From 038e06c7cbba8544f9b07b9d18cfd24357378ad4 Mon Sep 17 00:00:00 2001 From: Shubham Padkonde Date: Thu, 24 Sep 2026 09:25:29 +0000 Subject: [PATCH] Reject boolean values for the limit parameter get_typed_value turns limit=true into the boolean True, which passed the isinstance(..., int) check because bool is a subclass of int, so evaluate_limit returned True as the limit (and limit=false failed with "should be strictly positive"). Booleans are now rejected with the same "should be an integer" error as other non-integer values. --- pygeoapi/api/__init__.py | 3 ++- tests/api/test_api.py | 4 ++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/pygeoapi/api/__init__.py b/pygeoapi/api/__init__.py index e54b90e6a9..9685053e99 100644 --- a/pygeoapi/api/__init__.py +++ b/pygeoapi/api/__init__.py @@ -1322,7 +1322,8 @@ def evaluate_limit(requested: Union[None, int], server_limits: dict, else: requested2 = get_typed_value(requested) - if not isinstance(requested2, int): + # bool is a subclass of int, but limit=true is not a valid limit + if isinstance(requested2, bool) or not isinstance(requested2, int): raise ValueError('limit value should be an integer') if requested2 <= 0: diff --git a/tests/api/test_api.py b/tests/api/test_api.py index e0dc1e547a..1b07afc866 100644 --- a/tests/api/test_api.py +++ b/tests/api/test_api.py @@ -996,6 +996,10 @@ def test_evaluate_limit(): with pytest.raises(ValueError): assert evaluate_limit('-12', server, collection) == 10 + for value in ['true', 'false', True]: + with pytest.raises(ValueError, match='should be an integer'): + evaluate_limit(value, server, collection) + assert evaluate_limit('1', server, collection) == 1 collection = {}