here by the Orders REST lookup (5314b51); its route error mapping was the remaining gap.

A REST 404 is safe to map to "not found": unlike the storefront subgraph, the Orders API returns completed orders, so a paid order is a 200, never a 404.

Testing

  • pnpm --filter @godaddy/gd-commerce-server typecheck, lint, test — 174 passed
  • New route tests for 400 (absent, blank, padded, ., .., repeated param — no upstream call), 404 (upstream 404, store mismatch), and 500 (denied token, upstream 500, incomplete order), asserting upstream bodies are never exposed

🤖 Generated with Claude Code

Invalid order IDs (blank, padded, `.`, `..`) and missing orders previously
surfaced as 500s, indistinguishable from credential or upstream failures.

- getOrderStatus throws InvalidOrderIdError for invalid IDs and
  OrderNotFoundError when the Orders API returns 404 or the order is bound
  to another order ID, store, or channel. Incomplete responses stay generic.
- The order-status route maps these to 400 and 404; everything else is 500.
- Padded IDs are rejected rather than trimmed so the lookup never targets a
  different ID than the caller supplied.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@changeset-bot

changeset-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e7d6e79

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@godaddy/gd-commerce-server Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant