https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=40906 --- Comment #29 from Martin Renvoize (ashimema) <martin.renvoize@openfifth.co.uk> --- Created attachment 206867 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206867&action=edit Bug 40906: (QA follow-up) Handle Mana failures gracefully and fix permissions Koha::SharedContent::process_request never dies on a Mana failure (timeout, non-2xx response, malformed JSON) - it returns {code, msg} with data undef. Both the new REST endpoint and the report-details script ignored this and rendered the (empty) result as if it were a normal success, so a Mana outage surfaced as an opaque 500 from failed schema validation, or as a normal-looking, importable report with no content. Both now check the result code and render a clear error (503 from the endpoint, an inline message on the details page) instead. Also: * Wrap the whole controller body in try/catch, not just the render call, so the pattern matches every other Koha::REST::V1 controller. * Use the shared add_pagination_headers helper instead of a hand-rolled, lowercase x-total-count header, so pagination Link/X-Total-Count headers match the rest of the API. * Restrict both endpoints to the reports:create_reports permission (the permission already used for sharing reports to Mana), replacing the under-scoped 'catalogue' permission on the REST endpoint and the complete absence of a permission check on the CGI script. * Drop the unused 'match' swagger parameter (never read by the controller). * mana.js: add a .fail() handler to the report-details AJAX call (it had none, so any error left a permanently blank overlay); null-guard data.notes before .length/.slice (the API schema declares it nullable, and a report with no notes would otherwise throw inside DataTables' createdRow and break the whole results table); move the .return-div click and hidden.bs.modal listeners out of the per-row click handler so they're bound once instead of accumulating a duplicate on every row click; add an ajax error callback to the results DataTable so a Mana failure is shown to the user instead of DataTables' generic error. Verified against a local koha-mana test instance: stopping the Mana container now returns a 503 with a clear error body instead of a 500, and a report with no notes (confirmed null in Mana's own database) no longer breaks the results table. Signed-off-by: Martin Renvoize <martin.renvoize@openfifth.co.uk> -- You are receiving this mail because: You are watching all bug changes.