HydraIssues

District API silently clears venue when the field is omitted
open unclassified Project: hydracluster Reporter: anonymous 20 Aug 2026 09:13

Description

POST /api/v1/nodes/{id}/district silently clears a node's venue when the request body omits the venue field. The handler (pkg/api/handlers_api.go, handleAPISetDistrict) decodes district and venue into plain strings and passes both to st.SetDistrict, so an absent venue and an explicit empty venue are the same: both wipe the stored value. No warning, and the response is only {"status":"ok"}.

Real incident, 2026-08-20: a call with {"district":"bxl1-test-2"} to move the Air head (node-5e0ea2c8) between districts erased its venue (cloud-seven). Venue drives body eligibility (same_venue), so a wiped venue silently changes body selection for the head. It was caught only because the node record was re-read after the call.

The web admin path (handleWebSetDistrict) has the same pass-through, but the admin form always submits both fields, so the API path is where this bites.

Proposed fix:

  • In the API handler, decode venue as *string. Absent field = leave the stored venue unchanged. Explicit "" (or a separate clear flag) = intentional clear.
  • Consider the same absent-vs-empty treatment for district itself.
  • Return the resulting district and venue in the response body instead of a bare ok, so callers see what they changed.
  • Add a handler test: district-only payload must not touch venue.