{"record":{"id":"038bddb4507e1d93","repo":"koala73/worldmonitor","slug":"duplicate-airport-delay-parameter-key","errorCode":null,"errorMessage":"Duplicate airport delay parameter: ${key}","messagePattern":"Duplicate airport delay parameter: (.+?)","errorType":"http","errorClass":"ApiError","httpStatus":400,"severity":"error","filePath":"server/worldmonitor/aviation/v1/list-airport-delays.ts","lineNumber":44,"sourceCode":"// @ts-expect-error — JS module, no declaration file\nimport { captureSilentError } from '../../../../api/_sentry-edge.js';\n\nconst FAA_CACHE_KEY = 'aviation:delays:faa:v1';\nconst INTL_CACHE_KEY = 'aviation:delays:intl:v3';\n\nconst FAA_AIRPORT_SET = new Set(FAA_AIRPORTS);\nconst INTL_AIRPORT_SET = new Set(AVIATIONSTACK_AIRPORTS);\n\nconst ALLOWED_QUERY_PARAMS = new Set(['page_size', 'cursor', 'region', 'min_severity', 'jmespath', '_debug', 'rpc']);\n\nexport async function listAirportDelays(\n  ctx: ServerContext,\n  req: ListAirportDelaysRequest,\n): Promise<ListAirportDelaysResponse> {\n  const seenParams = new Set<string>();\n  for (const [key, value] of new URL(ctx.request.url).searchParams) {\n    if (!ALLOWED_QUERY_PARAMS.has(key)) throw new ApiError(400, `Unsupported airport delay parameter: ${key}`, '');\n    if (seenParams.has(key)) throw new ApiError(400, `Duplicate airport delay parameter: ${key}`, '');\n    seenParams.add(key);\n    if (key === 'page_size' && value !== '0') throw new ApiError(400, 'Airport delay page_size must be 0', '');\n    if (key === 'rpc' && value !== 'list-airport-delays') throw new ApiError(400, 'Invalid airport delay route', '');\n  }\n  if ((req.pageSize ?? 0) !== 0 || req.cursor\n    || (req.region && req.region !== 'AIRPORT_REGION_UNSPECIFIED')\n    || (req.minSeverity && req.minSeverity !== 'FLIGHT_DELAY_SEVERITY_UNSPECIFIED')) {\n    throw new ApiError(400, 'Airport delay filters are not supported', '');\n  }\n  // 1. FAA (US) — seed-only read\n  // faaSourceCovered = the seed cache hit AND returned a valid alerts array.\n  // A miss/parse-error means we have no telemetry for any FAA airport this\n  // tick — we MUST NOT publish synthetic \"normal\" rows for them. See #3707.\n  // PERF: the three inputs below are independent (different Redis keys / an\n  // independent fetcher) and merge only afterwards — start them concurrently\n  // instead of paying three serial round-trips per request.\n  const faaRead = (async (): Promise<{ faaAlerts: AirportDelayAlert[]; faaSourceCovered: boolean; available: boolean }> => {\n    let faaAlerts: AirportDelayAlert[] = [];","sourceCodeStart":26,"sourceCodeEnd":62,"githubUrl":"https://github.com/koala73/worldmonitor/blob/e586b8b4b80f595aa7ece295eec10d76f2921240/server/worldmonitor/aviation/v1/list-airport-delays.ts#L26-L62","documentation":"listAirportDelays rejects any query parameter repeated on the request URL. The handler iterates URL searchParams with a seenParams Set and throws ApiError 400 as soon as a key appears a second time, since repeated params are ambiguous for a seed-only listing endpoint.","triggerScenarios":"Calling GET .../list-airport-delays with the same query key twice, e.g. ?rpc=list-airport-delays&rpc=list-airport-delays or ?page_size=0&page_size=0 (including arrays serialized as key=a&key=b).","commonSituations":"Client code building query strings from objects/arrays where a value is a list; URLSearchParams.append called twice; framework serializers that emit repeated keys for array values; proxies rewriting and re-appending params.","solutions":["Remove the duplicated query parameter so each key appears at most once in the URL","Fix the client's query-string builder to deduplicate keys instead of appending per array item","Log ctx.request.url on failure to identify which key is repeated and which code path adds it","Add a client-side test asserting the generated query string has unique keys"],"exampleFix":"// before\nconst params = new URLSearchParams();\nregions.forEach(r => params.append('rpc', 'list-airport-delays'));\n// after\nconst params = new URLSearchParams({ rpc: 'list-airport-delays' });","handlingStrategy":"validation","validationCode":"const keys = [...new URL(url).searchParams.keys()];\nif (new Set(keys).size !== keys.length) throw new Error('duplicate query param');","typeGuard":"const hasUniqueParams = (url) => { const ks = [...new URL(url).searchParams.keys()]; return new Set(ks).size === ks.length; };","tryCatchPattern":"try { await listAirportDelays(ctx, req); } catch (e) { if (e instanceof ApiError && e.status === 400 && /Duplicate .* parameter/.test(e.message)) { rebuildQueryUnique(); } else throw e; }","preventionTips":["Build query strings from plain objects, not repeated append calls","Never serialize array values as repeated query keys for this endpoint","Add a unit test asserting unique query keys","Deduplicate params in any fetch wrapper before sending"],"tags":["http","validation","query-parameters"],"backgroundTag":"duplicate-query-parameter","analyzedSha":"e586b8b4b80f595aa7ece295eec10d76f2921240","analyzedAt":"2026-09-22T01:50:49.965Z","contentChangedAt":"2026-09-22T01:50:49.965Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}