diff --git a/README.md b/README.md index b84a68b..c7f8d06 100644 --- a/README.md +++ b/README.md @@ -179,10 +179,11 @@ A message has: the SimpleX relay, to the second; for a sent one, when the bot sent it. -The answer is `400` if the query cannot be read (it holds a `;`, or a -`%` not followed by two hexadecimal digits) or `count` is not a whole -number from 1 to 100, and `404` if `GET /api/v1/chats` does not list -`id`. +The answer is `400` if `count` is not a whole number from 1 to 100, and +`404` if `GET /api/v1/chats` does not list `id`. A query the server +cannot read gets `400` with `the query cannot be read`; examples are a +query that holds a `;`, a `%` not followed by two hexadecimal digits, or +more than 10,000 parts separated by `&`. ### `POST /api/v1/chats/{id}/messages` diff --git a/internal/api/messages_test.go b/internal/api/messages_test.go index c56322b..24d1de7 100644 --- a/internal/api/messages_test.go +++ b/internal/api/messages_test.go @@ -152,6 +152,7 @@ func TestMessagesCount(t *testing.T) { // TestMessagesUnreadableQuery: a query that cannot be decoded is refused // with a sentence that says so, whether or not the bad part is count. +// The last query has 10,001 parts, more than Go's url.ParseQuery takes. func TestMessagesUnreadableQuery(t *testing.T) { t.Parallel() @@ -159,6 +160,7 @@ func TestMessagesUnreadableQuery(t *testing.T) { for _, query := range []string{ "?count=1%", "?count=5&x=%zz", "?x=%zz", "?count=5;x=1", + "?count=5" + strings.Repeat("&", 10000), } { client := &fakeClient{contacts: oneChat()} rec := request(t, newAPI(credential, client),