{"record":{"id":"2a4a595f3aac1511","repo":"siyuan-note/siyuan","slug":"invalid-plugin-sse-status","errorCode":null,"errorMessage":"invalid plugin SSE status","messagePattern":"invalid plugin SSE status","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/apicontract/plugin_service_protocol.go","lineNumber":162,"sourceCode":"\tif !known {\n\t\treturn fmt.Errorf(\"unknown plugin service mode: %s\", mode)\n\t}\n\tswitch mode {\n\tcase PluginServiceAdmission:\n\t\tif status != 400 && status != 404 && status != 500 && status != 503 {\n\t\t\treturn fmt.Errorf(\"undeclared plugin admission status\")\n\t\t}\n\tcase PluginServiceRedirect:\n\t\tif status != 201 && (status < 300 || status > 308) {\n\t\t\treturn fmt.Errorf(\"invalid plugin redirect status\")\n\t\t}\n\tcase PluginServiceWebSocket:\n\t\tif status != 101 && status != 400 && status != 500 {\n\t\t\treturn fmt.Errorf(\"invalid plugin WebSocket status\")\n\t\t}\n\tcase PluginServiceSSE:\n\t\tif status != 200 && status != 500 {\n\t\t\treturn fmt.Errorf(\"invalid plugin SSE status\")\n\t\t}\n\t}\n\treturn nil\n}\n\nfunc (b *Bundle) validatePluginServiceHTTPResponse(endpoint EndpointSchema, status int, contentType string, payload []byte) error {\n\tif status < 100 || status > 999 {\n\t\treturn fmt.Errorf(\"invalid plugin service HTTP status\")\n\t}\n\tif endpoint.Method == \"HEAD\" || status < 200 || status == 204 || status == 304 {\n\t\tif len(payload) > 0 {\n\t\t\treturn fmt.Errorf(\"plugin service response forbids a body\")\n\t\t}\n\t\treturn nil\n\t}\n\t// 原始文件、代理及插件自选媒体允许任意字节，具体分支由 ValidatePluginServiceResponse 校验。\n\treturn nil\n}","sourceCodeStart":144,"sourceCodeEnd":180,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/apicontract/plugin_service_protocol.go#L144-L180","documentation":"SSE-mode plugin service responses may only use status 200 (stream started) or 500 (stream failed to start); validatePluginServiceStatus rejects anything else. This guarantees the event-stream contract only ever advertises a successful stream or an explicit server failure.","triggerScenarios":"Calling StreamPluginService(PluginServiceSSE, status, serve) or ValidatePluginServiceResponse with sse mode and a status other than 200 or 500 (e.g. 204, 404, or 403).","commonSituations":"Trying to signal 'no events' with 204; using 401/403 to gate an SSE stream; copying a redirect status into an SSE response.","solutions":["Return 200 when the event stream starts, 500 when it cannot","Handle auth/rejection logic before entering the SSE variant, or use 500 for unrecoverable stream-start failures","Use a different variant (e.g. admission or JSON) for gating responses"],"exampleFix":"// before\nStreamPluginService(PluginServiceSSE, http.StatusNoContent, serve)\n// after\nStreamPluginService(PluginServiceSSE, http.StatusOK, serve)","handlingStrategy":"validation","validationCode":"func validSSEStatus(status int) bool {\n\treturn status == http.StatusOK || status == http.StatusInternalServerError\n}","typeGuard":null,"tryCatchPattern":"defer func() {\n\tif rec := recover(); rec != nil {\n\t\tlog.Printf(\"invalid SSE status: %v\", rec)\n\t}\n}() // around StreamPluginService(PluginServiceSSE, ...)","preventionTips":["Only 200 or 500 for SSE responses","Perform gating/auth before switching to SSE mode","Cover the stream-failure (500) path in tests"],"tags":["go","api-contract","plugin-service","sse","http-status"],"backgroundTag":"unexpected-http-status","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}