fix(ses): reject malformed startDate/endDate in list_suppressed_destinations (#5461)

startDate/endDate were passed through new Date(...) with no validity
check, so a malformed non-empty string became an Invalid Date and was
still forwarded to AWS, surfacing as a generic 500. The contract now
rejects unparseable date strings with a clear 400.
This commit is contained in:
Waleed
2026-07-06 19:03:11 -07:00
committed by GitHub
parent 11be2a3167
commit 017e8ca68f
@@ -17,8 +17,18 @@ const ListSuppressedDestinationsSchema = z.object({
accessKeyId: z.string().min(1, 'AWS access key ID is required'),
secretAccessKey: z.string().min(1, 'AWS secret access key is required'),
reasons: z.string().nullish(),
startDate: z.string().nullish(),
endDate: z.string().nullish(),
startDate: z
.string()
.nullish()
.refine((v) => !v || !Number.isNaN(new Date(v).getTime()), {
message: 'startDate must be a valid date string',
}),
endDate: z
.string()
.nullish()
.refine((v) => !v || !Number.isNaN(new Date(v).getTime()), {
message: 'endDate must be a valid date string',
}),
pageSize: z.number().int().min(1).max(1000).nullish(),
nextToken: z.string().nullish(),
})