affaan-m/ECC · error · HTTPException

User not found

Error message

User not found

What it means

Illustrative not-found branch from the fastapi-patterns skill: after authorization passed, UserService.update found no user with the given user_id, so the router returns 404. The path parameter referencing a nonexistent user is the invalid input.

Solutions

  1. Distinguish 401/403/404 so callers cannot probe resource existence
  2. Return a consistent 404 shape across routes
  3. Log 404s with the requesting user for abuse detection
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at skills/fastapi-patterns/SKILL.md:283 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of affaan-m/ECC@d8409a4b08 (2026-08-26). Data as JSON: /api/errors/a90ff2346dc491e1. Report an issue: GitHub.

Appendix: source

Thrown at skills/fastapi-patterns/SKILL.md:283

    return UserListResponse(total=total, items=users)


@router.patch("/{user_id}", response_model=UserResponse)
async def update_user(
    user_id: int,
    payload: UserUpdate,
    db: DbDep,
    current_user: ActiveUserDep,
) -> UserResponse:
    if current_user.id != user_id:
        raise HTTPException(status_code=403, detail="Not authorized")
    service = UserService(db)
    try:
        user = await service.update(user_id, payload)
    except DuplicateUserError:
        raise HTTPException(status_code=400, detail="Email already registered")
    if user is None:
        raise HTTPException(status_code=404, detail="User not found")
    return user


@router.post("/token")
async def login(
    form_data: Annotated[OAuth2PasswordRequestForm, Depends()],
    db: DbDep,
) -> dict[str, str]:
    service = UserService(db)
    token = await service.authenticate(form_data.username, form_data.password)
    if token is None:
        raise HTTPException(
            status_code=status.HTTP_401_UNAUTHORIZED,
            detail="Incorrect username or password",
            headers={"WWW-Authenticate": "Bearer"},
        )
    return {"access_token": token, "token_type": "bearer"}
```

View on GitHub (pinned to d8409a4b08)